Overwriting Shellcode with read() Syscall?

Viewed 806

I am trying to get past a rather complex shellcode filter, and to do so I am using a multi-stage shellcode injection. For my first stage, I have the following:

.global _start
_start:
.intel_syntax noprefix

        mov rax, 0
        mov rdi, 0
        lea rsi, [rip+10]  
        mov rdx, 1000
        syscall

this calls read(0, rip+10, 1000) which is supposed to read additional shellcode from stdin, and inserts it after the syscall, however I am getting a

read(0, 0x401018, 1000)                 = -1 EFAULT (Bad address)

when executed. I have compiled with

gcc -Wl,-N --static -nostdlib -o stage1 stage1.s

and extracted the raw .text section with

objcopy --dump-section .text=stage1-opcodes --writable-text stage1

which should make the .text section of the code writeable. I am not sure what else I need to do to ensure that the memory address [rip+10] is accessible and doesn't throw a bad address error.

0 Answers
Related