This media is not supported in your browser
VIEW IN TELEGRAM
The debug is taking more time than the actual code architecture desing and writing.
picasothedealer_com@cloudshell:~/ZeroShadow$ ./runtime/shadow_stub & sleep 0.5 && sudo ./ZeroShadow $! ./runtime/shadow_stub
[6] 8635
[6]+ Stopped ./runtime/shadow_stub
[*] booting ZeroShadow supervisor...
[+] memory boundaries mapped.
[*] hooking PID: 8635...
[+] connected to prosses: 8635. monitoring loop active.
[*] dynamic ASLR base offset applied to all monitored regions.
[*] draining any leftover signals...
[DEBUG] drain signal: 19
[DEBUG] drain signal: 5
[DEBUG] drained, RIP: 0x5749d70b801f
[+] synchronised and drained. Starting main loop.
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region:0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8031 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b803b signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b803b signal: b
region: 0x95974652084224 - 0x95974652088320
[!] CRITICAL: control flow hijack detected! RIP: 0x5749d70b803b signal: b
Error: supervisor loop drooped or connection lost.
[6]+ Killed ./runtime/shadow_stub
đŁ đ̶đąÌ¶đ±Ì¶đ°Ì¶đ±Ì¶đ̶đ ̶đšÌ¶ đŁ
0x95974652084224 - 0x95974652088320 [DEBUG] Check RIP: 0x5749d70b8029 signal: 5 region: 0x95974652084224 - 0x95974652088320 [DEBUG] Check RIP: 0x5749d70b802c signal: 5 region: 0x95974652084224 - 0x95974652088320 [DEBUG] Check RIP: 0x5749d70b802fâŠ
aight okay, now it's detecting the jump. Just a slight problem the allowed map was corrupted and then the verify_instructur_pointer see's it doesn't make sense and the stop that happened at the end doesn't show what happened.
I don't want to write the offset boundary "by hand" so i will use ai, jk. I will read it from the
directly from the process memory map.
exact executable segment boundaries
directly from the process memory map.
okay boom, it has detected it correctly.
picasothedealer_com@cloudshell:~/ZeroShadow$ ./runtime/shadow_stub & sleep 0.5 && sudo ./ZeroShadow $! ./runtime/shadow_stub
[6] 11834
[6]+ Stopped ./runtime/shadow_stub
[*] booting ZeroShadow supervisor...
[+] memory boundaries mapped.
[*] hooking PID: 11834...
[+] connected to prosses: 11834. monitoring loop active.
[*] loaded 2 executable segment(s) from maps.
[*] draining any leftover signals...
[DEBUG] drain signal: 19
[DEBUG] drain signal: 5
[DEBUG] drained, RIP: 0x58075f76301f
[+] synchronised and drained. Starting main loop.
[!] SIGSEGV at instruction 0x58075f76303b, fault address = 0x0
[!] CRITICAL: control flow hijack detected! RIP: 0x58075f76303b signal: b
Error: supervisor loop drooped or connection lost.
[6]+ Killed ./runtime/shadow_stubif (sig != SIGTRAP || !verify_instruction_pointer(regs)) {
std::cerr << "[!] CRITICAL: control flow hijack detected! " << "RIP: 0x" << std::hex << regs.rip << " signal: " << std::dec << sig << "\n";
ptrace(PTRACE_KILL, pid, nullptr, nullptr);
waitpid(pid, &status, 0); // read the killed process
return false;
}
This logic is a bit greedy it's not differentiating b/n a crash and a hijack on the system. Too greedy it treets a hijack as a crash and a crash as a hijack.Okay some tweaks have been done and the output is amazing, mostly complete it has detected the memory fault by the dummy shadow_stub.s
picasothedealer_com@cloudshell:~/ZeroShadow$ ./runtime/shadow_stub & sleep 0.5 && sudo ./ZeroShadow $! ./runtime/shadow_stub
[6] 12577
[6]+ Stopped ./runtime/shadow_stub
[*] booting ZeroShadow supervisor...
[+] memory boundaries mapped.
[*] hooking PID: 12577...
[+] connected to prosses: 12577. monitoring loop active.
[*] loaded 2 executable segment(s) from maps.
[*] draining any leftover signals...
[DEBUG] drain signal: 19
[DEBUG] drain signal: 5
[DEBUG] drained, RIP: 0x572eb2d8901f
[+] synchronised and drained. Starting main loop.
[!] SIGSEGV at instruction 0x572eb2d8903b, fault address = 0x0
[!] CRITICAL: Memory Fault (SIGSEGV) at 0x572eb2d8903b accessing invalid address 0x0
Error: supervisor loop drooped or connection lost.
[6]+ Killed ./runtime/shadow_stubnow for the stack based buffer overflow test
for real tho i really hate putting the PID every time i am gonna test so yeah i ma add some lines
I am 19, atlast gotta pack my bag after matrik I guess
đ6
So now, ZeroShadow is missing some things which are:
,
,
,
.
The "Signal Race" (Asynchronous Bypassing),
Time-of-Check to Time-of-Use (TOCTOU),
Direct Memory Access (DMA) / Side-Channel,
Signal Masking.
Okay done, so another debug i was using hardcoding syscall number which is okay for x86-64, and i made t strictly bound, i will change it and add
<sys/syscall.h> to include ARM and RISC-V. And a dead lock riskgood mending, I will rlease the project today.