KitPloit - PenTest Tools!
Exrop - Automatic ROP Chain Generation
___________________________
@hacking_Attack
@Hacking_Video
Exrop - Automatic ROP Chain Generation
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Exrop - Automatic ROP Chain Generation
Exrop - Automatic ROP Chain Generation
http://www.kitploit.com/2022/02/exrop-automatic-rop-chain-generation.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/02/exrop-automatic-rop-chain-generation.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Exrop - Automatic ROP Chain Generation
Exrop is automatic ROP chains generator (https://www.kitploit.com/search/label/Generator) tool which can build gadget chain automatically from given binary and constraints Requirements : Triton (https://github.com/JonathanSalwan/Triton), ROPGadget (https://github.com/JonathanSalwan/ROPgadget) Only support for x86-64 for now! Features: handling non-return gadgets (https://www.kitploit.com/search/label/Gadgets) (jmp reg, call reg) set registers (rdi=0xxxxxx, rsi=0xxxxxx) set register to register (rdi=rax) write to mem write string/bytes to mem function call (open('/etc/passwd',0)) pass register in function call (read('rax', bss, 0x100)) avoiding badchars stack pivoting (https://www.kitploit.com/search/label/Pivoting) (Exrop.stack_pivot) syscall (Exrop.syscall) see examples (https://github.com/d4em0n/exrop/blob/master/examples)
Installation install python (3.6 is recomended and tested) install triton (https://triton.quarkslab.com/documentation/doxygen/index.html#linux_install_sec), make sure you add -DPYTHON36=on as cmake option install ropgadget (https://www.kitploit.com/search/label/ROPgadget) (https://github.com/JonathanSalwan/ROPgadget) to install exrop, easily add export PYTHONPATH=/path/to/exrop:$PYTHONPATH in your .bashrc (depends on your shell) Demo from Exrop import Exrop
rop = Exrop("/bin/ls")
rop.find_gadgets(cache=True)
print("write-regs gadgets: rdi=0x41414141, rsi:0x42424242, rdx: 0x43434343, rax:0x44444444, rbx=0x45454545")
chain = rop.set_regs({'rdi':0x41414141, 'rsi': 0x42424242, 'rdx':0x43434343, 'rax':0x44444444, 'rbx': 0x45454545})
chain.dump()
print("write-what-where gadgets: [0x41414141]=0xdeadbeefff, [0x43434343]=0x110011")
chain = rop.set_writes({0x41414141: 0xdeadbeefff, 0x43434343: 0x00110011})
chain.dump()
print("write-string gadgets 0x41414141=\"Hello world!\\n\"")
chain = rop.set_string({0x41414141: "Hello world!\n"})
chain.dump()
print("func-call gadgets 0x41414141(0x20, 0x30, \"Hello\")")
chain = rop.func_call(0x41414141, (0x20, 0x30, "Hello"), 0x7fffff00)
chain.dump() Output: write-regs gadget: rdi=0x41414141, rsi:0x42424242, rdx: 0x43434343, rax:0x44444444, rbx=0x45454545
$RSP+0x0000 : 0x00000000000060d0 # pop rbx; ret
$RSP+0x0008 : 0x0000000044444444
$RSP+0x0010 : 0x0000000000014852 # mov rax, rbx; pop rbx; ret
$RSP+0x0018 : 0x0000000000000000
$RSP+0x0020 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0028 : 0x0000000041414141
$RSP+0x0030 : 0x000000000000629c # pop rsi; ret
$RSP+0x0038 : 0x0000000042424242
$RSP+0x0040 : 0x0000000000003a62 # pop rdx; ret
$RSP+0x0048 : 0x0000000043434343
$RSP+0x0050 : 0x00000000000060d0 # pop rbx; ret
$RSP+0x0058 : 0x0000000045454545
write-what-where gadgets: [0x41414141]=0xdeadbeefff, [0x43434343]=0x110011
$RSP+0x0000 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0008 : 0x000000deadbeefff
$RSP+0x0010 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0018 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0020 : 0x0000000041414139
$RSP+0x0028 : 0 x000000000000e0fb # mov qword ptr [rdi + 8], rax; ret
$RSP+0x0030 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0038 : 0x0000000000110011
$RSP+0x0040 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0048 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0050 : 0x000000004343433b
$RSP+0x0058 : 0x000000000000e0fb # mov qword ptr [rdi + 8], rax; ret
write-string gadgets 0x41414141="Hello world!\n"
$RSP+0x0000 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0008 : 0x6f77206f6c6c6548
$RSP+0x0010 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0018 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0020 : 0x0000000041414139
$RSP+0x0028 : 0x000000000000e0fb # mov qword ptr [rdi + 8], rax; ret
$RSP+0x0030 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0038 : 0x0000000a21646c72
$RSP+0x0040 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0048 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0050 : 0x0000000041414141
$RSP+0x0058 : 0x000000000000e0 fb # mov qword ptr [rdi + 8], rax; ret
func-call gadgets 0x41414141(0x20, 0x30, "Hello")
___________________________
@hacking_Attack
@Hacking_Video
Installation install python (3.6 is recomended and tested) install triton (https://triton.quarkslab.com/documentation/doxygen/index.html#linux_install_sec), make sure you add -DPYTHON36=on as cmake option install ropgadget (https://www.kitploit.com/search/label/ROPgadget) (https://github.com/JonathanSalwan/ROPgadget) to install exrop, easily add export PYTHONPATH=/path/to/exrop:$PYTHONPATH in your .bashrc (depends on your shell) Demo from Exrop import Exrop
rop = Exrop("/bin/ls")
rop.find_gadgets(cache=True)
print("write-regs gadgets: rdi=0x41414141, rsi:0x42424242, rdx: 0x43434343, rax:0x44444444, rbx=0x45454545")
chain = rop.set_regs({'rdi':0x41414141, 'rsi': 0x42424242, 'rdx':0x43434343, 'rax':0x44444444, 'rbx': 0x45454545})
chain.dump()
print("write-what-where gadgets: [0x41414141]=0xdeadbeefff, [0x43434343]=0x110011")
chain = rop.set_writes({0x41414141: 0xdeadbeefff, 0x43434343: 0x00110011})
chain.dump()
print("write-string gadgets 0x41414141=\"Hello world!\\n\"")
chain = rop.set_string({0x41414141: "Hello world!\n"})
chain.dump()
print("func-call gadgets 0x41414141(0x20, 0x30, \"Hello\")")
chain = rop.func_call(0x41414141, (0x20, 0x30, "Hello"), 0x7fffff00)
chain.dump() Output: write-regs gadget: rdi=0x41414141, rsi:0x42424242, rdx: 0x43434343, rax:0x44444444, rbx=0x45454545
$RSP+0x0000 : 0x00000000000060d0 # pop rbx; ret
$RSP+0x0008 : 0x0000000044444444
$RSP+0x0010 : 0x0000000000014852 # mov rax, rbx; pop rbx; ret
$RSP+0x0018 : 0x0000000000000000
$RSP+0x0020 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0028 : 0x0000000041414141
$RSP+0x0030 : 0x000000000000629c # pop rsi; ret
$RSP+0x0038 : 0x0000000042424242
$RSP+0x0040 : 0x0000000000003a62 # pop rdx; ret
$RSP+0x0048 : 0x0000000043434343
$RSP+0x0050 : 0x00000000000060d0 # pop rbx; ret
$RSP+0x0058 : 0x0000000045454545
write-what-where gadgets: [0x41414141]=0xdeadbeefff, [0x43434343]=0x110011
$RSP+0x0000 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0008 : 0x000000deadbeefff
$RSP+0x0010 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0018 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0020 : 0x0000000041414139
$RSP+0x0028 : 0 x000000000000e0fb # mov qword ptr [rdi + 8], rax; ret
$RSP+0x0030 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0038 : 0x0000000000110011
$RSP+0x0040 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0048 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0050 : 0x000000004343433b
$RSP+0x0058 : 0x000000000000e0fb # mov qword ptr [rdi + 8], rax; ret
write-string gadgets 0x41414141="Hello world!\n"
$RSP+0x0000 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0008 : 0x6f77206f6c6c6548
$RSP+0x0010 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0018 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0020 : 0x0000000041414139
$RSP+0x0028 : 0x000000000000e0fb # mov qword ptr [rdi + 8], rax; ret
$RSP+0x0030 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0038 : 0x0000000a21646c72
$RSP+0x0040 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0048 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0050 : 0x0000000041414141
$RSP+0x0058 : 0x000000000000e0 fb # mov qword ptr [rdi + 8], rax; ret
func-call gadgets 0x41414141(0x20, 0x30, "Hello")
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
$RSP+0x0000 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0008 : 0x0000006f6c6c6548
$RSP+0x0010 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0018 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0020 : 0x000000007ffffef8
$RSP+0x0028 : 0x000000000000e0fb # mov qword ptr [rdi + 8], rax; ret
$RSP+0x0030 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0038 : 0x0000000000000020
$RSP+0x0040 : 0x000000000000629c # pop rsi; ret
$RSP+0x0048 : 0x0000000000000030
$RSP+0x0050 : 0x0000000000003a62 # pop rdx; ret
$RSP+0x0058 : 0x000000007fffff00
$RSP+0x0060 : 0x0000000041414141
python3 tests.py 1,48s user 0,05s system 97% cpu 1,566 total
Another example: open-read-write gadgets! from pwn import *
import time
from Exrop import Exrop
binname = "/lib/x86_64-linux-gnu/libc.so.6"
libc = ELF(binname, checksec=False)
open = libc.symbols['open']
read = libc.symbols['read']
write = libc.symbols['write']
bss = libc.bss()
t = time.mktime(time.gmtime())
rop = Exrop(binname)
rop.find_gadgets(cache=True)
print("open('/etc/passwd', 0)")
chain = rop.func_call(open, ("/etc/passwd", 0), bss)
chain.set_base_addr(0x00007ffff79e4000)
chain.dump()
print("read('rax', bss, 0x100)") # register can be used as argument too!
chain = rop.func_call(read, ('rax', bss, 0x100))
chain.set_base_addr(0x00007ffff79e4000)
chain.dump()
print("write(1, bss, 0x100)")
chain = rop.func_call(write, (1, bss, 0x100))
chain.set_base_addr(0x00007ffff79e4000)
chain.dump()
print("done in {}s".format(time.mktime(time.gmtime ()) - t)) Output: (0x0002155f) # pop rdi ; ret $RSP+0x0038 : 0x00007ffff7a0555f # pop rdi ; ret $RSP+0x0040 : 0x7361702f6374652f $RSP+0x0048 : 0x00007ffff7b251c7 # mov qword ptr [r9], rdi ; ret $RSP+0x0050 : 0x00007ffff7a05a45 # pop r13 ; ret $RSP+0x0058 : 0x00000000003ec868 $RSP+0x0060 : 0x00007ffff7a7630c # xor edi, edi ; pop rbx ; mov rax, rdi ; pop rbp ; pop r12 ; ret $RSP+0x0068 : 0x00007ffff7a0555f $RSP+0x0070 : 0x0000000000000000 $RSP+0x0078 : 0x0000000000000000 $RSP+0x0080 : 0x00007ffff7a06b8a # mov r9, r13 ; call rbx: next -> (0x0002155f) # pop rdi ; ret $RSP+0x0088 : 0x00007ffff7a0555f # pop rdi ; ret $RSP+0x0090 : 0x0000000000647773 $RSP+0x0098 : 0x00007ffff7b251c7 # mov qword ptr [r9], rdi ; ret $RSP+0x00a0 : 0x00007ffff7a62c70 # xor esi, esi ; mov rax, rsi ; ret $RSP+0x00a8 : 0x00007ffff7a0555f # pop rdi ; ret $RSP+0x00b0 : 0x00000000003ec860 $RSP+0x00b8 : 0x000000000010fc40 read('rax', bss, 0x100) $RSP+0x0000 : 0x00007ffff7a71362 # mov dh, 0xc5 ; pop rbx ; pop rbp ; pop r12 ; ret $RSP+0x0008 : 0x0000000000000000 $RSP+0x0010 : 0x0000000000000000 $RSP+0x0018 : 0x00007ffff7a0555f $RSP+0x0020 : 0x00007ffff7aea899 # mov r8, rax ; call r12: next -> (0x0002155f) # pop rdi ; ret $RSP+0x0028 : 0x00007ffff7b4a3b1 # pop rax ; pop rdx ; pop rbx ; ret $RSP+0x0030 : 0x00007ffff79e5b96 $RSP+0x0038 : 0x0000000000000000 $RSP+0x0040 : 0x0000000000000000 $RSP+0x0048 : 0x00007ffff7a7fa08 # mov rdi, r8 ; call rax: next -> (0x00001b96) # pop rdx ; ret $RSP+0x0050 : 0x00007ffff79e5b96 # pop rdx ; ret $RSP+0x0058 : 0x0000000000000100 $RSP+0x0060 : 0x00007ffff7a07e6a # pop rsi ; ret $RSP+0x0068 : 0x00000000003ec860 $RSP+0x0070 : 0x0000000000110070 write(1, bss, 0x100) $RSP+0x0000 : 0x00007ffff7a0555f # pop rdi ; ret $RSP+0x0008 : 0x0000000000000001 $RSP+0x0010 : 0x00007ffff79e5b96 # pop rdx ; ret $RSP+0x0018 : 0x0000000000000100 $RSP+0x0020 : 0x00007ffff7a07e6a # pop rsi ; ret $RSP+0x0028 : 0x00000000003ec860 $RSP+0x0030 : 0x0000000000110140 done in 3.0s (Running on: A9-9420 RADEON R5 2C+3G (2) @ 3.000GHz (using cached))">open('/etc/passwd', 0)
$RSP+0x0000 : 0x00007ffff7a05a45 # pop r13 ; ret
$RSP+0x0008 : 0x00000000003ec860
$RSP+0x0010 : 0x00007ffff7a7630c # xor edi, edi ; pop rbx ; mov rax, rdi ; pop rbp ; pop r12 ; ret
$RSP+0x0018 : 0x00007ffff7a0555f
$RSP+0x0020 : 0x0000000000000000
$RSP+0x0028 : 0x0000000000000000
$RSP+0x0030 : 0x00007ffff7a06b8a # mov r9, r13 ; call rbx: next -> (0x0002155f) # pop rdi ; ret
___________________________
@hacking_Attack
@Hacking_Video
$RSP+0x0008 : 0x0000006f6c6c6548
$RSP+0x0010 : 0x000000000000d91f # mov rax, rdi; ret
$RSP+0x0018 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0020 : 0x000000007ffffef8
$RSP+0x0028 : 0x000000000000e0fb # mov qword ptr [rdi + 8], rax; ret
$RSP+0x0030 : 0x0000000000004ce5 # pop rdi; ret
$RSP+0x0038 : 0x0000000000000020
$RSP+0x0040 : 0x000000000000629c # pop rsi; ret
$RSP+0x0048 : 0x0000000000000030
$RSP+0x0050 : 0x0000000000003a62 # pop rdx; ret
$RSP+0x0058 : 0x000000007fffff00
$RSP+0x0060 : 0x0000000041414141
python3 tests.py 1,48s user 0,05s system 97% cpu 1,566 total
Another example: open-read-write gadgets! from pwn import *
import time
from Exrop import Exrop
binname = "/lib/x86_64-linux-gnu/libc.so.6"
libc = ELF(binname, checksec=False)
open = libc.symbols['open']
read = libc.symbols['read']
write = libc.symbols['write']
bss = libc.bss()
t = time.mktime(time.gmtime())
rop = Exrop(binname)
rop.find_gadgets(cache=True)
print("open('/etc/passwd', 0)")
chain = rop.func_call(open, ("/etc/passwd", 0), bss)
chain.set_base_addr(0x00007ffff79e4000)
chain.dump()
print("read('rax', bss, 0x100)") # register can be used as argument too!
chain = rop.func_call(read, ('rax', bss, 0x100))
chain.set_base_addr(0x00007ffff79e4000)
chain.dump()
print("write(1, bss, 0x100)")
chain = rop.func_call(write, (1, bss, 0x100))
chain.set_base_addr(0x00007ffff79e4000)
chain.dump()
print("done in {}s".format(time.mktime(time.gmtime ()) - t)) Output: (0x0002155f) # pop rdi ; ret $RSP+0x0038 : 0x00007ffff7a0555f # pop rdi ; ret $RSP+0x0040 : 0x7361702f6374652f $RSP+0x0048 : 0x00007ffff7b251c7 # mov qword ptr [r9], rdi ; ret $RSP+0x0050 : 0x00007ffff7a05a45 # pop r13 ; ret $RSP+0x0058 : 0x00000000003ec868 $RSP+0x0060 : 0x00007ffff7a7630c # xor edi, edi ; pop rbx ; mov rax, rdi ; pop rbp ; pop r12 ; ret $RSP+0x0068 : 0x00007ffff7a0555f $RSP+0x0070 : 0x0000000000000000 $RSP+0x0078 : 0x0000000000000000 $RSP+0x0080 : 0x00007ffff7a06b8a # mov r9, r13 ; call rbx: next -> (0x0002155f) # pop rdi ; ret $RSP+0x0088 : 0x00007ffff7a0555f # pop rdi ; ret $RSP+0x0090 : 0x0000000000647773 $RSP+0x0098 : 0x00007ffff7b251c7 # mov qword ptr [r9], rdi ; ret $RSP+0x00a0 : 0x00007ffff7a62c70 # xor esi, esi ; mov rax, rsi ; ret $RSP+0x00a8 : 0x00007ffff7a0555f # pop rdi ; ret $RSP+0x00b0 : 0x00000000003ec860 $RSP+0x00b8 : 0x000000000010fc40 read('rax', bss, 0x100) $RSP+0x0000 : 0x00007ffff7a71362 # mov dh, 0xc5 ; pop rbx ; pop rbp ; pop r12 ; ret $RSP+0x0008 : 0x0000000000000000 $RSP+0x0010 : 0x0000000000000000 $RSP+0x0018 : 0x00007ffff7a0555f $RSP+0x0020 : 0x00007ffff7aea899 # mov r8, rax ; call r12: next -> (0x0002155f) # pop rdi ; ret $RSP+0x0028 : 0x00007ffff7b4a3b1 # pop rax ; pop rdx ; pop rbx ; ret $RSP+0x0030 : 0x00007ffff79e5b96 $RSP+0x0038 : 0x0000000000000000 $RSP+0x0040 : 0x0000000000000000 $RSP+0x0048 : 0x00007ffff7a7fa08 # mov rdi, r8 ; call rax: next -> (0x00001b96) # pop rdx ; ret $RSP+0x0050 : 0x00007ffff79e5b96 # pop rdx ; ret $RSP+0x0058 : 0x0000000000000100 $RSP+0x0060 : 0x00007ffff7a07e6a # pop rsi ; ret $RSP+0x0068 : 0x00000000003ec860 $RSP+0x0070 : 0x0000000000110070 write(1, bss, 0x100) $RSP+0x0000 : 0x00007ffff7a0555f # pop rdi ; ret $RSP+0x0008 : 0x0000000000000001 $RSP+0x0010 : 0x00007ffff79e5b96 # pop rdx ; ret $RSP+0x0018 : 0x0000000000000100 $RSP+0x0020 : 0x00007ffff7a07e6a # pop rsi ; ret $RSP+0x0028 : 0x00000000003ec860 $RSP+0x0030 : 0x0000000000110140 done in 3.0s (Running on: A9-9420 RADEON R5 2C+3G (2) @ 3.000GHz (using cached))">open('/etc/passwd', 0)
$RSP+0x0000 : 0x00007ffff7a05a45 # pop r13 ; ret
$RSP+0x0008 : 0x00000000003ec860
$RSP+0x0010 : 0x00007ffff7a7630c # xor edi, edi ; pop rbx ; mov rax, rdi ; pop rbp ; pop r12 ; ret
$RSP+0x0018 : 0x00007ffff7a0555f
$RSP+0x0020 : 0x0000000000000000
$RSP+0x0028 : 0x0000000000000000
$RSP+0x0030 : 0x00007ffff7a06b8a # mov r9, r13 ; call rbx: next -> (0x0002155f) # pop rdi ; ret
___________________________
@hacking_Attack
@Hacking_Video
$RSP+0x0038 : 0x00007ffff7a0555f # pop rdi ; ret
$RSP+0x0040 : 0x7361702f6374652f
$RSP+0x0048 : 0x00007ffff7b251c7 # mov qword ptr [r9], rdi ; ret
$RSP+0x0050 : 0x00007ffff7a05a45 # pop r13 ; ret
$RSP+0x0058 : 0x00000000003ec868
$RSP+0x0060 : 0x00007ffff7a7630c # xor edi, edi ; pop rbx ; mov rax, rdi ; pop rbp ; pop r12 ; ret
$RSP+0x0068 : 0x00007ffff7a0555f
$RSP+0x0070 : 0x0000000000000000
$RSP+0x0078 : 0x0000000000000000
$RSP+0x0 080 : 0x00007ffff7a06b8a # mov r9, r13 ; call rbx: next -> (0x0002155f) # pop rdi ; ret
$RSP+0x0088 : 0x00007ffff7a0555f # pop rdi ; ret
$RSP+0x0090 : 0x0000000000647773
$RSP+0x0098 : 0x00007ffff7b251c7 # mov qword ptr [r9], rdi ; ret
$RSP+0x00a0 : 0x00007ffff7a62c70 # xor esi, esi ; mov rax, rsi ; ret
$RSP+0x00a8 : 0x00007ffff7a0555f # pop rdi ; ret
$RSP+0x00b0 : 0x00000000003ec860
$RSP+0x00b8 : 0x000000000010fc40
read('rax', bss, 0x100)
$RSP+0x0000 : 0x00007ffff7a71362 # mov dh, 0xc5 ; pop rbx ; pop rbp ; pop r12 ; ret
$RSP+0x0008 : 0x0000000000000000
$RSP+0x0010 : 0x0000000000000000
$RSP+0x0018 : 0x00007ffff7a0555f
$RSP+0x0020 : 0x00007ffff7aea899 # mov r8, rax ; call r12: next -> (0x0002155f) # pop rdi ; ret
$RSP+0x0028 : 0x00007ffff7b4a3b1 # pop rax ; pop rdx ; pop rbx ; ret
$RSP+0x0030 : 0x00007ffff79e5b96
$RSP+0x0038 : 0x0000000000000000
$RSP+0x0040 : 0x0000000000000000
$RSP+0x0048 : 0x00007fff f7a7fa08 # mov rdi, r8 ; call rax: next -> (0x00001b96) # pop rdx ; ret
$RSP+0x0050 : 0x00007ffff79e5b96 # pop rdx ; ret
$RSP+0x0058 : 0x0000000000000100
$RSP+0x0060 : 0x00007ffff7a07e6a # pop rsi ; ret
$RSP+0x0068 : 0x00000000003ec860
$RSP+0x0070 : 0x0000000000110070
write(1, bss, 0x100)
$RSP+0x0000 : 0x00007ffff7a0555f # pop rdi ; ret
$RSP+0x0008 : 0x0000000000000001
$RSP+0x0010 : 0x00007ffff79e5b96 # pop rdx ; ret
$RSP+0x0018 : 0x0000000000000100
$RSP+0x0020 : 0x00007ffff7a07e6a # pop rsi ; ret
$RSP+0x0028 : 0x00000000003ec860
$RSP+0x0030 : 0x0000000000110140
done in 3.0s (Running on: A9-9420 RADEON R5 2C+3G (2) @ 3.000GHz (using cached))
Download Exrop (https://github.com/d4em0n/exrop)
___________________________
@hacking_Attack
@Hacking_Video
$RSP+0x0040 : 0x7361702f6374652f
$RSP+0x0048 : 0x00007ffff7b251c7 # mov qword ptr [r9], rdi ; ret
$RSP+0x0050 : 0x00007ffff7a05a45 # pop r13 ; ret
$RSP+0x0058 : 0x00000000003ec868
$RSP+0x0060 : 0x00007ffff7a7630c # xor edi, edi ; pop rbx ; mov rax, rdi ; pop rbp ; pop r12 ; ret
$RSP+0x0068 : 0x00007ffff7a0555f
$RSP+0x0070 : 0x0000000000000000
$RSP+0x0078 : 0x0000000000000000
$RSP+0x0 080 : 0x00007ffff7a06b8a # mov r9, r13 ; call rbx: next -> (0x0002155f) # pop rdi ; ret
$RSP+0x0088 : 0x00007ffff7a0555f # pop rdi ; ret
$RSP+0x0090 : 0x0000000000647773
$RSP+0x0098 : 0x00007ffff7b251c7 # mov qword ptr [r9], rdi ; ret
$RSP+0x00a0 : 0x00007ffff7a62c70 # xor esi, esi ; mov rax, rsi ; ret
$RSP+0x00a8 : 0x00007ffff7a0555f # pop rdi ; ret
$RSP+0x00b0 : 0x00000000003ec860
$RSP+0x00b8 : 0x000000000010fc40
read('rax', bss, 0x100)
$RSP+0x0000 : 0x00007ffff7a71362 # mov dh, 0xc5 ; pop rbx ; pop rbp ; pop r12 ; ret
$RSP+0x0008 : 0x0000000000000000
$RSP+0x0010 : 0x0000000000000000
$RSP+0x0018 : 0x00007ffff7a0555f
$RSP+0x0020 : 0x00007ffff7aea899 # mov r8, rax ; call r12: next -> (0x0002155f) # pop rdi ; ret
$RSP+0x0028 : 0x00007ffff7b4a3b1 # pop rax ; pop rdx ; pop rbx ; ret
$RSP+0x0030 : 0x00007ffff79e5b96
$RSP+0x0038 : 0x0000000000000000
$RSP+0x0040 : 0x0000000000000000
$RSP+0x0048 : 0x00007fff f7a7fa08 # mov rdi, r8 ; call rax: next -> (0x00001b96) # pop rdx ; ret
$RSP+0x0050 : 0x00007ffff79e5b96 # pop rdx ; ret
$RSP+0x0058 : 0x0000000000000100
$RSP+0x0060 : 0x00007ffff7a07e6a # pop rsi ; ret
$RSP+0x0068 : 0x00000000003ec860
$RSP+0x0070 : 0x0000000000110070
write(1, bss, 0x100)
$RSP+0x0000 : 0x00007ffff7a0555f # pop rdi ; ret
$RSP+0x0008 : 0x0000000000000001
$RSP+0x0010 : 0x00007ffff79e5b96 # pop rdx ; ret
$RSP+0x0018 : 0x0000000000000100
$RSP+0x0020 : 0x00007ffff7a07e6a # pop rsi ; ret
$RSP+0x0028 : 0x00000000003ec860
$RSP+0x0030 : 0x0000000000110140
done in 3.0s (Running on: A9-9420 RADEON R5 2C+3G (2) @ 3.000GHz (using cached))
Download Exrop (https://github.com/d4em0n/exrop)
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - d4em0n/exrop: Automatic ROPChain Generation
Automatic ROPChain Generation. Contribute to d4em0n/exrop development by creating an account on GitHub.
#Bug Bounty - How I was able to purchased premium feature just for “1” PKR by (Parameter…
Price ManipulationContinue reading on Medium »
Read more...
Price ManipulationContinue reading on Medium »
Read more...
hacking: security in practice
How to take ethical revenge on extortion scammer?
I know it’s a little off topic but yesterday I checked my spam and saw an extortion email(with an outdated password I haven’t used for long) and I was wondering what can I do to revenge, some people might fall for it and maybe I can do my part. Any help is greatly appreciated!
submitted by /u/MarbleMan100
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
How to take ethical revenge on extortion scammer?
I know it’s a little off topic but yesterday I checked my spam and saw an extortion email(with an outdated password I haven’t used for long) and I was wondering what can I do to revenge, some people might fall for it and maybe I can do my part. Any help is greatly appreciated!
submitted by /u/MarbleMan100
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
How to take ethical revenge on extortion scammer?
I know it’s a little off topic but yesterday I checked my spam and saw an extortion email(with an outdated password I haven’t used for long) and I...
hacking: security in practice
Aspiring ethical hacker here, how much of networks should I know?
I know that I should not only know about networks but also programming, Linux, Windows to get a solid base before studying how hacking works. I am watching the same videos that people watch to pass the Cisco certification and using flashcards. Should I prepare like I were going to pass Ciscos test? Or just get to know about networks superficially with a handful of videos or a short guide? Any recommendations? Also, I plan just to become a bounty hunter of vulnerabilities, and just do it as a hobby.
submitted by /u/digitalwriternow
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Aspiring ethical hacker here, how much of networks should I know?
I know that I should not only know about networks but also programming, Linux, Windows to get a solid base before studying how hacking works. I am watching the same videos that people watch to pass the Cisco certification and using flashcards. Should I prepare like I were going to pass Ciscos test? Or just get to know about networks superficially with a handful of videos or a short guide? Any recommendations? Also, I plan just to become a bounty hunter of vulnerabilities, and just do it as a hobby.
submitted by /u/digitalwriternow
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Aspiring ethical hacker here, how much of networks should I know?
I know that I should not only know about networks but also programming, Linux, Windows to get a solid base before studying how hacking works. I...
hacking: security in practice
capturing deleted files
I have a program that is creating temp files, doing something with them and then deleting them very quickly. What is the best way to capture these files so I can see what is in them? Windows os. Thanks!
submitted by /u/ricka777
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
capturing deleted files
I have a program that is creating temp files, doing something with them and then deleting them very quickly. What is the best way to capture these files so I can see what is in them? Windows os. Thanks!
submitted by /u/ricka777
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
capturing deleted files
I have a program that is creating temp files, doing something with them and then deleting them very quickly. What is the best way to capture...
eXtreme Short Scripting Game | Intigriti’s February XSS Challenge
https://jmrcsnchz.medium.com/extreme-short-scripting-game-intigritis-february-xss-challenge-c19938fecc74?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://jmrcsnchz.medium.com/extreme-short-scripting-game-intigritis-february-xss-challenge-c19938fecc74?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Today, I will be sharing about my solution on Intigriti’s February XSS Challenge 0222.Continue reading on Medium » (https://jmrcsnchz.medium.com/extreme-short-scripting-game-intigritis-february-xss-challenge-c19938fecc74?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
eXtreme Short Scripting Game | Intigriti’s February XSS Challenge
Today, I will be sharing about my solution on Intigriti’s February XSS Challenge 0222.Continue reading on Medium »
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Today, I will be sharing about my solution on Intigriti’s February XSS Challenge 0222.Continue reading on Medium »
Read more...
___________________________
@hacking_Attack
@Hacking_Video
Intigriti XSS Challenge 0222 — Write-Up
XSS challenge by intigriti Solved by Th3MindContinue reading on Medium »
Read more...
XSS challenge by intigriti Solved by Th3MindContinue reading on Medium »
Read more...
Intigriti XSS Challenge 0222 — Write-Up
https://medium.com/@th3mind/intigriti-xss-challenge-0222-write-up-bee3d93ad915?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@th3mind/intigriti-xss-challenge-0222-write-up-bee3d93ad915?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Intigriti XSS Challenge 0222 — Write-Up
XSS challenge by intigriti Solved by Th3Mind
XSS challenge by intigriti Solved by Th3MindContinue reading on Medium » (https://medium.com/@th3mind/intigriti-xss-challenge-0222-write-up-bee3d93ad915?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Intigriti XSS Challenge 0222 — Write-Up
XSS challenge by intigriti Solved by Th3Mind
How I Hacked A Reputed Hacker
https://www.reddit.com/r/redteamsec/comments/srx9d9/how_i_hacked_a_reputed_hacker/
submitted by /u/banginpadr (https://www.reddit.com/user/banginpadr)
[link] (https://medium.com/geekculture/how-i-hacked-a-reputed-hacker-6e6b31818d12) [comments] (https://www.reddit.com/r/redteamsec/comments/srx9d9/how_i_hacked_a_reputed_hacker/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/srx9d9/how_i_hacked_a_reputed_hacker/
submitted by /u/banginpadr (https://www.reddit.com/user/banginpadr)
[link] (https://medium.com/geekculture/how-i-hacked-a-reputed-hacker-6e6b31818d12) [comments] (https://www.reddit.com/r/redteamsec/comments/srx9d9/how_i_hacked_a_reputed_hacker/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
How I Hacked A Reputed Hacker
Posted in r/redteamsec by u/banginpadr • 0 points and 2 comments