This commit is contained in:
pbonilla 2024-04-17 12:21:50 +02:00
commit 9b39864ee8
6 changed files with 15 additions and 10 deletions

View File

@ -18,7 +18,8 @@ void ft_lstdelone(t_list *lst, void (*del)(void *))
return ;
if (del)
{
free(lst);
del(lst->content);
free(lst);
}
}

1
gen_payload.sh Executable file
View File

@ -0,0 +1 @@
nasm -f elf64 -o print.o print.s && ld -o print print.o && nasm -f bin -o payload print.s && hexdump -v -e '"\\\x\" 1/1 "%02x"' payload

View File

@ -51,3 +51,4 @@ int prepare_injection(t_elf_content *woody);
void encrypt(char *file, unsigned long int offset, unsigned long int size);
#endif

View File

@ -43,3 +43,4 @@ int main(int ac, char **av)
return ret;
return prepare_injection(&woody);
}

View File

@ -1,6 +1,5 @@
#include "../includes/woody.h"
int elf_magic_numbers(char *str)
{
return (!ft_strncmp(str, ELFMAG, SELFMAG));
@ -109,7 +108,7 @@ int insert_payload(t_elf_content *woody, t_payload *payload, size_t payload_posi
int32_t woody_index = ptr_woody - payload->payload;
int32_t jmp_index = ptr_jmp - payload->payload;
int32_t jump_value = (payload_position - woody->Ehdr->e_entry + jmp_index - 1) * -1;
int32_t jump_value = ((payload_position + jmp_index + 5) - woody->Ehdr->e_entry) * -1; // 5 = JUMP SIZE (OPCODE + 4 bytes operand)
ft_memcpy(&payload->payload[jmp_index + 1], &jump_value, sizeof(jump_value));
int64_t text_index = ptr_text_section - payload->payload;
@ -129,7 +128,7 @@ int insert_payload(t_elf_content *woody, t_payload *payload, size_t payload_posi
printf("Old entry : %ld (%lx)\n", woody->Ehdr->e_entry, woody->Ehdr->e_entry);
printf("Code cave start = %ld (%lx)\n", payload_position, payload_position);
printf("Payload size = %ld (%lx)\n", payload->len, payload->len);
printf("Backwar d offset = %d (%x)(%x)\n", jump_value, jump_value, -jump_value);
printf("Backward offset = %d (%x)(%x)\n", jump_value, jump_value, -jump_value);
return EXIT_SUCCESS;
}
return EXIT_FAILURE;
@ -207,6 +206,7 @@ int get_elf_sections(t_elf_content *woody)
break;
}
}
return EXIT_SUCCESS;
}
@ -226,3 +226,4 @@ int prepare_injection(t_elf_content *woody)
free(woody_file);
return EXIT_SUCCESS;
}