There are many basic shellcodes that can be emulated from the beginning from the end providing IOC like where is connecting and so on. But what can we do when the emulation get stuck at some point?
The console has many tools to interact with the emulator like it was a debugger but the shellcode really is not being executed so is safer than a debugger.
target/release/scemu -f ~/Downloads/shellcodes_matched/drv_shellcode.bin -vv
In some shellcodes the emulator emulates millions of instructions without problem, but in this case at instruction number 176 there is a crash, the [esp + 30h] contain an unexpected 0xffffffff.
There are two ways to trace the memory, tracing all memory operations with -m or inspecting specific place with -i which allow to use registers to express the memory location:
target/release/scemu -f ~/Downloads/shellcodes_matched/drv_shellcode.bin -i 'dword ptr [esp + 0x30]'
Now we know that in position 174 the value 0xffffffff is set.
But we have more control if we set the console at first instruction with -c 1 and set a memory breakpoint on write.
This "dec" instruction changes the zero for the 0xffffffff, and the instruction 90 is what actually is changing the stack value.
Lets trace the eax register to see if its a kind of counter or what is doing.
Read more
- Hacker
- Pentest Tools Find Subdomains
- Physical Pentest Tools
- Hack App
- Hacking App
- Install Pentest Tools Ubuntu
- How To Make Hacking Tools
- Hack Apps
- Hacking Tools Usb
- Hacker Tools Mac
- Hacking Tools For Kali Linux
- Hacking Tools Mac
- Hacker Tools 2020
- Best Pentesting Tools 2018
- Pentest Tools Find Subdomains
- How To Make Hacking Tools
- Hacking Tools Download
- Pentest Tools Website Vulnerability
- Hack Tools Pc
- Pentest Box Tools Download
- Hacking Tools For Windows Free Download
- What Is Hacking Tools
- Hack Tool Apk
- Pentest Tools Open Source
- Blackhat Hacker Tools
- Pentest Tools Download
- Beginner Hacker Tools
- Hacker Hardware Tools
- Growth Hacker Tools
- New Hack Tools
- Hacking Tools Windows
- Hack Tools For Mac
- Hacker Tools Linux
- Game Hacking
- Nsa Hack Tools
- Hack Tools For Windows
- Hack Rom Tools
- Hacking Tools Pc
- Hacking Tools Online
- Github Hacking Tools
- Pentest Tools Port Scanner
- Hacker Tools Windows
- Pentest Tools Tcp Port Scanner
- Hack Tools 2019
- Hack Tools Online
- Hacking Tools For Windows Free Download
- Github Hacking Tools
- Hack Rom Tools
- Pentest Tools Open Source
- Hacking Tools Hardware
- Blackhat Hacker Tools
- Hacker
- Pentest Tools Open Source
- Hack Rom Tools
- Hack App
No comments:
Post a Comment