I’m happy to announce that the unicode code alignment feature mentioned in another post made it into the main corelan mona repository. As usual, mona can be downloaded from the official mona redmine. Usage:
Generates a venetian shellcode alignment stub which can be placed directly before unicode shellcode. Arguments: -a <address> : Specify the address where the alignment code will start/be placed Optional arguments: -l : Prepend alignment with a null byte compensating nop equivalent (Use this if the last instruction before the alignment routine 'leaks' a null byte) -b <reg> : Set the bufferregister, defaults to eax -t <seconds> : Time in seconds to run heuristics (defaults to 15) -ebp <value> : Overrule the use of the 'current' value of ebp, ebp/address will be used to calculate offset to shellcode
Instead of “!mona unicodealign” you can use the short version “!mona ua”. Here’s a short video on how the new feature can be used:
Although I used the -a argument, if your EIP is already at the correct position (as in the video) you can simply run “!mona ua” without any arguments.