There are many basic shellcodes that can be emulated from the beginning from the end providing IOC like where is connecting and so on. But what can we do when the emulation get stuck at some point?
The console has many tools to interact with the emulator like it was a debugger but the shellcode really is not being executed so is safer than a debugger.
target/release/scemu -f ~/Downloads/shellcodes_matched/drv_shellcode.bin -vv
In some shellcodes the emulator emulates millions of instructions without problem, but in this case at instruction number 176 there is a crash, the [esp + 30h] contain an unexpected 0xffffffff.
There are two ways to trace the memory, tracing all memory operations with -m or inspecting specific place with -i which allow to use registers to express the memory location:
target/release/scemu -f ~/Downloads/shellcodes_matched/drv_shellcode.bin -i 'dword ptr [esp + 0x30]'
Now we know that in position 174 the value 0xffffffff is set.
But we have more control if we set the console at first instruction with -c 1 and set a memory breakpoint on write.
This "dec" instruction changes the zero for the 0xffffffff, and the instruction 90 is what actually is changing the stack value.
Lets trace the eax register to see if its a kind of counter or what is doing.
Related links
- Pentest Tools Review
- Install Pentest Tools Ubuntu
- Hacker Tools Linux
- Pentest Tools Port Scanner
- Pentest Recon Tools
- Growth Hacker Tools
- Nsa Hack Tools Download
- Pentest Tools Url Fuzzer
- Hacking Tools For Kali Linux
- Hacker Tools Mac
- Hacking Tools For Pc
- What Is Hacking Tools
- Hacking Tools Name
- Wifi Hacker Tools For Windows
- Hacking Tools Windows
- Hacker Tools 2019
- Underground Hacker Sites
- Best Hacking Tools 2020
- Hack Website Online Tool
- Best Hacking Tools 2020
- World No 1 Hacker Software
- Hack Tools For Windows
- Hacking Tools For Windows
- How To Hack
- Pentest Tools Framework
- Beginner Hacker Tools
- Easy Hack Tools
- Hacking Tools For Games
- Pentest Recon Tools
- Hacker Tool Kit
- Hacker Hardware Tools
- Pentest Tools Url Fuzzer
- Best Hacking Tools 2019
- Pentest Tools Online
- Hacker
- Tools Used For Hacking
- Bluetooth Hacking Tools Kali
- Best Hacking Tools 2019
- Pentest Tools For Windows
- Hack Tools
- Ethical Hacker Tools
- Underground Hacker Sites
- New Hacker Tools
- Pentest Tools For Ubuntu
- Pentest Tools For Mac
- Hacker Tools For Ios
- Hacker
- Hacker Tools List
- What Is Hacking Tools
- Pentest Reporting Tools
- How To Install Pentest Tools In Ubuntu
- Hacking Tools Hardware
- Free Pentest Tools For Windows
- Hacking Tools For Pc
No comments:
Post a Comment