Windows Shellcode中被调用地址反转而字符串不反转的原因探究
关于x86架构下Windows与Linux Shellcode中字符串PUSH顺序的疑问
我在Windows 7 SP1(32位)虚拟机中运行一段调用Windows ShellExecute函数的C++ shellcode,对应函数调用为:
ShellExecute(0,"open","cmd",NULL,0,SW_MAXIMIZE);
以下是实现该功能的shellcode:
#include <windows.h> char code[] = "\x68\x63\x6d\x64\x00" // PUSH "cmd" - string already terminated "\x8B\xDC" // MOV EBX, ESP: // puts the pointer to the text "cmd" into ebx "\x6A\x00" // PUSH the string terminator for 'open' "\x68\x6f\x70\x65\x6e" // PUSH "open" onto the stack "\x8B\xCC" // MOV ECX, ESP: // puts the pointer to the text "open" into ecx "\x6A\x03" // PUSH 3: Push the last argument "\x33\xC0" // xor eax, eax: zero out eax "\x50" // PUSH EAX: push second to last argument - 0 "\x50" // PUSH EAX: push third to last argument - 0 "\x53" // PUSH EBX: push pointer to string 'cmd' <---- not reversed "\x51" // PUSH ECX: push pointer to string 'open' <---- not reversed "\x50" // PUSH EAX: push the first argument - 0 "\xB8\xc0\x87\x8e\x76" // MOV EAX,0x768e87c0: move ShellExecuteA <---- reversed // address into EAX "\xff\xD0" // CALL EAX: call the function ShellExecuteA ; // Terminates the C instruction int main(int argc, char **argv) { LoadLibraryA("Shell32.dll"); // Load shell32.dll library int (*func)(); func = (int (*)()) code; (int)(*func)(); }
在这段shellcode中,被调用的ShellExecuteA地址因x86小端序被反转,但PUSH的'cmd'、'open'字符串却未反转。我产生了以下疑问:是CALL与PUSH操作的差异导致该现象?但Linux环境下的shellcode案例中,PUSH的字符串是反转的;而Windows环境的同类案例中,PUSH的字符串未反转。难道是操作系统差异导致?但小端序与CPU架构绑定,所有案例均基于x86架构,这让我十分困惑。
内容的提问来源于stack exchange,提问作者Nadim Hussami
相关产品推荐
相关产品推荐

