Devilzc0de Forum Follow @devilzc0de
  • Home
  • Hacking
  • Networking
  • Programming
  • O.S
  • Server
  • Tweets
  • Search
  • Member List
  • Calendar
Current time: 05-22-2013, 04:26 AM Hello There, Guest! (Login — Register)
Devilzc0de Forum › Information Technology › Programming › Assembly v
1 2 3 Next »

[POC] sys_execve("/usr/bin/ftp", "sdf.lonestar.org", NULL)

Home General Computer Multimedia Business Lounge

Pages (3): 1 2 3 Next »
Post Reply 
Tweet
Threaded Mode | Linear Mode
[POC] sys_execve("/usr/bin/ftp", "sdf.lonestar.org", NULL)
10-24-2011, 06:56 PM (This post was last modified: 10-24-2011 06:57 PM by syn_attack.)
Post: #1
syn_attack Away
execl("/bin/sh", "sh", NULL);
**
Moderators
Posts: 306
Joined: Sep 2011
Reputation: 55
[POC] sys_execve("/usr/bin/ftp", "sdf.lonestar.org", NULL)
kakak-kakakku sekalian, aku mau share program assembly aku yang cupu ni kak...

ini source codenya sudah sekalian POCnya kak....
mohon koreksinya ya kak, kalau ada yang salah....

code + POC

Code:
; sys_execve("/usr/bin/ftp", "sdf.lonestar.org", NULL);
; Programmer : Paulus Gandung Prakosa_ (0x1337day)

; code + penjelasan
; Thanks a lot to : mywisdom, chaer.newbie, wenkhairu, ketek, gunslinger_, nofia_fitri, xtr0nic,
;                   t3k0, tabun, petimati, and all devilzc0de member...

section .text

global _start

_start :

; sys_execve("/usr/bin/ftp", "sdf.lonestar.org", NULL);
xor    eax, eax        ; kosongkan register eax (dengan metoda XOR)
sub    esp, byte 0x1        ; alokasikan memori pada register esp sebanyak 1 bytes
mov    [esp], al        ; pindahkan ukuran (sizeof) register al menuju alamat register esp
push    dword 0x67726f2e    ; dorong string "gro." ke dalam stack (bentuk little endian)
push    dword 0x72617473    ; dorong string "rats" ke dalam stack (bentuk little endian)
push    dword 0x656e6f6c    ; dorong string "enol" ke dalam stack (bentuk little endian)
push    dword 0x2e666473    ; dorong string ".fds" ke dalam stack (bentuk little endian)
mov    esi, esp        ; pindah isi stack ke dalam register esi (extended source index)
sub    esp, byte 0x1        ; alokasikan memori pada register esp sebanyak 1 bytes
mov    [esp], al        ; pindahkan ukuran (sizeof) register al menuju alamat register esp
push    dword 0x7074662f    ; dorong string "ptf/" ke dalam stack (bentuk little endian)
push    dword 0x6e69622f    ; dorong string "nib/" ke dalam stack (bentuk little endian)
push    dword 0x7273752f    ; dorong string "rsu/" ke dalam stack (bentuk little endian)
push    eax            ; dorong nilai register eax = NULL ke dalam stack
push    esi            ; dorong isi register esi ke dalam stack
sub    esi,  byte 0xd        ; alokasikan memori pada register esi sebanyak 13 bytes
push    esi            ; dorong nilai 13 = 0xd (sebagai "carriage return") ke dalam stack
mov    al, 0xb            ; pindahkan nilai syscall 0xb = 11 = sys_execve() ke dalam register al
mov    ebx, esi        ; pindahkan nilai register esi "0xd = carriage return" ke register ebx
mov    ecx, esp        ; pindahkan nilai register esp "gro.ratsenol.fds ptf/nib/rsu/" (little endian)
                                ; ke dalam register ecx
xor    edx, edx        ; kosongkan register edx (dengan metoda XOR)
int    0x80            ; interupsi kernel

; sys_exit(0)
mov    al, 0x1            ; pindahkan nilai 1 = 0x1 = sys_exit() ke dalam register al
xor    ebx, ebx        ; kosongkan register ebx (dengan metoda XOR) sebagai argumen pertama _exit(0)
int    0x80            ; interupsi kernel

compilenya kak...
I. nasm -f elf syn_ftp.asm
II. ld -s -o syn_ftp syn_ftp.o

("syn_ftp" nya bisa diganti sesuka hati kakak) wawa wawa

cara pakai :

Code:
syn-attack@localhost:~/asm_code/elf_binary$ ./syn_ftp
220 sdf.lonestar.org FTP server (NetBSD-ftpd 20100320) ready.
Name (sdf.lonestar.org:syn-attack):
Visit this user's website Find all posts by this user
Quote this message in a reply
 Reputed by :  ev1lut10n(+1)
10-24-2011, 07:05 PM
Post: #2
ian182 Offline
DC Senior
***
Posts: 425
Joined: Dec 2009
Reputation: 14
RE: [POC] sys_execve("/usr/bin/ftp", "sdf.lonestar.org", NULL)
keren om
Visit this user's website Find all posts by this user
Quote this message in a reply
10-24-2011, 07:07 PM
Post: #3
th3pRed4t0r Offline
./Devilz 1st Cadet
Posts: 18
Joined: Feb 2011
Reputation: 0
RE: [POC] sys_execve("/usr/bin/ftp", "sdf.lonestar.org", NULL)
om satu ne memang keren.!!

=}}
Find all posts by this user
Quote this message in a reply
10-24-2011, 07:27 PM
Post: #4
syn_attack Away
execl("/bin/sh", "sh", NULL);
**
Moderators
Posts: 306
Joined: Sep 2011
Reputation: 55
RE: [POC] sys_execve("/usr/bin/ftp", "sdf.lonestar.org", NULL)
kakak ian182 ~# monggo dicoba kakak... wawa wawa
kakak th3pRed4t0r ~# kakak yang satu ni, wkwkkw,, monggo dicoba kak... wawa wawa
Visit this user's website Find all posts by this user
Quote this message in a reply
10-24-2011, 07:33 PM
Post: #5
selfdefense Offline
./Devilz Commodore
Posts: 1,260
Joined: Aug 2010
Reputation: 46
RE: [POC] sys_execve("/usr/bin/ftp", "sdf.lonestar.org", NULL)
omnya hacker elite nih... sering maen di sdf.... mantap
ijin nyobain om.... ketawa
Find all posts by this user
Quote this message in a reply
10-24-2011, 07:38 PM
Post: #6
mariachi Away
has been reboot
**
Moderators
Posts: 2,361
Joined: Nov 2010
Reputation: 55
RE: [POC] sys_execve("/usr/bin/ftp", "sdf.lonestar.org", NULL)
ada nama ane malu

keren banget dech om mantap
Find all posts by this user
Quote this message in a reply
10-24-2011, 07:38 PM
Post: #7
ian182 Offline
DC Senior
***
Posts: 425
Joined: Dec 2009
Reputation: 14
RE: [POC] sys_execve("/usr/bin/ftp", "sdf.lonestar.org", NULL)
makin rame nih asm di dc ketawaketawa
Visit this user's website Find all posts by this user
Quote this message in a reply
10-24-2011, 07:46 PM (This post was last modified: 10-24-2011 07:48 PM by syn_attack.)
Post: #8
syn_attack Away
execl("/bin/sh", "sh", NULL);
**
Moderators
Posts: 306
Joined: Sep 2011
Reputation: 55
RE: [POC] sys_execve("/usr/bin/ftp", "sdf.lonestar.org", NULL)
kakak selfdefense ~# udah kak ah ngejeknya.... wkwkwkwk piss

aku bukan hacker kak..... apalagi hacker elite.... aduh wawa wawa

itu cita-cita yang terlalu tinggi,, gpp dech... tetapi mantap....
kakak t3k0 ~# iya kak,, kakak secara tidak langsung memotivasi ane untuk lebuh giat belajar....
kakak ian82 ~# semoga kak,,, wawa wawa
Visit this user's website Find all posts by this user
Quote this message in a reply
10-24-2011, 07:49 PM
Post: #9
selfdefense Offline
./Devilz Commodore
Posts: 1,260
Joined: Aug 2010
Reputation: 46
RE: [POC] sys_execve("/usr/bin/ftp", "sdf.lonestar.org", NULL)
(10-24-2011 07:46 PM)syn_attack Wrote:  kakak selfdefense ~# udah kak ah ngejeknya.... wkwkwkwk piss

aku bukan hacker kak..... apalagi hacker elite.... aduh wawa wawa

itu cita-cita yang terlalu tinggi,, gpp dech... tetapi mantap....
kakak t3k0 ~# iya kak,, kakak secara tidak langsung memotivasi ane untuk lebuh giat belajar....
kakak ian82 ~# semoga kak,,, wawa wawa

eh asli ane g ngejek.... ente seklas dom2 nih... dlu dia juga sering maen di sdf kayanya... ketawa
Find all posts by this user
Quote this message in a reply
10-24-2011, 07:54 PM
Post: #10
syn_attack Away
execl("/bin/sh", "sh", NULL);
**
Moderators
Posts: 306
Joined: Sep 2011
Reputation: 55
RE: [POC] sys_execve("/usr/bin/ftp", "sdf.lonestar.org", NULL)
kakak selfdefense ~# bisa aja si kakak cakep nich...... wawa wawa
Visit this user's website Find all posts by this user
Quote this message in a reply
« Next Oldest | Next Newest »
Pages (3): 1 2 3 Next »
Post Reply 


Topic Tools
Topic Link :
BBCode :
HTML Code :
View a Printable Version Send Thread to a Friend Subscribe to this thread
Submit Google Submit Face book Submit to Digg Submit to Reddit Submit to Furl Submit to Del.icio.us Submit to Jeqq

Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  shellcode execve("/bin/ps",NULL,NULL); ev1lut10n 7 1,059 10-18-2011 04:10 PM
Last Post: syn_attack

Users Browsing
1 Guest(s)

  • Contact Us
  • devilzc0de
  • Return to Top
  • Mobile Version
  • RSS Syndication
  • Help
Current time: 05-22-2013, 04:26 AM Powered By MyBB, © 2002-2013 MyBB Group. Theme created by Justin S. | Mixed By Chaer.Newbie | Fixed By Aditya

USING THIS SITE INDICATES THAT YOU HAVE READ AND ACCEPT OUR TERMS. IF YOU DO NOT ACCEPT THESE TERMS, YOU ARE NOT AUTHORIZED TO USE THIS SITE