asm_execve.s:sys_execve系统调用
.section .data file_to_run: .ascii "/bin/sh" .section .text .globl main main: pushl %ebp movl %esp, %ebp subl $0x8, %esp # array of two pointers. array[0] = file_to_run array[1] = 0 movl file_to_run, %edi movl %edi, -0x4(%ebp) movl $0, -0x8(%ebp) movl $11, %eax # sys_execve movl file_to_run, %ebx # file to execute leal -4(%ebp), %ecx # command line parameters movl $0, %edx # environment block int $0x80 leave ret
生成文件:
NAME = asm_execve $(NAME) : $(NAME).s gcc -o $(NAME) $(NAME).s
程序被执行,但sys_execve不叫:
[email protected]:~/project$ make gcc -o asm_execve asm_execve.s [email protected]:~/project$ ./asm_execve [email protected]:~/project$
预期成果是:
[email protected]:~/project$ ./asm_execve $ exit [email protected]:~/project$
本届大会的程序应该像下面的C代码工作:
char *data[2]; data[0] = "/bin/sh"; data[1] = NULL; execve(data[0], data, NULL);
一些错误的系统调用的参数?
使用'strace -e execve'来跟踪你的程序* exec *调用的execve调用。 – 2017-10-03 22:24:28