𓆣 đ”—Ì¶đ”ąÌ¶đ”±Ì¶đ”°Ì¶đ”±Ì¶đ”žÌ¶đ” Ì¶đ”šÌ¶ 𓆣
107 subscribers
176 photos
2 videos
4 files
43 links
Download Telegram
The debug is taking more time than the actual code architecture desing and writing.
picasothedealer_com@cloudshell:~/ZeroShadow$ ./runtime/shadow_stub & sleep 0.5 && sudo ./ZeroShadow $! ./runtime/shadow_stub
[6] 8635

[6]+ Stopped ./runtime/shadow_stub
[*] booting ZeroShadow supervisor...
[+] memory boundaries mapped.
[*] hooking PID: 8635...
[+] connected to prosses: 8635. monitoring loop active.
[*] dynamic ASLR base offset applied to all monitored regions.
[*] draining any leftover signals...
[DEBUG] drain signal: 19
[DEBUG] drain signal: 5
[DEBUG] drained, RIP: 0x5749d70b801f
[+] synchronised and drained. Starting main loop.
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8026 signal: 5
region:
0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8029 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802c signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b802f signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b8031 signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b803b signal: 5
region: 0x95974652084224 - 0x95974652088320
[DEBUG] Check RIP: 0x5749d70b803b signal: b
region: 0x95974652084224 - 0x95974652088320
[!] CRITICAL: control flow hijack detected! RIP: 0x5749d70b803b signal: b
Error: supervisor loop drooped or connection lost.
[6]+ Killed ./runtime/shadow_stub
I don't want to write the offset boundary "by hand" so i will use ai, jk. I will read it from the

exact executable segment boundaries


directly from the process memory map.
okay boom, it has detected it correctly.
picasothedealer_com@cloudshell:~/ZeroShadow$ ./runtime/shadow_stub & sleep 0.5 && sudo ./ZeroShadow $! ./runtime/shadow_stub
[6] 11834

[6]+ Stopped ./runtime/shadow_stub
[*] booting ZeroShadow supervisor...
[+] memory boundaries mapped.
[*] hooking PID: 11834...
[+] connected to prosses: 11834. monitoring loop active.
[*] loaded 2 executable segment(s) from maps.
[*] draining any leftover signals...
[DEBUG] drain signal: 19
[DEBUG] drain signal: 5
[DEBUG] drained, RIP: 0x58075f76301f
[+] synchronised and drained. Starting main loop.
[!] SIGSEGV at instruction 0x58075f76303b, fault address = 0x0
[!] CRITICAL: control flow hijack detected! RIP: 0x58075f76303b signal: b
Error: supervisor loop drooped or connection lost.
[6]+ Killed ./runtime/shadow_stub
if (sig != SIGTRAP || !verify_instruction_pointer(regs)) {
std::cerr << "[!] CRITICAL: control flow hijack detected! " << "RIP: 0x" << std::hex << regs.rip << " signal: " << std::dec << sig << "\n";
ptrace(PTRACE_KILL, pid, nullptr, nullptr);
waitpid(pid, &status, 0); // read the killed process
return false;
}


This logic is a bit greedy it's not differentiating b/n a crash and a hijack on the system. Too greedy it treets a hijack as a crash and a crash as a hijack.
Okay some tweaks have been done and the output is amazing, mostly complete it has detected the memory fault by the dummy shadow_stub.s

picasothedealer_com@cloudshell:~/ZeroShadow$ ./runtime/shadow_stub & sleep 0.5 && sudo ./ZeroShadow $! ./runtime/shadow_stub
[6] 12577

[6]+ Stopped ./runtime/shadow_stub
[*] booting ZeroShadow supervisor...
[+] memory boundaries mapped.
[*] hooking PID: 12577...
[+] connected to prosses: 12577. monitoring loop active.
[*] loaded 2 executable segment(s) from maps.
[*] draining any leftover signals...
[DEBUG] drain signal: 19
[DEBUG] drain signal: 5
[DEBUG] drained, RIP: 0x572eb2d8901f
[+] synchronised and drained. Starting main loop.
[!] SIGSEGV at instruction 0x572eb2d8903b, fault address = 0x0
[!] CRITICAL: Memory Fault (SIGSEGV) at 0x572eb2d8903b accessing invalid address 0x0
Error: supervisor loop drooped or connection lost.
[6]+ Killed ./runtime/shadow_stub
for real tho i really hate putting the PID every time i am gonna test so yeah i ma add some lines
vuala but i feel like i will need to test it more before launching too,
I am 19, atlast gotta pack my bag after matrik I guess
👀6
found one bug false alert fires up because i am missing one executable memory region is missing from the valid_maps list.
So now, ZeroShadow is missing some things which are:
The "Signal Race" (Asynchronous Bypassing)

,
Time-of-Check to Time-of-Use (TOCTOU)

,
Direct Memory Access (DMA) / Side-Channel

,
Signal Masking

.
Okay done, so another debug i was using hardcoding syscall number which is okay for x86-64, and i made t strictly bound, i will change it and add <sys/syscall.h> to include ARM and RISC-V. And a dead lock risk