You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

x86-64位Shellcode在测试器中无法正常执行execve系统调用

x86-64 Shellcode在测试器中无法传递execve参数的问题排查与修复

问题根源

你导出的Shellcode错误包含了非_start入口的冗余指令(开头的\x48\x89\xe5是栈帧设置指令,不属于你编写的Shellcode逻辑),这些额外指令会破坏测试器运行时的栈结构,导致execve参数传递异常。

从测试器的Shellcode内容看,开头的\x48\x89\xe5(对应mov rbp, rsp)是编译链接后引入的无关代码,而你编写的_start入口实际是从xor rax, rax(\x48\x31\xc0)开始的。

修复步骤

1. 修正Shellcode导出命令

使用以下命令仅提取_start标签对应的指令,避免包含无关代码:

objdump -d ./shell-64Bit | grep -A 20 '_start:' | grep -v 'file' | cut -f2 -d: | cut -f1-6 -d' ' | tr -s ' ' | tr '\t' ' ' | sed 's/ $//g' | sed 's/ /\\x/g' | paste -d '' -s | sed 's/^/"/' | sed 's/$/"/g'

注:-A 20表示截取_start开始的20行指令,可根据你的Shellcode实际长度调整数值。

2. 替换测试器中的正确Shellcode

修正后导出的Shellcode开头应为"\x48\x31\xc0\x48\x31\xd2...",替换测试器中shellcode数组的内容:

const unsigned char shellcode[] = "\x48\x31\xc0\x48\x31\xd2\x52\x48\xbb\x2f\x2f\x62\x69\x2f\x73\x68\x53\x48\x89\xe7\x52\x48\x83\xec\x02\x66\xc7\x04\x24\x2d\x63\x48\x8d\x34\x24\x52\x48\x83\xec\x06\x66\xc7\x04\x24\x77\x68\xc7\x44\x24\x02\x6f\x61\x69\x48\x8d\x0c\x24\x52\x51\x56\x57\x48\x8d\x34\x24\x6a\x3b\x58\x0f\x05\x6a\x3c\x58\x48\xd1\xe7\x48\xf7\xdf\x0f\x05";

3. 栈对齐优化(可选)

x86-64系统调用要求syscall执行时栈保持16字节对齐,可在push 0x3b前添加调整指令优化:

sub rsp, 8   ; 调整栈到16字节对齐
push 0x3b
pop rax
syscall

验证修复

重新编译测试器并运行,此时execve的参数数组能正确传递,可正常执行whoami命令。


内容的提问来源于stack exchange,提问作者Marius Romeiser

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 01:44:58