-
Notifications
You must be signed in to change notification settings - Fork 16
Expand file tree
/
Copy pathdosyscall.S
More file actions
57 lines (46 loc) · 1.64 KB
/
Copy pathdosyscall.S
File metadata and controls
57 lines (46 loc) · 1.64 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
# DoSyscall - Indirect Syscall Stub for GCC/MinGW (x64)
#
# By 28Zaakypro@proton.me
#
# Windows x64 calling convention:
# RCX = ssn, RDX = syscallAddr, R8 = arg1, R9 = arg2
# Stack: arg3, arg4, arg5, arg6
#
# Syscall expects:
# EAX = SSN, R10 = arg1, RDX = arg2, R8 = arg3, R9 = arg4
# Stack: arg5, arg6
.text
.globl DoSyscall
.def DoSyscall; .scl 2; .type 32; .endef
DoSyscall:
# Save non-volatile registers
pushq %rbx
pushq %rsi
# Save syscallAddr and SSN
movq %rdx, %rbx # RBX = syscallAddr
movl %ecx, %esi # ESI = SSN
# Load arguments before modifying stack
# R10 = arg1, RDX = arg2, R8 = arg3, R9 = arg4
movq %r8, %r10 # R10 = arg1
movq %r9, %rdx # RDX = arg2
movq 0x38(%rsp), %r8 # R8 = arg3 (0x28 + 0x10 for 2 pushes)
movq 0x40(%rsp), %r9 # R9 = arg4
# Setup stack for CALL
# We need arg5 and arg6 at correct positions
# Currently: arg5 at [RSP+0x48], arg6 at [RSP+0x50] (because of 2 pushes)
# After sub and call ; arg5 must be at [RSP+0x28], arg6 at [RSP+0x30]
subq $0x38, %rsp # Allocate 56 bytes (shadow 32 + 24 for args)
# Copy arg5 and arg6
movq 0x80(%rsp), %rax # arg5 original (0x48+0x38=0x80)
movq %rax, 0x20(%rsp) # arg5 at RSP+0x20 -> RSP+0x28 after CALL
movq 0x88(%rsp), %rax # arg6 original (0x50+0x38=0x88)
movq %rax, 0x28(%rsp) # arg6 at RSP+0x28 -> RSP+0x30 after CALL
# Set SSN
movl %esi, %eax
# CALL syscall gadget
call *%rbx
# Cleanup
addq $0x38, %rsp
popq %rsi
popq %rbx
ret