asm_execve.s:sys_execve系統調用
.section .data file_to_run: .ascii "/bin/sh" .section .text .globl main main: pushl %ebp movl %esp, %ebp subl $0x8, %esp # array of two pointers. array[0] = file_to_run array[1] = 0 movl file_to_run, %edi movl %edi, -0x4(%ebp) movl $0, -0x8(%ebp) movl $11, %eax # sys_execve movl file_to_run, %ebx # file to execute leal -4(%ebp), %ecx # command line parameters movl $0, %edx # environment block int $0x80 leave ret
生成文件:
NAME = asm_execve $(NAME) : $(NAME).s gcc -o $(NAME) $(NAME).s
程序被執行,但sys_execve不叫:
[email protected]:~/project$ make gcc -o asm_execve asm_execve.s [email protected]:~/project$ ./asm_execve [email protected]:~/project$
預期成果是:
[email protected]:~/project$ ./asm_execve $ exit [email protected]:~/project$
本屆大會的程序應該像下面的C代碼工作:
char *data[2]; data[0] = "/bin/sh"; data[1] = NULL; execve(data[0], data, NULL);
一些錯誤的系統調用的參數?
使用'strace -e execve'來跟蹤你的程序* exec *調用的execve調用。 – 2017-10-03 22:24:28