Shellcode
Also known as:Machine code payload
Shellcode: Compact machine code executed directly by the target process after successful exploitation. The name comes from the classic goal of spawning a command shell, but the payloadPayloadPart of an attack or exploit that executes the intended malicious effect. can perform arbitrary actions.
How it works and where it fits
Shellcode is position-independent machine code for a specific architecture and operating system. It typically issues system calls directly rather than using library functions, and often has to satisfy hard constraints: a fixed maximum length, no null bytes, sometimes printable characters only. An execve("/bin/sh") needs between 20 and 40 bytes depending on architecture; the embedded path string is frequently addressed PC-relative to save space.
Practical security relevance
For shellcode to run at all, the target memory must be both writable and executable. Non-executable memory and the W^X rule prevent exactly that, which is why hardened environments usually see ROPReturn-Oriented ProgrammingExploit technique that chains existing code fragments instead of injecting new code. in place of classic shellcode. As a finding, shellcode execution stays especially critical where an application allocates RWX memory itself and reads unvalidated input into it — a pattern that recurs in debug and diagnostic services on embedded devices.
Related concepts
- Binary ExploitationBinary ExploitationExploitation of memory or logic errors in compiled applications.: Exploitation of memory or logic errors in compiled applications.
- Return-Oriented ProgrammingReturn-Oriented ProgrammingExploit technique that chains existing code fragments instead of injecting new code.: Exploit technique that chains existing code fragments instead of injecting new code.
- PayloadPayloadPart of an attack or exploit that executes the intended malicious effect.: Part of an attack or exploit that executes the intended malicious effect.
- Buffer OverflowBuffer OverflowWriting beyond the bounds of a memory buffer, overwriting adjacent data.: Writing beyond the bounds of a memory buffer, overwriting adjacent data.