Come estrarre il numero di porta dallo shellcode
Sep 27 2020
Ho visto questo codice shell e quando usano la connectfunzione passano il numero di porta 4444:
set_address:
push byte 0x05 ; retry counter
push 0x0100007F ; host 127.0.0.1
push 0x5C110002 ; family AF_INET and port 4444
mov esi, esp ; save pointer to sockaddr struct
O in un altro sito web come quello:
0000001A push dword 0x5c110002 ; [0x5c110002, 0x81caa8c0, 0x1, 0x0] // sin_port and sin_family (4444, 0x0002)
Ma spingono 0x5C110002, come estraggono 4444 da 0x5C110002?
Risposte
2 ShaneReilly Sep 28 2020 at 07:30
La connectsyscall accetta una sockaddrstruttura come argomento, che assomiglia a questo:
struct sockaddr_in {
short sin_family;
u_short sin_port;
struct in_addr sin_addr;
char sin_zero[8];
};
Non stanno estraendo 4444, è semplicemente passato allo stack come short di due byte. Stai passando a connect, in ordine little-endian:
sin_family: 0x0002 (AF_INET)sin_port: 0x5c11 (4444 in hex, little endian)sin_addr: 0x0100007F ([127] [0] [0] [1], little endian)
E235 Sep 27 2020 at 16:23
Ho trovato qui come convertirlo con python.
import socket
port = 4444
hex(socket.htons(port))
Result : 0x5c11
L'opposto è così:
socket.htons(0x5c11)