Tuesday, May 30, 2023

Pointers Part 1: The Basics



So you're eager to learn about pointers but unfortunately you got stuck because they seemed to you terrible in nature? That's not true I know, but many of the people get confused when they arrive at the topic of pointers. Well pointers are the most important tools in C programming and are the one that can make you fly (unless you don't know how to ride over them). In this article we're going to learn basics of pointers.
Pointers are the varaibles that store addresses of other variables. Easy ain't it?
So lets start with the decleration of a pointer, pointer is decreleared as:
data_type *var_name;
e,g
int *pt;
well the astrisk(*) before the variable name is the thing that makes variable a pointer. So far so good now what?
Now lets say we want to store address of a variable in our pointer variable that seems pretty complex..!
Let's do it:
int number = 100;
int *pt = #
Is it really complex..?
what we are doing here is that we are first declaring and initializing a integer variable (number) with value of 100 and then we declare and initialize a pointer variable (pt) with the address of number variable. Now pt (pointer variable) contains the address of number (integer varaible). So what? Now we can use this pointer variable to change the value of number variable. Is this some kind of Magic? Maybe. Lets' do it:
*pt = 200;
what we have done here is that we De-referencing the pt variable with the asterisk (*) and then assigned it the value of 200 now the number variable contains 200. Isn't it a magic? De-referencing is used for accessing the value of the variable towards which our pointer is pointing simple. So lets write a full program of what we have learned so far.
/*Pointer Basics: Creating and Using Pointers*/
#include<stdio.h>
int main(void){
  int number = 100;
  int *pt = &number;
  printf("Value of 'number' is: %d", number);
  printf("Address of 'number' is: %p", pt);
  *pt = 200;
  printf("New value of 'number' is: %d", number);
  return 0;
}
What this whole program did was it created a integer variable and a pointer to integer variable and then printed out the value and address of the 'number' variable and after that we De-referenced the pointer variable so that we can access the value to which our pointer variable is pointing and changed the old 100 value with new 200 value and at last we printed that out. Easy isn't it?
But do you know that you can get the address of a variable even by using ampersand (&) operator? Lemme show you how. I'll declare and initialize a variable 'var' and then print it to screen using ampersand (&) operator:
int var = 10;
printf("Address of 'var' is %p\n", &var);
the last statement here will print out the address of 'var' not value so that means it is equal to this statement:
int *pt = &var;
printf("Address of 'var' is %p\n", pt);
here we first assigned the address of 'var' to pointer variable 'pt' and then printed out the address of 'var' using the pointer variable (pt).
So lets write another program that will wrap up this part of 'Pointer Basics':
/*Pointer Basics Part 1: Program 2*/
#include<stdio.h>
int main(void){
   int var = 10;
   int *pt = &var;
   printf("The Value of 'var' is: %d\n", var);
   printf("De-referencing: *pt = %d\n", *pt);
   printf("Ampersand: The Address of 'var' is %p\n",  &var);
   printf("pt = %p\n", pt);
   return 0;
}
So that's the end of first part watch out for the next part in which we'll tighten our grip on pointers and get ready for some Advanced '*po(inter)-fo'.
Continue reading

  1. Pentest Tools Apk
  2. Hacking Tools For Windows
  3. Hacking Tools For Beginners
  4. Hack Tools Online
  5. Hacking Tools 2019
  6. Best Hacking Tools 2020
  7. Pentest Tools Website Vulnerability
  8. Pentest Tools Linux
  9. Pentest Tools Windows
  10. Pentest Tools Find Subdomains
  11. Kik Hack Tools
  12. Hacker Security Tools
  13. Pentest Tools Download
  14. Physical Pentest Tools
  15. Pentest Box Tools Download
  16. Hacking Tools Github
  17. Pentest Tools Port Scanner
  18. Hacker Tools Github
  19. Hack Rom Tools
  20. Hacking Tools And Software
  21. Hack Tools For Pc
  22. Top Pentest Tools
  23. Pentest Tools Open Source
  24. Hacker Tools Online
  25. Hack And Tools
  26. Usb Pentest Tools
  27. Beginner Hacker Tools
  28. Hak5 Tools
  29. Pentest Tools Apk
  30. Hacking Tools For Pc
  31. Hacker Security Tools
  32. Hacking Tools Online
  33. Ethical Hacker Tools
  34. Pentest Tools For Ubuntu
  35. Hak5 Tools
  36. Pentest Tools Apk
  37. Free Pentest Tools For Windows
  38. Hacker Tools Mac
  39. Pentest Tools Alternative
  40. Hackers Toolbox
  41. New Hacker Tools
  42. Hacking Tools Download
  43. Hack Tools For Pc
  44. Install Pentest Tools Ubuntu
  45. Hack Tools For Pc
  46. Hack Tools
  47. Hacking Tools For Kali Linux
  48. Free Pentest Tools For Windows
  49. Hacking Tools Windows 10
  50. Pentest Tools Kali Linux
  51. What Are Hacking Tools
  52. Hack Tool Apk No Root
  53. Hacking Tools For Windows
  54. Tools For Hacker
  55. New Hack Tools
  56. Hack App
  57. Growth Hacker Tools
  58. Hack Tools For Windows
  59. Tools For Hacker
  60. Hacking Tools Download
  61. Hack Tools
  62. Pentest Tools Review
  63. Game Hacking
  64. Underground Hacker Sites
  65. Pentest Box Tools Download
  66. Hack Tools
  67. Beginner Hacker Tools
  68. Pentest Tools
  69. Kik Hack Tools
  70. Hacker Tools Linux
  71. Hacking Tools
  72. Hacker Tools Hardware
  73. Nsa Hacker Tools
  74. Hacker Tools Free
  75. Pentest Tools Free
  76. Hack Tools For Windows
  77. Hacking Tools Download
  78. Hacks And Tools
  79. Hack Tools Pc
  80. Pentest Tools Website
  81. Termux Hacking Tools 2019
  82. Pentest Box Tools Download
  83. Free Pentest Tools For Windows
  84. Pentest Tools Subdomain
  85. Hacking Tools 2020
  86. Nsa Hack Tools Download
  87. Pentest Tools Alternative
  88. Hacking Tools For Beginners
  89. Hack Tools For Games
  90. Tools Used For Hacking
  91. Hacker Tools For Windows
  92. Hack Tools Pc
  93. Free Pentest Tools For Windows
  94. Pentest Tools Android
  95. Hacking App
  96. How To Make Hacking Tools
  97. Hacker Techniques Tools And Incident Handling
  98. Hacking App
  99. Hacker Tools Apk Download
  100. Hacking Tools Hardware
  101. Hacking Tools Windows 10
  102. Hack Tool Apk
  103. Hackers Toolbox
  104. Hacking Tools Kit
  105. Pentest Tools Windows
  106. Hacking Tools For Pc
  107. New Hacker Tools
  108. Pentest Tools Framework
  109. Usb Pentest Tools
  110. Beginner Hacker Tools
  111. Hacking Tools Kit
  112. Hacker Tools Linux
  113. Hacking Tools 2020
  114. Hacking Tools Pc
  115. Pentest Tools Free
  116. Hacking Tools Pc
  117. Hacking Tools For Windows
  118. Hacking Tools For Kali Linux
  119. Hacker Tools Github
  120. Bluetooth Hacking Tools Kali
  121. Hack Website Online Tool
  122. Hacker Hardware Tools
  123. Hacker Tools Hardware
  124. Hacking Tools 2019
  125. Hak5 Tools
  126. Hacking Tools Windows
  127. Hacking Tools Usb
  128. Pentest Tools Subdomain
  129. Hacks And Tools
  130. Hack Tools Download
  131. New Hack Tools
  132. Free Pentest Tools For Windows
  133. Hacking Tools For Windows Free Download
  134. Pentest Tools
  135. Pentest Tools Bluekeep
  136. Best Hacking Tools 2020
  137. Hak5 Tools
  138. Hacker Tools For Mac
  139. Hack Apps
  140. Easy Hack Tools
  141. What Are Hacking Tools
  142. Pentest Tools For Windows
  143. World No 1 Hacker Software
  144. Hacking Tools Kit
  145. Hacking Tools Pc
  146. Tools For Hacker
  147. Hacker Techniques Tools And Incident Handling
  148. Hacking Tools Online
  149. Hacker
  150. Hacking Tools Free Download
  151. Hack Tools For Windows
  152. Hack Tools Mac
  153. Nsa Hacker Tools
  154. Pentest Tools
  155. Pentest Tools Tcp Port Scanner
  156. Tools For Hacker
  157. Hacking Tools Usb
  158. Pentest Tools List
  159. Hacking Tools 2019
  160. Pentest Tools Github
  161. Computer Hacker
  162. Hacker Tools 2020
  163. Free Pentest Tools For Windows
  164. Underground Hacker Sites
  165. Hack And Tools
  166. Hacking Tools For Mac
  167. Hacker Tools Hardware
  168. Hack Tools For Games
  169. Hacking Tools For Windows 7
  170. Nsa Hack Tools Download
  171. Game Hacking
  172. Hacker Tools List
  173. Hack Tools Mac
  174. Pentest Tools Github
  175. Hacker Security Tools
  176. Pentest Reporting Tools

Emulating Shellcodes - Chapter 2

 Lets check different  Cobalt Strike shellcodes and stages in the shellcodes emulator SCEMU.




This stages are fully emulated well and can get the IOC and the behavior of the shellcode.

But lets see another first stage big shellcode with c runtime embedded in a second stage.


In this case is loading tons of API using GetProcAddress at the beginning, then some encode/decode pointer and tls get/set values to store an address. And ends up crashing because is jumping an address that seems more code than address 0x9090f1eb.

Here there are two types of allocations:


Lets spawn a console on -c 3307548 and see if some of this allocations has the next stage.

The "m" command show all the memory maps but the "ma" show only the allocations done by the shellcode.



Dumping memory with "md" we see that there is data, and dissasembling this address with "d" we see the prolog of a function.

So we have second stage unpacked in alloc_e40064


With "mdd" we do a memory dump to disk we found the size in previous screenshot,  and we can do  some static reversing of stage2 in radare/ghidra/ida

In radare we can verify that the extracted is the next stage:


I usually do correlation between the emulation and ghidra, to understand the algorithms.

If wee look further we can realize that the emulator called a function on the stage2, we can see the change of code base address and  is calling the allocated buffer in 0x4f...



And this  stage2 perform several API calls let's check it in ghidra.


We can see in the emulator that enters in the IF block, and what are the (*DAT_...)() calls

Before a crash lets continue to the SEH pointer, in this case is the way, and the exception routine checks IsDebuggerPresent() which is not any debugger pressent for sure, so eax = 0;



So lets say yes and continue the emulation.


Both IsDebuggerPresent() and UnHandledExceptionFilter() can be used to detect a debugger, but the emulator return what has to return to not be detected. 

Nevertheless the shellcode detects something and terminates the process.

Lets trace the branches to understand the logic:


target/release/scemu -f shellcodes/unsuported_cs.bin -vv | egrep '(\*\*|j|cmp|test)'



Continuing the emulation it's setting the SEH  pointer to previous stage:


Lets see from the console where is pointing the SEH chain item:


to be continued ...


https://github.com/sha0coder/scemu






Related word

Blockchain Exploitation Labs - Part 3 Exploiting Integer Overflows And Underflows




In part 1 and 2 we covered re-entrancy and authorization attack scenarios within the Ethereum smart contract environment. In this blog we will cover integer attacks against blockchain decentralized applications (DAPs) coded in Solidity.

Integer Attack Explanation:

An integer overflow and underflow happens when a check on a value is used with an unsigned integer, which either adds or subtracts beyond the limits the variable can hold. If you remember back to your computer science class each variable type can hold up to a certain value length. You will also remember some variable types only hold positive numbers while others hold positive and negative numbers.

If you go outside of the constraints of the number type you are using it may handle things in different ways such as an error condition or perhaps cutting the number off at the maximum or minimum value.

In the Solidity language for Ethereum when we reach values past what our variable can hold it in turn wraps back around to a number it understands. So for example if we have a variable that can only hold a 2 digit number when we hit 99 and go past it, we will end up with 00. Inversely if we had 00 and we subtracted 1 we would end up with 99.


Normally in your math class the following would be true:

99 + 1 = 100
00 - 1 = -1


In solidity with unsigned numbers the following is true:

99 + 1 = 00
00 - 1 = 99



So the issue lies with the assumption that a number will fail or provide a correct value in mathematical calculations when indeed it does not. So comparing a variable with a require statement is not sufficiently accurate after performing a mathematical operation that does not check for safe values.

That comparison may very well be comparing the output of an over/under flowed value and be completely meaningless. The Require statement may return true, but not based on the actual intended mathematical value. This in turn will lead to an action performed which is beneficial to the attacker for example checking a low value required for a funds validation but then receiving a very high value sent to the attacker after the initial check. Lets go through a few examples.

Simple Example:

Lets say we have the following Require check as an example:
require(balance - withdraw_amount > 0) ;


Now the above statement seems reasonable, if the users balance minus the withdrawal amount is less than 0 then obviously they don't have the money for this transaction correct?

This transaction should fail and produce an error because not enough funds are held within the account for the transaction. But what if we have 5 dollars and we withdraw 6 dollars using the scenario above where we can hold 2 digits with an unsigned integer?

Let's do some math.
5 - 6 = 99

Last I checked 99 is greater than 0 which poses an interesting problem. Our check says we are good to go, but our account balance isn't large enough to cover the transaction. The check will pass because the underflow creates the wrong value which is greater than 0 and more funds then the user has will be transferred out of the account.

Because the following math returns true:
 require(99 > 0) 

Withdraw Function Vulnerable to an UnderFlow:

The below example snippet of code illustrates a withdraw function with an underflow vulnerability:

function withdraw(uint _amount){

    require(balances[msg.sender] - _amount > 0);
    msg.sender.transfer(_amount);
    balances[msg.sender] -= _amount;

}


In this example the require line checks that the balance is greater then 0 after subtracting the _amount but if the _amount is greater than the balance it will underflow to a value above 0 even though it should fail with a negative number as its true value.

require(balances[msg.sender] - _amount > 0);


It will then send the value of the _amount variable to the recipient without any further checks:

msg.sender.transfer(_amount);

Followed by possibly increasing the value of the senders account with an underflow condition even though it should have been reduced:

balances[msg.sender] -= _amount;


Depending how the Require check and transfer functions are coded the attacker may not lose any funds at all but be able to transfer out large sums of money to other accounts under his control simply by underflowing the require statements which checks the account balance before transferring funds each time.

Transfer Function Vulnerable to a Batch Overflow:

Overflow conditions often happen in situations where you are sending a batched amount of values to recipients. If you are doing an airdrop and have 200 users who are each receiving a large sum of tokens but you check the total sum of all users tokens against the total funds it may trigger an overflow. The logic would compare a smaller value to the total tokens and think you have enough to cover the transaction for example if your integer can only hold 5 digits in length or 00,000 what would happen in the below scenario?


You have 10,000 tokens in your account
You are sending 200 users 499 tokens each
Your total sent is 200*499 or 99,800

The above scenario would fail as it should since we have 10,000 tokens and want to send a total of 99,800. But what if we send 500 tokens each? Lets do some more math and see how that changes the outcome.


You have 10,000 tokens in your account
You are sending 200 users 500 tokens each
Your total sent is 200*500 or 100,000
New total is actually 0

This new scenario produces a total that is actually 0 even though each users amount is 500 tokens which may cause issues if a require statement is not handled with safe functions which stop an overflow of a require statement.



Lets take our new numbers and plug them into the below code and see what happens:

1. uint total = _users.length * _tokens;
2. require(balances[msg.sender] >= total);
3. balances[msg.sender] = balances[msg.sender] -total;

4. for(uint i=0; i < users.length; i++){ 

5.       balances[_users[i]] = balances[_users[i]] + _value;



Same statements substituting the variables for our scenarios values:

1. uint total = _200 * 500;
2. require(10,000 >= 0);
3. balances[msg.sender] = 10,000 - 0;

4. for(uint i=0; i < 500; i++){ 

5.      balances[_recievers[i]] = balances[_recievers[i]] + 500;


Batch Overflow Code Explanation:

1: The total variable is 100,000 which becomes 0 due to the 5 digit limit overflow when a 6th digit is hit at 99,999 + 1 = 0. So total now becomes 0.

2: This line checks if the users balance is high enough to cover the total value to be sent which in this case is 0 so 10,000 is more then enough to cover a 0 total and this check passes due to the overflow.

3: This line deducts the total from the senders balance which does nothing since the total of 10,000 - 0 is 10,000.  The sender has lost no funds.

4-5: This loop iterates over the 200 users who each get 500 tokens and updates the balances of each user individually using the real value of 500 as this does not trigger an overflow condition. Thus sending out 100,000 tokens without reducing the senders balance or triggering an error due to lack of funds. Essentially creating tokens out of thin air.

In this scenario the user retained all of their tokens but was able to distribute 100k tokens across 200 users regardless if they had the proper funds to do so.

Lab Follow Along Time:

We went through what might have been an overwhelming amount of concepts in this chapter regarding over/underflow scenarios now lets do an example lab in the video below to illustrate this point and get a little hands on experience reviewing, writing and exploiting smart contracts. Also note in the blockchain youtube playlist we cover the same concepts from above if you need to hear them rather then read them.

For this lab we will use the Remix browser environment with the current solidity version as of this writing 0.5.12. You can easily adjust the compiler version on Remix to this version as versions update and change frequently.
https://remix.ethereum.org/

Below is a video going through coding your own vulnerable smart contract, the video following that goes through exploiting the code you create and the videos prior to that cover the concepts we covered above:


Download Video Lab Example Code:

Download Sample Code:

//Underflow Example Code: 
//Can you bypass the restriction? 
//--------------------------------------------
 pragma solidity ^0.5.12;

contract Underflow{
     mapping (address =>uint) balances;

     function contribute() public payable{
          balances[msg.sender] = msg.value;  
     }

     function getBalance() view public returns (uint){
          return balances[msg.sender];     
     }

     function transfer(address _reciever, uint _value) public payable{
         require(balances[msg.sender] - _value >= 5);
         balances[msg.sender] = balances[msg.sender] - _value;  

         balances[_reciever] = balances[_reciever] + _value;
     }
    
}

This next video walks through exploiting the code above, preferably hand coded by you into the remix environment. As the best way to learn is to code it yourself and understand each piece:


 

Conclusion: 

We covered a lot of information at this point and the video series playlist associated with this blog series has additional information and walk throughs. Also other videos as always will be added to this playlist including fixing integer overflows in the code and attacking an actual live Decentralized Blockchain Application. So check out those videos as they are dropped and the current ones, sit back and watch and re-enforce the concepts you learned in this blog and in the previous lab. This is an example from a full set of labs as part of a more comprehensive exploitation course we have been working on.

More info


  1. Pentest Tools Github
  2. Hacker Tools Hardware
  3. Hack Tools Online
  4. Hacker Tools Linux
  5. Install Pentest Tools Ubuntu
  6. Pentest Tools Subdomain
  7. Github Hacking Tools
  8. Hacker Tools Github
  9. Hacker Tools Linux
  10. Usb Pentest Tools
  11. Pentest Tools Framework
  12. Hacker Tools For Pc
  13. Hack Tools 2019
  14. Pentest Tools Alternative
  15. Kik Hack Tools
  16. Hack Tools 2019
  17. Pentest Tools Free
  18. Pentest Automation Tools
  19. Hack Tools For Games
  20. Hacking Tools 2019
  21. Bluetooth Hacking Tools Kali
  22. Kik Hack Tools
  23. Hack Tools For Pc
  24. How To Hack
  25. Beginner Hacker Tools
  26. Hacking Tools Windows 10
  27. How To Hack
  28. New Hack Tools
  29. Hacker Tools List
  30. Pentest Tools Open Source
  31. Hacker Hardware Tools
  32. Beginner Hacker Tools
  33. Hacking Tools Kit
  34. Pentest Reporting Tools
  35. Hacking Tools Github
  36. Physical Pentest Tools
  37. Hacker Search Tools
  38. Hackrf Tools
  39. Hacking Tools
  40. Android Hack Tools Github
  41. Hacking Tools For Windows 7
  42. Hacker Tools
  43. New Hack Tools
  44. Pentest Tools For Ubuntu
  45. Hacking Tools 2020
  46. Hack Tools Online
  47. Hacker Tools For Mac
  48. Hacker
  49. Hack Tools For Games
  50. Hacker Tools Mac
  51. Ethical Hacker Tools
  52. New Hacker Tools
  53. Hacking Tools For Windows Free Download
  54. Hack Tools Online
  55. Nsa Hack Tools
  56. Hack Tools Mac
  57. Hack Apps
  58. Hacking Tools For Windows 7
  59. Hacker Tools Software
  60. Pentest Tools Bluekeep
  61. Hack Tools Github
  62. Hacking Tools Github
  63. How To Hack
  64. Hack Tools Mac
  65. Hacking Tools For Games
  66. Pentest Tools Apk
  67. Hacking Tools
  68. Hacking Tools Github
  69. Hack App
  70. Hacker Tools For Pc
  71. Best Hacking Tools 2020
  72. Black Hat Hacker Tools
  73. Hacking Tools For Windows 7
  74. Pentest Tools Subdomain
  75. Hacker Tools Apk Download
  76. Pentest Tools Online
  77. Hacker Tools Linux
  78. Nsa Hack Tools Download
  79. Hacker Tools Linux
  80. Hacker Tools List
  81. Hacking App
  82. Hack Website Online Tool
  83. Hacker Techniques Tools And Incident Handling
  84. Hacker Tools Apk
  85. Pentest Tools Url Fuzzer
  86. Hacker Tools List
  87. Pentest Tools Windows
  88. Pentest Tools List
  89. Hacking Tools Mac
  90. Hacking Tools Pc