【问题标题】:Shellcode compiling errorsShellcode 编译错误
【发布时间】:2021-04-20 19:24:21
【问题描述】:

我编写了汇编代码来测试 shellcode 示例。 但是,编译汇编代码时出现以下错误。 我也尝试将汇编代码编译为 .S.s。 另外,我也尝试编译为 "gcc -nostdlib -static shellcode.s -o shellcode-elf""as shellcode.s -o shellcode.o"

谁能帮我在 Ubuntu 上编译简单的汇编代码?(使用 mac M1 芯片)

uname -a :

Linux ubuntu 5.8.0-49-generic #55~20.04.1-Ubuntu SMP Fri Mar 26 01:00:41 UTC 2021 aarch64 aarch64 aarch64 GNU/Linux

错误:

shellcode.s: Assembler messages:
shellcode.s:6: Error: operand 1 must be an integer register -- `mov rax,59'
shellcode.s:7: Error: unknown mnemonic `lea' -- `lea rdi,[rip+binsh]'
shellcode.s:8: Error: operand 1 must be an integer register -- `mov rsi,0'
shellcode.s:9: Error: operand 1 must be an integer register -- `mov rdx,0'
shellcode.s:10: Error: unknown mnemonic `syscall' -- `syscall'

汇编代码:

global _start
_start:
xor %eax, %eax
xor %edx, %edx
push %eax
push $0x68732f2f
push $0x6e69622f
mov %esp, %ebx
push %edx
push %ebx
mov %esp, %ecx
movb $0x0B, %al
int $0x80

【问题讨论】:

  • 这是 x86 汇编代码。它不会为 aarch64 芯片组装或运行。
  • 感谢 cmets。你能告诉我应该在哪里修吗?我尝试了不同的代码,但问题是......它无法编译......
  • 没有办法解决这个问题。重写aarch64的代码。
  • 唯一的方法是使用某种模拟。该芯片无法运行 x86 代码,世界上没有任何事情可以改变这一点。
  • 这个shellcode只有在你试图利用一个本身在仿真下运行的x86可执行文件时才有用。所以你可以例如在 qemu 中运行整个事情。然后,您需要使用交叉汇编器来构建 x86 shellcode。

标签: ubuntu assembly arm64 shellcode apple-m1


【解决方案1】:

正如 cmets 中所指出的,您可以使用交叉编译器和模拟器(例如 qemu-user)在 AArch64 Linux 系统上编译/执行针对 x86-64 Linux 的程序。

请注意,该程序不会在本地执行。但是,这应该足以满足您的需求。

本示例基于 Aarch64 Ubuntu 20.04 系统构建:

uname -a
Linux orangepipc2 5.10.21-sunxi64 #21.02.3 SMP Mon Mar 8 00:45:13 UTC 2021 aarch64 aarch64 aarch64 GNU/Linux

# install the cross-compiler and qemu-user
sudo apt-get install gcc-10-multilib-x86-64-linux-gnu
sudo apt-get install qemu-user

创建hello.s(学分:https://cs.lmu.edu/~ray/notes/gasexamples/),因为您提供的代码没有正确组装。指出为什么超出当前答案的范围 - 一旦安装了 x86-64 交叉编译器,您应该能够自己修复代码。

hello.s:
       .global main
       .text
main:
        # write(1, message, 13)
        mov     $1, %rax                # system call 1 is write
        mov     $1, %rdi                # file handle 1 is stdout
        mov     $message, %rsi          # address of string to output
        mov     $13, %rdx               # number of bytes
        syscall                         # invoke operating system to do the write

        # exit(0)
        mov     $60, %rax               # system call 60 is exit
        xor     %rdi, %rdi              # we want return code 0
        syscall                         # invoke operating system to exit
message:
        .ascii  "Hello, world\n"

/usr/bin/x86_64-linux-gnu-gcc-10 -static  -o hello hello.s
file hello
hello: ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), statically linked, BuildID[sha1]=2fb401aedb8c9593ea93c0c2dd59b91f11b57b10, for GNU/Linux 3.2.0, not stripped

qemu-x86_64  hello
Hello, world

【讨论】:

  • 天啊...这真的很有帮助。你这么多:)
  • 嗨@Seonghun Son:很高兴读到。如果此答案或任何答案解决了您的问题,请单击复选标记考虑accepting it。这向更广泛的社区表明您已经找到了解决方案,并为回答者和您自己提供了一些声誉。当然没有义务这样做。
猜你喜欢
  • 1970-01-01
  • 2014-03-17
  • 2011-09-04
相关资源
最近更新 更多