What it is
Hand-written x86-64 shellcode for a CSE 466 Computer Systems Security challenge. The program under
test rejects any input that contains the raw bytes of a syscall instruction, which normally rules
out shellcode that talks to the kernel.
What I built
Shellcode that still makes the system calls it needs: open /flag, read it into a buffer and write
the contents to stdout. It is position independent, so it runs wherever it lands in memory.
How it works
The filter only inspects the input region. So the shellcode never contains a syscall instruction
itself. Instead, it sets up a second writable page, writes a small syscall; ret gadget there at
run time, and calls that gadget indirectly each time it needs the kernel. The forbidden bytes only
exist in memory the filter never sees.
The lesson: a filter that checks bytes in one place is not a filter on behavior. Code that can write and then jump to new memory can rebuild whatever the filter removed.