Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

shellcc

SHELLCC is a build environment for making shellcode in C using GCC and other binary tool. It is meant to enable people with limited knowledge of assembly to write quality shellcode as well as bring code maintainability by using a high level language (specifically C).

Generally speaking shellcode does not require complex logic i.e. printfs, heavy abstraction or threading. These functions are left to the implants. Shellcode is expected to setup the environment and load the next stage of the attack. This step consists of doing cleanups and making a relatively small number of system call. For example, creating a reverse shell or downloading and executing the next stage implant. However, these functions can still be quite complex to write in assembly and it is hard to maintain them over time. Basically, all the reasons why we use compilers.

The main reason is, of course, I was not very good at writting ARM assembly by hand. So, I needed some help from a compiler.

Example

It is easy to see what this code, it calls out to an IP:PORT address and sends out a message. There is excessive error checking which would be really hard to do by hand. This code demonstrates how easy it is to build up the logic and let the compiler use its optimization magic in order to produce the best possible code.

intmain() {
intsockfd;
structsockaddr_inserv_addr;
sockfd=scc_socket(AF_INET, SOCK_STREAM, 0);
if (sockfd<0) {
scc_exit(43);
}
bzero((structsockaddr*)&serv_addr,sizeof(serv_addr));
serv_addr.sin_family=AF_INET;
serv_addr.sin_addr.s_addr=SERVER_IP;
serv_addr.sin_port=htons(SERVER_PORT);
if(scc_connect(sockfd,(structsockaddr*)&serv_addr,sizeof(serv_addr)) <0) {
scc_exit(44);
}
if(scc_write(sockfd, MESSAGE, MESSAGE_LEN) <= 0) {
scc_exit(45);
}
scc_close(sockfd);
// end the processscc_exit(42);
}

The aboce C code produces a nice concise ARM64 ASM. It is likely that a dedicated person could produce an even more concise version, but that would take time better spent on finding vulnerabilities.

 0000000100007ecc	stp	x29, x30,[sp, #-16]! 0000000100007ed0	mov x29,sp 0000000100007ed4	subsp,sp, #16 0000000100007ed8	movz	x2, #0 0000000100007edc	orr	w8, wzr, #0x2 0000000100007ee0	orr	w0, wzr, #0x2 0000000100007ee4	orr	w1, wzr, #0x1 0000000100007ee8	movz	w16, #0x61 0000000100007eec	svc	#0x80 0000000100007ef0	neg x1, x0 0000000100007ef4	csel	x0, x0, x1, lo 0000000100007ef8	tbz	w0, #31,0x100007f04 0000000100007efc	movz	w0, #0x2b 0000000100007f00	bl	_scc_exit 0000000100007f04	stp xzr, xzr,[sp] 0000000100007f08	strb	w8,[sp, #1] 0000000100007f0c	movz	w8, #0x501,lsl #16 0000000100007f10	movk	w8, #0xa8c0 0000000100007f14	str	w8,[sp, #4] 0000000100007f18	movz	w9, #0xf27 0000000100007f1c	sxtw	x8, w0 0000000100007f20	strh	w9,[sp, #2] 0000000100007f24	mov x1,sp 0000000100007f28	orr	w2, wzr, #0x10 0000000100007f2c	movz	w16, #0x62 0000000100007f30	mov x0, x8 0000000100007f34	svc	#0x80 0000000100007f38	neg x1, x0 0000000100007f3c	csel	x0, x0, x1, lo 0000000100007f40	tbz	w0, #31,0x100007f4c 0000000100007f44	movz	w0, #0x2c 0000000100007f48	bl	_scc_exit 0000000100007f4c	adr	x1, #96 ; literal pool for: "Hello Dude\n" 0000000100007f50	nop 0000000100007f54	orr	w2, wzr, #0xc 0000000100007f58	orr	w16, wzr, #0x4 0000000100007f5c	mov x0, x8 0000000100007f60	svc	#0x80 0000000100007f64	neg x1, x0 0000000100007f68	csel	x0, x0, x1, lo 0000000100007f6c	cmp w0, #0 0000000100007f70	b.gt	0x100007f7c 0000000100007f74	movz	w0, #0x2d 0000000100007f78	bl	_scc_exit 0000000100007f7c	movz	w0, #0x2a 0000000100007f80	bl	_scc_exit _scc_exit: 0000000100007f84	stp	x29, x30,[sp, #-16]! 0000000100007f88	mov x29,sp 0000000100007f8c	sxtw	x0, w0 0000000100007f90	orr	w1, wzr, #0x1 0000000100007f94	bl	_scc_syscall1 _scc_syscall1: 0000000100007f98	mov x16, x1 0000000100007f9c	svc	#0x80 0000000100007fa0	neg x1, x0 0000000100007fa4	csel	x0, x0, x1, lo 0000000100007fa8	ret

[1] http://shell-storm.org/shellcode/

About

Building optimized shellcode using GCC. Suited for learning assembly and playing with the ABI

Resources

Stars

78 stars

Watchers

7 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

shellcc

SHELLCC is a build environment for making shellcode in C using GCC and other binary tool. It is meant to enable people with limited knowledge of assembly to write quality shellcode as well as bring code maintainability by using a high level language (specifically C).

Generally speaking shellcode does not require complex logic i.e. printfs, heavy abstraction or threading. These functions are left to the implants. Shellcode is expected to setup the environment and load the next stage of the attack. This step consists of doing cleanups and making a relatively small number of system call. For example, creating a reverse shell or downloading and executing the next stage implant. However, these functions can still be quite complex to write in assembly and it is hard to maintain them over time. Basically, all the reasons why we use compilers.

The main reason is, of course, I was not very good at writting ARM assembly by hand. So, I needed some help from a compiler.

Example

It is easy to see what this code, it calls out to an IP:PORT address and sends out a message. There is excessive error checking which would be really hard to do by hand. This code demonstrates how easy it is to build up the logic and let the compiler use its optimization magic in order to produce the best possible code.

intmain() {
intsockfd;
structsockaddr_inserv_addr;
sockfd=scc_socket(AF_INET, SOCK_STREAM, 0);
if (sockfd<0) {
scc_exit(43);
}
bzero((structsockaddr*)&serv_addr,sizeof(serv_addr));
serv_addr.sin_family=AF_INET;
serv_addr.sin_addr.s_addr=SERVER_IP;
serv_addr.sin_port=htons(SERVER_PORT);
if(scc_connect(sockfd,(structsockaddr*)&serv_addr,sizeof(serv_addr)) <0) {
scc_exit(44);
}
if(scc_write(sockfd, MESSAGE, MESSAGE_LEN) <= 0) {
scc_exit(45);
}
scc_close(sockfd);
// end the processscc_exit(42);
}

The aboce C code produces a nice concise ARM64 ASM. It is likely that a dedicated person could produce an even more concise version, but that would take time better spent on finding vulnerabilities.

 0000000100007ecc	stp	x29, x30,[sp, #-16]! 0000000100007ed0	mov x29,sp 0000000100007ed4	subsp,sp, #16 0000000100007ed8	movz	x2, #0 0000000100007edc	orr	w8, wzr, #0x2 0000000100007ee0	orr	w0, wzr, #0x2 0000000100007ee4	orr	w1, wzr, #0x1 0000000100007ee8	movz	w16, #0x61 0000000100007eec	svc	#0x80 0000000100007ef0	neg x1, x0 0000000100007ef4	csel	x0, x0, x1, lo 0000000100007ef8	tbz	w0, #31,0x100007f04 0000000100007efc	movz	w0, #0x2b 0000000100007f00	bl	_scc_exit 0000000100007f04	stp xzr, xzr,[sp] 0000000100007f08	strb	w8,[sp, #1] 0000000100007f0c	movz	w8, #0x501,lsl #16 0000000100007f10	movk	w8, #0xa8c0 0000000100007f14	str	w8,[sp, #4] 0000000100007f18	movz	w9, #0xf27 0000000100007f1c	sxtw	x8, w0 0000000100007f20	strh	w9,[sp, #2] 0000000100007f24	mov x1,sp 0000000100007f28	orr	w2, wzr, #0x10 0000000100007f2c	movz	w16, #0x62 0000000100007f30	mov x0, x8 0000000100007f34	svc	#0x80 0000000100007f38	neg x1, x0 0000000100007f3c	csel	x0, x0, x1, lo 0000000100007f40	tbz	w0, #31,0x100007f4c 0000000100007f44	movz	w0, #0x2c 0000000100007f48	bl	_scc_exit 0000000100007f4c	adr	x1, #96 ; literal pool for: "Hello Dude\n" 0000000100007f50	nop 0000000100007f54	orr	w2, wzr, #0xc 0000000100007f58	orr	w16, wzr, #0x4 0000000100007f5c	mov x0, x8 0000000100007f60	svc	#0x80 0000000100007f64	neg x1, x0 0000000100007f68	csel	x0, x0, x1, lo 0000000100007f6c	cmp w0, #0 0000000100007f70	b.gt	0x100007f7c 0000000100007f74	movz	w0, #0x2d 0000000100007f78	bl	_scc_exit 0000000100007f7c	movz	w0, #0x2a 0000000100007f80	bl	_scc_exit _scc_exit: 0000000100007f84	stp	x29, x30,[sp, #-16]! 0000000100007f88	mov x29,sp 0000000100007f8c	sxtw	x0, w0 0000000100007f90	orr	w1, wzr, #0x1 0000000100007f94	bl	_scc_syscall1 _scc_syscall1: 0000000100007f98	mov x16, x1 0000000100007f9c	svc	#0x80 0000000100007fa0	neg x1, x0 0000000100007fa4	csel	x0, x0, x1, lo 0000000100007fa8	ret

[1] http://shell-storm.org/shellcode/

About

Building optimized shellcode using GCC. Suited for learning assembly and playing with the ABI

Resources

Stars

78 stars

Watchers

7 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

shellcc

SHELLCC is a build environment for making shellcode in C using GCC and other binary tool. It is meant to enable people with limited knowledge of assembly to write quality shellcode as well as bring code maintainability by using a high level language (specifically C).

Generally speaking shellcode does not require complex logic i.e. printfs, heavy abstraction or threading. These functions are left to the implants. Shellcode is expected to setup the environment and load the next stage of the attack. This step consists of doing cleanups and making a relatively small number of system call. For example, creating a reverse shell or downloading and executing the next stage implant. However, these functions can still be quite complex to write in assembly and it is hard to maintain them over time. Basically, all the reasons why we use compilers.

The main reason is, of course, I was not very good at writting ARM assembly by hand. So, I needed some help from a compiler.

Example

It is easy to see what this code, it calls out to an IP:PORT address and sends out a message. There is excessive error checking which would be really hard to do by hand. This code demonstrates how easy it is to build up the logic and let the compiler use its optimization magic in order to produce the best possible code.

intmain() {
intsockfd;
structsockaddr_inserv_addr;
sockfd=scc_socket(AF_INET, SOCK_STREAM, 0);
if (sockfd<0) {
scc_exit(43);
}
bzero((structsockaddr*)&serv_addr,sizeof(serv_addr));
serv_addr.sin_family=AF_INET;
serv_addr.sin_addr.s_addr=SERVER_IP;
serv_addr.sin_port=htons(SERVER_PORT);
if(scc_connect(sockfd,(structsockaddr*)&serv_addr,sizeof(serv_addr)) <0) {
scc_exit(44);
}
if(scc_write(sockfd, MESSAGE, MESSAGE_LEN) <= 0) {
scc_exit(45);
}
scc_close(sockfd);
// end the processscc_exit(42);
}

The aboce C code produces a nice concise ARM64 ASM. It is likely that a dedicated person could produce an even more concise version, but that would take time better spent on finding vulnerabilities.

 0000000100007ecc	stp	x29, x30,[sp, #-16]! 0000000100007ed0	mov x29,sp 0000000100007ed4	subsp,sp, #16 0000000100007ed8	movz	x2, #0 0000000100007edc	orr	w8, wzr, #0x2 0000000100007ee0	orr	w0, wzr, #0x2 0000000100007ee4	orr	w1, wzr, #0x1 0000000100007ee8	movz	w16, #0x61 0000000100007eec	svc	#0x80 0000000100007ef0	neg x1, x0 0000000100007ef4	csel	x0, x0, x1, lo 0000000100007ef8	tbz	w0, #31,0x100007f04 0000000100007efc	movz	w0, #0x2b 0000000100007f00	bl	_scc_exit 0000000100007f04	stp xzr, xzr,[sp] 0000000100007f08	strb	w8,[sp, #1] 0000000100007f0c	movz	w8, #0x501,lsl #16 0000000100007f10	movk	w8, #0xa8c0 0000000100007f14	str	w8,[sp, #4] 0000000100007f18	movz	w9, #0xf27 0000000100007f1c	sxtw	x8, w0 0000000100007f20	strh	w9,[sp, #2] 0000000100007f24	mov x1,sp 0000000100007f28	orr	w2, wzr, #0x10 0000000100007f2c	movz	w16, #0x62 0000000100007f30	mov x0, x8 0000000100007f34	svc	#0x80 0000000100007f38	neg x1, x0 0000000100007f3c	csel	x0, x0, x1, lo 0000000100007f40	tbz	w0, #31,0x100007f4c 0000000100007f44	movz	w0, #0x2c 0000000100007f48	bl	_scc_exit 0000000100007f4c	adr	x1, #96 ; literal pool for: "Hello Dude\n" 0000000100007f50	nop 0000000100007f54	orr	w2, wzr, #0xc 0000000100007f58	orr	w16, wzr, #0x4 0000000100007f5c	mov x0, x8 0000000100007f60	svc	#0x80 0000000100007f64	neg x1, x0 0000000100007f68	csel	x0, x0, x1, lo 0000000100007f6c	cmp w0, #0 0000000100007f70	b.gt	0x100007f7c 0000000100007f74	movz	w0, #0x2d 0000000100007f78	bl	_scc_exit 0000000100007f7c	movz	w0, #0x2a 0000000100007f80	bl	_scc_exit _scc_exit: 0000000100007f84	stp	x29, x30,[sp, #-16]! 0000000100007f88	mov x29,sp 0000000100007f8c	sxtw	x0, w0 0000000100007f90	orr	w1, wzr, #0x1 0000000100007f94	bl	_scc_syscall1 _scc_syscall1: 0000000100007f98	mov x16, x1 0000000100007f9c	svc	#0x80 0000000100007fa0	neg x1, x0 0000000100007fa4	csel	x0, x0, x1, lo 0000000100007fa8	ret

[1] http://shell-storm.org/shellcode/

About

Building optimized shellcode using GCC. Suited for learning assembly and playing with the ABI

Resources

Stars

78 stars

Watchers

7 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

shellcc

SHELLCC is a build environment for making shellcode in C using GCC and other binary tool. It is meant to enable people with limited knowledge of assembly to write quality shellcode as well as bring code maintainability by using a high level language (specifically C).

Generally speaking shellcode does not require complex logic i.e. printfs, heavy abstraction or threading. These functions are left to the implants. Shellcode is expected to setup the environment and load the next stage of the attack. This step consists of doing cleanups and making a relatively small number of system call. For example, creating a reverse shell or downloading and executing the next stage implant. However, these functions can still be quite complex to write in assembly and it is hard to maintain them over time. Basically, all the reasons why we use compilers.

The main reason is, of course, I was not very good at writting ARM assembly by hand. So, I needed some help from a compiler.

Example

It is easy to see what this code, it calls out to an IP:PORT address and sends out a message. There is excessive error checking which would be really hard to do by hand. This code demonstrates how easy it is to build up the logic and let the compiler use its optimization magic in order to produce the best possible code.

intmain() {
intsockfd;
structsockaddr_inserv_addr;
sockfd=scc_socket(AF_INET, SOCK_STREAM, 0);
if (sockfd<0) {
scc_exit(43);
}
bzero((structsockaddr*)&serv_addr,sizeof(serv_addr));
serv_addr.sin_family=AF_INET;
serv_addr.sin_addr.s_addr=SERVER_IP;
serv_addr.sin_port=htons(SERVER_PORT);
if(scc_connect(sockfd,(structsockaddr*)&serv_addr,sizeof(serv_addr)) <0) {
scc_exit(44);
}
if(scc_write(sockfd, MESSAGE, MESSAGE_LEN) <= 0) {
scc_exit(45);
}
scc_close(sockfd);
// end the processscc_exit(42);
}

The aboce C code produces a nice concise ARM64 ASM. It is likely that a dedicated person could produce an even more concise version, but that would take time better spent on finding vulnerabilities.

 0000000100007ecc	stp	x29, x30,[sp, #-16]! 0000000100007ed0	mov x29,sp 0000000100007ed4	subsp,sp, #16 0000000100007ed8	movz	x2, #0 0000000100007edc	orr	w8, wzr, #0x2 0000000100007ee0	orr	w0, wzr, #0x2 0000000100007ee4	orr	w1, wzr, #0x1 0000000100007ee8	movz	w16, #0x61 0000000100007eec	svc	#0x80 0000000100007ef0	neg x1, x0 0000000100007ef4	csel	x0, x0, x1, lo 0000000100007ef8	tbz	w0, #31,0x100007f04 0000000100007efc	movz	w0, #0x2b 0000000100007f00	bl	_scc_exit 0000000100007f04	stp xzr, xzr,[sp] 0000000100007f08	strb	w8,[sp, #1] 0000000100007f0c	movz	w8, #0x501,lsl #16 0000000100007f10	movk	w8, #0xa8c0 0000000100007f14	str	w8,[sp, #4] 0000000100007f18	movz	w9, #0xf27 0000000100007f1c	sxtw	x8, w0 0000000100007f20	strh	w9,[sp, #2] 0000000100007f24	mov x1,sp 0000000100007f28	orr	w2, wzr, #0x10 0000000100007f2c	movz	w16, #0x62 0000000100007f30	mov x0, x8 0000000100007f34	svc	#0x80 0000000100007f38	neg x1, x0 0000000100007f3c	csel	x0, x0, x1, lo 0000000100007f40	tbz	w0, #31,0x100007f4c 0000000100007f44	movz	w0, #0x2c 0000000100007f48	bl	_scc_exit 0000000100007f4c	adr	x1, #96 ; literal pool for: "Hello Dude\n" 0000000100007f50	nop 0000000100007f54	orr	w2, wzr, #0xc 0000000100007f58	orr	w16, wzr, #0x4 0000000100007f5c	mov x0, x8 0000000100007f60	svc	#0x80 0000000100007f64	neg x1, x0 0000000100007f68	csel	x0, x0, x1, lo 0000000100007f6c	cmp w0, #0 0000000100007f70	b.gt	0x100007f7c 0000000100007f74	movz	w0, #0x2d 0000000100007f78	bl	_scc_exit 0000000100007f7c	movz	w0, #0x2a 0000000100007f80	bl	_scc_exit _scc_exit: 0000000100007f84	stp	x29, x30,[sp, #-16]! 0000000100007f88	mov x29,sp 0000000100007f8c	sxtw	x0, w0 0000000100007f90	orr	w1, wzr, #0x1 0000000100007f94	bl	_scc_syscall1 _scc_syscall1: 0000000100007f98	mov x16, x1 0000000100007f9c	svc	#0x80 0000000100007fa0	neg x1, x0 0000000100007fa4	csel	x0, x0, x1, lo 0000000100007fa8	ret

[1] http://shell-storm.org/shellcode/

About

Building optimized shellcode using GCC. Suited for learning assembly and playing with the ABI

Resources

Stars

78 stars

Watchers

7 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

shellcc

SHELLCC is a build environment for making shellcode in C using GCC and other binary tool. It is meant to enable people with limited knowledge of assembly to write quality shellcode as well as bring code maintainability by using a high level language (specifically C).

Generally speaking shellcode does not require complex logic i.e. printfs, heavy abstraction or threading. These functions are left to the implants. Shellcode is expected to setup the environment and load the next stage of the attack. This step consists of doing cleanups and making a relatively small number of system call. For example, creating a reverse shell or downloading and executing the next stage implant. However, these functions can still be quite complex to write in assembly and it is hard to maintain them over time. Basically, all the reasons why we use compilers.

The main reason is, of course, I was not very good at writting ARM assembly by hand. So, I needed some help from a compiler.

Example

It is easy to see what this code, it calls out to an IP:PORT address and sends out a message. There is excessive error checking which would be really hard to do by hand. This code demonstrates how easy it is to build up the logic and let the compiler use its optimization magic in order to produce the best possible code.

intmain() {
intsockfd;
structsockaddr_inserv_addr;
sockfd=scc_socket(AF_INET, SOCK_STREAM, 0);
if (sockfd<0) {
scc_exit(43);
}
bzero((structsockaddr*)&serv_addr,sizeof(serv_addr));
serv_addr.sin_family=AF_INET;
serv_addr.sin_addr.s_addr=SERVER_IP;
serv_addr.sin_port=htons(SERVER_PORT);
if(scc_connect(sockfd,(structsockaddr*)&serv_addr,sizeof(serv_addr)) <0) {
scc_exit(44);
}
if(scc_write(sockfd, MESSAGE, MESSAGE_LEN) <= 0) {
scc_exit(45);
}
scc_close(sockfd);
// end the processscc_exit(42);
}

The aboce C code produces a nice concise ARM64 ASM. It is likely that a dedicated person could produce an even more concise version, but that would take time better spent on finding vulnerabilities.

 0000000100007ecc	stp	x29, x30,[sp, #-16]! 0000000100007ed0	mov x29,sp 0000000100007ed4	subsp,sp, #16 0000000100007ed8	movz	x2, #0 0000000100007edc	orr	w8, wzr, #0x2 0000000100007ee0	orr	w0, wzr, #0x2 0000000100007ee4	orr	w1, wzr, #0x1 0000000100007ee8	movz	w16, #0x61 0000000100007eec	svc	#0x80 0000000100007ef0	neg x1, x0 0000000100007ef4	csel	x0, x0, x1, lo 0000000100007ef8	tbz	w0, #31,0x100007f04 0000000100007efc	movz	w0, #0x2b 0000000100007f00	bl	_scc_exit 0000000100007f04	stp xzr, xzr,[sp] 0000000100007f08	strb	w8,[sp, #1] 0000000100007f0c	movz	w8, #0x501,lsl #16 0000000100007f10	movk	w8, #0xa8c0 0000000100007f14	str	w8,[sp, #4] 0000000100007f18	movz	w9, #0xf27 0000000100007f1c	sxtw	x8, w0 0000000100007f20	strh	w9,[sp, #2] 0000000100007f24	mov x1,sp 0000000100007f28	orr	w2, wzr, #0x10 0000000100007f2c	movz	w16, #0x62 0000000100007f30	mov x0, x8 0000000100007f34	svc	#0x80 0000000100007f38	neg x1, x0 0000000100007f3c	csel	x0, x0, x1, lo 0000000100007f40	tbz	w0, #31,0x100007f4c 0000000100007f44	movz	w0, #0x2c 0000000100007f48	bl	_scc_exit 0000000100007f4c	adr	x1, #96 ; literal pool for: "Hello Dude\n" 0000000100007f50	nop 0000000100007f54	orr	w2, wzr, #0xc 0000000100007f58	orr	w16, wzr, #0x4 0000000100007f5c	mov x0, x8 0000000100007f60	svc	#0x80 0000000100007f64	neg x1, x0 0000000100007f68	csel	x0, x0, x1, lo 0000000100007f6c	cmp w0, #0 0000000100007f70	b.gt	0x100007f7c 0000000100007f74	movz	w0, #0x2d 0000000100007f78	bl	_scc_exit 0000000100007f7c	movz	w0, #0x2a 0000000100007f80	bl	_scc_exit _scc_exit: 0000000100007f84	stp	x29, x30,[sp, #-16]! 0000000100007f88	mov x29,sp 0000000100007f8c	sxtw	x0, w0 0000000100007f90	orr	w1, wzr, #0x1 0000000100007f94	bl	_scc_syscall1 _scc_syscall1: 0000000100007f98	mov x16, x1 0000000100007f9c	svc	#0x80 0000000100007fa0	neg x1, x0 0000000100007fa4	csel	x0, x0, x1, lo 0000000100007fa8	ret

[1] http://shell-storm.org/shellcode/

About

Building optimized shellcode using GCC. Suited for learning assembly and playing with the ABI

Resources

Stars

78 stars

Watchers

7 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

shellcc

SHELLCC is a build environment for making shellcode in C using GCC and other binary tool. It is meant to enable people with limited knowledge of assembly to write quality shellcode as well as bring code maintainability by using a high level language (specifically C).

Generally speaking shellcode does not require complex logic i.e. printfs, heavy abstraction or threading. These functions are left to the implants. Shellcode is expected to setup the environment and load the next stage of the attack. This step consists of doing cleanups and making a relatively small number of system call. For example, creating a reverse shell or downloading and executing the next stage implant. However, these functions can still be quite complex to write in assembly and it is hard to maintain them over time. Basically, all the reasons why we use compilers.

The main reason is, of course, I was not very good at writting ARM assembly by hand. So, I needed some help from a compiler.

Example

It is easy to see what this code, it calls out to an IP:PORT address and sends out a message. There is excessive error checking which would be really hard to do by hand. This code demonstrates how easy it is to build up the logic and let the compiler use its optimization magic in order to produce the best possible code.

intmain() {
intsockfd;
structsockaddr_inserv_addr;
sockfd=scc_socket(AF_INET, SOCK_STREAM, 0);
if (sockfd<0) {
scc_exit(43);
}
bzero((structsockaddr*)&serv_addr,sizeof(serv_addr));
serv_addr.sin_family=AF_INET;
serv_addr.sin_addr.s_addr=SERVER_IP;
serv_addr.sin_port=htons(SERVER_PORT);
if(scc_connect(sockfd,(structsockaddr*)&serv_addr,sizeof(serv_addr)) <0) {
scc_exit(44);
}
if(scc_write(sockfd, MESSAGE, MESSAGE_LEN) <= 0) {
scc_exit(45);
}
scc_close(sockfd);
// end the processscc_exit(42);
}

The aboce C code produces a nice concise ARM64 ASM. It is likely that a dedicated person could produce an even more concise version, but that would take time better spent on finding vulnerabilities.

 0000000100007ecc	stp	x29, x30,[sp, #-16]! 0000000100007ed0	mov x29,sp 0000000100007ed4	subsp,sp, #16 0000000100007ed8	movz	x2, #0 0000000100007edc	orr	w8, wzr, #0x2 0000000100007ee0	orr	w0, wzr, #0x2 0000000100007ee4	orr	w1, wzr, #0x1 0000000100007ee8	movz	w16, #0x61 0000000100007eec	svc	#0x80 0000000100007ef0	neg x1, x0 0000000100007ef4	csel	x0, x0, x1, lo 0000000100007ef8	tbz	w0, #31,0x100007f04 0000000100007efc	movz	w0, #0x2b 0000000100007f00	bl	_scc_exit 0000000100007f04	stp xzr, xzr,[sp] 0000000100007f08	strb	w8,[sp, #1] 0000000100007f0c	movz	w8, #0x501,lsl #16 0000000100007f10	movk	w8, #0xa8c0 0000000100007f14	str	w8,[sp, #4] 0000000100007f18	movz	w9, #0xf27 0000000100007f1c	sxtw	x8, w0 0000000100007f20	strh	w9,[sp, #2] 0000000100007f24	mov x1,sp 0000000100007f28	orr	w2, wzr, #0x10 0000000100007f2c	movz	w16, #0x62 0000000100007f30	mov x0, x8 0000000100007f34	svc	#0x80 0000000100007f38	neg x1, x0 0000000100007f3c	csel	x0, x0, x1, lo 0000000100007f40	tbz	w0, #31,0x100007f4c 0000000100007f44	movz	w0, #0x2c 0000000100007f48	bl	_scc_exit 0000000100007f4c	adr	x1, #96 ; literal pool for: "Hello Dude\n" 0000000100007f50	nop 0000000100007f54	orr	w2, wzr, #0xc 0000000100007f58	orr	w16, wzr, #0x4 0000000100007f5c	mov x0, x8 0000000100007f60	svc	#0x80 0000000100007f64	neg x1, x0 0000000100007f68	csel	x0, x0, x1, lo 0000000100007f6c	cmp w0, #0 0000000100007f70	b.gt	0x100007f7c 0000000100007f74	movz	w0, #0x2d 0000000100007f78	bl	_scc_exit 0000000100007f7c	movz	w0, #0x2a 0000000100007f80	bl	_scc_exit _scc_exit: 0000000100007f84	stp	x29, x30,[sp, #-16]! 0000000100007f88	mov x29,sp 0000000100007f8c	sxtw	x0, w0 0000000100007f90	orr	w1, wzr, #0x1 0000000100007f94	bl	_scc_syscall1 _scc_syscall1: 0000000100007f98	mov x16, x1 0000000100007f9c	svc	#0x80 0000000100007fa0	neg x1, x0 0000000100007fa4	csel	x0, x0, x1, lo 0000000100007fa8	ret

[1] http://shell-storm.org/shellcode/

About

Building optimized shellcode using GCC. Suited for learning assembly and playing with the ABI

Resources

Stars

78 stars

Watchers

7 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

shellcc

SHELLCC is a build environment for making shellcode in C using GCC and other binary tool. It is meant to enable people with limited knowledge of assembly to write quality shellcode as well as bring code maintainability by using a high level language (specifically C).

Generally speaking shellcode does not require complex logic i.e. printfs, heavy abstraction or threading. These functions are left to the implants. Shellcode is expected to setup the environment and load the next stage of the attack. This step consists of doing cleanups and making a relatively small number of system call. For example, creating a reverse shell or downloading and executing the next stage implant. However, these functions can still be quite complex to write in assembly and it is hard to maintain them over time. Basically, all the reasons why we use compilers.

The main reason is, of course, I was not very good at writting ARM assembly by hand. So, I needed some help from a compiler.

Example

It is easy to see what this code, it calls out to an IP:PORT address and sends out a message. There is excessive error checking which would be really hard to do by hand. This code demonstrates how easy it is to build up the logic and let the compiler use its optimization magic in order to produce the best possible code.

intmain() {
intsockfd;
structsockaddr_inserv_addr;
sockfd=scc_socket(AF_INET, SOCK_STREAM, 0);
if (sockfd<0) {
scc_exit(43);
}
bzero((structsockaddr*)&serv_addr,sizeof(serv_addr));
serv_addr.sin_family=AF_INET;
serv_addr.sin_addr.s_addr=SERVER_IP;
serv_addr.sin_port=htons(SERVER_PORT);
if(scc_connect(sockfd,(structsockaddr*)&serv_addr,sizeof(serv_addr)) <0) {
scc_exit(44);
}
if(scc_write(sockfd, MESSAGE, MESSAGE_LEN) <= 0) {
scc_exit(45);
}
scc_close(sockfd);
// end the processscc_exit(42);
}

The aboce C code produces a nice concise ARM64 ASM. It is likely that a dedicated person could produce an even more concise version, but that would take time better spent on finding vulnerabilities.

 0000000100007ecc	stp	x29, x30,[sp, #-16]! 0000000100007ed0	mov x29,sp 0000000100007ed4	subsp,sp, #16 0000000100007ed8	movz	x2, #0 0000000100007edc	orr	w8, wzr, #0x2 0000000100007ee0	orr	w0, wzr, #0x2 0000000100007ee4	orr	w1, wzr, #0x1 0000000100007ee8	movz	w16, #0x61 0000000100007eec	svc	#0x80 0000000100007ef0	neg x1, x0 0000000100007ef4	csel	x0, x0, x1, lo 0000000100007ef8	tbz	w0, #31,0x100007f04 0000000100007efc	movz	w0, #0x2b 0000000100007f00	bl	_scc_exit 0000000100007f04	stp xzr, xzr,[sp] 0000000100007f08	strb	w8,[sp, #1] 0000000100007f0c	movz	w8, #0x501,lsl #16 0000000100007f10	movk	w8, #0xa8c0 0000000100007f14	str	w8,[sp, #4] 0000000100007f18	movz	w9, #0xf27 0000000100007f1c	sxtw	x8, w0 0000000100007f20	strh	w9,[sp, #2] 0000000100007f24	mov x1,sp 0000000100007f28	orr	w2, wzr, #0x10 0000000100007f2c	movz	w16, #0x62 0000000100007f30	mov x0, x8 0000000100007f34	svc	#0x80 0000000100007f38	neg x1, x0 0000000100007f3c	csel	x0, x0, x1, lo 0000000100007f40	tbz	w0, #31,0x100007f4c 0000000100007f44	movz	w0, #0x2c 0000000100007f48	bl	_scc_exit 0000000100007f4c	adr	x1, #96 ; literal pool for: "Hello Dude\n" 0000000100007f50	nop 0000000100007f54	orr	w2, wzr, #0xc 0000000100007f58	orr	w16, wzr, #0x4 0000000100007f5c	mov x0, x8 0000000100007f60	svc	#0x80 0000000100007f64	neg x1, x0 0000000100007f68	csel	x0, x0, x1, lo 0000000100007f6c	cmp w0, #0 0000000100007f70	b.gt	0x100007f7c 0000000100007f74	movz	w0, #0x2d 0000000100007f78	bl	_scc_exit 0000000100007f7c	movz	w0, #0x2a 0000000100007f80	bl	_scc_exit _scc_exit: 0000000100007f84	stp	x29, x30,[sp, #-16]! 0000000100007f88	mov x29,sp 0000000100007f8c	sxtw	x0, w0 0000000100007f90	orr	w1, wzr, #0x1 0000000100007f94	bl	_scc_syscall1 _scc_syscall1: 0000000100007f98	mov x16, x1 0000000100007f9c	svc	#0x80 0000000100007fa0	neg x1, x0 0000000100007fa4	csel	x0, x0, x1, lo 0000000100007fa8	ret

[1] http://shell-storm.org/shellcode/

About

Building optimized shellcode using GCC. Suited for learning assembly and playing with the ABI

Resources

Stars

78 stars

Watchers

7 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Latest commit

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

shellcc

SHELLCC is a build environment for making shellcode in C using GCC and other binary tool. It is meant to enable people with limited knowledge of assembly to write quality shellcode as well as bring code maintainability by using a high level language (specifically C).

Generally speaking shellcode does not require complex logic i.e. printfs, heavy abstraction or threading. These functions are left to the implants. Shellcode is expected to setup the environment and load the next stage of the attack. This step consists of doing cleanups and making a relatively small number of system call. For example, creating a reverse shell or downloading and executing the next stage implant. However, these functions can still be quite complex to write in assembly and it is hard to maintain them over time. Basically, all the reasons why we use compilers.

The main reason is, of course, I was not very good at writting ARM assembly by hand. So, I needed some help from a compiler.

Example

It is easy to see what this code, it calls out to an IP:PORT address and sends out a message. There is excessive error checking which would be really hard to do by hand. This code demonstrates how easy it is to build up the logic and let the compiler use its optimization magic in order to produce the best possible code.

intmain() {
intsockfd;
structsockaddr_inserv_addr;
sockfd=scc_socket(AF_INET, SOCK_STREAM, 0);
if (sockfd<0) {
scc_exit(43);
}
bzero((structsockaddr*)&serv_addr,sizeof(serv_addr));
serv_addr.sin_family=AF_INET;
serv_addr.sin_addr.s_addr=SERVER_IP;
serv_addr.sin_port=htons(SERVER_PORT);
if(scc_connect(sockfd,(structsockaddr*)&serv_addr,sizeof(serv_addr)) <0) {
scc_exit(44);
}
if(scc_write(sockfd, MESSAGE, MESSAGE_LEN) <= 0) {
scc_exit(45);
}
scc_close(sockfd);
// end the processscc_exit(42);
}

The aboce C code produces a nice concise ARM64 ASM. It is likely that a dedicated person could produce an even more concise version, but that would take time better spent on finding vulnerabilities.

 0000000100007ecc	stp	x29, x30,[sp, #-16]! 0000000100007ed0	mov x29,sp 0000000100007ed4	subsp,sp, #16 0000000100007ed8	movz	x2, #0 0000000100007edc	orr	w8, wzr, #0x2 0000000100007ee0	orr	w0, wzr, #0x2 0000000100007ee4	orr	w1, wzr, #0x1 0000000100007ee8	movz	w16, #0x61 0000000100007eec	svc	#0x80 0000000100007ef0	neg x1, x0 0000000100007ef4	csel	x0, x0, x1, lo 0000000100007ef8	tbz	w0, #31,0x100007f04 0000000100007efc	movz	w0, #0x2b 0000000100007f00	bl	_scc_exit 0000000100007f04	stp xzr, xzr,[sp] 0000000100007f08	strb	w8,[sp, #1] 0000000100007f0c	movz	w8, #0x501,lsl #16 0000000100007f10	movk	w8, #0xa8c0 0000000100007f14	str	w8,[sp, #4] 0000000100007f18	movz	w9, #0xf27 0000000100007f1c	sxtw	x8, w0 0000000100007f20	strh	w9,[sp, #2] 0000000100007f24	mov x1,sp 0000000100007f28	orr	w2, wzr, #0x10 0000000100007f2c	movz	w16, #0x62 0000000100007f30	mov x0, x8 0000000100007f34	svc	#0x80 0000000100007f38	neg x1, x0 0000000100007f3c	csel	x0, x0, x1, lo 0000000100007f40	tbz	w0, #31,0x100007f4c 0000000100007f44	movz	w0, #0x2c 0000000100007f48	bl	_scc_exit 0000000100007f4c	adr	x1, #96 ; literal pool for: "Hello Dude\n" 0000000100007f50	nop 0000000100007f54	orr	w2, wzr, #0xc 0000000100007f58	orr	w16, wzr, #0x4 0000000100007f5c	mov x0, x8 0000000100007f60	svc	#0x80 0000000100007f64	neg x1, x0 0000000100007f68	csel	x0, x0, x1, lo 0000000100007f6c	cmp w0, #0 0000000100007f70	b.gt	0x100007f7c 0000000100007f74	movz	w0, #0x2d 0000000100007f78	bl	_scc_exit 0000000100007f7c	movz	w0, #0x2a 0000000100007f80	bl	_scc_exit _scc_exit: 0000000100007f84	stp	x29, x30,[sp, #-16]! 0000000100007f88	mov x29,sp 0000000100007f8c	sxtw	x0, w0 0000000100007f90	orr	w1, wzr, #0x1 0000000100007f94	bl	_scc_syscall1 _scc_syscall1: 0000000100007f98	mov x16, x1 0000000100007f9c	svc	#0x80 0000000100007fa0	neg x1, x0 0000000100007fa4	csel	x0, x0, x1, lo 0000000100007fa8	ret

[1] http://shell-storm.org/shellcode/

About

Building optimized shellcode using GCC. Suited for learning assembly and playing with the ABI

Resources

Stars

78 stars

Watchers

7 watching

Forks

Releases

Packages

Contributors

Languages