put all the documentation stuff in the main branch so there isnt some weird disjointed tree (#59)
@@ -0,0 +1,21 @@
|
||||
MIT License
|
||||
|
||||
Copyright (c) 2022 Kevin Conley
|
||||
|
||||
Permission is hereby granted, free of charge, to any person obtaining a copy
|
||||
of this software and associated documentation files (the "Software"), to deal
|
||||
in the Software without restriction, including without limitation the rights
|
||||
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
|
||||
copies of the Software, and to permit persons to whom the Software is
|
||||
furnished to do so, subject to the following conditions:
|
||||
|
||||
The above copyright notice and this permission notice shall be included in all
|
||||
copies or substantial portions of the Software.
|
||||
|
||||
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
|
||||
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
|
||||
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
|
||||
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
|
||||
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
|
||||
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
|
||||
SOFTWARE.
|
||||
@@ -0,0 +1,15 @@
|
||||
theme: jekyll-theme-cayman
|
||||
markdown: kramdown
|
||||
plugins:
|
||||
- jekyll-relative-links
|
||||
relative_links:
|
||||
enabled: true
|
||||
collections: true
|
||||
include:
|
||||
- hash_params.md
|
||||
- process_hollowing.md
|
||||
- process_migration.md
|
||||
- tcp_reverse_shell.md
|
||||
- xor_params.md
|
||||
- LICENSE
|
||||
- assets/js/copy_code.js
|
||||
|
After Width: | Height: | Size: 152 KiB |
|
After Width: | Height: | Size: 547 KiB |
|
After Width: | Height: | Size: 853 KiB |
|
After Width: | Height: | Size: 691 KiB |
|
After Width: | Height: | Size: 904 KiB |
|
After Width: | Height: | Size: 578 KiB |
|
After Width: | Height: | Size: 604 KiB |
|
After Width: | Height: | Size: 552 KiB |
|
After Width: | Height: | Size: 34 KiB |
|
After Width: | Height: | Size: 38 KiB |
|
After Width: | Height: | Size: 34 KiB |
|
After Width: | Height: | Size: 39 KiB |
|
After Width: | Height: | Size: 34 KiB |
|
After Width: | Height: | Size: 36 KiB |
|
After Width: | Height: | Size: 37 KiB |
|
After Width: | Height: | Size: 37 KiB |
|
After Width: | Height: | Size: 36 KiB |
|
After Width: | Height: | Size: 35 KiB |
|
After Width: | Height: | Size: 35 KiB |
|
After Width: | Height: | Size: 36 KiB |
|
After Width: | Height: | Size: 34 KiB |
|
After Width: | Height: | Size: 39 KiB |
|
After Width: | Height: | Size: 38 KiB |
|
After Width: | Height: | Size: 38 KiB |
|
After Width: | Height: | Size: 38 KiB |
|
After Width: | Height: | Size: 37 KiB |
|
After Width: | Height: | Size: 34 KiB |
|
After Width: | Height: | Size: 37 KiB |
|
After Width: | Height: | Size: 34 KiB |
|
After Width: | Height: | Size: 37 KiB |
|
After Width: | Height: | Size: 37 KiB |
|
After Width: | Height: | Size: 36 KiB |
|
After Width: | Height: | Size: 34 KiB |
@@ -0,0 +1,28 @@
|
||||
---
|
||||
title: "Hash params"
|
||||
---
|
||||
|
||||
# RCO: Hash Params
|
||||
|
||||
[](https://github.com/kmanc/remote_code_oxidation/tree/master/hash_params)
|
||||
|
||||
[](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/gifs/hash_params.gif)
|
||||
|
||||
|
||||
## How it works
|
||||
|
||||
Hash params performs Rust's default hash algorithm ([SipHash-1-3 at the time of this writing](https://en.wikipedia.org/wiki/SipHash)) on command line arguments and prints their output in hex. This should not be considered cryptographically secure, but works for obfuscating a value in a repeatable way.
|
||||
|
||||
|
||||
## Using it
|
||||
|
||||
1. *[Not shown in demo]* Compile the executable
|
||||
1. For Linux
|
||||
```commandline
|
||||
cargo build -p hash_params --release
|
||||
```
|
||||
2. For Windows
|
||||
```commandline
|
||||
cargo build --target x86_64-pc-windows-gnu -p hash_params --release
|
||||
```
|
||||
2. Run the executable with the desired hash targets
|
||||
@@ -0,0 +1,77 @@
|
||||
---
|
||||
title: "Remote Code Oxidation"
|
||||
---
|
||||
|
||||
# Remote Code Oxidation (RCO)
|
||||
|
||||
[](https://github.com/kmanc/remote_code_oxidation/actions/workflows/linux.yml)
|
||||
[](https://github.com/kmanc/remote_code_oxidation/actions/workflows/windows.yml)
|
||||

|
||||
[](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/master/LICENSE)
|
||||
|
||||
Remote Code Oxidation is a collection of offensive security tools written in Rust. My main goal for the project is to enable offensive security professionals and practitioners to prepare the tools needed for an engagement with as little overhead as possible.
|
||||
|
||||
RCO tools can be compiled on either Linux or Windows systems to provide its users flexibility in their attack infrastructure. Similarly the tools work against either Linux or Windows targets to suit the needs of the task at hand.
|
||||
|
||||
|
||||
## Tools list
|
||||
[](https://kmanc.github.io/remote_code_oxidation/hash_params.html)
|
||||
|
||||
[](https://kmanc.github.io/remote_code_oxidation/process_hollowing.html)
|
||||
|
||||
[](https://kmanc.github.io/remote_code_oxidation/process_migration.html)
|
||||
|
||||
[](https://kmanc.github.io/remote_code_oxidation/tcp_reverse_shell.html)
|
||||
|
||||
[](https://kmanc.github.io/remote_code_oxidation/xor_params.html)
|
||||
|
||||
## Setup
|
||||
|
||||
Clone the repo
|
||||
```commandline
|
||||
git clone https://github.com/kmanc/remote_code_oxidation.git
|
||||
```
|
||||
|
||||
|
||||
### From Linux host for Linux target
|
||||
|
||||
Install Rust
|
||||
```commandline
|
||||
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
|
||||
```
|
||||
|
||||
Add dependencies for compiling
|
||||
```commandline
|
||||
sudo apt install build-essential
|
||||
```
|
||||
|
||||
Build!
|
||||
```commandline
|
||||
cargo build [-p package_name] [--features [xor][antisand]] [--release]
|
||||
```
|
||||
|
||||
|
||||
### From Linux host for Windows target
|
||||
|
||||
Install Rust
|
||||
```commandline
|
||||
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
|
||||
```
|
||||
|
||||
Add dependencies for cross-compiling
|
||||
```commandline
|
||||
sudo apt install mingw-w64
|
||||
rustup target add x86_64-pc-windows-gnu
|
||||
```
|
||||
|
||||
Build!
|
||||
```commandline
|
||||
cargo build --target x86_64-pc-windows-gnu [-p package_name] [--features [xor][antisand]] [--release]
|
||||
```
|
||||
|
||||
|
||||
### From Windows host for Linux target
|
||||
#### Todo
|
||||
|
||||
### From Windows host for Windows target
|
||||
#### Todo
|
||||
@@ -0,0 +1,66 @@
|
||||
---
|
||||
title: "Process Hollowing"
|
||||
datatable: true
|
||||
---
|
||||
|
||||
# RCO: Process Hollowing
|
||||
|
||||
[](https://github.com/kmanc/remote_code_oxidation/tree/master/process_hollowing)
|
||||
|
||||
<div class="datatable-begin"></div>
|
||||
|
||||
Target OS | Demo
|
||||
--------- | ----
|
||||
Linux | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/gifs/process_hollowing.gif)
|
||||
Windows | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/gifs/process_hollowing_windows.gif)
|
||||
|
||||
<div class="datatable-end"></div>
|
||||
|
||||
## How it works
|
||||
|
||||
Windows process hollowing works by creating a suspended process and writing the [shellcode](https://en.wikipedia.org/wiki/Shellcode) over the entry point of the process's main thread. It then resumes the suspended process, which in turn executes the shellcode.
|
||||
|
||||
Linux process hollowing functions a little differently. First, the executable creates a child process by cloning itself. Then it overwrites the child process's [instruction pointer](https://datacadamia.com/computer/instruction/instruction_pointer) with shellcode. Because this process was not running before the attack, it is unlikely this will cause any issues on the victim machine.
|
||||
|
||||
|
||||
## Using it
|
||||
|
||||
1. *[Not shown in demo]* Generate shellcode for the desired end result (for example, use [msfvenom](https://book.hacktricks.xyz/shells/shells/msfvenom) to generate a reverse TCP shell shellcode for the target operating system)
|
||||
2. *[Not shown in demo]* Open [the config file](https://github.com/kmanc/remote_code_oxidation/blob/master/rco_config/src/lib.rs)
|
||||
and change the shellcode to the shellcode generated in step 1
|
||||
3. *[Optional - shown in [xor_params demo](https://kmanc.github.io/remote_code_oxidation/xor_params.html)]* Encrypt the shellcode and target process using [xor_params](https://github.com/kmanc/remote_code_oxidation/blob/master/xor_shellcode) and update the encrypted shellcode value in [the config file](https://github.com/kmanc/remote_code_oxidation/blob/master/rco_config/src/lib.rs)
|
||||
4. *[Not shown in demo]* Compile the executable, only including `--features xor` if you did step 3
|
||||
1. Build for Linux target
|
||||
```commandline
|
||||
cargo build -p process_hollowing [antisand][,][antistring][,][xor]] --release
|
||||
```
|
||||
2. Build for Windows target
|
||||
```commandline
|
||||
cargo build --target x86_64-pc-windows-gnu -p process_hollowing [antisand][,][antistring][,][xor]] --release
|
||||
```
|
||||
5. Start a netcat listener on the attacking machine on the same port you configured the shellcode to connect to in step 1
|
||||
```commandline
|
||||
nc -nlvp 4444
|
||||
```
|
||||
6. Execute the payload on the victim machine
|
||||
7. Return to the listener and enter desired commands for the victim machine to run
|
||||
|
||||
|
||||
## Detection rates
|
||||
|
||||
<div class="datatable-begin"></div>
|
||||
|
||||
Target OS | Features | Detections | Screenshot
|
||||
--------- | ----------------------------- | -------------------------------------- | ----------
|
||||
Linux | None | [7 / 40](https://kleenscan.com/scan_result/1177abafe77dc580337ec6294c68bdc4873ceb36a4eeac057fd0673c3ae50e7f) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing.png)
|
||||
Linux | `xor` | [0 / 40](https://kleenscan.com/scan_result/8a0268ca750a14fc93f40f6b1864f13ce94318c4c4a7ecc49dfeb332b9c9d860) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing_xor.png)
|
||||
Windows | None | [12 / 40](https://kleenscan.com/scan_result/dd7858b48235bc782383fa5a929125369c7918d3c119a9196b0fdab791624763) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing_exe.png)
|
||||
Windows | `antisand` | [12 / 40](https://kleenscan.com/scan_result/dc73a322924b772b90957aaffe8d2735acd6d6049e0607a1befada2bc5aa86f3) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing_antisand_exe.png)
|
||||
Windows | `antistring` | [12 / 40](https://kleenscan.com/scan_result/1505ac5f33afe16a79796045d80c6c55617944c86396411487f1cbd934e875fb) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing_antistring_exe.png)
|
||||
Windows | `antisand,antistring` | [12 / 40](https://kleenscan.com/scan_result/177242f39b392107e4953a8cb717afbc6f912daa5bd9ec8d71a959834942db8d) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing_antisand_antistring_exe.png)
|
||||
Windows | `xor` | [6 / 40](https://kleenscan.com/scan_result/455d775c517cf26a6e83a42b3eae7982364d8a8174127eca377094c05e0dd948) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing_xor_exe.png)
|
||||
Windows | `antistring,xor` | [1 / 40](https://kleenscan.com/scan_result/e6214cb0175737d1e3bba8bafbaa17d5aa575f613dab718a6d35dd46c7af8767) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing_antistring_xor_exe.png)
|
||||
Windows | `antisand,xor` | [0 / 40](https://kleenscan.com/scan_result/de899245ec6a258d741b6243d18cf10fae5e6a1fe344ab3d02f17899a67d2bb7) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing_antisand_xor_exe.png)
|
||||
Windows | `antisand,antistring,xor` | [0 / 40](https://kleenscan.com/scan_result/49f53e2e15b86d9e5425d684e9ab964289d2d96fef8ca61ba927e3826ebd0392) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_hollowing_antisand_antistring_xor_exe.png)
|
||||
|
||||
<div class="datatable-end"></div>
|
||||
@@ -0,0 +1,68 @@
|
||||
---
|
||||
title: "Process Migration"
|
||||
datatable: true
|
||||
---
|
||||
|
||||
# RCO: Process Migration
|
||||
|
||||
[](https://github.com/kmanc/remote_code_oxidation/tree/master/process_migration)
|
||||
|
||||
<div class="datatable-begin"></div>
|
||||
|
||||
Target OS | Demo
|
||||
--------- | ----
|
||||
Linux | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/gifs/process_migration.gif)
|
||||
Windows | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/gifs/process_migration_windows.gif)
|
||||
|
||||
<div class="datatable-end"></div>
|
||||
|
||||
|
||||
## How it works
|
||||
|
||||
Windows process migration works by obtaining a handle to the target process and writing [shellcode](https://en.wikipedia.org/wiki/Shellcode) to it. A remote thread is then created; the starting point of this thread is the newly written shellcode.
|
||||
|
||||
Linux process migration works slightly differently. After temporarily pausing the target process, RCO writes shellcode over the process's [instruction pointer](https://datacadamia.com/computer/instruction/instruction_pointer). This can cause issues (the most likely of which is crashing) for the victim machine.
|
||||
|
||||
|
||||
## Using it
|
||||
|
||||
1. *[Not shown in demo]* Generate shellcode for the desired end result (for example, use [msfvenom](https://book.hacktricks.xyz/shells/shells/msfvenom) to generate a reverse TCP
|
||||
shell shellcode for the target operating system)
|
||||
2. *[Not shown in demo]* Open [the config file](https://github.com/kmanc/remote_code_oxidation/blob/master/rco_config/src/lib.rs)
|
||||
and change the shellcode to the shellcode generated in step 1
|
||||
3. *[Optional - shown in the [xor_params demo](https://kmanc.github.io/remote_code_oxidation/xor_params.html)]* Encrypt the shellcode and target process using [xor_params](https://github.com/kmanc/remote_code_oxidation/blob/master/xor_shellcode) and update the encrypted shellcode value in [the config file](https://github.com/kmanc/remote_code_oxidation/blob/master/rco_config/src/lib.rs)
|
||||
4. *[Not shown in demo]* Compile the executable, only including `--features xor` if you did step 3
|
||||
1. Build for Linux target
|
||||
```commandline
|
||||
cargo build -p process_migration [antisand][,][antistring][,][xor]] --release
|
||||
```
|
||||
2. Build for Windows target
|
||||
```commandline
|
||||
cargo build --target x86_64-pc-windows-gnu -p process_migration [antisand][,][antistring][,][xor]] --release
|
||||
```
|
||||
5. Start a netcat listener on the attacking machine on the same port you configured the shellcode to connect to in step 1
|
||||
```commandline
|
||||
nc -nlvp 4444
|
||||
```
|
||||
6. Execute the payload on the victim machine
|
||||
7. Return to the listener and enter desired commands for the victim machine to run
|
||||
|
||||
|
||||
## Detection rates
|
||||
|
||||
<div class="datatable-begin"></div>
|
||||
|
||||
Target OS | Features | Detections | Screenshot
|
||||
--------- | ----------------------------- | -------------------------------------- | ----------
|
||||
Linux | None | [7 / 40](https://kleenscan.com/scan_result/5d88b167a6fdf674a0a81514e37f171a4d0eb63c0b063dec1dd02a5d9b63d4fb) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration.png)
|
||||
Linux | `xor` | [0 / 40](https://kleenscan.com/scan_result/5568475e28d65306af33f75df28e215e7024daa922241fbd9c1e9205cd27a96d) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration_xor.png)
|
||||
Windows | None | [12 / 40](https://kleenscan.com/scan_result/ebebddfa24b6d95c65900003629914cbcadf09fddcd9a70db614b9f8e9f5fc42) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration_exe.png)
|
||||
Windows | `antisand` | [12 / 40](https://kleenscan.com/scan_result/dc73a322924b772b90957aaffe8d2735acd6d6049e0607a1befada2bc5aa86f3) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration_antisand_exe.png)
|
||||
Windows | `antistring` | [12 / 40](https://kleenscan.com/scan_result/7200bae53ce50bd8b0f3a528026ee72d71b47615235cf96384fe0752a1ff6145) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration_antistring_exe.png)
|
||||
Windows | `antisand,antistring` | [12 / 40](https://kleenscan.com/scan_result/e702816970ee629f718e6dbec58a129b03742b0ac7644bc3de942d8368e7252b) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration_antisand_antistring_exe.png)
|
||||
Windows | `xor` | [1 / 40](https://kleenscan.com/scan_result/8b3feb5f4db1b06a9fd33a9597b62d22847f518f607d7f049579b87b44ce8fea) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration_xor_exe.png)
|
||||
Windows | `antistring,xor` | [1 / 40](https://kleenscan.com/scan_result/f580330422109325f3c83fd1fa51a966798cb173d0edca5c1b4c310a2c95c082) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration_antistring_xor_exe.png)
|
||||
Windows | `antisand,xor` | [0 / 40](https://kleenscan.com/scan_result/19a7640ebedb91c375aeebf9d576ea005260610ca0eb23621413dc058a8ff067) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration_antisand_xor_exe.png)
|
||||
Windows | `antisand,antistring,xor` | [0 / 40](https://kleenscan.com/scan_result/1de23cfca021214907bb51174df2b8d69d2fe45cb6ebc903c1e3328bb958678f) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/process_migration_antisand_antistring_xor_exe.png)
|
||||
|
||||
<div class="datatable-end"></div>
|
||||
@@ -0,0 +1,57 @@
|
||||
---
|
||||
title: "TCP Reverse Shell"
|
||||
datatable: true
|
||||
---
|
||||
|
||||
# RCO: TCP Reverse Shell
|
||||
|
||||
[](https://github.com/kmanc/remote_code_oxidation/tree/master/tcp_reverse_shell)
|
||||
|
||||
<div class="datatable-begin"></div>
|
||||
|
||||
Target OS | Demo
|
||||
--------- | ----
|
||||
Linux | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/gifs/tcp_reverse_shell.gif)
|
||||
Windows | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/gifs/tcp_reverse_shell_windows.gif)
|
||||
|
||||
<div class="datatable-end"></div>
|
||||
|
||||
## How it works
|
||||
|
||||
The reverse shells for both Linux and Windows work by establishing a [Transmission Control Protocol (TCP) session](https://www.scottklement.com/rpg/socktut/overview.html) from the victim machine to the attacking machine. Then a Terminal (Linux) or Command Prompt (Windows) process starts with its [standard input](https://en.wikipedia.org/wiki/Standard_streams#Standard_input_(stdin)), [standard output](https://en.wikipedia.org/wiki/Standard_streams#Standard_output_(stdout)), and [standard error](https://en.wikipedia.org/wiki/Standard_streams#Standard_error_(stderr)) all assigned to the TCP session. This means that input commands and output results are read from and written to (respectively) the TCP stream.
|
||||
|
||||
|
||||
## Using it
|
||||
|
||||
1. *[Not shown in demo]* Open [the config file](https://github.com/kmanc/remote_code_oxidation/blob/master/rco_config/src/lib.rs)
|
||||
and change the IP address and port to match the IP address of your attacking machine and the port you will use for a listener respectively
|
||||
2. *[Not shown in demo]* Compile the executable
|
||||
1. For Linux targets
|
||||
```commandline
|
||||
cargo build -p tcp_reverse_shell [antisand][,][antistring]] --release
|
||||
```
|
||||
2. For Windows targets
|
||||
```commandline
|
||||
cargo build --target x86_64-pc-windows-gnu -p tcp_reverse_shell [antisand][,][antistring]] --release
|
||||
```
|
||||
3. Start a netcat listener on the attacking machine on the same port you configured in step 1
|
||||
```commandline
|
||||
nc -nlvp 4444
|
||||
```
|
||||
4. Execute the payload on the victim machine
|
||||
5. Return to the listener and enter desired commands for the victim machine to run
|
||||
|
||||
|
||||
## Detection rates
|
||||
|
||||
<div class="datatable-begin"></div>
|
||||
|
||||
Target OS | Features | Detections | Screenshot
|
||||
--------- | ----------------------------- | -------------------------------------- | ----------
|
||||
Linux | None | [0 / 40](https://kleenscan.com/scan_result/c01984f5bc45f0ff82723fe6ceab770fe48e955081f8b02e17a8232e6ba2bbeb) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/tcp_reverse_shell.png)
|
||||
Windows | None | [0 / 40](https://kleenscan.com/scan_result/ce74ac206b59e9acc4e7f528bcec06f2a1dcc8ac0a1fb622c0b646cdfd2602d5) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/tcp_reverse_shell_exe.png)
|
||||
Windows | `antisand` | [0 / 40](https://kleenscan.com/scan_result/28fce6da1a75b3d0073649613d5e69b73019091e1a7c2a2033b1551755c5fad4) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/tcp_reverse_shell_antisand_exe.png)
|
||||
Windows | `antistring` | [0 / 40](https://kleenscan.com/scan_result/fafcad9c3689cf811184cacc3c1e9f939017b4e5d362712468839a6126f82278) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/tcp_reverse_shell_antistring_exe.png)
|
||||
Windows | `antisand,antistring` | [0 / 40](https://kleenscan.com/scan_result/ff8c1a3fda94bd5f73314e15c9861284250b88720f045351aedc937435b9d8bd) | [](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/images/tcp_reverse_shell_antisand_antistring_exe.png)
|
||||
|
||||
<div class="datatable-end"></div>
|
||||
@@ -0,0 +1,32 @@
|
||||
---
|
||||
title: "XOR Params"
|
||||
---
|
||||
|
||||
# RCO: XOR Params
|
||||
|
||||
[](https://github.com/kmanc/remote_code_oxidation/tree/master/xor_params)
|
||||
|
||||
[](https://raw.githubusercontent.com/kmanc/remote_code_oxidation/gh-pages/assets/gifs/xor_params.gif)
|
||||
|
||||
|
||||
## How it works
|
||||
|
||||
XOR params performs an [exclusive OR (XOR)](https://en.wikipedia.org/wiki/Exclusive_or) operation on each byte of the shellcode with each byte of the key (repeating the key if need be).
|
||||
|
||||
|
||||
## Using it
|
||||
|
||||
1. *[Not shown in demo]* Generate shellcode for the desired end result (for example, use [msfvenom](https://book.hacktricks.xyz/shells/shells/msfvenom) to generate a reverse TCP shell shellcode for the target operating system)
|
||||
2. *[Not shown in demo]* Open [the config file](https://github.com/kmanc/remote_code_oxidation/blob/master/rco_config/src/lib.rs) and change the shellcode to the shellcode generated in step 1
|
||||
3. *[Not shown in demo]* Open [the config file](https://github.com/kmanc/remote_code_oxidation/blob/master/rco_config/src/lib.rs) and change the key to a desired key
|
||||
4. *[Not shown in demo]* Compile the executable
|
||||
1. For Linux
|
||||
```commandline
|
||||
cargo build -p xor_params --release
|
||||
```
|
||||
2. For Windows
|
||||
```commandline
|
||||
cargo build --target x86_64-pc-windows-gnu -p xor_params --release
|
||||
```
|
||||
5. Run the executable
|
||||
6. Open [the config file](https://github.com/kmanc/remote_code_oxidation/blob/master/rco_config/src/lib.rs) and change encrypted payload to the output of step 5
|
||||