Data update
This commit is contained in:
parent
81fd053722
commit
52a6ef48dd
10248 changed files with 63654 additions and 6775 deletions
|
|
@ -1,3 +1,49 @@
|
|||
;;Update 2024: the previous code is likely not going to work on modern OS, because there is a need to allocate memory with the correct permissions (readable, writable, and executable). We will update with another machine code, equivalent to the function 'ash' in common lisp
|
||||
|
||||
89 f8 mov %edi,%eax
|
||||
89 f1 mov %esi,%ecx
|
||||
d3 e8 shr %cl,%eax
|
||||
c3 ret
|
||||
|
||||
;;sbcl
|
||||
(require :sb-posix)
|
||||
|
||||
(defconstant +PROT-READ+ 1)
|
||||
(defconstant +PROT-WRITE+ 2)
|
||||
(defconstant +PROT-EXEC+ 4)
|
||||
(defconstant +MAP-PRIVATE+ 2)
|
||||
(defconstant +MAP-ANONYMOUS+ #x20)
|
||||
|
||||
(defun allocate-executable-memory (size)
|
||||
(sb-posix:mmap nil
|
||||
size
|
||||
(logior +PROT-READ+ +PROT-WRITE+ +PROT-EXEC+)
|
||||
(logior +MAP-PRIVATE+ +MAP-ANONYMOUS+)
|
||||
-1
|
||||
0))
|
||||
|
||||
;; Example usage:
|
||||
(defparameter *shellcode* #(#x89 #xf8 #x89 #xf1 #xd3 #xe8 #xc3))
|
||||
(defparameter *mem-ptr* (allocate-executable-memory (length *shellcode*)))
|
||||
|
||||
;; Copy shellcode to allocated memory
|
||||
(loop for byte across *shellcode*
|
||||
for i from 0
|
||||
do (setf (sb-sys:sap-ref-8 *mem-ptr* i) byte))
|
||||
|
||||
;; Create a callable function pointer
|
||||
(defparameter *func* (sb-alien:sap-alien *mem-ptr* (sb-alien:function sb-alien:unsigned-int sb-alien:unsigned-int sb-alien:unsigned-int)))
|
||||
|
||||
;; Call the function
|
||||
(sb-alien:alien-funcall *func* 18 1)
|
||||
;; 9
|
||||
;;(ash 18 -1) => 9
|
||||
|
||||
;; Don't forget to free the memory when done
|
||||
;;(sb-posix:munmap *mem-ptr* (length *shellcode*))
|
||||
|
||||
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
|
||||
;;old contribution starts here
|
||||
;;Note that by using the 'CFFI' library, one can apply this procedure portably in any lisp implementation;
|
||||
;; in this code however I chose to demonstrate only the implementation-dependent programs.
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue