diff --git a/.custom_shields/hash_params.json b/.custom_shields/hash_params.json deleted file mode 100644 index a86dc65..0000000 --- a/.custom_shields/hash_params.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "schemaVersion": 1, - "label": "hash_params", - "message": "1.0.0", - "color": "blue" -} \ No newline at end of file diff --git a/.custom_shields/process_hollowing.json b/.custom_shields/process_hollowing.json deleted file mode 100644 index b54d63c..0000000 --- a/.custom_shields/process_hollowing.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "schemaVersion": 1, - "label": "process_hollowing", - "message": "1.7.1", - "color": "blue" -} \ No newline at end of file diff --git a/.custom_shields/process_migration.json b/.custom_shields/process_migration.json deleted file mode 100644 index 35072f3..0000000 --- a/.custom_shields/process_migration.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "schemaVersion": 1, - "label": "process_migration", - "message": "1.9.1", - "color": "blue" -} \ No newline at end of file diff --git a/.custom_shields/tcp_reverse_shell.json b/.custom_shields/tcp_reverse_shell.json deleted file mode 100644 index f66ecd1..0000000 --- a/.custom_shields/tcp_reverse_shell.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "schemaVersion": 1, - "label": "tcp_reverse_shell", - "message": "1.3.1", - "color": "blue" -} \ No newline at end of file diff --git a/.custom_shields/xor_params.json b/.custom_shields/xor_params.json deleted file mode 100644 index fa19ae5..0000000 --- a/.custom_shields/xor_params.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "schemaVersion": 1, - "label": "xor_params", - "message": "1.2.0", - "color": "blue" -} \ No newline at end of file diff --git a/.gitignore b/.gitignore index 7d832c2..014d5d2 100644 --- a/.gitignore +++ b/.gitignore @@ -4,4 +4,5 @@ target/ # Files -*.txt \ No newline at end of file +*.txt +.DS_Store diff --git a/Cargo.lock b/Cargo.lock index 0d0b621..1e6832a 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -109,9 +109,9 @@ checksum = "baf1de4339761588bc0619e3cbc0120ee582ebb74b53b4efbf79117bd2da40sfd" [[package]] name = "getrandom" -version = "0.2.7" +version = "0.2.8" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "4eb1a864a501629691edf6c15a593b7a51eebaa1e8468e9ddc623de7c9b58ec6" +checksum = "c05aeb6a22b8f62540c194aac980f2115af067bfe15a0734d7277a768d396b31" dependencies = [ "cfg-if", "libc", @@ -120,7 +120,7 @@ dependencies = [ [[package]] name = "hash_params" -version = "1.0.0" +version = "1.0.1" dependencies = [ "rco_config", "rco_utils", @@ -128,9 +128,9 @@ dependencies = [ [[package]] name = "libc" -version = "0.2.132" +version = "0.2.137" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "8371e4e5341c3a96db127eb2465ac681ced4c433e01dd0e938adbef26ba93ba5" +checksum = "fc7fcc620a3bff7cdd7a365be3376c97191aeaccc2a603e600951e452615bf89" [[package]] name = "log" @@ -219,13 +219,13 @@ checksum = "8b870d8c151b6f2fb93e84a13146138f05d02ed11c7e7c54f8826aaaf7c9f184" [[package]] name = "ppv-lite86" -version = "0.2.16" +version = "0.2.17" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "eb9f9e6e233e5c4a35559a617bf40a4ec447db2e84c20b55a6f83167b7e57872" +checksum = "5b40af805b3121feab8a3c29f04d8ad262fa8e0561883e7653e024ae4479e6de" [[package]] name = "process_hollowing" -version = "1.7.1" +version = "1.10.0" dependencies = [ "nix", "rco_config", @@ -235,7 +235,7 @@ dependencies = [ [[package]] name = "process_migration" -version = "1.9.1" +version = "1.11.0" dependencies = [ "nix", "rco_config", @@ -279,7 +279,7 @@ version = "0.2.0" [[package]] name = "rco_utils" -version = "1.0.1" +version = "1.2.0" dependencies = [ "rand", "windows", @@ -370,7 +370,7 @@ checksum = "20518fe4a4c9acf048008599e464deb21beeae3d3578418951a189c235a7a9a8" [[package]] name = "tcp_reverse_shell" -version = "1.3.1" +version = "1.4.1" dependencies = [ "rco_config", "rco_utils", @@ -385,9 +385,9 @@ checksum = "9c8d87e72b64a3b4db28d11ce29237c246188f4f51057d65a7eab63b7987e423" [[package]] name = "windows" -version = "0.40.0" +version = "0.43.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "e30acc718a52fb130fec72b1cb5f55ffeeec9253e1b785e94db222178a6acaa1" +checksum = "04662ed0e3e5630dfa9b26e4cb823b817f1a9addda855d973a9458c236556244" dependencies = [ "windows_aarch64_gnullvm", "windows_aarch64_msvc", @@ -400,45 +400,45 @@ dependencies = [ [[package]] name = "windows_aarch64_gnullvm" -version = "0.40.0" +version = "0.42.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "f3caa4a1a16561b714323ca6b0817403738583033a6a92e04c5d10d4ba37ca10" +checksum = "41d2aa71f6f0cbe00ae5167d90ef3cfe66527d6f613ca78ac8024c3ccab9a19e" [[package]] name = "windows_aarch64_msvc" -version = "0.40.0" +version = "0.42.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "328973c62dfcc50fb1aaa8e7100676e0b642fe56bac6bafff3327902db843ab4" +checksum = "dd0f252f5a35cac83d6311b2e795981f5ee6e67eb1f9a7f64eb4500fbc4dcdb4" [[package]] name = "windows_i686_gnu" -version = "0.40.0" +version = "0.42.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "aa5b09fad70f0df85dea2ac2a525537e415e2bf63ee31cf9b8e263645ee9f3c1" +checksum = "fbeae19f6716841636c28d695375df17562ca208b2b7d0dc47635a50ae6c5de7" [[package]] name = "windows_i686_msvc" -version = "0.40.0" +version = "0.42.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "2a1ad4031c1a98491fa195d8d43d7489cb749f135f2e5c4eed58da094bd0d876" +checksum = "84c12f65daa39dd2babe6e442988fc329d6243fdce47d7d2d155b8d874862246" [[package]] name = "windows_x86_64_gnu" -version = "0.40.0" +version = "0.42.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "520ff37edd72da8064b49d2281182898e17f0688ae9f4070bca27e4b5c162ac7" +checksum = "bf7b1b21b5362cbc318f686150e5bcea75ecedc74dd157d874d754a2ca44b0ed" [[package]] name = "windows_x86_64_gnullvm" -version = "0.40.0" +version = "0.42.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "046e5b82215102c44fd75f488f1b9158973d02aa34d06ed85c23d6f5520a2853" +checksum = "09d525d2ba30eeb3297665bd434a54297e4170c7f1a44cad4ef58095b4cd2028" [[package]] name = "windows_x86_64_msvc" -version = "0.40.0" +version = "0.42.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "2a0c9c6df55dd1bfa76e131cef44bdd8ec9c819ef3611f04dfe453fd5bfeda28" +checksum = "f40009d85759725a34da6d89a94e63d7bdc50a862acf0dbc7c8e488f1edcb6f5" [[package]] name = "xor_params" diff --git a/docs/_config.yml b/docs/_config.yml index 553feb1..5154ef9 100644 --- a/docs/_config.yml +++ b/docs/_config.yml @@ -11,4 +11,3 @@ include: - process_migration.md - tcp_reverse_shell.md - xor_params.md - - assets/js/copy_code.js diff --git a/docs/assets/images/linux/hollowing.png b/docs/assets/images/linux/hollowing.png new file mode 100644 index 0000000..b5260bd Binary files /dev/null and b/docs/assets/images/linux/hollowing.png differ diff --git a/docs/assets/images/linux/hollowing_xor.png b/docs/assets/images/linux/hollowing_xor.png new file mode 100644 index 0000000..8ca5cd6 Binary files /dev/null and b/docs/assets/images/linux/hollowing_xor.png differ diff --git a/docs/assets/images/linux/migration.png b/docs/assets/images/linux/migration.png new file mode 100644 index 0000000..35c07fd Binary files /dev/null and b/docs/assets/images/linux/migration.png differ diff --git a/docs/assets/images/linux/migration_xor.png b/docs/assets/images/linux/migration_xor.png new file mode 100644 index 0000000..f7006a6 Binary files /dev/null and b/docs/assets/images/linux/migration_xor.png differ diff --git a/docs/assets/images/linux/shell.png b/docs/assets/images/linux/shell.png new file mode 100644 index 0000000..2416dc6 Binary files /dev/null and b/docs/assets/images/linux/shell.png differ diff --git a/docs/assets/images/process_hollowing.png b/docs/assets/images/process_hollowing.png deleted file mode 100644 index 640f8c8..0000000 Binary files a/docs/assets/images/process_hollowing.png and /dev/null differ diff --git a/docs/assets/images/process_hollowing_antisand_antistring_exe.png b/docs/assets/images/process_hollowing_antisand_antistring_exe.png deleted file mode 100644 index d603f3c..0000000 Binary files a/docs/assets/images/process_hollowing_antisand_antistring_exe.png and /dev/null differ diff --git a/docs/assets/images/process_hollowing_antisand_antistring_xor_exe.png b/docs/assets/images/process_hollowing_antisand_antistring_xor_exe.png deleted file mode 100644 index 7f330ca..0000000 Binary files a/docs/assets/images/process_hollowing_antisand_antistring_xor_exe.png and /dev/null differ diff --git a/docs/assets/images/process_hollowing_antisand_exe.png b/docs/assets/images/process_hollowing_antisand_exe.png deleted file mode 100644 index f4ac7e2..0000000 Binary files a/docs/assets/images/process_hollowing_antisand_exe.png and /dev/null differ diff --git a/docs/assets/images/process_hollowing_antisand_xor_exe.png b/docs/assets/images/process_hollowing_antisand_xor_exe.png deleted file mode 100644 index 0eb3add..0000000 Binary files a/docs/assets/images/process_hollowing_antisand_xor_exe.png and /dev/null differ diff --git a/docs/assets/images/process_hollowing_antistring_exe.png b/docs/assets/images/process_hollowing_antistring_exe.png deleted file mode 100644 index 69e757b..0000000 Binary files a/docs/assets/images/process_hollowing_antistring_exe.png and /dev/null differ diff --git a/docs/assets/images/process_hollowing_antistring_xor_exe.png b/docs/assets/images/process_hollowing_antistring_xor_exe.png deleted file mode 100644 index b2d3d8b..0000000 Binary files a/docs/assets/images/process_hollowing_antistring_xor_exe.png and /dev/null differ diff --git a/docs/assets/images/process_hollowing_exe.png b/docs/assets/images/process_hollowing_exe.png deleted file mode 100644 index 69c37bb..0000000 Binary files a/docs/assets/images/process_hollowing_exe.png and /dev/null differ diff --git a/docs/assets/images/process_hollowing_xor.png b/docs/assets/images/process_hollowing_xor.png deleted file mode 100644 index efb598f..0000000 Binary files a/docs/assets/images/process_hollowing_xor.png and /dev/null differ diff --git a/docs/assets/images/process_hollowing_xor_exe.png b/docs/assets/images/process_hollowing_xor_exe.png deleted file mode 100644 index dfeb622..0000000 Binary files a/docs/assets/images/process_hollowing_xor_exe.png and /dev/null differ diff --git a/docs/assets/images/process_migration.png b/docs/assets/images/process_migration.png deleted file mode 100644 index 969f163..0000000 Binary files a/docs/assets/images/process_migration.png and /dev/null differ diff --git a/docs/assets/images/process_migration_antisand_antistring_exe.png b/docs/assets/images/process_migration_antisand_antistring_exe.png deleted file mode 100644 index 2cd2949..0000000 Binary files a/docs/assets/images/process_migration_antisand_antistring_exe.png and /dev/null differ diff --git a/docs/assets/images/process_migration_antisand_antistring_xor_exe.png b/docs/assets/images/process_migration_antisand_antistring_xor_exe.png deleted file mode 100644 index 5c8b4a3..0000000 Binary files a/docs/assets/images/process_migration_antisand_antistring_xor_exe.png and /dev/null differ diff --git a/docs/assets/images/process_migration_antisand_exe.png b/docs/assets/images/process_migration_antisand_exe.png deleted file mode 100644 index 9c7fe91..0000000 Binary files a/docs/assets/images/process_migration_antisand_exe.png and /dev/null differ diff --git a/docs/assets/images/process_migration_antisand_xor_exe.png b/docs/assets/images/process_migration_antisand_xor_exe.png deleted file mode 100644 index a3e4d4b..0000000 Binary files a/docs/assets/images/process_migration_antisand_xor_exe.png and /dev/null differ diff --git a/docs/assets/images/process_migration_antistring_exe.png b/docs/assets/images/process_migration_antistring_exe.png deleted file mode 100644 index 9aa5902..0000000 Binary files a/docs/assets/images/process_migration_antistring_exe.png and /dev/null differ diff --git a/docs/assets/images/process_migration_antistring_xor_exe.png b/docs/assets/images/process_migration_antistring_xor_exe.png deleted file mode 100644 index 3e7ec9f..0000000 Binary files a/docs/assets/images/process_migration_antistring_xor_exe.png and /dev/null differ diff --git a/docs/assets/images/process_migration_exe.png b/docs/assets/images/process_migration_exe.png deleted file mode 100644 index 1a6c660..0000000 Binary files a/docs/assets/images/process_migration_exe.png and /dev/null differ diff --git a/docs/assets/images/process_migration_xor.png b/docs/assets/images/process_migration_xor.png deleted file mode 100644 index 2b033b9..0000000 Binary files a/docs/assets/images/process_migration_xor.png and /dev/null differ diff --git a/docs/assets/images/process_migration_xor_exe.png b/docs/assets/images/process_migration_xor_exe.png deleted file mode 100644 index ced6fa5..0000000 Binary files a/docs/assets/images/process_migration_xor_exe.png and /dev/null differ diff --git a/docs/assets/images/tcp_reverse_shell.png b/docs/assets/images/tcp_reverse_shell.png deleted file mode 100644 index 3baa000..0000000 Binary files a/docs/assets/images/tcp_reverse_shell.png and /dev/null differ diff --git a/docs/assets/images/tcp_reverse_shell_antisand_antistring_exe.png b/docs/assets/images/tcp_reverse_shell_antisand_antistring_exe.png deleted file mode 100644 index 61521e1..0000000 Binary files a/docs/assets/images/tcp_reverse_shell_antisand_antistring_exe.png and /dev/null differ diff --git a/docs/assets/images/tcp_reverse_shell_antisand_exe.png b/docs/assets/images/tcp_reverse_shell_antisand_exe.png deleted file mode 100644 index 38dd182..0000000 Binary files a/docs/assets/images/tcp_reverse_shell_antisand_exe.png and /dev/null differ diff --git a/docs/assets/images/tcp_reverse_shell_antistring_exe.png b/docs/assets/images/tcp_reverse_shell_antistring_exe.png deleted file mode 100644 index 3fac177..0000000 Binary files a/docs/assets/images/tcp_reverse_shell_antistring_exe.png and /dev/null differ diff --git a/docs/assets/images/tcp_reverse_shell_exe.png b/docs/assets/images/tcp_reverse_shell_exe.png deleted file mode 100644 index 44c303d..0000000 Binary files a/docs/assets/images/tcp_reverse_shell_exe.png and /dev/null differ diff --git a/docs/assets/images/windows/hollowing.png b/docs/assets/images/windows/hollowing.png new file mode 100644 index 0000000..90aeba2 Binary files /dev/null and b/docs/assets/images/windows/hollowing.png differ diff --git a/docs/assets/images/windows/hollowing_antisand.png b/docs/assets/images/windows/hollowing_antisand.png new file mode 100644 index 0000000..e7071ff Binary files /dev/null and b/docs/assets/images/windows/hollowing_antisand.png differ diff --git a/docs/assets/images/windows/hollowing_antisand_antistring.png b/docs/assets/images/windows/hollowing_antisand_antistring.png new file mode 100644 index 0000000..73c1291 Binary files /dev/null and b/docs/assets/images/windows/hollowing_antisand_antistring.png differ diff --git a/docs/assets/images/windows/hollowing_antisand_antistring_xor.png b/docs/assets/images/windows/hollowing_antisand_antistring_xor.png new file mode 100644 index 0000000..6ed8f2c Binary files /dev/null and b/docs/assets/images/windows/hollowing_antisand_antistring_xor.png differ diff --git a/docs/assets/images/windows/hollowing_antisand_xor.png b/docs/assets/images/windows/hollowing_antisand_xor.png new file mode 100644 index 0000000..6b8175e Binary files /dev/null and b/docs/assets/images/windows/hollowing_antisand_xor.png differ diff --git a/docs/assets/images/windows/hollowing_antistring.png b/docs/assets/images/windows/hollowing_antistring.png new file mode 100644 index 0000000..bc51a57 Binary files /dev/null and b/docs/assets/images/windows/hollowing_antistring.png differ diff --git a/docs/assets/images/windows/hollowing_antistring_xor.png b/docs/assets/images/windows/hollowing_antistring_xor.png new file mode 100644 index 0000000..782fe2d Binary files /dev/null and b/docs/assets/images/windows/hollowing_antistring_xor.png differ diff --git a/docs/assets/images/windows/hollowing_xor.png b/docs/assets/images/windows/hollowing_xor.png new file mode 100644 index 0000000..d485997 Binary files /dev/null and b/docs/assets/images/windows/hollowing_xor.png differ diff --git a/docs/assets/images/windows/migration.png b/docs/assets/images/windows/migration.png new file mode 100644 index 0000000..8bb28c6 Binary files /dev/null and b/docs/assets/images/windows/migration.png differ diff --git a/docs/assets/images/windows/migration_antisand.png b/docs/assets/images/windows/migration_antisand.png new file mode 100644 index 0000000..39fc370 Binary files /dev/null and b/docs/assets/images/windows/migration_antisand.png differ diff --git a/docs/assets/images/windows/migration_antisand_antistring.png b/docs/assets/images/windows/migration_antisand_antistring.png new file mode 100644 index 0000000..82ce83d Binary files /dev/null and b/docs/assets/images/windows/migration_antisand_antistring.png differ diff --git a/docs/assets/images/windows/migration_antisand_antistring_xor.png b/docs/assets/images/windows/migration_antisand_antistring_xor.png new file mode 100644 index 0000000..852d0a2 Binary files /dev/null and b/docs/assets/images/windows/migration_antisand_antistring_xor.png differ diff --git a/docs/assets/images/windows/migration_antisand_xor.png b/docs/assets/images/windows/migration_antisand_xor.png new file mode 100644 index 0000000..a65db0f Binary files /dev/null and b/docs/assets/images/windows/migration_antisand_xor.png differ diff --git a/docs/assets/images/windows/migration_antistring.png b/docs/assets/images/windows/migration_antistring.png new file mode 100644 index 0000000..97d41b2 Binary files /dev/null and b/docs/assets/images/windows/migration_antistring.png differ diff --git a/docs/assets/images/windows/migration_antistring_xor.png b/docs/assets/images/windows/migration_antistring_xor.png new file mode 100644 index 0000000..228b514 Binary files /dev/null and b/docs/assets/images/windows/migration_antistring_xor.png differ diff --git a/docs/assets/images/windows/migration_xor.png b/docs/assets/images/windows/migration_xor.png new file mode 100644 index 0000000..a2a2ece Binary files /dev/null and b/docs/assets/images/windows/migration_xor.png differ diff --git a/docs/assets/images/windows/shell.png b/docs/assets/images/windows/shell.png new file mode 100644 index 0000000..3649ee4 Binary files /dev/null and b/docs/assets/images/windows/shell.png differ diff --git a/docs/assets/images/windows/shell_antisand.png b/docs/assets/images/windows/shell_antisand.png new file mode 100644 index 0000000..8aac164 Binary files /dev/null and b/docs/assets/images/windows/shell_antisand.png differ diff --git a/docs/assets/images/windows/shell_antisand_antistring.png b/docs/assets/images/windows/shell_antisand_antistring.png new file mode 100644 index 0000000..0c1c47d Binary files /dev/null and b/docs/assets/images/windows/shell_antisand_antistring.png differ diff --git a/docs/assets/images/windows/shell_antistring.png b/docs/assets/images/windows/shell_antistring.png new file mode 100644 index 0000000..4067135 Binary files /dev/null and b/docs/assets/images/windows/shell_antistring.png differ diff --git a/docs/hash_params.md b/docs/hash_params.md index c25ffea..15283f5 100644 --- a/docs/hash_params.md +++ b/docs/hash_params.md @@ -4,9 +4,7 @@ title: "Hash params" # RCO: Hash Params -[](https://github.com/kmanc/remote_code_oxidation/tree/master/hash_params) - -[](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/gifs/hash_params.gif) +[](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/gifs/hash_params.gif) ## How it works diff --git a/docs/index.md b/docs/index.md index 6d2caff..33451d4 100644 --- a/docs/index.md +++ b/docs/index.md @@ -15,17 +15,21 @@ RCO tools can be compiled on either Linux or Windows systems to provide its user ## Tools list -[](https://kmanc.github.io/remote_code_oxidation/hash_params.html) -[](https://kmanc.github.io/remote_code_oxidation/process_hollowing.html) +[](https://kmanc.github.io/remote_code_oxidation/process_hollowing.html) -[](https://kmanc.github.io/remote_code_oxidation/process_migration.html) +[](https://kmanc.github.io/remote_code_oxidation/process_migration.html) -[](https://kmanc.github.io/remote_code_oxidation/tcp_reverse_shell.html) +[](https://kmanc.github.io/remote_code_oxidation/tcp_reverse_shell.html) -[](https://kmanc.github.io/remote_code_oxidation/xor_params.html) -## Setup +## Helper tools + +1. [hash_params](https://kmanc.github.io/remote_code_oxidation/hash_params.html) + +2. [xor_params](https://kmanc.github.io/remote_code_oxidation/xor_params.html) + +## Building the executables Clone the repo ```commandline @@ -33,7 +37,11 @@ git clone https://github.com/kmanc/remote_code_oxidation.git ``` -### From Linux host for Linux target +### From Linux +--- + +##### For Linux +--- Install Rust ```commandline @@ -47,31 +55,127 @@ sudo apt install build-essential Build! ```commandline -cargo build [-p package_name] [--features [xor][antisand]] [--release] +cargo build [-p package_name] [--features [antisand][,][antistring][,][xor]] [--release] ``` - -### From Linux host for Windows target +##### For Windows +--- Install Rust ```commandline curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh ``` -Add dependencies for cross-compiling +Add dependencies for cross-compiling (1) +```commandline +rustup target add x86_64-pc-windows-gnu +``` + +Add dependencies for cross-compiling (2) ```commandline sudo apt install mingw-w64 -rustup target add x86_64-pc-windows-gnu ``` Build! ```commandline -cargo build --target x86_64-pc-windows-gnu [-p package_name] [--features [xor][antisand]] [--release] +cargo build --target x86_64-pc-windows-gnu [-p package_name] [--features [antisand][,][antistring][,][xor]] [--release] ``` -### From Windows host for Linux target -#### Todo +### From Mac +--- -### From Windows host for Windows target -#### Todo +##### For Linux +--- + +Install Rust +``` +curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh +``` + +Add dependencies for cross-compiling (1) +```commandline +rustup target add x86_64-unknown-linux-musl +``` + +Add dependencies for cross-compiling (2) +```commandline +brew install filosottile/musl-cross/musl-cross +``` + +Configure linker for cross-compiling +```commandline +Create a file in your home directory's .cargo directory called config.toml with the following contents +[target.x86_64-unknown-linux-musl] +linker = "x86_64-linux-musl-gcc" +``` + +Build! +```commandline +cargo build --target x86_64-unknown-linux-musl [-p package_name] [--features [antisand][,][antistring][,][xor]] [--release] +``` + +##### For Windows +--- + +Install Rust +``` +curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh +``` + +Add dependencies for cross-compiling (1) +```commandline +rustup target add x86_64-pc-windows-gnu +``` + +Add dependencies for cross-compiling (2) +```commandline +brew install mingw-w64 +``` + +Build! +```commandline +cargo build --target x86_64-pc-windows-gnu [-p package_name] [--features [antisand][,][antistring][,][xor]] [--release] +``` + + +### From Windows +--- + +##### For Linux +--- + +Install Rust +``` +Download and run the installer from the Rust website +``` + +Add dependencies for cross-compiling +```commandline +rustup target add x86_64-pc-windows-gnu +``` + +Configure linker for cross-compiling +```commandline +Create a file in your home directory's .cargo directory called config.toml with the following contents +[target.x86_64-unknown-linux-musl] +linker = "rust-lld" +``` + +Build! +```commandline +cargo build --target x86_64-unknown-linux-musl [-p package_name] [--features [antisand][,][antistring][,][xor]] [--release] +``` + +##### For Windows +--- + +Install Rust +``` +Download and run the installer from the Rust website +``` + +Build! +```commandline +cargo build [-p package_name] [--features [antisand][,][antistring][,][xor]] [--release] +``` diff --git a/docs/process_hollowing.md b/docs/process_hollowing.md index 26cf5e3..95ecee9 100644 --- a/docs/process_hollowing.md +++ b/docs/process_hollowing.md @@ -5,14 +5,14 @@ datatable: true # RCO: Process Hollowing -[](https://github.com/kmanc/remote_code_oxidation/tree/master/process_hollowing) +[](https://github.com/kmanc/remote_code_oxidation/tree/master/process_hollowing)
Target OS | Demo --------- | ---- -Linux | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/gifs/process_hollowing.gif) -Windows | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/gifs/process_hollowing_windows.gif) +Linux | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/gifs/process_hollowing.gif) +Windows | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/gifs/process_hollowing_windows.gif) @@ -52,15 +52,15 @@ nc -nlvp 4444 Target OS | Features | Detections | Screenshot --------- | ----------------------------- | -------------------------------------- | ---------- -Linux | None | [7 / 40](https://kleenscan.com/scan_result/1177abafe77dc580337ec6294c68bdc4873ceb36a4eeac057fd0673c3ae50e7f) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing.png) -Linux | `xor` | [0 / 40](https://kleenscan.com/scan_result/8a0268ca750a14fc93f40f6b1864f13ce94318c4c4a7ecc49dfeb332b9c9d860) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing_xor.png) -Windows | None | [12 / 40](https://kleenscan.com/scan_result/dd7858b48235bc782383fa5a929125369c7918d3c119a9196b0fdab791624763) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing_exe.png) -Windows | `antisand` | [12 / 40](https://kleenscan.com/scan_result/dc73a322924b772b90957aaffe8d2735acd6d6049e0607a1befada2bc5aa86f3) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing_antisand_exe.png) -Windows | `antistring` | [12 / 40](https://kleenscan.com/scan_result/1505ac5f33afe16a79796045d80c6c55617944c86396411487f1cbd934e875fb) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing_antistring_exe.png) -Windows | `antisand,antistring` | [12 / 40](https://kleenscan.com/scan_result/177242f39b392107e4953a8cb717afbc6f912daa5bd9ec8d71a959834942db8d) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing_antisand_antistring_exe.png) -Windows | `xor` | [6 / 40](https://kleenscan.com/scan_result/455d775c517cf26a6e83a42b3eae7982364d8a8174127eca377094c05e0dd948) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing_xor_exe.png) -Windows | `antistring,xor` | [1 / 40](https://kleenscan.com/scan_result/e6214cb0175737d1e3bba8bafbaa17d5aa575f613dab718a6d35dd46c7af8767) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing_antistring_xor_exe.png) -Windows | `antisand,xor` | [0 / 40](https://kleenscan.com/scan_result/de899245ec6a258d741b6243d18cf10fae5e6a1fe344ab3d02f17899a67d2bb7) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing_antisand_xor_exe.png) -Windows | `antisand,antistring,xor` | [0 / 40](https://kleenscan.com/scan_result/49f53e2e15b86d9e5425d684e9ab964289d2d96fef8ca61ba927e3826ebd0392) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing_antisand_antistring_xor_exe.png) +Linux | None | [7 / 40](https://kleenscan.com/scan_result/a6de6fa00c7b8c0d3bb1fbd1f207509987610fd7037bd3ab7818c12030d6c266) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/linux/hollowing.png) +Linux | `xor` | [1 / 40](https://kleenscan.com/scan_result/fd3affec1eaed16e9d6077e05f3807897a0994c33d3067ba53cdb907690b70e6) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/linux/hollowing_xor.png) +Windows | None | [12 / 40](https://kleenscan.com/scan_result/74e2475b5b5e881d3b31c5d3bac5e36f4c8bfa33235eb810706c33f338dbeb7c) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/hollowing.png) +Windows | `antisand` | [11 / 40](https://kleenscan.com/scan_result/1ce970448fa81ba854643bf4663afef87b2bdb7aa05ceda720ef82a70f8d932a) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/hollowing_antisand.png) +Windows | `antisand,antistring` | [11 / 40](https://kleenscan.com/scan_result/643bf03eb63541f6854d2898d2c809c368a14f82b57b9f85f7ec75f216aceef9) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/hollowing_antisand_antistring.png) +Windows | `antistring` | [11 / 40](https://kleenscan.com/scan_result/6a5599f63c58f1d3e09a7c11add05ab3abb2226682c8290d1b0dc445ac8279bc) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/hollowing_antistring.png) +Windows | `antistring,xor` | [1 / 40](https://kleenscan.com/scan_result/08572b59b640b6fea8a5f164d17056c48d4252a43a6a336e5091f024e3d25a4b) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/hollowing_antistring_xor.png) +Windows | `xor` | [1 / 40](https://kleenscan.com/scan_result/fd3affec1eaed16e9d6077e05f3807897a0994c33d3067ba53cdb907690b70e6) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/hollowing_xor.png) +Windows | `antisand,xor` | [0 / 40](https://kleenscan.com/scan_result/a7baee8c968a997f48257e8e67d197f92dfd52f1281a65e2a5557f654adb33f8) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/hollowing_antisand_xor.png) +Windows | `antisand,antistring,xor` | [0 / 40](https://kleenscan.com/scan_result/b2fb0120a966d36e2158fad5867a4caed0cea52db00d87244f1122e1f380122e) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/hollowing_antisand_antistring_xor.png) diff --git a/docs/process_migration.md b/docs/process_migration.md index 7039c7a..f0f004a 100644 --- a/docs/process_migration.md +++ b/docs/process_migration.md @@ -5,14 +5,14 @@ datatable: true # RCO: Process Migration -[](https://github.com/kmanc/remote_code_oxidation/tree/master/process_migration) +[](https://github.com/kmanc/remote_code_oxidation/tree/master/process_migration) Target OS | Demo --------- | ---- -Linux | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/gifs/process_migration.gif) -Windows | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/gifs/process_migration_windows.gif) +Linux | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/gifs/process_migration.gif) +Windows | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/gifs/process_migration_windows.gif) @@ -54,15 +54,15 @@ nc -nlvp 4444 Target OS | Features | Detections | Screenshot --------- | ----------------------------- | -------------------------------------- | ---------- -Linux | None | [7 / 40](https://kleenscan.com/scan_result/5d88b167a6fdf674a0a81514e37f171a4d0eb63c0b063dec1dd02a5d9b63d4fb) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration.png) -Linux | `xor` | [0 / 40](https://kleenscan.com/scan_result/5568475e28d65306af33f75df28e215e7024daa922241fbd9c1e9205cd27a96d) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration_xor.png) -Windows | None | [12 / 40](https://kleenscan.com/scan_result/ebebddfa24b6d95c65900003629914cbcadf09fddcd9a70db614b9f8e9f5fc42) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration_exe.png) -Windows | `antisand` | [12 / 40](https://kleenscan.com/scan_result/dc73a322924b772b90957aaffe8d2735acd6d6049e0607a1befada2bc5aa86f3) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration_antisand_exe.png) -Windows | `antistring` | [12 / 40](https://kleenscan.com/scan_result/7200bae53ce50bd8b0f3a528026ee72d71b47615235cf96384fe0752a1ff6145) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration_antistring_exe.png) -Windows | `antisand,antistring` | [12 / 40](https://kleenscan.com/scan_result/e702816970ee629f718e6dbec58a129b03742b0ac7644bc3de942d8368e7252b) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration_antisand_antistring_exe.png) -Windows | `xor` | [1 / 40](https://kleenscan.com/scan_result/8b3feb5f4db1b06a9fd33a9597b62d22847f518f607d7f049579b87b44ce8fea) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration_xor_exe.png) -Windows | `antistring,xor` | [1 / 40](https://kleenscan.com/scan_result/f580330422109325f3c83fd1fa51a966798cb173d0edca5c1b4c310a2c95c082) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration_antistring_xor_exe.png) -Windows | `antisand,xor` | [0 / 40](https://kleenscan.com/scan_result/19a7640ebedb91c375aeebf9d576ea005260610ca0eb23621413dc058a8ff067) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration_antisand_xor_exe.png) -Windows | `antisand,antistring,xor` | [0 / 40](https://kleenscan.com/scan_result/1de23cfca021214907bb51174df2b8d69d2fe45cb6ebc903c1e3328bb958678f) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration_antisand_antistring_xor_exe.png) +Linux | None | [6 / 40](https://kleenscan.com/scan_result/6dac826ee10612cecc1dec4043f590638a2287416904518d38c8347d55bda054) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/linux/migration.png) +Linux | `xor` | [0 / 40](https://kleenscan.com/scan_result/22551c73a19a51c251c8a3d95cd226bafad298db08bd0ec726591e86ef383ded) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/linux/migration_xor.png) +Windows | None | [11 / 40](https://kleenscan.com/scan_result/53ed56235d4d13d7e64fb567e4033a6e72743a0fc6bf7be3fc6af2c538170cf7) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/migration.png) +Windows | `antisand` | [11 / 40](https://kleenscan.com/scan_result/65a24b211b0f9c7012c6deebb0e46dab75314a5c7422a262f77c64a196599c3f) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/migration_antisand.png) +Windows | `antisand,antistring` | [11 / 40](https://kleenscan.com/scan_result/28c7306b456435e6794752ad0965ad62c2c330bfcf99c8026c425ca6188f3b0c) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/migration_antistring.png) +Windows | `antistring` | [11 / 40](https://kleenscan.com/scan_result/838c5b612c0419346395df55dfcd6c9278228e1003be78734bcf2210244d627d) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/migration_antistring.png) +Windows | `antistring,xor` | [1 / 40](https://kleenscan.com/scan_result/9466c0bbfacb8f7ebc8e92b50947bdf836cc2b4adeed10ed1d92040c9366f555) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/migration_antistring_xor.png) +Windows | `xor` | [1 / 40](https://kleenscan.com/scan_result/b65915b1a318d18c48195aa11fafd26937deb40c7fd60f123e447c279d9e9010) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/migration_xor.png) +Windows | `antisand,xor` | [0 / 40](https://kleenscan.com/scan_result/f343f23b7a8f3704784beb3f0902f994d97d4aae21f60383617a3c778365d9eb) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/migration_antisand_xor.png) +Windows | `antisand,antistring,xor` | [0 / 40](https://kleenscan.com/scan_result/3291825d7fe6b514dfb40f28d8beae090bbf6d040b5f7206b6eb3c6ad10f43d7) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/migration_antisand_antistring_xor.png) diff --git a/docs/tcp_reverse_shell.md b/docs/tcp_reverse_shell.md index 088c1cb..6549782 100644 --- a/docs/tcp_reverse_shell.md +++ b/docs/tcp_reverse_shell.md @@ -5,14 +5,14 @@ datatable: true # RCO: TCP Reverse Shell -[](https://github.com/kmanc/remote_code_oxidation/tree/master/tcp_reverse_shell) +[](https://github.com/kmanc/remote_code_oxidation/tree/master/tcp_reverse_shell) Target OS | Demo --------- | ---- -Linux | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/gifs/tcp_reverse_shell.gif) -Windows | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/gifs/tcp_reverse_shell_windows.gif) +Linux | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/gifs/tcp_reverse_shell.gif) +Windows | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/gifs/tcp_reverse_shell_windows.gif) @@ -48,10 +48,10 @@ nc -nlvp 4444 Target OS | Features | Detections | Screenshot --------- | ----------------------------- | -------------------------------------- | ---------- -Linux | None | [0 / 40](https://kleenscan.com/scan_result/c01984f5bc45f0ff82723fe6ceab770fe48e955081f8b02e17a8232e6ba2bbeb) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/tcp_reverse_shell.png) -Windows | None | [0 / 40](https://kleenscan.com/scan_result/ce74ac206b59e9acc4e7f528bcec06f2a1dcc8ac0a1fb622c0b646cdfd2602d5) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/tcp_reverse_shell_exe.png) -Windows | `antisand` | [0 / 40](https://kleenscan.com/scan_result/28fce6da1a75b3d0073649613d5e69b73019091e1a7c2a2033b1551755c5fad4) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/tcp_reverse_shell_antisand_exe.png) -Windows | `antistring` | [0 / 40](https://kleenscan.com/scan_result/fafcad9c3689cf811184cacc3c1e9f939017b4e5d362712468839a6126f82278) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/tcp_reverse_shell_antistring_exe.png) -Windows | `antisand,antistring` | [0 / 40](https://kleenscan.com/scan_result/ff8c1a3fda94bd5f73314e15c9861284250b88720f045351aedc937435b9d8bd) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/tcp_reverse_shell_antisand_antistring_exe.png) +Linux | None | [0 / 40](https://kleenscan.com/scan_result/a940621ddd4de3ac694ab97584536a1e0a06a222f174d023051c5c7786cb02ce) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/linux/shell.png) +Windows | None | [0 / 40](https://kleenscan.com/scan_result/3125f79d0b309eaecab29d4dbd8fb1521a53ca9bbd0f0b08f469a9c21cb0cb7b) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/shell.png) +Windows | `antisand` | [0 / 40](https://kleenscan.com/scan_result/5554067d19d276e3b9c85967d1c0044bdf3d1ab3ca36be816cc4f80d0296df1b) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/shell_antisand.png) +Windows | `antisand,antistring` | [0 / 40](https://kleenscan.com/scan_result/a0dc07b781618acdbc07c32cb12e5a41a860904672c288ba860a830e645eaaf8) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/shell_antisand_antistring.png) +Windows | `antistring` | [0 / 40](https://kleenscan.com/scan_result/2430b38a062a6aa57ac52f508308bcc171b258fc04c06d9d05ae39c0bd1e7417) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/images/windows/shell_antistring.png) diff --git a/docs/xor_params.md b/docs/xor_params.md index 0f70255..e62069e 100644 --- a/docs/xor_params.md +++ b/docs/xor_params.md @@ -4,9 +4,7 @@ title: "XOR Params" # RCO: XOR Params -[](https://github.com/kmanc/remote_code_oxidation/tree/master/xor_params) - -[](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/gifs/xor_params.gif) +[](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/main/docs/assets/gifs/xor_params.gif) ## How it works diff --git a/hash_params/Cargo.toml b/hash_params/Cargo.toml index df2190d..bff8be6 100644 --- a/hash_params/Cargo.toml +++ b/hash_params/Cargo.toml @@ -1,12 +1,12 @@ [package] -name = "hash_params" -version = "1.0.0" -edition = "2021" authors = ["Kevin Conley