1. Preface
On the forum, I saw many friends who did not know what is the ESP law, what is the scope of application of ESP, what is the principle of ESP law, and how to use the ESP law? I saw my findings in the "" investigation and found that everyone is very interested in the ESP law, of course, because it is so easy to use, now I will tell you what is the ESP law, what is its principle!
BTW: After Reading 18 articles about manual shelling, reading this article may be more helpful to you!
Download from the address below:
Asp? Id = 37350 & no = 1 "> http://www.jetdown.com/down/down.asp? Id = 37350 & no = 1
2. Prerequisites
Before we begin to discuss the ESP law, I will explain some simple assembly knowledge to you.
1. call
This command is a basic assembly instruction for accessing subprograms. Maybe you said, I already know this! Don't worry, please continue watching.
What is the true meaning of call? We can understand this as follows: 1. The address of the next program is pushed to the stack; 2. The address of the subroutine from JMP to call. For example:
00401029. E8 DA240A00 call 004A3508
0040102E. 5A pop edx
After 00401029 is executed, the program will press 0040102E into the stack, and then JMP to 004A3508 address!
2. RET
The corresponding call is RET. We can understand RET as follows: 1. Stack the address pointed to in the current ESP; 2. Send JMP to this address.
This completes the process of calling a subroutine. The key here is: if we want to return the parent program, when we perform stack operations in the stack, we must ensure that before the RET command, ESP points to the address we press into the stack. This is also the famous "Stack balancing" principle!
3. Narrow ESP Law
The principle of ESP law is the "Stack balance" principle.
Let's take a look at the entrance to the program!
1. This is the value of each register when the entrance of the UPX shell is added!
EAX 00000000
ECX 0012FFB0
EDX 7FFE0304
EBX 7FFDF000
ESP 0012FFC4
EBP 0012FFF0
ESI 77F51778 ntdll.77F51778
EDI 77F517E6 ntdll.77F517E6
EIP 0040EC90 note-upx.
C 0 ES 0023 32bit 0 (FFFFFFFF)
P 1 CS 001B 32bit 0 (FFFFFFFF)
A 0 SS 0023 32bit 0 (FFFFFFFF)
Z 0 DS 0023 32bit 0 (FFFFFFFF)
S 1 FS 0038 32bit 7FFDE000 (FFF)
T 0 GS 0000 NULL
D 0
O 0 LastErr ERROR_MOD_NOT_FOUND (0000007E)
2. This is the value of the Register after the UPX shell JMP goes to OEP!
EAX 00000000
ECX 0012FFB0
EDX 7FFE0304
EBX 7FFDF000
ESP 0012FFC4
EBP 0012FFF0
ESI 77F51778 ntdll.77F51778
EDI 77F517E6 ntdll.77F517E6
EIP 004010CC note-upx.004010CC.
C 0 ES 0023 32bit 0 (FFFFFFFF)
P 1 CS 001B 32bit 0 (FFFFFFFF)
A 0 SS 0023 32bit 0 (FFFFFFFF)
Z 1 DS 0023 32bit 0 (FFFFFFFF)
S 0 FS 0038 32bit 7FFDE000 (FFF)
T 0 GS 0000 NULL
D 0
O 0 LastErr ERROR_MOD_NOT_FOUND (0000007E)
Haha ~ Is it the same except for the EIP!
Why?
Let's take a look at the first line of the UPX shell:
0040EC90 n> 60 pushad // ***** pay attention to this *****
0040EC91 BE 15B04000 mov esi, note-upx.0040B015
PUSHAD is to press all registers on the stack! At the end of the shell, let's take a look:
0040EE0F 61 popad // ***** Note *****
0040EE10-E9 B722FFFF jmp note-upx.004010CC // JMP to OEP
POP is to take all registers out of the stack!
When we PUSHAD, ESP pushed the Register into the stack of 0012FFC0--0012FFA4! As follows:
0012FFA4 77F517E6 returned to ntdll.77F517E6 from ntdll.77F78C4E // EDI
0012FFA8 77F51778 returned to ntdll.77F51778 from ntdll.77F517B5 // ESI
0012 FFAC 0012FFF0 // EBP
0012FFB0 0012FFC4 // ESP
0012FFB4 7FFDF000 // EBX
0012FFB8 7FFE0304 // EDX
0012 FFBC 0012FFB0 // ECX
0012FFC0 00000000 // EAX
In this case, we will tell you the hardware access breakpoint for the ESP 0012FFA4. That is to say, when the program needs to access these stacks, so as to restore the original register value and prepare to jump to the search OEP, OD helps us to interrupt.
So we stopped at ee10!
Summary: Let's assume the shell is a subroutine. After the shell unzips the code and decompress it, what he must do is follow the stack Balancing Principle and let ESP execute it to OEP, make ESP = 0012FFC4.
4. General ESP Law
After reading the tutorial, many people will ask: is the ESP law 0012FFA4? Is the ESP law applicable only to compression shells!
My answer is: NO!
After reading the above, you will know that if you use 0012FFA8, you can also use the ESP law not only to compress the shell, but also to encrypt the shell !!!
First, tell you an experience that is also true-when the PE file starts running, that is, the first line of code that enters the shell. The register value is always the value above. If you don't believe it, try it yourself! When OEP is reached, most of the programs will start with a pressure stack! (Apart from the programs compiled by BC, BC usually uses the following statements to press the stack)
Now, based on the above ESP principle, we know that most shells run to OEP when ESP = 0012FFC4. That is to say, the first sentence of the program is to write 0012FFC0!
Finally, we get the general ESP law. If the hardware writes a breakpoint under 0012FFC0, we can stop at the second sentence of OEP !!
Let's take an example. Let's go to the first article on shelling!
After loading OD, come here:
0040D042 N> B8 00D04000 mov eax, Notepad.0040D000 // stop here
00