{"id":335,"date":"2021-11-30T10:29:07","date_gmt":"2021-11-30T02:29:07","guid":{"rendered":"http:\/\/pareto.fun\/?p=335"},"modified":"2021-12-06T21:50:30","modified_gmt":"2021-12-06T13:50:30","slug":"elf%e6%96%87%e4%bb%b6%e6%84%9f%e6%9f%93","status":"publish","type":"post","link":"http:\/\/pareto.fun\/?p=335","title":{"rendered":"ELF\u6587\u4ef6\u611f\u67d3"},"content":{"rendered":"\n<p>\u6838\u5fc3\u903b\u8f91\uff1a\u62d3\u5c55elf\u6587\u4ef6\u7a7a\u95f4\uff0c\u5199\u5165shellcode\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">silvio elf\u6587\u4ef6\u611f\u67d3\u65b9\u6cd5<\/h2>\n\n\n\n<p>\u76f4\u63a5\u4ecelinux\u4e8c\u8fdb\u5236\u5206\u6790\u91cc\u9762\u6284\u7b97\u6cd5<\/p>\n\n\n\n<p><strong>.text\u611f\u67d3\u7b97\u6cd5<\/strong><\/p>\n\n\n\n<ul><li>\u589e\u52a0ELF\u6587\u4ef6\u5934\u4e2d\u7684ehdr->e_shoff\uff08\u8282\u8868\u504f\u79fb\uff09\u7684PAGE_SIZE\uff08\u9875\u957f\u5ea6\uff09<\/li><li>\u5b9a\u4f4dtext\u6bb5\u7684phdr \u4fee\u6539\u5165\u53e3\u70b9<code>ehdr->e_entry = phdr[TEXT].p_vaddr + phdr[TEXT].p_filesz<\/code> \u589e\u52a0phdr[TEXT].p_filesz\uff08\u6587\u4ef6\u957f\u5ea6\uff09\u7684\u957f\u5ea6\u4e3a\u5bc4\u751f\u4ee3\u7801\u7684\u957f\u5ea6 \u589e\u52a0phdr[TEXT].p_memsz\uff08\u5185\u5b58\u957f\u5ea6\uff09\u7684\u957f\u5ea6\u4e3a\u5bc4\u751f\u4ee3\u7801\u7684\u957f\u5ea6<\/li><li>\u5bf9\u6bcf\u4e2aphdr\uff08\u7a0b\u5e8f\u5934\uff09\uff0c\u5bf9\u5e94\u6bb5\u82e5\u5728\u5bc4\u751f\u4ee3\u7801\u4e4b\u540e\uff0c\u5219\u6839\u636e\u9875\u957f\u5ea6\u589e\u52a0\u5bf9\u5e94\u7684\u504f\u79fb<\/li><li>\u627e\u5230text\u6bb5\u7684\u6700\u540e\u4e00\u4e2ashdr(\u8282\u5934)\uff0c\u628ashdr[x].sh_size\u589e\u52a0\u4e3a\u5bc4\u751f\u4ee3\u7801\u7684\u957f\u5ea6<\/li><li>\u5bf9\u6bcf\u4e2a\u4f4d\u4e8e\u5bc4\u751f\u4ee3\u7801\u63d2\u5165\u4f4d\u7f6e\u4e4b\u540eshdr\uff0c\u6839\u636e\u9875\u957f\u5ea6\u589e\u52a0\u5bf9\u5e94\u7684\u504f\u79fb<\/li><li>\u5c06\u771f\u6b63\u7684\u5bc4\u751f\u4ee3\u7801\u63d2\u5165\u5230text\u6bb5\u7684file_base + phdr[TEXT].p_filesz\uff08text\u6bb5\u7684\u5c3e\u90e8\uff09<\/li><\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5b9e\u73b0\u62c6\u89e3<\/h4>\n\n\n\n<p>\u4e66\u4e2d\uff0c\u611f\u67d3\u7b97\u6cd5\u662f\u8d70C\u8bed\u8a00\u4ee3\u7801\u5b9e\u73b0\u7684\uff08\u800c\u4e14\u7f51\u4e0a\u6284\u7684\u4ee3\u7801\u8dd1\u4e0d\u8d77\u6765\uff0c\u4e5f\u4e0d\u597d\u8bfb\u3002\u3002\u3002\u3002\u6240\u4ee5\u8fd8\u662f\u5f97\u81ea\u5df1\u5199\u4e00\u904d\uff09\uff0c\u7531\u4e8e\u5f53\u65f6\u6ca1\u6709\u597d\u7684elf\u6587\u4ef6patch\u5de5\u5177\uff0c\u4f46\u662f\u73b0\u5728\u6211\u4eec\u6709\u4e86lief\uff0c\u4e3a\u7406\u89e3silvio\u7684\u6587\u4ef6\u611f\u67d3\u601d\u8def\uff0c\u6253\u7b97\u4f7f\u7528lief\u6765\u5b9e\u73b0\u4e00\u904d\u3002\u6211\u4eec\u628asilvio \u611f\u67d3\u5206\u4e3a\u4e24\u6b65\uff0c\u62d3\u5c55 \uff0c\u690d\u5165<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>\u5982\u4e0b\u4ee3\u7801\u5b9e\u73b0\u4e86\u62d3\u5c55\uff0c\u90a3\u690d\u5165\u5c31\u770b\u5404\u81ea\u6240\u9700\u4e86\u3002<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">import lief<br><br>obj = lief.parse(\".\/elf1\")<br>segments = obj.segments<br>sections = obj.sections<br>header  = obj.header<br>text_sec = obj.get_section(\".text\")<br># print segment which .text belong to .<br>text_segment = \"\"<br>load_flag = False<br># extend segments<br>for segment in segments:<br>   if segment.type == lief.ELF.SEGMENT_TYPES.LOAD:<br>       if segment.has(\".text\") :<br>           text_segment = segment<br>           segment.physical_size = segment.physical_size + 0x800<br>           segment.virtual_size += 0x800<br>           load_flag = True<br>           continue<br>       # if load_flag == True :<br>           # segment.physical_size += 0x800<br><br># extent sections<br>sec_flag = False<br>for sec in sections:<br>    if sec.name == \".fini\" :<br>        sec.size += 0x800<br>        #sec.virtual_address += 0x1000<br>        sec_flag = True<br>        continue<br>    # if sec_flag == True :<br>    #     sec.size += 0x800<br><br># modify entryp_point<br><br>#header.entrypoint = obj.entrypoint + 0x1000<br>print(type(obj.entrypoint))<br>obj.write(\"update_segment_section\")<br><br><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">\u5176\u4ed6\u5404\u79cd\u6587\u4ef6\u611f\u67d3\u65b9\u6cd5<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">data\u6bb5\u611f\u67d3<\/h3>\n\n\n\n<p>\u6309\u7167\u4e4b\u524d\u7684\u903b\u8f91\uff0c\u5148\u62d3\u5c55segment\uff0csection\uff0c\u518d\u5199\u5165shellcode<\/p>\n\n\n\n<p>\u5047\u8bbeshellcode\u957f\u5ea6\u4e3aSIZEdai\u3002<\/p>\n\n\n\n<ol><li>\u589e\u52a0data section\u7684offset<\/li><li>\u589e\u52a0data\u6240\u5728segment\u7684memsize \u548cfilesize\u3002<\/li><li>\u5ef6\u540ebss section\u7684\u4f4d\u7f6e &#8212;-\u300b \u62d3\u5c55\u7ed3\u675f<\/li><li>\u8c03\u6574data\u6743\u9650\uff0c \u8d4b\u4e88\u6267\u884c\u6743\u9650\u3002<\/li><li>data \u7a7a\u4f59\u90e8\u5206\u5199\u5165shellcode \u3002<\/li><li>\u4fee\u6539ep\u3002<\/li><\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">\u5c06PT_NOTE \u8f6c\u5316PT_LOAD<\/h3>\n\n\n\n<p>\u8fd9\u4e2a\u5f88\u7b80\u5355\uff0cPT_NOTE \u662f\u4e34\u8fd1PT_LOAD\u7684\u6700\u540e\u4e00\u4e2asegment\uff0c\u4e14\u4e0d\u4f1a\u88ab\u52a0\u8f7d\u5230\u5185\u5b58\u3002<\/p>\n\n\n\n<p><a href=\"https:\/\/www.symbolcrash.com\/2019\/03\/27\/pt_note-to-pt_load-injection-in-elf\/\">&#8216;\u53c2\u8003\u94fe\u63a5&#8217;<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u81ea\u7531\u7ec4\u5408load\u6216\u81ea\u7531\u4f7f\u7528\u95f4\u9699<\/h3>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6838\u5fc3\u903b\u8f91\uff1a\u62d3\u5c55elf\u6587\u4ef6\u7a7a\u95f4\uff0c\u5199\u5165shellcode\u3002 silvio elf\u6587\u4ef6\u611f\u67d3\u65b9\u6cd5 \u76f4\u63a5\u4eceli [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[19],"tags":[25,27,26],"_links":{"self":[{"href":"http:\/\/pareto.fun\/index.php?rest_route=\/wp\/v2\/posts\/335"}],"collection":[{"href":"http:\/\/pareto.fun\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/pareto.fun\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/pareto.fun\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/pareto.fun\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=335"}],"version-history":[{"count":2,"href":"http:\/\/pareto.fun\/index.php?rest_route=\/wp\/v2\/posts\/335\/revisions"}],"predecessor-version":[{"id":353,"href":"http:\/\/pareto.fun\/index.php?rest_route=\/wp\/v2\/posts\/335\/revisions\/353"}],"wp:attachment":[{"href":"http:\/\/pareto.fun\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=335"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/pareto.fun\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=335"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/pareto.fun\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=335"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}