Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
NOW — NØW는 원시 셸코드 바이트를 자연스러운 영어 문장으로 변환하는 워드 기반 셸코드 인코딩 및 난독화 도구입니다. | Kitploit
도구/GitHubGitHub/nirvanaon/now
Exploit FrameworksPayload GenerationShellcodeMalware AnalysisCryptographyCTFLearning & EducationRed Teaming
GitHubnirvanaon/now

NOW

NØW는 원시 셸코드 바이트를 자연스러운 영어 문장으로 변환하는 워드 기반 셸코드 인코딩 및 난독화 도구입니다.

저장소 보기
7551개월 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

NØW — 단어 기반 셸코드 인코더

셸코드를 자연스러운 영어 문장으로 인코딩합니다. 올바른 문장과 비밀번호를 사용하면 다시 디코딩할 수 있습니다.

NOW

NØW란 무엇인가?

NØW(Natural Output Words)는 원시 셸코드 바이트를 사람이 읽을 수 있는 영어 텍스트로 변환하는 C 도구입니다. 단어 코드의 단순한 목록 또는 문장과 단락이 포함된 유창하고 자연스러운 산문 형태로 출력할 수 있습니다. 출력 결과는 16진수 덤프나 base64 블롭이 아닌 평범한 글처럼 보입니다.

모든 바이트 값(0x00–0xFF)은 사용자가 제공하는 비밀 문장에서 파생된 고유한 단어에 매핑됩니다. 스트림 암호(RC4 또는 AES-256-CTR)는 비밀번호를 기반으로 바이트-단어 할당을 셔플합니다. 문장과 비밀번호가 모두 없으면 인코딩된 텍스트는 그저 노이즈일 뿐입니다.


📝 NØW

자연 출력 단어

셸코드가 산문이 되는 곳.


Version Language Platform Cipher Word Pool Output Status


Input Output Formats Architecture Compiler


NØW는 원시 셸코드 바이트를 자연스러운 영어 산문으로 변환하는 단어 기반 셸코드 인코딩 및 난독화 도구입니다. 비밀 문장, 비밀번호 및 스트림 암호(RC4 또는 AES-256-CTR)를 사용하여 원본 셸코드를 읽을 수 있는 텍스트로 인코딩한 후 역과정을 통해 복구할 수 있습니다.

보안 연구, 악성코드 분석, 레드팀 실험, CTF 개발을 위해 고안되었습니다.


작동 방식

root@kitploit:~
Shellcode bytes
      │
      ▼
Stream cipher (RC4 or AES-256-CTR) shuffles byte→word table
      │
      ▼
Each byte → one codeword from your secret sentence (padded to 256 unique words)
      │
      ▼
Optional: wrap in natural prose with connectors, punctuation, paragraph breaks
      │
      ▼
Output text file  (looks like an essay or paragraph)

복호화는 이 과정을 반대로 수행합니다. 텍스트를 읽고 구두점과 연결 단어를 제거한 다음 각 코드 단어를 해당 바이트 값으로 다시 매핑합니다.


예제

1

위 이미지에서는 NØW 단어 기반 셸코드 도구를 사용하여 셸코드를 암호화했습니다. 원본 셸코드는 먼저 선택한 스트림 암호(이 예제에서는 RC4)와 비밀번호 **"nirvana"**로 암호화되었습니다. 암호화 후 각 암호화된 바이트는 미리 정의된 단어 풀의 단어에 매핑되어 명백한 셸코드 바이트 대신 자연스러운 텍스트 블록이 생성되었습니다.

생성된 출력에는 hope, bottle, spiral, fog, ink, snow 같은 단어가 포함된 일반 산문이 표시됩니다. 그러나 이 텍스트는 의미 있는 단락으로 읽기 위한 것이 아닙니다. 각 단어는 암호화된 바이트 값을 나타내며, 단어의 순서는 암호화된 셸코드 데이터를 보존합니다.

복호화 중에 도구는 다음 역과정을 수행합니다.

  1. 단어를 해당 바이트 값으로 다시 변환합니다.
  2. 암호화된 셸코드 바이트 스트림을 재구성합니다.
  3. 동일한 비밀번호와 스트림 암호 설정(RC4)을 사용하여 데이터를 복호화합니다.
  4. 암호화 전과 동일한 원본 셸코드를 복구합니다.

이 기법은 셸코드를 사람이 읽을 수 있는 텍스트로 변환하여 원시 16진수 바이트 배열보다 페이로드가 덜 의심스럽게 보이도록 하면서도 올바른 비밀번호와 암호 설정이 제공되면 원본 셸코드를 재구성할 수 있게 합니다.

참고: 비밀 문장에는 영문 단어만 사용해야 합니다. 비영어 문자(중국어, 일본어, 아랍어, 이모지 등)는 인코딩 또는 파싱 문제를 일으켜 암호화/복호화 과정을 깨뜨릴 수 있습니다. 안정적인 결과를 위해 표준 영어 ASCII 텍스트를 사용하세요.

암호화된 텍스트

root@kitploit:~
Probably, laughed hope polishing, how most perhaps sleep would bottle, additionally, somewhere bottle, immediately bottle me spiral me time fog. Immediately, spiral animal certainly hope all by, previously do elsewhere hope perhaps ink fog, also hope ink, consequently fog? Door hope ink, meanwhile fog equally snow hope ink, recently room time hope get then immediately house, importantly house. Written all window hope all would, eventually vanished fire notably one he, elsewhere than?

Accordingly, roof snow me waves window, somewhere into me obviously now waves great, particularly ago fog. Nonetheless, me spiral hope ink, regardless fog snow consequently ink shore, fire moreover hope now birds, indirectly ink. Probably, peace floor bottle, everywhere bottle, everywhere bottle hope never would earth, white hope. Now birds time, ink hope door black, ink faded consequently snow.

About now birds moon animal, hope us window however me, currently ink similarly leaving floor. Regardless, hope now map written all window, hope all would vanished me waves? Probably, window into me furthermore now waves calm, there bucket basically horse ceiling star ceiling, dying. Furthermore, which evening pig because, bucket even word black ink!

Additionally, faded dying about now, however birds specifically used me, ink revolver hope, black ink originally faded, equally see. About now consequently birds certainly me ink two, floor particularly hope obviously now birds me. Word me word, my packed bag, me word me otherwise packed me, bag hope. Polishing father snow, me fog us, there word me packed, immediately bag hope everywhere ink.

Particularly, happy flower your, us, equally us, likewise us partly years about meanwhile fresh make, indirectly cat therefore just. Namely, not we just bottle, chiefly bottle me animal, about subsequently stone moreover to hope fish? Basically, father dawn nevertheless now, bottle, although bottle about stone prank, about but than, regardless bottle? Now home would lighthouse, immediately now go namely me until, similarly about indirectly stone.

Additionally, how ceiling stone horse, additionally me they ceiling make, its. Equally, fear us yellow chiefly ceiling stone a, old eventually now notably, whereas now eventually bottle, mainly bottle packed me. They mouse originally peace for, bottle us yellow, time, furthermore time written nowhere all window, written likewise all! Would hope us would hope stone, her hope.

Us would hope stone, alternatively waves me probably they moreover a, consequently get want there us, particularly yellow hope. Stone every currently something, notably or me word ceiling stone, great however hope stone, human me they indirectly angry. Prayer earth mostly one, nevertheless us yellow accordingly hope fish, staircase equally faded than bottle, obviously bottle about thinking leather? Buried bird bottle, chiefly bottle mainly, accordingly bottle, partly bottle, anywhere bottle moreover me perhaps time, me.

Time hope certainly stone, somewhere great your whereas, obviously your, originally your written all would. Something into packed me, time great partly laughed, regardless used every black, nonetheless dying until moreover now, somewhere now hope. Another black dying, similarly door previously stopped additionally bottle old, indeed hope stone. To animal time me time, particularly me time me.

Time about originally us, particularly would me time about, everywhere us dream meanwhile written initially stone, eventually waves ceiling meanwhile stone. Waves me they, chiefly sea whereas rocky washed leaf us, somewhere yellow hope. Mainly, all by hope us, containing ink dog, otherwise me they which. Rolled duck also, chiefly us yellow home most constant, war animal me, they found.

Long who what us yellow, hope polishing nowhere staircase? Look fire wall, indirectly he garden peace, differently waters there additionally bucket coming. Nevertheless, home ice notably have whereas room, sky something bottle packed, me stone cloud us. Importantly, yellow.

2

단어를 셸코드로 다시 복호화

암호화된 텍스트는 올바른 비밀번호(nirvana)와 스트림 암호(RC4)와 함께 도구에 제공됩니다. 도구는 구두점과 서식을 제거하고 각 단어를 해당 바이트 값으로 변환한 다음 암호화된 바이트 스트림을 재구성하고 복호화하여 원본 셸코드를 복구합니다.

과정: Shellcode → Encrypted Bytes → Words → Words → Encrypted Bytes → Original Shellcode

참고: 비밀번호와 암호는 암호화 중 사용된 값과 일치해야 합니다. 불일치가 있으면 잘못된 복호화 또는 복호화 실패가 발생합니다.


기능

  • 256단어 코드북 — 사용자가 제공하는 모든 문장으로 구축되며, 일반적인 영어 단어로 자동 패딩됩니다

  • 바이트-단어 셔플링을 위한 두 가지 스트림 암호:

    • RC4 — 크로스 플랫폼, RC4ENC/RC4DEC와 호환
    • AES-256-CTR — Windows 전용(CryptoAPI 경유), AESENC/AESDEC와 호환
  • 네 가지 출력 스타일:


프로젝트 구조

root@kitploit:~
├── main.c            # Entry point, main menu loop
├── menu.c / menu.h   # Interactive CLI actions (encrypt, decrypt, help)
├── encrypt.c / .h    # Shellcode → word encoding (plain + natural prose)
├── decrypt.c / .h    # Word text → shellcode decoding
├── word_mapping.c/.h # Builds the 256-word codebook and byte↔word lookup tables
├── rc4.c / .h        # RC4 stream cipher implementation
├── io.c / .h         # File I/O, hex parsing, multi-line input
├── platform.c / .h   # Platform-specific shellcode execution (Windows)
├── util.c / .h       # String helpers (trim, clean tokens, etc.)
└── common.h          # Shared constants, macros, and type definitions

빌드

  1. Visual Studio 2022에서 프로젝트를 엽니다.
  2. 모든 .c 및 .h 파일을 프로젝트에 추가합니다.
  3. x64 및 Release를 선택합니다.
  4. 솔루션을 빌드합니다(Ctrl + Shift + B).

요구 사항:

  • Visual Studio 2022
  • Windows SDK

권장 사항: Windows에서 Visual Studio를 사용하여 빌드하세요.


사용법

바이너리를 실행하고 대화형 메뉴를 따르세요:

root@kitploit:~
  NØW v2.2 - Word-Based Shellcode Tool
  RC4 or AES stream | Natural prose output

Main menu:
  1. Encrypt shellcode -> words
  2. Decrypt words -> shellcode
  3. Help
  4. Exit

암호화

  1. 옵션 1을 선택합니다
  2. 비밀 문장을 입력합니다(아무 문구나 가능; 고유 단어가 많을수록 코드북이 더 좋음)
  3. 비밀번호를 입력합니다(최소 4자)
  4. 스트림 암호(RC4 또는 AES-256-CTR)를 선택합니다
  5. 출력 스타일을 선택합니다(0 = 일반, 1–3 = 자연 산문)
  6. 셸코드를 16진수 바이트로 붙여넣거나 .bin 파일을 로드합니다
  7. 출력이 .txt 파일로 저장됩니다

복호화

  1. 옵션 2를 선택합니다
  2. 암호화 중 사용한 동일한 비밀 문장과 비밀번호를 입력합니다
  3. 동일한 스트림 암호를 선택합니다
  4. 인코딩된 텍스트를 붙여넣거나 파일을 로드합니다
  5. 출력이 .bin, .c, .hex로 저장됩니다

보안 참고 사항

  • 인코딩의 보안은 전적으로 문장과 비밀번호를 비밀로 유지하는 데 달려 있습니다
  • 단어 코드북은 결정적입니다. 동일한 문장 + 비밀번호 + 암호는 항상 동일한 매핑을 생성합니다
  • 이 도구는 보안 연구, CTF 챌린지, 레드팀 페이로드 난독화를 위해 고안되었습니다
  • 셸코드 실행(platform.c)은 Windows 전용이며 런타임에 명시적인 사용자 확인이 필요합니다

Medium : https://medium.com/@0xnirsec

도구 다운로드
LevelDescription
0 — Plain원시 단어 목록, 구두점 없음
1 — Light prose더 긴 문장, 최소한의 채움 단어
2 — Medium prose균형 잡힌 문단 (기본값)
3 — Heavy prose잦은 연결어와 문단 나눔
  • 라운드트립 자체 테스트 — 저장 전에 인코드→디코드가 정확히 동일한 바이트를 생성하는지 자동으로 검증합니다

  • 다중 입력 형식 — 16진수 바이트를 직접 붙여넣거나 .bin 파일을 로드

  • 복호화 시 다중 출력 형식 — .bin, .c(C 배열), .hex 저장

  • 선택적 셸코드 실행(Windows 전용) — VirtualAlloc + CreateThread를 통해 디코딩된 셸코드를 메모리에서 실행