Skip to content

invalid handling address math in long mode #2391

Description

@kotee4ko

Describe the bug
Version 2.3.2660 Personal (Build ID 88f343c3)

root@l0c4lh05t:/opt/binaryninja/scc-docs# md5sum ../plugins/scc 
87c53569ecae19e5bb2f899c9146dedb  ../plugins/scc

To Reproduce
Steps to reproduce the behavior:

int main(void)
{
char *data = 0x00;
int fd = 0x00, len = 0x00;

data = (char*)malloc(0x1000);
if ( !data )
	return -228;

memset(data, 0x00, 0x1000);
    fd = open("/etc/passwd", O_RDONLY, 0x00);
    len = read(fd, data, 0x1000);
    //write(0x01, "h4h0r1n5\n", strlen("h4h0r1n5\n"));
puts("31337\n");
write(0x01, data, len);
printf("%s\n", data);
free(data);
data = 0x00;
return 0x00;
//printf("grabbed data:\n%s\n", data);

}" > test.c```
2. scc --return-reg rax --mixed-mode --platform linux --unsafe-stack --encode-pointers --pie --arch x64 -m64 -O0 --exec-stack --allow-return --align 64 ./test.c -f elf -o test.elf
3. or alternatively `scc --pie --arch x64 -m64 -O0 -f elf ./test.c -o test.elf`
3. ./test.elf
4. See error

Expected behavior
scc invalid handle x64 addressing.
when generated elf binary do operations with half-register in long mode - it just lost other half.

https://i.ibb.co/58DLv0f/image.png
https://i.ibb.co/sQ6pwxn/image.png
https://i.ibb.co/mDNKbmX/image.png

Desktop (please complete the following information):

root@l0c4lh05t:/opt/binaryninja/scc-docs# hostnamectl 
   Static hostname: l0c4lh05t
         Icon name: computer-laptop
           Chassis: laptop
        Machine ID: 0a71446503e9469d85974c0bf232cec1
           Boot ID: c73453a976fd4db4886536101e8b209b
  Operating System: Debian b00st3r GNU/Linux
            Kernel: Linux 5.10.0-4-amd64
      Architecture: x86-64

Additional context


Program received signal SIGSEGV, Segmentation fault.
0x0000555555554d56 in ?? ()
LEGEND: STACK | HEAP | CODE | DATA | RWX | RODATA
[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]{────[ REGISTERS ]────}
 RAX  0x55555d80
 RBX  0x0
 RCX  0xd2da39aff55c
 RDX  0xd2da39aff55c
 RDI  0x7ffff7ffe180 —▸ 0x555555554000 ◂— jg     0x555555554047
 RSI  0x7ffff7ffe720 ◂— 0x0
 R8   0x0
 R9   0x0
 R10  0x555555554000 ◂— jg     0x555555554047
 R11  0x7ffff7ffe180 —▸ 0x555555554000 ◂— jg     0x555555554047
 R12  0x5555555541ac ◂— sub    rsp, 0x1000
 R13  0x7fffffffe3a0 ◂— 0x1
 R14  0x0
 R15  0x0
 RBP  0xffffd388
 RSP  0x7fffffffd388 —▸ 0x7fffffffd398 ◂— 0x0
 RIP  0x555555554d56 ◂— mov    eax, dword ptr [rax]
 EFLAGS 0x10206 [ cf PF af zf sf IF df of ]
[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|{────[ DISASM ]────}
    0x555555554d42    mov    ebp, esp
    0x555555554d44    call   0x555555554d49
    0x555555554d49    pop    rax
    0x555555554d4a    lea    eax, [rax - 0xb9d]
    0x555555554d50    lea    eax, [rax + 0x1bd4]
 —► 0x555555554d56    mov    eax, dword ptr [rax]
    0x555555554d58    leave  
    0x555555554d59    xor    dword ptr [rsp], eax
    0x555555554d5c    ret    
    0x555555554d5d    add    byte ptr [rax], al
    0x555555554d5f    add    byte ptr [rax], al
[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[||{────[ STACK ]────}
00:0000 rsp  0x7fffffffd388 —▸ 0x7fffffffd398 ◂— 0x0
01:0008      0x7fffffffd390 ◂— 0x878f6cfab4b8
02:0010      0x7fffffffd398 ◂— 0x0
... ↓
[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]{────[ BACKTRACE ]────}
 —► [w00p-w00t]0     555555554d56 
    [w00p-w00t]1     7fffffffd398 
    [w00p-w00t]2     878f6cfab4b8 
    [w00p-w00t]3                0 
[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||]=[|||
pwndbg> 

So, I try to work around this via --base-reg - I think if I set it to long-mode reg - it will generate valid code.
But,
scc --base-reg rax --pie --arch x64 -m64 -O0 -f elf ./test.c -o test.elf
error: unrecognized option '--base-reg'

In general I'm writing standalone LKM modules, so, such compiler can be helpfully for me a lot.
Can you, please, fix this?

Activity

  1. kotee4ko commented on Apr 25, 2021

    @kotee4ko
    Author

    scc --arch x64 -m32 -f elf ./test.c -o test.elf
    file ./test.elf
    test.elf: ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, no section header
    and the same with
    scc -m32 --arch x64 -f elf ./test.c -o test.elf

    32-bit binary working. at least it's print via printf() without crash.
    so, what are the meaning of --arch?

     2 int main(void)
     3 {
     4         char *string = "str\n";
     5         char data[0x100];
     6         int fd = 0x00, len = 0x00;
     7         void *p = malloc(0x100);
     8
     9         printf("%s p = %#llx \n p = %llx\n", string, p, p);
    

    and output

    root@l0c4lh05t:/opt/binaryninja/shells# ./test.elf 
    str
     p = #llx 
     p = llx
    31337
    

    oh, shit :D

  2. added
    Impact: LowIssue is a papercut or has a good, supported workaround
    Component: SCCIssue needs changes to the shellcode compiler
    on Apr 28, 2021
  3. kotee4ko commented on May 1, 2021

    @kotee4ko
    Author

    ikd, but maybe this https://github.com/kotee4ko/MUSLShell can be useful or helpful for someone.
    It allow generate long-mode raw shellcode with using C and musl libc. Speaking true - all magic happens in msmake.sh and kopycatim.lds

    Thanks

  4. added theissue type on Jun 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Component: SCCIssue needs changes to the shellcode compilerImpact: LowIssue is a papercut or has a good, supported workaround

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions