Skip to content

Shellcoding

Syscalls

Arch Instruction Number Args Return
x86-64 syscall rax rdi, rsi, rdx, r10, r8, r9 rax
x86 (32-bit) int 0x80 eax ebx, ecx, edx, esi, edi, ebp eax
ARM64 svc #0 x8 x0-x5 x0
ARM32 svc 0 r7 r0-r5 r0
  • Assemble .asm: gcc -nostdlib -static shellcode.s -o shellcode
  • Extract shellcode: objcopy --dump-section .text=shellcode-raw shellcode
  • Analyze shellcode: objdump -M intel -d shellcode

  • Shellcode Loader for debugging

  • Run: cat shellcode-raw | ./tester
page = mmap(0x1337000, 0x100, PROT_READ|PROT_WRITE|PROT_EXEC, MAP_PRIVATE|MAP_ANON, 0,0);
read(0, page, 0x1000);
((void(*)())page)();

Filter Bypass

  • Write bytes and patch during execution to achieve syscall
# translates to code 0f 05 => syscall
inc BYTE PTR [rip+6]
inc BYTE PTR [rip+1]
.byte 0x0e
.byte 0x04
  • Long NOP sleds
.rept 0x1000
nop
.endr

Resources

Syscall.sh