Data update

This commit is contained in:
Ingy döt Net 2024-10-16 18:07:41 -07:00
parent 81fd053722
commit 52a6ef48dd
10248 changed files with 63654 additions and 6775 deletions

View file

@ -1,3 +1,49 @@
;;Update 2024: the previous code is likely not going to work on modern OS, because there is a need to allocate memory with the correct permissions (readable, writable, and executable). We will update with another machine code, equivalent to the function 'ash' in common lisp
89 f8 mov %edi,%eax
89 f1 mov %esi,%ecx
d3 e8 shr %cl,%eax
c3 ret
;;sbcl
(require :sb-posix)
(defconstant +PROT-READ+ 1)
(defconstant +PROT-WRITE+ 2)
(defconstant +PROT-EXEC+ 4)
(defconstant +MAP-PRIVATE+ 2)
(defconstant +MAP-ANONYMOUS+ #x20)
(defun allocate-executable-memory (size)
(sb-posix:mmap nil
size
(logior +PROT-READ+ +PROT-WRITE+ +PROT-EXEC+)
(logior +MAP-PRIVATE+ +MAP-ANONYMOUS+)
-1
0))
;; Example usage:
(defparameter *shellcode* #(#x89 #xf8 #x89 #xf1 #xd3 #xe8 #xc3))
(defparameter *mem-ptr* (allocate-executable-memory (length *shellcode*)))
;; Copy shellcode to allocated memory
(loop for byte across *shellcode*
for i from 0
do (setf (sb-sys:sap-ref-8 *mem-ptr* i) byte))
;; Create a callable function pointer
(defparameter *func* (sb-alien:sap-alien *mem-ptr* (sb-alien:function sb-alien:unsigned-int sb-alien:unsigned-int sb-alien:unsigned-int)))
;; Call the function
(sb-alien:alien-funcall *func* 18 1)
;; 9
;;(ash 18 -1) => 9
;; Don't forget to free the memory when done
;;(sb-posix:munmap *mem-ptr* (length *shellcode*))
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
;;old contribution starts here
;;Note that by using the 'CFFI' library, one can apply this procedure portably in any lisp implementation;
;; in this code however I chose to demonstrate only the implementation-dependent programs.