Syscall Mechanics (x86-64)
- •
What it is
- •
The Linux x86-64 convention for calling the kernel directly: put the syscall number in
rax, load its arguments, then executesyscall.
- •
- •
How it works
- •
On Linux x86-64,
raxholds the syscall number; arguments userdi, rsi, rdx, r10, r8, r9. The instruction clobbersrcxandr11; the result returns inrax. - •
rax = syscall number rdi = arg1 rsi = arg2 rdx = arg3 r10 = arg4 r8 = arg5 r9 = arg6 syscall ; traps into the kernel, result returned in rax - •
Encountered so far:
open(rax=2),sendfile(rax=40),chmod(rax=90), andexecve(rax=59, covered conceptually in the intro video for spawning/bin/sh).
- •
- •
- •
- •
pwntools
- •
from pwn import constants print(constants.SYS_open, constants.SYS_sendfile)
- •
- •
Debugging
- •
catch syscall info registers rax rdi rsi rdx r10
- •
- •
- •