-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathmain.cpp
More file actions
32 lines (28 loc) · 1.16 KB
/
Copy pathmain.cpp
File metadata and controls
32 lines (28 loc) · 1.16 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
#include <cmath>
#include <iostream>
#include <unistd.h>
#include <sys/mman.h>
union Datta {
volatile unsigned long long* forShellCode;
volatile unsigned* forAnyShell;
volatile unsigned char* forShell;
void* forPerms;
volatile unsigned long long forPlus;
};
int main() {
volatile int fdSh = 0;
volatile Datta dq{reinterpret_cast<volatile unsigned long long*>(main)};
dq.forPlus = static_cast<unsigned long long>(std::floor(dq.forPlus/4096))*4096;
mprotect(dq.forPerms, sizeof(dq.forPerms), PROT_READ|PROT_WRITE|PROT_EXEC);
dq.forShellCode = reinterpret_cast<volatile unsigned long long*>(main);
// (1:)
dq.forPlus+=154;
*dq.forAnyShell = 0x02F445C7;
// Закомментируйте текст помеченный (1:) выше и раскомментируйте данный текст, чтобы вывести текст скомпилировав как написано в README
// Comment out the text marked (1:) above and uncomment this text to output the text compiled as written in README.
// dq.forPlus+=148;
// *dq.forShell = 0x02;
fdSh = 1;
write(fdSh, "hello world\n", 12);
return 0;
}