đŁ đ̶đąÌ¶đ±Ì¶đ°Ì¶đ±Ì¶đ̶đ ̶đšÌ¶ đŁ
Damn 14 followers on github
Suspicious pattern tho, new followers have either forked the same repo or just have same bio.
đ1
This media is not supported in your browser
VIEW IN TELEGRAM
The debug is taking more time than the actual code architecture desing and writing.
picasothedealer_com@cloudshell:~/ZeroShadow$ ./runtime/shadow_stub & sleep 0.5 && sudo ./ZeroShadow $! ./runtime/shadow_stub
[6] 8635
[6]+ Stopped ./runtime/shadow_stub
[*] booting ZeroShadow supervisor...
[+] memory boundaries mapped.
[*] hooking PID: 8635...
[+] connected to prosses: 8635. monitoring loop active.
[*] dynamic ASLR base offset applied to all monitored regions.
[*] draining any leftover signals...
[DEBUG] drain signal: 19
[DEBUG] drain signal: 5
[DEBUG] drained, RIP: 0x5749d70b801f
[+] synchronised and drained. Starting main loop.
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region:0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8031 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b803b signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b803b signal: b
region: 0x95974652084224 - 0x95974652088320
[!] CRITICAL: control flow hijack detected! RIP: 0x5749d70b803b signal: b
Error: supervisor loop drooped or connection lost.
[6]+ Killed ./runtime/shadow_stub
đŁ đ̶đąÌ¶đ±Ì¶đ°Ì¶đ±Ì¶đ̶đ ̶đšÌ¶ đŁ
0x95974652084224 - 0x95974652088320 [DEBUG] Check RIP: 0x5749d70b8029 signal: 5 region: 0x95974652084224 - 0x95974652088320 [DEBUG] Check RIP: 0x5749d70b802c signal: 5 region: 0x95974652084224 - 0x95974652088320 [DEBUG] Check RIP: 0x5749d70b802fâŠ
aight okay, now it's detecting the jump. Just a slight problem the allowed map was corrupted and then the verify_instructur_pointer see's it doesn't make sense and the stop that happened at the end doesn't show what happened.
I don't want to write the offset boundary "by hand" so i will use ai, jk. I will read it from the
directly from the process memory map.
exact executable segment boundaries
directly from the process memory map.
okay boom, it has detected it correctly.
picasothedealer_com@cloudshell:~/ZeroShadow$ ./runtime/shadow_stub & sleep 0.5 && sudo ./ZeroShadow $! ./runtime/shadow_stub
[6] 11834
[6]+ Stopped ./runtime/shadow_stub
[*] booting ZeroShadow supervisor...
[+] memory boundaries mapped.
[*] hooking PID: 11834...
[+] connected to prosses: 11834. monitoring loop active.
[*] loaded 2 executable segment(s) from maps.
[*] draining any leftover signals...
[DEBUG] drain signal: 19
[DEBUG] drain signal: 5
[DEBUG] drained, RIP: 0x58075f76301f
[+] synchronised and drained. Starting main loop.
[!] SIGSEGV at instruction 0x58075f76303b, fault address = 0x0
[!] CRITICAL: control flow hijack detected! RIP: 0x58075f76303b signal: b
Error: supervisor loop drooped or connection lost.
[6]+ Killed ./runtime/shadow_stubif (sig != SIGTRAP || !verify_instruction_pointer(regs)) {
std::cerr << "[!] CRITICAL: control flow hijack detected! " << "RIP: 0x" << std::hex << regs.rip << " signal: " << std::dec << sig << "\n";
ptrace(PTRACE_KILL, pid, nullptr, nullptr);
waitpid(pid, &status, 0); // read the killed process
return false;
}
This logic is a bit greedy it's not differentiating b/n a crash and a hijack on the system. Too greedy it treets a hijack as a crash and a crash as a hijack.Okay some tweaks have been done and the output is amazing, mostly complete it has detected the memory fault by the dummy shadow_stub.s
picasothedealer_com@cloudshell:~/ZeroShadow$ ./runtime/shadow_stub & sleep 0.5 && sudo ./ZeroShadow $! ./runtime/shadow_stub
[6] 12577
[6]+ Stopped ./runtime/shadow_stub
[*] booting ZeroShadow supervisor...
[+] memory boundaries mapped.
[*] hooking PID: 12577...
[+] connected to prosses: 12577. monitoring loop active.
[*] loaded 2 executable segment(s) from maps.
[*] draining any leftover signals...
[DEBUG] drain signal: 19
[DEBUG] drain signal: 5
[DEBUG] drained, RIP: 0x572eb2d8901f
[+] synchronised and drained. Starting main loop.
[!] SIGSEGV at instruction 0x572eb2d8903b, fault address = 0x0
[!] CRITICAL: Memory Fault (SIGSEGV) at 0x572eb2d8903b accessing invalid address 0x0
Error: supervisor loop drooped or connection lost.
[6]+ Killed ./runtime/shadow_stubnow for the stack based buffer overflow test
for real tho i really hate putting the PID every time i am gonna test so yeah i ma add some lines
I am 19, atlast gotta pack my bag after matrik I guess
đ6
So now, ZeroShadow is missing some things which are:
,
,
,
.
The "Signal Race" (Asynchronous Bypassing),
Time-of-Check to Time-of-Use (TOCTOU),
Direct Memory Access (DMA) / Side-Channel,
Signal Masking.
Okay done, so another debug i was using hardcoding syscall number which is okay for x86-64, and i made t strictly bound, i will change it and add
<sys/syscall.h> to include ARM and RISC-V. And a dead lock riskgood mending, I will rlease the project today.