mirror of
https://github.com/tijme/kong-loader
synced 2026-06-06 16:54:30 +00:00
Added explicit checks to crash on direct syscalls, as these are not supported yet.
This commit is contained in:
Binary file not shown.
@@ -19,4 +19,4 @@ clean:
|
||||
rm -f ./dst/$(TARGET).*
|
||||
|
||||
./dst/$(TARGET).x64.exe:
|
||||
$(CC_X64) ./src/$(TARGET).c -o ./dst/$(TARGET).x64.exe -masm=intel -I inc -ldbghelp
|
||||
$(CC_X64) ./src/$(TARGET).c -o ./dst/$(TARGET).x64.exe -masm=intel -I inc -ldbghelp -lkernel32 -luser32 -lntdll -lole32 -loleaut32
|
||||
|
||||
+4
-3
@@ -76,7 +76,8 @@
|
||||
*
|
||||
* Our custom shellcode is loaded from `Shellcode.c` for easy adjustability.
|
||||
*/
|
||||
#include "shellcode/Custom-Storage-1.c" // Working
|
||||
// #include "shellcode/Custom-Storage-1.c" // Working
|
||||
// #include "shellcode/Custom-Syscall-1.c" // Working
|
||||
// #include "shellcode/Custom-ArgumentOnStack-1.c" // Working
|
||||
// #include "shellcode/Custom-AccessViolation-1.c" // Working
|
||||
// #include "shellcode/Custom-ArgumentAsString-1.c" // Working
|
||||
@@ -85,7 +86,7 @@
|
||||
// #include "shellcode/Msfvenom-WinExec-1.c" // Working
|
||||
// #include "shellcode/Msfvenom-ShellReverseTCP-1.c" // Working? (from C:\ drive)
|
||||
// #include "shellcode/Msfvenom-MeterpreterReverseTCP-2.c" // Working
|
||||
// #include "shellcode/Msfvenom-MeterpreterReverseTCP-1.c" // Not working
|
||||
#include "shellcode/Msfvenom-MeterpreterReverseTCP-1.c" // Not working
|
||||
// #include "shellcode/Proprietary-CobaltStrike-StagelessHTTP-1.c" // Not working
|
||||
// #include "shellcode/Donut-MessageBoxA-1.c" // Not working
|
||||
|
||||
@@ -211,7 +212,7 @@ void main(int argc, char** argv) {
|
||||
PRINT_SUCCESS("Creating Payload Descriptor (PD) and the `%s` payload within it.", STATIC_SHELLCODE_NAME);
|
||||
if (NT_SUCCESS(dwResult = CreatePayloadAndDescriptor((uint8_t*) &StaticShellcode, sizeof(StaticShellcode), (uint8_t*) &StaticPassword, sizeof(StaticPassword), STATIC_SHELLCODE_IS_ALREADY_ENCRYPTED, &lpPD))) {
|
||||
PRINT_SUCCESS("Succesfully created the Payload Descriptor (PD) with a size of %d bytes.", lpPD.dwPayloadSize);
|
||||
PRINT_SUCCESS("Base address of payload is %p.", lpPD.lpPayload);
|
||||
PRINT_SUCCESS("Base address of payload is 0x%p (ending at 0x%p).", lpPD.lpPayload, lpPD.lpPayload + lpPD.dwPayloadSize);
|
||||
} else {
|
||||
PRINT_FAILURE_AND_ABORT("Could not create the Payload Descriptor (PD) and the payload within it: 0x%X.", dwResult);
|
||||
}
|
||||
|
||||
@@ -180,7 +180,7 @@ char* GetFunctionNameFromAddress(uint8_t* lpAddress) {
|
||||
if (!SymFromAddr(hProcess, (DWORD64) lpAddress, &dqDisplacement, lpSymbol)) {
|
||||
PRINT_WARNING("SymFromAddr failed for 0x%p in GetCurrentProcess: 0x%X.", lpAddress, GetLastError());
|
||||
SymCleanup(hProcess);
|
||||
return "_unknown_";
|
||||
return "_unknown_";
|
||||
}
|
||||
|
||||
// Allocate memory for the function name
|
||||
@@ -365,7 +365,7 @@ uint64_t GetBestEffortSizeOfByteSequence(ZydisDecodedInstruction* zdInstruction,
|
||||
}
|
||||
|
||||
RETURN_RESULT:
|
||||
PRINT_VERBOSE("GetBestEffortSizeOfByteSequence of %s located at %p resulted in: %d.", lpFunctionName, lpCurrentBD->lpLastKnownNextAddress, qwSizeToReturn);
|
||||
PRINT_VERBOSE("GetBestEffortSizeOfByteSequence of %s located at 0x%p resulted in: %d.", lpFunctionName, lpCurrentBD->lpLastKnownNextAddress, qwSizeToReturn);
|
||||
return qwSizeToReturn;
|
||||
}
|
||||
|
||||
@@ -438,6 +438,13 @@ void EnrichByteDescriptor(ZydisDecodedInstruction* zdInstruction, ZydisDecodedOp
|
||||
|
||||
break;
|
||||
|
||||
/**
|
||||
* Syscall
|
||||
*/
|
||||
case ZYDIS_MNEMONIC_SYSCALL:
|
||||
PRINT_FAILURE_AND_ABORT("Syscalls have not yet been implemented");
|
||||
break;
|
||||
|
||||
/**
|
||||
* Call
|
||||
*
|
||||
|
||||
@@ -0,0 +1,38 @@
|
||||
/**
|
||||
* Mozilla Public License (MPL) Version 2.0.
|
||||
*
|
||||
* Copyright (c) 2024 Tijme Gommers (@tijme).
|
||||
*
|
||||
* This source code file is part of Kong Loader. Kong Loader is
|
||||
* licensed under Mozilla Public License (MPL) Version 2.0, and
|
||||
* you are free to use, modify, and distribute this file under
|
||||
* its terms. However, any modified versions of this file must
|
||||
* include this same license and copyright notice.
|
||||
*/
|
||||
|
||||
/**
|
||||
* Predefined definitions
|
||||
*/
|
||||
#define STATIC_SHELLCODE_NAME "Custom-KitchenSink-1" // Name to be printed
|
||||
#define STATIC_SHELLCODE_IS_ALREADY_ENCRYPTED 0x0 // May only be negative for debugging purposes with plain static shellcode
|
||||
#define STATIC_SHELLCODE_HAS_RETURN_VALUE 0x1 // Print return value of the shellcode to the console
|
||||
|
||||
/**
|
||||
* The XOR password to use.
|
||||
*/
|
||||
static uint8_t StaticPassword[] = { 0xAA };
|
||||
|
||||
/**
|
||||
* The shellcode to use.
|
||||
*
|
||||
* This is custom written shellcode. It calls NtTerminateProcess using a syscall
|
||||
*/
|
||||
static uint8_t StaticShellcode[] = {
|
||||
// Setup syscall for NtTerminateProcess
|
||||
0x4C, 0x8B, 0xD1, // mov r10, rcx ; Move rcx to r10 (for syscall convention)
|
||||
0xB8, 0x2C, 0x00, 0x00, 0x00, // mov eax, 0x2C ; Syscall number for NtTerminateProcess
|
||||
0xBA, 0xFF, 0xFF, 0xFF, 0xFF, // mov edx, 0xFFFFFFFF ; Handle for current process (-1)
|
||||
0x48, 0x31, 0xF6, // xor rsi, rsi ; Exit status 0 (STATUS_SUCCESS)
|
||||
0x0F, 0x05, // syscall ; Perform syscall
|
||||
0xC3 // ret ; Return
|
||||
};
|
||||
Reference in New Issue
Block a user