mirror of
https://github.com/monoxgas/sRDI
synced 2026-06-06 16:14:36 +00:00
Added 5th argument for arbitrary flags to RDI
Moved the clear header capability to the flags arg Moved stack alignment from the C project to the bootstrap Updated Python and Powershell conversion scripts (missed this last time)
This commit is contained in:
+97
-43
File diff suppressed because one or more lines are too long
+88
-34
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
@@ -1,13 +1,14 @@
|
||||
import argparse
|
||||
from ShellcodeRDI import *
|
||||
|
||||
__version__ = '1.0'
|
||||
__version__ = '1.1'
|
||||
|
||||
def main():
|
||||
parser = argparse.ArgumentParser(description='RDI Shellcode Converter', conflict_handler='resolve')
|
||||
parser.add_argument('-v', '--version', action='version', version='%(prog)s Version: ' + __version__)
|
||||
parser.add_argument('input_dll', help='DLL to convert to shellcode')
|
||||
parser.add_argument('-f', '--function-name', dest='function_name', default='SayHello', help='The function to call after DllMain')
|
||||
parser.add_argument('-c', '--clear-header', dest='clear_header', action="store_true", help='Clear the PE header on load')
|
||||
arguments = parser.parse_args()
|
||||
|
||||
input_dll = arguments.input_dll
|
||||
@@ -16,7 +17,13 @@ def main():
|
||||
print('Creating Shellcode: {}'.format(output_bin))
|
||||
dll = open(arguments.input_dll, 'rb').read()
|
||||
|
||||
converted_dll = ConvertToShellcode(dll, HashFunctionName(arguments.function_name))
|
||||
flags = 0
|
||||
|
||||
if arguments.clear_header:
|
||||
flags |= 0x1
|
||||
|
||||
converted_dll = ConvertToShellcode(dll, HashFunctionName(arguments.function_name), b'dave', flags)
|
||||
|
||||
with open(output_bin, 'wb') as f:
|
||||
f.write(converted_dll)
|
||||
|
||||
|
||||
+67
-31
File diff suppressed because one or more lines are too long
@@ -1,10 +0,0 @@
|
||||
#if defined(_WIN64)
|
||||
extern VOID AlignRSP( VOID );
|
||||
|
||||
VOID Begin( VOID )
|
||||
{
|
||||
// Call the ASM stub that will guarantee 16-byte stack alignment.
|
||||
// The stub will then call the ExecutePayload.
|
||||
AlignRSP();
|
||||
}
|
||||
#endif
|
||||
@@ -1,37 +0,0 @@
|
||||
; Author: Matthew Graeber (@mattifestation)
|
||||
; License: BSD 3-Clause
|
||||
; Syntax: MASM
|
||||
; Build Syntax: ml64 /c /Cx AdjustStack.asm
|
||||
; Output: AdjustStack.obj
|
||||
; Notes: I really wanted to avoid having this external dependency but I couldn't
|
||||
; come up with any other way to guarantee 16-byte stack alignment in 64-bit
|
||||
; shellcode written in C.
|
||||
|
||||
EXTRN ExecutePayload:PROC
|
||||
PUBLIC AlignRSP ; Marking AlignRSP as PUBLIC allows for the function
|
||||
; to be called as an extern in our C code.
|
||||
|
||||
_TEXT SEGMENT
|
||||
|
||||
; AlignRSP is a simple call stub that ensures that the stack is 16-byte aligned prior
|
||||
; to calling the entry point of the payload. This is necessary because 64-bit functions
|
||||
; in Windows assume that they were called with 16-byte stack alignment. When amd64
|
||||
; shellcode is executed, you can't be assured that you stack is 16-byte aligned. For example,
|
||||
; if your shellcode lands with 8-byte stack alignment, any call to a Win32 function will likely
|
||||
; crash upon calling any ASM instruction that utilizes XMM registers (which require 16-byte)
|
||||
; alignment.
|
||||
|
||||
AlignRSP PROC
|
||||
push rsi ; Preserve RSI since we're stomping on it
|
||||
mov rsi, rsp ; Save the value of RSP so it can be restored
|
||||
and rsp, 0FFFFFFFFFFFFFFF0h ; Align RSP to 16 bytes
|
||||
sub rsp, 020h ; Allocate homing space for ExecutePayload
|
||||
call ExecutePayload ; Call the entry point of the payload
|
||||
mov rsp, rsi ; Restore the original value of RSP
|
||||
pop rsi ; Restore RSI
|
||||
ret ; Return to caller
|
||||
AlignRSP ENDP
|
||||
|
||||
_TEXT ENDS
|
||||
|
||||
END
|
||||
@@ -4,10 +4,6 @@
|
||||
|
||||
#include "GetProcAddressWithHash.h"
|
||||
|
||||
#ifndef TESTING
|
||||
#include "64BitHelper.h"
|
||||
#endif
|
||||
|
||||
#include <windows.h>
|
||||
#include <intrin.h>
|
||||
|
||||
@@ -51,6 +47,8 @@ typedef BOOL(*EXPORTFUNC)(LPVOID, DWORD);
|
||||
|
||||
#define HASH_KEY 13
|
||||
|
||||
#define SRDI_CLEARHEADER 0x1
|
||||
|
||||
#ifdef _WIN64
|
||||
#define HOST_MACHINE IMAGE_FILE_MACHINE_AMD64
|
||||
#else
|
||||
@@ -156,7 +154,7 @@ AlignValueUp(size_t value, size_t alignment) {
|
||||
// Write the logic for the primary payload here
|
||||
// Normally, I would call this 'main' but if you call a function 'main', link.exe requires that you link against the CRT
|
||||
// Rather, I will pass a linker option of "/ENTRY:ExecutePayload" in order to get around this issue.
|
||||
ULONG_PTR ExecutePayload(ULONG_PTR uiLibraryAddress, DWORD dwFunctionHash, LPVOID lpUserData, DWORD nUserdataLen)
|
||||
ULONG_PTR ExecutePayload(ULONG_PTR uiLibraryAddress, DWORD dwFunctionHash, LPVOID lpUserData, DWORD nUserdataLen, DWORD flags)
|
||||
{
|
||||
#pragma warning( push )
|
||||
#pragma warning( disable : 4055 ) // Ignore cast warnings
|
||||
@@ -169,7 +167,7 @@ ULONG_PTR ExecutePayload(ULONG_PTR uiLibraryAddress, DWORD dwFunctionHash, LPVOI
|
||||
NTFLUSHINSTRUCTIONCACHE pNtFlushInstructionCache = NULL;
|
||||
GETNATIVESYSTEMINFO pGetNativeSystemInfo = NULL;
|
||||
VIRTUALPROTECT pVirtualProtect = NULL;
|
||||
//MESSAGEBOXA pMessageBoxA = NULL;
|
||||
MESSAGEBOXA pMessageBoxA = NULL;
|
||||
|
||||
PIMAGE_DATA_DIRECTORY directory = NULL;
|
||||
PIMAGE_EXPORT_DIRECTORY exports = NULL;
|
||||
@@ -286,7 +284,7 @@ ULONG_PTR ExecutePayload(ULONG_PTR uiLibraryAddress, DWORD dwFunctionHash, LPVOI
|
||||
uiValueE = FIELD_OFFSET(IMAGE_DOS_HEADER, e_lfanew);
|
||||
|
||||
while (uiValueA--) {
|
||||
if (uiValueD < (uiHeaderValue - uiLibraryAddress) && (uiValueD < uiValueE || uiValueD > (uiValueE + sizeof(WORD)))) {
|
||||
if ((flags & SRDI_CLEARHEADER) && uiValueD < (uiHeaderValue - uiLibraryAddress) && (uiValueD < uiValueE || uiValueD > (uiValueE + sizeof(WORD)))) {
|
||||
// Blow away everything before the NT_HEADERS. Leave e_lfanew;
|
||||
*(BYTE *)uiValueC++ = '\0';
|
||||
uiValueB++;
|
||||
|
||||
@@ -23,7 +23,7 @@
|
||||
<Keyword>Win32Proj</Keyword>
|
||||
<RootNamespace>PIC_Bindshell</RootNamespace>
|
||||
<ProjectName>ShellcodeRDI</ProjectName>
|
||||
<WindowsTargetPlatformVersion>8.1</WindowsTargetPlatformVersion>
|
||||
<WindowsTargetPlatformVersion>10.0.15063.0</WindowsTargetPlatformVersion>
|
||||
</PropertyGroup>
|
||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.Default.props" />
|
||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|Win32'" Label="Configuration">
|
||||
@@ -699,18 +699,19 @@
|
||||
</Profile>
|
||||
<RegisterOutput>
|
||||
</RegisterOutput>
|
||||
<AdditionalDependencies>$(IntDir)\AdjustStack.obj</AdditionalDependencies>
|
||||
<AdditionalDependencies>
|
||||
</AdditionalDependencies>
|
||||
<AllowIsolation>
|
||||
</AllowIsolation>
|
||||
<EnableUAC>
|
||||
</EnableUAC>
|
||||
<GenerateMapFile>true</GenerateMapFile>
|
||||
<FunctionOrder>function_link_order64.txt</FunctionOrder>
|
||||
<FunctionOrder>function_link_order.txt</FunctionOrder>
|
||||
<IgnoreEmbeddedIDL>
|
||||
</IgnoreEmbeddedIDL>
|
||||
<DataExecutionPrevention>
|
||||
</DataExecutionPrevention>
|
||||
<EntryPointSymbol>Begin</EntryPointSymbol>
|
||||
<EntryPointSymbol>ExecutePayload</EntryPointSymbol>
|
||||
<LinkErrorReporting>
|
||||
</LinkErrorReporting>
|
||||
<ImageHasSafeExceptionHandlers>false</ImageHasSafeExceptionHandlers>
|
||||
@@ -731,10 +732,12 @@
|
||||
</VerboseOutput>
|
||||
</Manifest>
|
||||
<PreBuildEvent>
|
||||
<Command>ml64 /nologo /c /Cx /Fo $(ProjectDir)$(IntDir)AdjustStack.obj $(ProjectDir)AdjustStack.asm</Command>
|
||||
<Command>
|
||||
</Command>
|
||||
</PreBuildEvent>
|
||||
<PreBuildEvent>
|
||||
<Message>Build AdjustStack.asm</Message>
|
||||
<Message>
|
||||
</Message>
|
||||
</PreBuildEvent>
|
||||
<PostBuildEvent>
|
||||
<Command>powershell.exe -NoProfile -ExecutionPolicy Bypass -File "$(SolutionDir)lib\PowerShell\Out-Shellcode.ps1" "$(OutDir)$(TargetName)$(TargetExt)" "$(OutDir)$(TargetName).map" "$(SolutionDir)bin\$(TargetName)_x64.bin"</Command>
|
||||
@@ -856,18 +859,19 @@
|
||||
</Profile>
|
||||
<RegisterOutput>
|
||||
</RegisterOutput>
|
||||
<AdditionalDependencies>$(IntDir)\AdjustStack.obj</AdditionalDependencies>
|
||||
<AdditionalDependencies>
|
||||
</AdditionalDependencies>
|
||||
<AllowIsolation>
|
||||
</AllowIsolation>
|
||||
<EnableUAC>
|
||||
</EnableUAC>
|
||||
<GenerateMapFile>true</GenerateMapFile>
|
||||
<FunctionOrder>function_link_order64.txt</FunctionOrder>
|
||||
<FunctionOrder>function_link_order.txt</FunctionOrder>
|
||||
<IgnoreEmbeddedIDL>
|
||||
</IgnoreEmbeddedIDL>
|
||||
<DataExecutionPrevention>
|
||||
</DataExecutionPrevention>
|
||||
<EntryPointSymbol>Begin</EntryPointSymbol>
|
||||
<EntryPointSymbol>ExecutePayload</EntryPointSymbol>
|
||||
<LinkErrorReporting>
|
||||
</LinkErrorReporting>
|
||||
<ImageHasSafeExceptionHandlers>false</ImageHasSafeExceptionHandlers>
|
||||
@@ -890,10 +894,12 @@
|
||||
</VerboseOutput>
|
||||
</Manifest>
|
||||
<PreBuildEvent>
|
||||
<Command>ml64 /nologo /c /Cx /Fo $(ProjectDir)$(IntDir)AdjustStack.obj $(ProjectDir)AdjustStack.asm</Command>
|
||||
<Command>
|
||||
</Command>
|
||||
</PreBuildEvent>
|
||||
<PreBuildEvent>
|
||||
<Message>Build AdjustStack.asm</Message>
|
||||
<Message>
|
||||
</Message>
|
||||
</PreBuildEvent>
|
||||
<PostBuildEvent>
|
||||
<Command>powershell.exe -NoProfile -ExecutionPolicy Bypass -File $(SolutionDir)lib\PowerShell\Out-Shellcode.ps1 $(OutDir)$(TargetName)$(TargetExt) $(OutDir)$(TargetName).map $(SolutionDir)bin\$(TargetName)_x64.bin</Command>
|
||||
@@ -903,16 +909,12 @@
|
||||
</PostBuildEvent>
|
||||
</ItemDefinitionGroup>
|
||||
<ItemGroup>
|
||||
<ClInclude Include="64BitHelper.h" />
|
||||
<ClInclude Include="GetProcAddressWithHash.h" />
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<None Include="AdjustStack.asm" />
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<ClCompile Include="ShellcodeRDI.c" />
|
||||
</ItemGroup>
|
||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
|
||||
<ImportGroup Label="ExtensionTargets">
|
||||
</ImportGroup>
|
||||
</Project>
|
||||
</Project>
|
||||
@@ -15,18 +15,10 @@
|
||||
</Filter>
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<ClInclude Include="64BitHelper.h">
|
||||
<Filter>Header Files</Filter>
|
||||
</ClInclude>
|
||||
<ClInclude Include="GetProcAddressWithHash.h">
|
||||
<Filter>Header Files</Filter>
|
||||
</ClInclude>
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<None Include="AdjustStack.asm">
|
||||
<Filter>Source Files</Filter>
|
||||
</None>
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<ClCompile Include="ShellcodeRDI.c">
|
||||
<Filter>Source Files</Filter>
|
||||
|
||||
@@ -1,3 +0,0 @@
|
||||
Begin
|
||||
GetProcAddressWithHash
|
||||
ExecutePayload
|
||||
Reference in New Issue
Block a user