𓆣 đ”—Ì¶đ”ąÌ¶đ”±Ì¶đ”°Ì¶đ”±Ì¶đ”žÌ¶đ” Ì¶đ”šÌ¶ 𓆣
107 subscribers
176 photos
2 videos
4 files
43 links
Download Telegram
The debug is taking more time than the actual code architecture desing and writing.
picasothedealer_com@cloudshell:~/ZeroShadow$ ./runtime/shadow_stub & sleep 0.5 && sudo ./ZeroShadow $! ./runtime/shadow_stub
[6] 8635

[6]+ Stopped ./runtime/shadow_stub
[*] booting ZeroShadow supervisor...
[+] memory boundaries mapped.
[*] hooking PID: 8635...
[+] connected to prosses: 8635. monitoring loop active.
[*] dynamic ASLR base offset applied to all monitored regions.
[*] draining any leftover signals...
[DEBUG] drain signal: 19
[DEBUG] drain signal: 5
[DEBUG] drained, RIP: 0x5749d70b801f
[+] synchronised and drained. Starting main loop.
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region:
0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8031 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b803b signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b803b signal: b
region: 0x95974652084224 - 0x95974652088320
[!] CRITICAL: control flow hijack detected! RIP: 0x5749d70b803b signal: b
Error: supervisor loop drooped or connection lost.
[6]+ Killed ./runtime/shadow_stub
I don't want to write the offset boundary "by hand" so i will use ai, jk. I will read it from the

exact executable segment boundaries


directly from the process memory map.
okay boom, it has detected it correctly.
picasothedealer_com@cloudshell:~/ZeroShadow$ ./runtime/shadow_stub & sleep 0.5 && sudo ./ZeroShadow $! ./runtime/shadow_stub
[6] 11834

[6]+ Stopped ./runtime/shadow_stub
[*] booting ZeroShadow supervisor...
[+] memory boundaries mapped.
[*] hooking PID: 11834...
[+] connected to prosses: 11834. monitoring loop active.
[*] loaded 2 executable segment(s) from maps.
[*] draining any leftover signals...
[DEBUG] drain signal: 19
[DEBUG] drain signal: 5
[DEBUG] drained, RIP: 0x58075f76301f
[+] synchronised and drained. Starting main loop.
[!] SIGSEGV at instruction 0x58075f76303b, fault address = 0x0
[!] CRITICAL: control flow hijack detected! RIP: 0x58075f76303b signal: b
Error: supervisor loop drooped or connection lost.
[6]+ Killed ./runtime/shadow_stub
if (sig != SIGTRAP || !verify_instruction_pointer(regs)) {
std::cerr << "[!] CRITICAL: control flow hijack detected! " << "RIP: 0x" << std::hex << regs.rip << " signal: " << std::dec << sig << "\n";
ptrace(PTRACE_KILL, pid, nullptr, nullptr);
waitpid(pid, &status, 0); // read the killed process
return false;
}


This logic is a bit greedy it's not differentiating b/n a crash and a hijack on the system. Too greedy it treets a hijack as a crash and a crash as a hijack.
Okay some tweaks have been done and the output is amazing, mostly complete it has detected the memory fault by the dummy shadow_stub.s

picasothedealer_com@cloudshell:~/ZeroShadow$ ./runtime/shadow_stub & sleep 0.5 && sudo ./ZeroShadow $! ./runtime/shadow_stub
[6] 12577

[6]+ Stopped ./runtime/shadow_stub
[*] booting ZeroShadow supervisor...
[+] memory boundaries mapped.
[*] hooking PID: 12577...
[+] connected to prosses: 12577. monitoring loop active.
[*] loaded 2 executable segment(s) from maps.
[*] draining any leftover signals...
[DEBUG] drain signal: 19
[DEBUG] drain signal: 5
[DEBUG] drained, RIP: 0x572eb2d8901f
[+] synchronised and drained. Starting main loop.
[!] SIGSEGV at instruction 0x572eb2d8903b, fault address = 0x0
[!] CRITICAL: Memory Fault (SIGSEGV) at 0x572eb2d8903b accessing invalid address 0x0
Error: supervisor loop drooped or connection lost.
[6]+ Killed ./runtime/shadow_stub
for real tho i really hate putting the PID every time i am gonna test so yeah i ma add some lines
vuala but i feel like i will need to test it more before launching too,
I am 19, atlast gotta pack my bag after matrik I guess
👀6
found one bug false alert fires up because i am missing one executable memory region is missing from the valid_maps list.
So now, ZeroShadow is missing some things which are:
The "Signal Race" (Asynchronous Bypassing)

,
Time-of-Check to Time-of-Use (TOCTOU)

,
Direct Memory Access (DMA) / Side-Channel

,
Signal Masking

.
Okay done, so another debug i was using hardcoding syscall number which is okay for x86-64, and i made t strictly bound, i will change it and add <sys/syscall.h> to include ARM and RISC-V. And a dead lock risk
I finally present "ZeroShadow"

think of it like an automated debugger. you can watch functions execute, read memory or change how an app behaves on the fly without needing the source code.

it is a lightweight dynamic binary instrumentation engine for elf files. you use it to hook functions, trace execution paths and unpack malware without the massive overhead of heavy tools like frida.

https://github.com/PicasoTheDeal/ZeroShadow
đŸ”„5