There are many basic shellcodes that can be emulated from the beginning from the end providing IOC like where is connecting and so on. But what can we do when the emulation get stuck at some point?
The console has many tools to interact with the emulator like it was a debugger but the shellcode really is not being executed so is safer than a debugger.
target/release/scemu -f ~/Downloads/shellcodes_matched/drv_shellcode.bin -vv
In some shellcodes the emulator emulates millions of instructions without problem, but in this case at instruction number 176 there is a crash, the [esp + 30h] contain an unexpected 0xffffffff.
There are two ways to trace the memory, tracing all memory operations with -m or inspecting specific place with -i which allow to use registers to express the memory location:
target/release/scemu -f ~/Downloads/shellcodes_matched/drv_shellcode.bin -i 'dword ptr [esp + 0x30]'
Now we know that in position 174 the value 0xffffffff is set.
But we have more control if we set the console at first instruction with -c 1 and set a memory breakpoint on write.
This "dec" instruction changes the zero for the 0xffffffff, and the instruction 90 is what actually is changing the stack value.
Lets trace the eax register to see if its a kind of counter or what is doing.
Related links
- Pentest Tools Online
- Hackers Toolbox
- Hacking Tools Kit
- Hacking Tools For Beginners
- Hacker Hardware Tools
- Pentest Tools Subdomain
- Pentest Reporting Tools
- Pentest Tools Github
- How To Make Hacking Tools
- Hack Tools Pc
- Hack Tools Pc
- Growth Hacker Tools
- Physical Pentest Tools
- Hack Tools For Mac
- Hack Tools For Games
- Hack Tools For Pc
- Github Hacking Tools
- Pentest Tools Free
- Hacker Tools 2020
- How To Hack
- Pentest Box Tools Download
- Pentest Tools Android
- Hack Website Online Tool
- Growth Hacker Tools
- Hacker Tools Linux
- Pentest Tools Bluekeep
- Top Pentest Tools
- Pentest Tools Tcp Port Scanner
- Hacking Tools Name
- Hacking Tools For Windows
- Hack App
- Hacking Tools For Pc
- Hacker Tools For Ios
- Hacking Tools Windows 10
- Pentest Tools Linux
- Hacker Tools Windows
- Nsa Hack Tools Download
- Black Hat Hacker Tools
- Hack Tool Apk No Root
- Hack Tools
- Hacking Tools 2019
- Hack And Tools
- Hack Tools For Games
- Hacker Tools Free
- Hacking Tools For Windows Free Download
- Hacking Tools For Windows Free Download
- Pentest Tools Kali Linux
- Pentest Tools Nmap
- Android Hack Tools Github
- Hack Tools Github
- Bluetooth Hacking Tools Kali
- Hack Tools Github
- Hack Tools For Pc
- Pentest Tools List
- Termux Hacking Tools 2019
- Hacker Tools 2019
- How To Install Pentest Tools In Ubuntu
- Hacker Tools For Ios
- Pentest Tools Windows
- Tools For Hacker
- Hacker Tools 2020
- Pentest Tools Nmap
- Hack Tools Mac
- Usb Pentest Tools
- Hacking Tools
- Physical Pentest Tools
- Hacker Tool Kit
- Kik Hack Tools
- Github Hacking Tools

No comments:
Post a Comment