Added 5th argument for arbitrary flags to RDI

Moved the clear header capability to the flags arg
Moved stack alignment from the C project to the bootstrap

Updated Python and Powershell conversion scripts (missed this last time)
This commit is contained in:
Nick Landers
2018-02-21 16:57:52 -07:00
parent 04e0e038d7
commit b6ba50888f
11 changed files with 390 additions and 235 deletions
+97 -43
View File
File diff suppressed because one or more lines are too long
+88 -34
View File
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
+9 -2
View File
@@ -1,13 +1,14 @@
import argparse
from ShellcodeRDI import *
__version__ = '1.0'
__version__ = '1.1'
def main():
parser = argparse.ArgumentParser(description='RDI Shellcode Converter', conflict_handler='resolve')
parser.add_argument('-v', '--version', action='version', version='%(prog)s Version: ' + __version__)
parser.add_argument('input_dll', help='DLL to convert to shellcode')
parser.add_argument('-f', '--function-name', dest='function_name', default='SayHello', help='The function to call after DllMain')
parser.add_argument('-c', '--clear-header', dest='clear_header', action="store_true", help='Clear the PE header on load')
arguments = parser.parse_args()
input_dll = arguments.input_dll
@@ -16,7 +17,13 @@ def main():
print('Creating Shellcode: {}'.format(output_bin))
dll = open(arguments.input_dll, 'rb').read()
converted_dll = ConvertToShellcode(dll, HashFunctionName(arguments.function_name))
flags = 0
if arguments.clear_header:
flags |= 0x1
converted_dll = ConvertToShellcode(dll, HashFunctionName(arguments.function_name), b'dave', flags)
with open(output_bin, 'wb') as f:
f.write(converted_dll)
+67 -31
View File
File diff suppressed because one or more lines are too long
-10
View File
@@ -1,10 +0,0 @@
#if defined(_WIN64)
extern VOID AlignRSP( VOID );
VOID Begin( VOID )
{
// Call the ASM stub that will guarantee 16-byte stack alignment.
// The stub will then call the ExecutePayload.
AlignRSP();
}
#endif
-37
View File
@@ -1,37 +0,0 @@
; Author: Matthew Graeber (@mattifestation)
; License: BSD 3-Clause
; Syntax: MASM
; Build Syntax: ml64 /c /Cx AdjustStack.asm
; Output: AdjustStack.obj
; Notes: I really wanted to avoid having this external dependency but I couldn't
; come up with any other way to guarantee 16-byte stack alignment in 64-bit
; shellcode written in C.
EXTRN ExecutePayload:PROC
PUBLIC AlignRSP ; Marking AlignRSP as PUBLIC allows for the function
; to be called as an extern in our C code.
_TEXT SEGMENT
; AlignRSP is a simple call stub that ensures that the stack is 16-byte aligned prior
; to calling the entry point of the payload. This is necessary because 64-bit functions
; in Windows assume that they were called with 16-byte stack alignment. When amd64
; shellcode is executed, you can't be assured that you stack is 16-byte aligned. For example,
; if your shellcode lands with 8-byte stack alignment, any call to a Win32 function will likely
; crash upon calling any ASM instruction that utilizes XMM registers (which require 16-byte)
; alignment.
AlignRSP PROC
push rsi ; Preserve RSI since we're stomping on it
mov rsi, rsp ; Save the value of RSP so it can be restored
and rsp, 0FFFFFFFFFFFFFFF0h ; Align RSP to 16 bytes
sub rsp, 020h ; Allocate homing space for ExecutePayload
call ExecutePayload ; Call the entry point of the payload
mov rsp, rsi ; Restore the original value of RSP
pop rsi ; Restore RSI
ret ; Return to caller
AlignRSP ENDP
_TEXT ENDS
END
+5 -7
View File
@@ -4,10 +4,6 @@
#include "GetProcAddressWithHash.h"
#ifndef TESTING
#include "64BitHelper.h"
#endif
#include <windows.h>
#include <intrin.h>
@@ -51,6 +47,8 @@ typedef BOOL(*EXPORTFUNC)(LPVOID, DWORD);
#define HASH_KEY 13
#define SRDI_CLEARHEADER 0x1
#ifdef _WIN64
#define HOST_MACHINE IMAGE_FILE_MACHINE_AMD64
#else
@@ -156,7 +154,7 @@ AlignValueUp(size_t value, size_t alignment) {
// Write the logic for the primary payload here
// Normally, I would call this 'main' but if you call a function 'main', link.exe requires that you link against the CRT
// Rather, I will pass a linker option of "/ENTRY:ExecutePayload" in order to get around this issue.
ULONG_PTR ExecutePayload(ULONG_PTR uiLibraryAddress, DWORD dwFunctionHash, LPVOID lpUserData, DWORD nUserdataLen)
ULONG_PTR ExecutePayload(ULONG_PTR uiLibraryAddress, DWORD dwFunctionHash, LPVOID lpUserData, DWORD nUserdataLen, DWORD flags)
{
#pragma warning( push )
#pragma warning( disable : 4055 ) // Ignore cast warnings
@@ -169,7 +167,7 @@ ULONG_PTR ExecutePayload(ULONG_PTR uiLibraryAddress, DWORD dwFunctionHash, LPVOI
NTFLUSHINSTRUCTIONCACHE pNtFlushInstructionCache = NULL;
GETNATIVESYSTEMINFO pGetNativeSystemInfo = NULL;
VIRTUALPROTECT pVirtualProtect = NULL;
//MESSAGEBOXA pMessageBoxA = NULL;
MESSAGEBOXA pMessageBoxA = NULL;
PIMAGE_DATA_DIRECTORY directory = NULL;
PIMAGE_EXPORT_DIRECTORY exports = NULL;
@@ -286,7 +284,7 @@ ULONG_PTR ExecutePayload(ULONG_PTR uiLibraryAddress, DWORD dwFunctionHash, LPVOI
uiValueE = FIELD_OFFSET(IMAGE_DOS_HEADER, e_lfanew);
while (uiValueA--) {
if (uiValueD < (uiHeaderValue - uiLibraryAddress) && (uiValueD < uiValueE || uiValueD > (uiValueE + sizeof(WORD)))) {
if ((flags & SRDI_CLEARHEADER) && uiValueD < (uiHeaderValue - uiLibraryAddress) && (uiValueD < uiValueE || uiValueD > (uiValueE + sizeof(WORD)))) {
// Blow away everything before the NT_HEADERS. Leave e_lfanew;
*(BYTE *)uiValueC++ = '\0';
uiValueB++;
+18 -16
View File
@@ -23,7 +23,7 @@
<Keyword>Win32Proj</Keyword>
<RootNamespace>PIC_Bindshell</RootNamespace>
<ProjectName>ShellcodeRDI</ProjectName>
<WindowsTargetPlatformVersion>8.1</WindowsTargetPlatformVersion>
<WindowsTargetPlatformVersion>10.0.15063.0</WindowsTargetPlatformVersion>
</PropertyGroup>
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.Default.props" />
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|Win32'" Label="Configuration">
@@ -699,18 +699,19 @@
</Profile>
<RegisterOutput>
</RegisterOutput>
<AdditionalDependencies>$(IntDir)\AdjustStack.obj</AdditionalDependencies>
<AdditionalDependencies>
</AdditionalDependencies>
<AllowIsolation>
</AllowIsolation>
<EnableUAC>
</EnableUAC>
<GenerateMapFile>true</GenerateMapFile>
<FunctionOrder>function_link_order64.txt</FunctionOrder>
<FunctionOrder>function_link_order.txt</FunctionOrder>
<IgnoreEmbeddedIDL>
</IgnoreEmbeddedIDL>
<DataExecutionPrevention>
</DataExecutionPrevention>
<EntryPointSymbol>Begin</EntryPointSymbol>
<EntryPointSymbol>ExecutePayload</EntryPointSymbol>
<LinkErrorReporting>
</LinkErrorReporting>
<ImageHasSafeExceptionHandlers>false</ImageHasSafeExceptionHandlers>
@@ -731,10 +732,12 @@
</VerboseOutput>
</Manifest>
<PreBuildEvent>
<Command>ml64 /nologo /c /Cx /Fo $(ProjectDir)$(IntDir)AdjustStack.obj $(ProjectDir)AdjustStack.asm</Command>
<Command>
</Command>
</PreBuildEvent>
<PreBuildEvent>
<Message>Build AdjustStack.asm</Message>
<Message>
</Message>
</PreBuildEvent>
<PostBuildEvent>
<Command>powershell.exe -NoProfile -ExecutionPolicy Bypass -File "$(SolutionDir)lib\PowerShell\Out-Shellcode.ps1" "$(OutDir)$(TargetName)$(TargetExt)" "$(OutDir)$(TargetName).map" "$(SolutionDir)bin\$(TargetName)_x64.bin"</Command>
@@ -856,18 +859,19 @@
</Profile>
<RegisterOutput>
</RegisterOutput>
<AdditionalDependencies>$(IntDir)\AdjustStack.obj</AdditionalDependencies>
<AdditionalDependencies>
</AdditionalDependencies>
<AllowIsolation>
</AllowIsolation>
<EnableUAC>
</EnableUAC>
<GenerateMapFile>true</GenerateMapFile>
<FunctionOrder>function_link_order64.txt</FunctionOrder>
<FunctionOrder>function_link_order.txt</FunctionOrder>
<IgnoreEmbeddedIDL>
</IgnoreEmbeddedIDL>
<DataExecutionPrevention>
</DataExecutionPrevention>
<EntryPointSymbol>Begin</EntryPointSymbol>
<EntryPointSymbol>ExecutePayload</EntryPointSymbol>
<LinkErrorReporting>
</LinkErrorReporting>
<ImageHasSafeExceptionHandlers>false</ImageHasSafeExceptionHandlers>
@@ -890,10 +894,12 @@
</VerboseOutput>
</Manifest>
<PreBuildEvent>
<Command>ml64 /nologo /c /Cx /Fo $(ProjectDir)$(IntDir)AdjustStack.obj $(ProjectDir)AdjustStack.asm</Command>
<Command>
</Command>
</PreBuildEvent>
<PreBuildEvent>
<Message>Build AdjustStack.asm</Message>
<Message>
</Message>
</PreBuildEvent>
<PostBuildEvent>
<Command>powershell.exe -NoProfile -ExecutionPolicy Bypass -File $(SolutionDir)lib\PowerShell\Out-Shellcode.ps1 $(OutDir)$(TargetName)$(TargetExt) $(OutDir)$(TargetName).map $(SolutionDir)bin\$(TargetName)_x64.bin</Command>
@@ -903,16 +909,12 @@
</PostBuildEvent>
</ItemDefinitionGroup>
<ItemGroup>
<ClInclude Include="64BitHelper.h" />
<ClInclude Include="GetProcAddressWithHash.h" />
</ItemGroup>
<ItemGroup>
<None Include="AdjustStack.asm" />
</ItemGroup>
<ItemGroup>
<ClCompile Include="ShellcodeRDI.c" />
</ItemGroup>
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
<ImportGroup Label="ExtensionTargets">
</ImportGroup>
</Project>
</Project>
@@ -15,18 +15,10 @@
</Filter>
</ItemGroup>
<ItemGroup>
<ClInclude Include="64BitHelper.h">
<Filter>Header Files</Filter>
</ClInclude>
<ClInclude Include="GetProcAddressWithHash.h">
<Filter>Header Files</Filter>
</ClInclude>
</ItemGroup>
<ItemGroup>
<None Include="AdjustStack.asm">
<Filter>Source Files</Filter>
</None>
</ItemGroup>
<ItemGroup>
<ClCompile Include="ShellcodeRDI.c">
<Filter>Source Files</Filter>
-3
View File
@@ -1,3 +0,0 @@
Begin
GetProcAddressWithHash
ExecutePayload