Doge Ransom — IBAN Buffer Overflow with Control Byte Injection

The IBAN input field copies 28 bytes into a buffer with room for 49. Appending the control byte 0x03 after the valid IBAN data overflows into an adjacent flag variable and unlocks the ransomware payment path.

January 1, 2024 · 2 min · giordii