Shellcoding¶
Syscalls¶
| Arch | Instruction | Number | Args | Return |
|---|---|---|---|---|
| x86-64 | syscall | rax | rdi, rsi, rdx, r10, r8, r9 | rax |
| x86 (32-bit) | int 0x80 | eax | ebx, ecx, edx, esi, edi, ebp | eax |
| ARM64 | svc #0 | x8 | x0-x5 | x0 |
| ARM32 | svc 0 | r7 | r0-r5 | r0 |
- Assemble .asm:
gcc -nostdlib -static shellcode.s -o shellcode - Extract shellcode:
objcopy --dump-section .text=shellcode-raw shellcode -
Analyze shellcode:
objdump -M intel -d shellcode -
Shellcode Loader for debugging
- Run:
cat shellcode-raw | ./tester
page = mmap(0x1337000, 0x100, PROT_READ|PROT_WRITE|PROT_EXEC, MAP_PRIVATE|MAP_ANON, 0,0);
read(0, page, 0x1000);
((void(*)())page)();
Filter Bypass¶
- Write bytes and patch during execution to achieve syscall
# translates to code 0f 05 => syscall
inc BYTE PTR [rip+6]
inc BYTE PTR [rip+1]
.byte 0x0e
.byte 0x04
- Long NOP sleds