There are many basic shellcodes that can be emulated from the beginning from the end providing IOC like where is connecting and so on. But what can we do when the emulation get stuck at some point?
The console has many tools to interact with the emulator like it was a debugger but the shellcode really is not being executed so is safer than a debugger.
target/release/scemu -f ~/Downloads/shellcodes_matched/drv_shellcode.bin -vv
In some shellcodes the emulator emulates millions of instructions without problem, but in this case at instruction number 176 there is a crash, the [esp + 30h] contain an unexpected 0xffffffff.
There are two ways to trace the memory, tracing all memory operations with -m or inspecting specific place with -i which allow to use registers to express the memory location:
target/release/scemu -f ~/Downloads/shellcodes_matched/drv_shellcode.bin -i 'dword ptr [esp + 0x30]'
Now we know that in position 174 the value 0xffffffff is set.
But we have more control if we set the console at first instruction with -c 1 and set a memory breakpoint on write.
This "dec" instruction changes the zero for the 0xffffffff, and the instruction 90 is what actually is changing the stack value.
Lets trace the eax register to see if its a kind of counter or what is doing.
More info
- What Are Hacking Tools
- Hackers Toolbox
- Physical Pentest Tools
- Hacker Tools
- Hacking Tools Hardware
- Hacking Tools Name
- Pentest Tools Free
- Hack Website Online Tool
- Hacker Tools 2019
- Hack Tools Online
- Black Hat Hacker Tools
- Physical Pentest Tools
- Hack Rom Tools
- Hacker Tools Github
- Pentest Box Tools Download
- Hacking Tools Windows
- Hacking Tools Kit
- Pentest Tools List
- Underground Hacker Sites
- Hacker Hardware Tools
- Hack Apps
- Hacking Tools Free Download
- Hacking Tools 2020
- Hack Tools For Pc
- Hacker Tools For Mac
- Tools For Hacker
- Hackrf Tools
- Underground Hacker Sites
- Tools For Hacker
- Hacking Tools For Beginners
- How To Make Hacking Tools
- How To Make Hacking Tools
- Pentest Tools Android
- Tools For Hacker
- Pentest Tools Apk
- Github Hacking Tools
- Hack Tools
- Hacking Tools
- Pentest Tools For Mac
- Hacking Tools Online
- Hacker Tools Linux
- Hack Tools Download
- Pentest Recon Tools
- Hacker Tools
- Hack Tools For Mac
- Hacker Security Tools
- Pentest Tools Website
- Pentest Tools Find Subdomains
- Hacker Tool Kit
- Hacker
- Hacking Tools Online
- What Are Hacking Tools
- Hacking Tools For Games
- Best Hacking Tools 2019
- Hacking Tools For Kali Linux
- Pentest Tools Subdomain
- Hacker Tools Linux
- Hacker Tools Hardware
- Hacker Tools
- Hack Tools Mac
- Hacking Tools For Mac
- Hack Tool Apk No Root
- Pentest Tools Website
- Hacker Tools Windows
- Pentest Tools Apk
- Free Pentest Tools For Windows
- Hackrf Tools
No comments:
Post a Comment