Section: .. / shellcode /
| /// File Name: |
16-reuse.txt |
Description:
|
16 byte linux/x86 re-use of /bin/sh string in .rodata shellcode.
| | Author: | Marco Ivaldi | | File Size: | 1083 | | Last Modified: | Jul 26 02:15:03 2006 |
| MD5 Checksum: | e76a96888522ad50a73af95b324f138c |
|
| /// File Name: |
30-setuidexec.txt |
Description:
|
30 byte linux/x86 setuid(0) and /bin/sh execve() shellcode.
| | Author: | Marco Ivaldi | | File Size: | 1360 | | Last Modified: | Jul 26 02:13:14 2006 |
| MD5 Checksum: | a28408279594abbceee55a56bb402a44 |
|
| /// File Name: |
390chroot.c |
Description:
|
s390 shellcode which breaks out of a chrooted environment with setuid / setgid.
| | Homepage: | http://www.thc.org | | File Size: | 4419 | | Last Modified: | Dec 24 11:14:08 2002 |
| MD5 Checksum: | 7fd4ef3e9447f9bfe4d2510bd63149c3 |
|
| /// File Name: |
390connectback.c |
Description:
|
s390 shellcode which connects back to a listening netcat on port 31337 by default.
| | Homepage: | http://www.thc.org | | File Size: | 5169 | | Last Modified: | Dec 24 11:15:55 2002 |
| MD5 Checksum: | d0cc0d8c977991206d8fe2e6f1c6b982 |
|
| /// File Name: |
390execve.c |
Description:
|
Setuid/setgid 0 execve s390 shellcode.
| | Homepage: | http://www.thc.org | | File Size: | 2080 | | Last Modified: | Dec 24 11:16:45 2002 |
| MD5 Checksum: | 707d6b6af82a86eaf60c1c0a07e21f83 |
|
| /// File Name: |
390portbind.c |
Description:
|
s390 portbinding shellcode.
| | Homepage: | http://www.thc.org | | File Size: | 5693 | | Last Modified: | Dec 24 11:17:34 2002 |
| MD5 Checksum: | ada4dee501818a29ef45a4bc19a9c3be |
|
| /// File Name: |
45-ksh.c |
Description:
|
This is a 45 byte shellcode which does a setuid(0), execve /bin/ksh, exit().
| | Author: | Remy | | Homepage: | http://www.hackerforhire.nl | | File Size: | 259 | | Last Modified: | Oct 9 20:27:21 2002 |
| MD5 Checksum: | 88cc6dc6bec3a6f246b4c7b08849bac1 |
|
| /// File Name: |
96-setuidportbind.txt |
Description:
|
96 byte linux/x86 shellcode that binds a setuid(0) shell on tcp/31337.
| | Author: | Marco Ivaldi | | File Size: | 4201 | | Last Modified: | Jul 26 02:11:42 2006 |
| MD5 Checksum: | d0c4d50f411be4073b0db1be7494c579 |
|
| /// File Name: |
add.s |
Description:
|
32 bit asm code written in AT+T syntax for the x86 processor. It adds an user with root rights and no password from the command line.
| | Author: | Serial Killah | | File Size: | 4132 | | Last Modified: | Jan 18 01:04:27 2005 |
| MD5 Checksum: | ce6359b680fa9f91ea5610b611e8df4c |
|
| /// File Name: |
addpasswd.c |
Description:
|
This shellcode adds a new root-equivalent user "r00t" with no password to /etc/passwd in 69 bytes for Linux/x86.
| | Author: | Kris Katterjohn | | File Size: | 1121 | | Last Modified: | Nov 16 10:42:24 2006 |
| MD5 Checksum: | d665c46d144144b5c0d102ea37d78fb0 |
|
| /// File Name: |
alpha2.tar.gz |
Description:
|
ALPHA 2 Zero-tolerance is a shellcode encoder that will convert any x86 shellcode into 100% alphanumeric code. The resulting code has an OS independent decoder that will convert the encoded shellcode back to the original code and execute it. Features include creating 100% uppercase and unicode-proof code. It also supports automatic EIP grabbing for win32 targets using the Structured Exception Handler. A working version is available for testing on-line at http://www.edup.tudelft.nl/~bjwever.
| | Author: | Skylined | | Homepage: | http://www.edup.tudelft.nl/~bjwever | | File Size: | 8791 | | Last Modified: | Sep 23 00:48:59 2004 |
| MD5 Checksum: | b1ce6730838ac6ea6844b41089be00dc |
|
| /// File Name: |
as2hex.tgz |
Description:
|
An easy PowerPC shellcode generation program to extract the hex shellcode from an ASM program that has been assembled but not linked. Tested on programs assembled using the GAS (GNU Assembler) on OSX 10.2.6.
| | Author: | B-r00t | | Homepage: | http://doris.scriptkiddie.net | | File Size: | 3282 | | Last Modified: | Sep 9 20:56:19 2003 |
| MD5 Checksum: | 4290c15598dc2ac40d20926c0189dc92 |
|
| /// File Name: |
asg.c |
Description:
|
Advanced Shellcode Generator 1.1-1. - Very compact and simple to use. All notation written in Italian.
| | Author: | R[]l4nD | | File Size: | 4489 | | Last Modified: | Aug 10 19:19:41 2003 |
| MD5 Checksum: | 583bb43e020cb8e9d171157da8c4d16f |
|
| /// File Name: |
Auth-sc.c |
Description:
|
Shellcode for binding to port 48138 and requiring a password of haxor.
| | Author: | NrAziz | | File Size: | 3976 | | Last Modified: | May 11 00:11:50 2004 |
| MD5 Checksum: | cae6d91c60067fef1780d9845f0fef64 |
|
| /// File Name: |
bb.c |
Description:
|
Buffer Builder v1.5 is a tool which assists in building buffer overflow strings for local and remote exploits. Goes well with a disassembler and netcat and contains several useful shell codes.
| | Author: | Gml | | Homepage: | http://phrick.net/~gml | | Changes: | Added ability to change offset, cleaned up output, added more byte order parameters, added new shellcodes, fixed $SHELLCODE offset calculation problem on freebsd, and added author strings to shellcode. | | File Size: | 16568 | | Last Modified: | Dec 15 01:31:12 2003 |
| MD5 Checksum: | 088da053d8c6ca9dc937ad2d9ac53516 |
|
| /// File Name: |
beeplearn.tar.bz2 |
Description:
|
Beeplearn.tar.bz2 contains two linux x86 shellcodes written in ASM. One beeps the PC speaker and the other is a fork bomb.
| | Author: | nh | | File Size: | 1323 | | Last Modified: | Jan 3 05:10:31 2004 |
| MD5 Checksum: | c799d9fcdf75eaa179051030ef9864e7 |
|
| /// File Name: |
beta.c |
Description:
|
Tool that can encode shellcode in various ways. Released by the author of the InternetExploiter exploit. Documentation for this tool available here.
| | Author: | Skylined | | Homepage: | http://www.edup.tudelft.nl/~bjwever/ | | File Size: | 7609 | | Last Modified: | Dec 11 14:55:35 2004 |
| MD5 Checksum: | 826daa1037532d516a66af6ea4befc41 |
|
| /// File Name: |
bind-sc.c |
Description:
|
156 byte linux shellcode which binds /bin/sh to tcp port 30464.
| | Author: | R00T-dude | | Homepage: | http://www.netric.org | | File Size: | 4264 | | Last Modified: | Sep 6 01:36:46 2002 |
| MD5 Checksum: | dd54707d37453a538dfd24a3e6bc588b |
|
| /// File Name: |
bind-sparc-open.c |
Description:
|
Shellcode for OpenBSD under Sparc which binds a shell to tcp port 9999. Tested on OpenBSD 2.6(Sun4m) on a Sparc-station 5.
| | Author: | Killah | | File Size: | 925 | | Last Modified: | Jul 23 23:07:13 2002 |
| MD5 Checksum: | d9472269f2aaca77aae245c08023ffe3 |
|
| /// File Name: |
bindcode.c |
Description:
|
116 byte bindcode hardcoded for Windows XP SP1 that binds to port 58821.
| | Author: | silicon | | File Size: | 1155 | | Last Modified: | Jul 4 12:47:55 2003 |
| MD5 Checksum: | 1183b23d244693a0f1b8731ffe14b71a |
|
| /// File Name: |
bish.c |
Description:
|
Bish.c is multi-platform shellcode tested on FreeBSD 4.6-PRERELEASE, FreeBSD 4.5-RELEASE, OpenBSD 3.0, NetBSD 1.5.2, Linux 2.0.36, Linux 2.2.12-20, and Linux 2.2.16-22. Based on code by Zillion, added setuid().
| | Author: | Bob | | Homepage: | http://blaat.dtors.net | | File Size: | 1430 | | Last Modified: | Sep 17 09:55:09 2002 |
| MD5 Checksum: | d5f1336e3d3ab4c064e0960020fef945 |
|
| /// File Name: |
black-dl-exec-SOLARIS.c |
Description:
|
278 byte shellcode for Solaris that downloads a binary named evil-dl from a host and saves it to /tmp/ff and then executes it.
| | Author: | Russell Sanford | | File Size: | 2080 | | Last Modified: | Nov 28 21:36:03 2006 |
| MD5 Checksum: | fe45bd90775da60f68eb7c6551223c73 |
|
| /// File Name: |
black_RXenc-con-back-SOLARIS.tgz |
Description:
|
Solaris SPARC TCP connect-back shellcode (with XNOR encoded session) and client SPARC assembly shellcode.
| | Author: | xort | | Homepage: | http://www.blacksecurity.org/ | | File Size: | 4368 | | Last Modified: | Jul 24 01:58:46 2006 |
| MD5 Checksum: | a9e4b3320a115af737c4906692d94626 |
|
| /// File Name: |
bsd-bind-sc.c |
Description:
|
150 byte BSD shellcode that binds /bin/sh to tcp port 30464.
| | Author: | R00T-dude | | Homepage: | http://www.netric.org | | File Size: | 5082 | | Last Modified: | Sep 6 01:39:42 2002 |
| MD5 Checksum: | 678b618f452496978de5edc3b9e4355f |
|
|
|
|
|