minute ago the assembly file was running too fast for the tracer to catch now the tracer is too fast for the assembly
okay the address is repeating
003 , 006 and 009, so basically nothing is wrong with the assembly code or the tracer code the thing is the assembly code is running as it should in a loop those three address shows the CPU executing those three instruction and then bacl to start. Because these address falls inside the allowed segment, ZeroShadow thinks everything is fine and it is and keeps monitoring the loop. SO this is what is happening ZeroShadow is firing PTRACE_SINGLESTEP then checking the RIP, it looks at it and confirms it's safe then repeat. so now what my code is missing is as the stack is safe it never hit the error logic and because it's a loop it never exits. so it is just monitoring the heartbeat that never change. SO I will add a heartbeat or escape logic.I messed up in the calculation, i forgot that when the c++ zeroshadow jumps in the way and because it uses ptrace it is going at approximately 10,000 ptrace steps per second. If according to the iteration i submitted which is
0x1FFFFFFFFF WHICH IS ABOUT 137 BILLION iteration, the assembly would have finished about maybe 30 sec, but because of that ptrace it would have took 60 days before it reaches the hijacker.Project needed to be hault dad came home and it's families movie time. I will continue tomorrow morning
𓆣 𝔗̶𝔢̶𝔱̶𝔰̶𝔱̶𝔞̶𝔠̶𝔨̶ 𓆣
Damn 14 followers on github
Suspicious pattern tho, new followers have either forked the same repo or just have same bio.
👀1