4 ms·
> So, having never heard of shellcode before, I assumed it was just another way of saying shell script. But I scroll to the bottom and see (*(void(*)()) sh
by mdadm 10y ago
> So, having never heard of shellcode before, I assumed it was just another way of saying shell script. But I scroll to the bottom and see
(*(void(*)()) shellcode)();
> and suddenly this looks way more interesting. Is it really possible to literally just execute random bytes stored in a string like that?
Well it's just a sequence of bytes somewhere in-memory, no? If the C compiler allows the cast, then it'd compile fine, and the CPU wouldn't know the difference; it'd just execute whatever instructions the sequence of bytes listed.
- Buge 10y agoIt actually probably won't work. Because DEP aka W^X will mark the section of memory containing the string as non-executable, so it will segfault when the instruction pointer hits that address. You can disable that security feature though with a compiler option.
- vardump 10y ago> Because DEP aka W^X... DEP is just how Microsoft calls executable space protection. That's not industry standard terminology for it.
- cyphar 10y ago> Because DEP aka W^X will mark the section of memory containing the string as non-executable, so it will segfault when the instruction pointer hits that address. You can disable that security feature though with a compiler option. DEP is a kernel-level security feature no? Since the kernel is what sets up the .text and .data sections.
- vardump 10y agoCPU support is required. https://en.wikipedia.org/wiki/NX_bit https://en.wikipedia.org/wiki/NX_bit
- symtos 10y agonot necessarily. there are software emulation -- examples would be W^X on OpenBSD[1] and Grsecurity/PaX on linux[2]. Ubuntu[3] and RedHat[4] also has (partial) NX-emulation thanks to ExecShield. As for OpenBSD and Linux without grsec/pax, one can bypass NX (whether the CPU has the NX-bit or not) by marking the region with the shellcode as executable, eg: mprotect(shellcode & -pagesize, len, PROT_EXEC); ((void()()) shellcode)(); in an exploit this could be accomplished by ROPing 1: http://marc.info/?l=openbsd-misc&m=105056000801065 http://marc.info/?l=openbsd-misc&m=105056000801065 2: https://pax.grsecurity.net/docs/mprotect.txt https://pax.grsecurity.net/docs/mprotect.txt 3: https://outflux.net/blog/archives/2009/05/14/nx-emulation-in-ubuntu/ https://outflux.net/blog/archives/2009/05/14/nx-emulation-in... 4: https://en.wikipedia.org/wiki/Exec_Shield https://en.wikipedia.org/wiki/Exec_Shield
- cyphar 10y agoRight, but it doesn't change my statement that W^X is enforced by the kernel (meaning the kernel sets all of the program pages to have the right bitset). Not to mention that it was (is?) emulated in software for some kernels.
- Buge 10y agoI think so. But it's enabled by default in Linux and gcc. That was my point, that by default the code won't work.