Nathaniel Sauer

Cybersecurity and software engineer

All work

syscall-smuggler

Position-independent x86-64 shellcode that gets past a filter on syscall bytes

securitycoursework

What it is

Hand-written x86-64 shellcode for a CSE 466 Computer Systems Security challenge. The program under test rejects any input that contains the raw bytes of a syscall instruction, which normally rules out shellcode that talks to the kernel.

What I built

Shellcode that still makes the system calls it needs: open /flag, read it into a buffer and write the contents to stdout. It is position independent, so it runs wherever it lands in memory.

How it works

The filter only inspects the input region. So the shellcode never contains a syscall instruction itself. Instead, it sets up a second writable page, writes a small syscall; ret gadget there at run time, and calls that gadget indirectly each time it needs the kernel. The forbidden bytes only exist in memory the filter never sees.

The lesson: a filter that checks bytes in one place is not a filter on behavior. Code that can write and then jump to new memory can rebuild whatever the filter removed.