Saturday, January 27, 2024

Emulating Shellcodes - Chapter 1

 There are many basic shellcodes that can be emulated from the beginning from the end providing IOC like where is connecting and so on. But what can we do when the emulation get stuck at some point?

The console has many tools to interact with the emulator like it was a debugger but the shellcode really is not being executed so is safer than a debugger.

target/release/scemu -f ~/Downloads/shellcodes_matched/drv_shellcode.bin -vv 


In some shellcodes the emulator emulates millions of instructions without problem, but in this case at instruction number 176 there is a crash, the [esp + 30h] contain an unexpected 0xffffffff.

There are two ways to trace the memory, tracing all memory operations with -m or inspecting specific place with -i which allow to use registers to express the memory location:

target/release/scemu -f ~/Downloads/shellcodes_matched/drv_shellcode.bin  -i 'dword ptr [esp + 0x30]'


Now we know that in position 174 the value 0xffffffff is set.

But we have more control if we set the console at first instruction with -c 1 and set a memory breakpoint on write.




This "dec" instruction changes the zero for the 0xffffffff, and the instruction 90 is what actually is changing the stack value.

Lets trace the eax register to see if its a kind of counter or what is doing.


target/release/scemu -f ~/Downloads/shellcodes_matched/drv_shellcode.bin  --reg eax 


Eax is not a counter, is getting hardcoded values which is probably an API name:


In this case this shellcode depend on previous states and crash also in the debugger because of  register values. this is just an example of how to operate in cases where is not fully emulated.

In next chapter will see how to unpack and dump to disk using the emulator.


Read more

  1. Hacker
  2. Pentest Tools Find Subdomains
  3. Physical Pentest Tools
  4. Hack App
  5. Hacking App
  6. Install Pentest Tools Ubuntu
  7. How To Make Hacking Tools
  8. Hack Apps
  9. Hacking Tools Usb
  10. Hacker Tools Mac
  11. Hacking Tools For Kali Linux
  12. Hacking Tools Mac
  13. Hacker Tools 2020
  14. Best Pentesting Tools 2018
  15. Pentest Tools Find Subdomains
  16. How To Make Hacking Tools
  17. Hacking Tools Download
  18. Pentest Tools Website Vulnerability
  19. Hack Tools Pc
  20. Pentest Box Tools Download
  21. Hacking Tools For Windows Free Download
  22. What Is Hacking Tools
  23. Hack Tool Apk
  24. Pentest Tools Open Source
  25. Blackhat Hacker Tools
  26. Pentest Tools Download
  27. Beginner Hacker Tools
  28. Hacker Hardware Tools
  29. Growth Hacker Tools
  30. New Hack Tools
  31. Hacking Tools Windows
  32. Hack Tools For Mac
  33. Hacker Tools Linux
  34. Game Hacking
  35. Nsa Hack Tools
  36. Hack Tools For Windows
  37. Hack Rom Tools
  38. Hacking Tools Pc
  39. Hacking Tools Online
  40. Github Hacking Tools
  41. Pentest Tools Port Scanner
  42. Hacker Tools Windows
  43. Pentest Tools Tcp Port Scanner
  44. Hack Tools 2019
  45. Hack Tools Online
  46. Hacking Tools For Windows Free Download
  47. Github Hacking Tools
  48. Hack Rom Tools
  49. Pentest Tools Open Source
  50. Hacking Tools Hardware
  51. Blackhat Hacker Tools
  52. Hacker
  53. Pentest Tools Open Source
  54. Hack Rom Tools
  55. Hack App

No comments:

Post a Comment