This media is not supported in your browser
VIEW IN TELEGRAM
The debug is taking more time than the actual code architecture desing and writing.
picasothedealer_com@cloudshell:~/ZeroShadow$ ./runtime/shadow_stub & sleep 0.5 && sudo ./ZeroShadow $! ./runtime/shadow_stub
[6] 8635
[6]+ Stopped ./runtime/shadow_stub
[*] booting ZeroShadow supervisor...
[+] memory boundaries mapped.
[*] hooking PID: 8635...
[+] connected to prosses: 8635. monitoring loop active.
[*] dynamic ASLR base offset applied to all monitored regions.
[*] draining any leftover signals...
[DEBUG] drain signal: 19
[DEBUG] drain signal: 5
[DEBUG] drained, RIP: 0x5749d70b801f
[+] synchronised and drained. Starting main loop.
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region:0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8031 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b803b signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b803b signal: b
region: 0x95974652084224 - 0x95974652088320
[!] CRITICAL: control flow hijack detected! RIP: 0x5749d70b803b signal: b
Error: supervisor loop drooped or connection lost.
[6]+ Killed ./runtime/shadow_stub
đŁ đ̶đąÌ¶đ±Ì¶đ°Ì¶đ±Ì¶đ̶đ ̶đšÌ¶ đŁ
0x95974652084224 - 0x95974652088320 [DEBUG] Check RIP: 0x5749d70b8029 signal: 5 region: 0x95974652084224 - 0x95974652088320 [DEBUG] Check RIP: 0x5749d70b802c signal: 5 region: 0x95974652084224 - 0x95974652088320 [DEBUG] Check RIP: 0x5749d70b802fâŠ
aight okay, now it's detecting the jump. Just a slight problem the allowed map was corrupted and then the verify_instructur_pointer see's it doesn't make sense and the stop that happened at the end doesn't show what happened.
I don't want to write the offset boundary "by hand" so i will use ai, jk. I will read it from the
directly from the process memory map.
exact executable segment boundaries
directly from the process memory map.
okay boom, it has detected it correctly.
picasothedealer_com@cloudshell:~/ZeroShadow$ ./runtime/shadow_stub & sleep 0.5 && sudo ./ZeroShadow $! ./runtime/shadow_stub
[6] 11834
[6]+ Stopped ./runtime/shadow_stub
[*] booting ZeroShadow supervisor...
[+] memory boundaries mapped.
[*] hooking PID: 11834...
[+] connected to prosses: 11834. monitoring loop active.
[*] loaded 2 executable segment(s) from maps.
[*] draining any leftover signals...
[DEBUG] drain signal: 19
[DEBUG] drain signal: 5
[DEBUG] drained, RIP: 0x58075f76301f
[+] synchronised and drained. Starting main loop.
[!] SIGSEGV at instruction 0x58075f76303b, fault address = 0x0
[!] CRITICAL: control flow hijack detected! RIP: 0x58075f76303b signal: b
Error: supervisor loop drooped or connection lost.
[6]+ Killed ./runtime/shadow_stubif (sig != SIGTRAP || !verify_instruction_pointer(regs)) {
std::cerr << "[!] CRITICAL: control flow hijack detected! " << "RIP: 0x" << std::hex << regs.rip << " signal: " << std::dec << sig << "\n";
ptrace(PTRACE_KILL, pid, nullptr, nullptr);
waitpid(pid, &status, 0); // read the killed process
return false;
}
This logic is a bit greedy it's not differentiating b/n a crash and a hijack on the system. Too greedy it treets a hijack as a crash and a crash as a hijack.Okay some tweaks have been done and the output is amazing, mostly complete it has detected the memory fault by the dummy shadow_stub.s
picasothedealer_com@cloudshell:~/ZeroShadow$ ./runtime/shadow_stub & sleep 0.5 && sudo ./ZeroShadow $! ./runtime/shadow_stub
[6] 12577
[6]+ Stopped ./runtime/shadow_stub
[*] booting ZeroShadow supervisor...
[+] memory boundaries mapped.
[*] hooking PID: 12577...
[+] connected to prosses: 12577. monitoring loop active.
[*] loaded 2 executable segment(s) from maps.
[*] draining any leftover signals...
[DEBUG] drain signal: 19
[DEBUG] drain signal: 5
[DEBUG] drained, RIP: 0x572eb2d8901f
[+] synchronised and drained. Starting main loop.
[!] SIGSEGV at instruction 0x572eb2d8903b, fault address = 0x0
[!] CRITICAL: Memory Fault (SIGSEGV) at 0x572eb2d8903b accessing invalid address 0x0
Error: supervisor loop drooped or connection lost.
[6]+ Killed ./runtime/shadow_stubnow for the stack based buffer overflow test
for real tho i really hate putting the PID every time i am gonna test so yeah i ma add some lines
I am 19, atlast gotta pack my bag after matrik I guess
đ6
So now, ZeroShadow is missing some things which are:
,
,
,
.
The "Signal Race" (Asynchronous Bypassing),
Time-of-Check to Time-of-Use (TOCTOU),
Direct Memory Access (DMA) / Side-Channel,
Signal Masking.
Okay done, so another debug i was using hardcoding syscall number which is okay for x86-64, and i made t strictly bound, i will change it and add
<sys/syscall.h> to include ARM and RISC-V. And a dead lock riskgood mending, I will rlease the project today.
I finally present "ZeroShadow"
think of it like an automated debugger. you can watch functions execute, read memory or change how an app behaves on the fly without needing the source code.
it is a lightweight dynamic binary instrumentation engine for elf files. you use it to hook functions, trace execution paths and unpack malware without the massive overhead of heavy tools like frida.
https://github.com/PicasoTheDeal/ZeroShadow
think of it like an automated debugger. you can watch functions execute, read memory or change how an app behaves on the fly without needing the source code.
it is a lightweight dynamic binary instrumentation engine for elf files. you use it to hook functions, trace execution paths and unpack malware without the massive overhead of heavy tools like frida.
https://github.com/PicasoTheDeal/ZeroShadow
GitHub
GitHub - PicasoTheDeal/ZeroShadow: ELF binary tracing and instrumentation
ELF binary tracing and instrumentation. Contribute to PicasoTheDeal/ZeroShadow development by creating an account on GitHub.
đ„5
Okay I am so locked in right now, so boom next proeject lol.