Патчинг ROP-закодированных шеллкодов в PE-файлы
Инструмент, написанный на C (Win32), для преобразования любого шелл-кода в ROP и внедрения его в заданный переносимый исполняемый файл (PE). Поддерживает только 32-битные целевые PE и набор инструкций x86.
Представлен на Blackhat USA 2015, "ROPInjector: Using Return Oriented Programming for Polymorphism and Antivirus Evasion" Подробнее:
ropinjector <file-to-infect> <shellcode-file> <output-file>* [options]*
(* обозначает необязательные аргументы)
например
ropinjector.exe firefox.exe revshell.txt
file-to-infect : любой 32-битный, не упакованный PE
shellcode-file : шелл-код для внедрения в PE-файл
output-file (опционально) : Имя выходного файла. Если не указано, ROPInjector выберет подходящее имя файла, указывающее на тип выполненного внедрения.
опции :
text Force reading of shellcode file as text file. Shellcode in text
form must be in the \xHH\xHH\xHH format.
norop Don't transform shellcode to ROP.
nounroll Don't unroll SIBs.
noinj Don't inject missing gadgets.
getpc Don't replace getPC constructs in the shellcode.
entry Have shellcode run before the original PE code. Without this
option, ROPInjector will try to hook calls to ExitProcess(),
exit() and the like so that the shellcode runs last, right
before process exit.
-d<secs> Number of seconds to Sleep() before executing the shellcode.
When this option is specified, "entry" is also implicitly used.
ROPInjector выведет в конце некоторые статистические данные, разделённые запятыми. Они (в порядке появления):
GPLv2.0, http://www.gnu.org/licenses/old-licenses/gpl-2.0.html