Re[2]: OS X Shell Code

From: Meder Kydyraliev (mederchikat_private)
Date: Thu Jan 10 2002 - 20:05:57 PST

  • Next message: Robert Freeman: "Re: RPC/TCP Record Marking for IDS Evasion"

    you might want to take a look at some stuff here: 
    http://lsd-pl.net/papers.html
    
    > 
    > On Thu, Jan 10, 2002 at 04:38:54PM -0500, fintler said:
    > > Here's a sample of ppc shellcode (should work fine on mac os x) on ppc you
    > > have to worry about the link register having the return address, along with
    > > the copy on the stack, so it's not like you can just overwrite it like in
    > > x86. Makes it harder to overflow those off by ones I guess...this was
    > > written by someone named "Chris Shepard" I think:
    > 
    > Which leads to my next question, I am messing around with an app in OS X
    > that has an overflow condition, and this is my first time working with
    > non x86 based debugging, etc and I am a bit lost (where's the eip? ;).
    > Any good links/references for PPC specific ASM and/or overflow
    > techniques or tutorials?
    > 
    > > 
    > > char shellcode[] =
    > 
    > Thanks, this is very helpful...
    > -- 
    > Josha Bronson
    > dmuzat_private
    > AngryPacket Security
    > 
    
    ==============================================================
    UNIX is like a wighwam - No Gates, No Windows and Apache inside
    



    This archive was generated by hypermail 2b30 : Thu Jan 10 2002 - 20:20:15 PST