编写 shellcode 一直非常有趣,但有些部分极其枯燥且容易出错。只需专注于有趣的部分,使用 ShellNoob 吧!
快速了解,请查看 Black Hat Arsenal 演讲的幻灯片:link
想贡献代码?有功能请求?报告 Bug?想骂人?所有反馈都欢迎!!(当然,某些类型的反馈会比其他的更受欢迎 :-))。
如有任何问题,欢迎在 Twitter 上联系我 @reyammer 或发送邮件至 yanick[AT]cs.ucsb.edu!
01/21/2014 - ShellNoob 2.1 发布!完全支持 Python 3,并修复了大量 Bug。全部功劳归于 Levente Polyak!
07/29/2013 - ShellNoob 2.0 发布!
06/08/2013 - ShellNoob 被 Black Hat Arsenal 收录!公告见:link。
--intel 开关。--64 开关。-c 开关。--to-strace 和 --to-gdb 选项!--file-patch、--vm-patch、--fork-nopper 选项轻松实现二进制补丁!(详情如下)$ ./shellnoob.py -h
shellnoob.py [--from-INPUT] (input_file_path | - ) [--to-OUTPUT] [output_file_path | - ]
shellnoob.py -c (prepend a breakpoint (Warning: only few platforms/OS are supported!)
shellnoob.py --64 (64 bits mode, default: 32 bits)
shellnoob.py --intel (intel syntax mode, default: att)
shellnoob.py -q (quite mode)
shellnoob.py -v (or -vv, -vvv)
shellnoob.py --to-strace (compiles it & run strace)
shellnoob.py --to-gdb (compiles it & run gdb & set breakpoint on entrypoint)
Standalone "plugins"
shellnoob.py -i [--to-asm | --to-opcode ] (for interactive mode)
shellnoob.py --get-const <const>
shellnoob.py --get-sysnum <sysnum>
shellnoob.py --get-errno <errno>
shellnoob.py --file-patch <exe_fp> <file_offset> <data> (in hex). (Warning: tested only on x86/x86_64)
shellnoob.py --vm-patch <exe_fp> <vm_address> <data> (in hex). (Warning: tested only on x86/x86_64)
shellnoob.py --fork-nopper <exe_fp> (this nops out the calls to fork(). Warning: tested only on x86/x86_64)
"Installation"
shellnoob.py --install [--force] (this just copies the script in a convinient position)
shellnoob.py --uninstall [--force]
Supported INPUT format: asm, obj, bin, hex, c, shellstorm
Supported OUTPUT format: asm, obj, exe, bin, hex, c, completec, python, bash, ruby, pretty, safeasm
All combinations from INPUT to OUTPUT are supported!
$ ./shellnoob.py --install
这只是把脚本复制到 /usr/local/bin/snoob。就这样。(运行 ./shellnoob.py --uninstall 即可撤销)。
$ snoob --from-asm shell.asm --to-bin shell.bin
一些等效的替代写法(该工具会尝试根据文件扩展名猜测你的意图……)
$ snoob --from-asm shell.asm --to-bin
$ snoob shell.asm --to-bin
$ snoob shell.asm --to-bin - > shell.bin
$ cat shell.asm | snoob --from-asm - --to-bin - > shell.bin
--intel 切换为 Intel 语法。(更多细节见 "asm as output" 部分)--from-shellstorm 开关接受一个 <shellcode_id> 作为参数。ShellNoob 会从 shell-storm shellcode 数据库获取所选 shellcode,并将其转换为所选格式。$ snoob -c shell.asm --to-exe shell
$ gdb -q shell
$ run
Reading symbols from ./shell...(no debugging symbols found)...done.
(gdb) run
Starting program: ./shell
Program received signal SIGTRAP, Trace/breakpoint trap.
0x08048055 in ?? ()
(gdb)
或者你也可以使用新的 --to-strace 和 --to-gdb 开关!
$ snoob open-read-write.asm --to-strace
Converting open-read-write.asm (asm) into /tmp/tmpBaQbzP (exe)
execve("/tmp/tmpBaQbzP", ["/tmp/tmpBaQbzP"], [/* 97 vars */]) = 0
[ Process PID=12237 runs in 32 bit mode. ]
open("/tmp/secret", O_RDONLY) = 3
read(3, "thesecretisthedolphin\n", 255) = 22
write(1, "thesecretisthedolphin\n", 22thesecretisthedolphin
) = 22
_exit(0)
$ snoob open-read-write.asm --to-gdb
Converting open-read-write.asm (asm) into /tmp/tmpZdImWw (exe)
Reading symbols from /tmp/tmpZdImWw...(no debugging symbols found)...done.
(gdb) Breakpoint 1 at 0x8048054
(gdb)
注意 ShellNoob 会自动在入口点设置断点!
$ snoob --get-sysnum read
i386 ~> 3
x86_64 ~> 0
$ snoob --get-sysnum fork
i386 ~> 2
x86_64 ~> 57
$ snoob --get-const O_RDONLY
O_RDONLY ~> 0
$ snoob --get-const O_CREAT
O_CREAT ~> 64
$ snoob --get-const EINVAL
EINVAL ~> 22
$ snoob --get-errno EINVAL
EINVAL ~> Invalid argument
$ snoob --get-errno 22
22 ~> Invalid argument
$ snoob --get-errno EACCES
EACCES ~> Permission denied
$ snoob --get-errno 13
13 ~> Permission denied
$ ./shellnoob.py -i --to-opcode
asm_to_opcode selected
>> mov %eax, %ebx
mov %eax, %ebx ~> 89c3
>>
./shellnoob.py -i --to-asm
opcode_to_asm selected
>> 89c3
89c3 ~> mov %eax,%ebx
>>
$ python
>>> from shellnoob import ShellNoob
>>> sn = ShellNoob(flag_intel=True)
>>> sn.asm_to_hex('nop; mov ebx,eax; xor edx,edx')
'9089c331d2'
>>> sn.hex_to_inss('9089c331d2')
['nop', 'mov ebx,eax', 'xor edx,edx']
>>> sn.do_resolve_syscall('fork')
i386 ~> 2
x86_64 ~> 57
当 "asm" 作为输出格式时,ShellNoob 会尽力而为。Objdump 被用作反汇编器,但它的输出并非万无一失。ShellNoob 会尝试通过添加字节(.byte 表示法)来增强反汇编结果,并在适当时显示对应的 ASCII(.ascii 表示法)。当你想要修改/汇编 objdump 的输出但需要快速修复时,这非常有用。
Example with the .byte notation:
jmp 0x37 # .byte 0xeb,0x35
pop %ebx # .byte 0x5b
mov %ebx,%eax # .byte 0x89,0xd8
add $0xb,%eax # .byte 0x83,0xc0,0x0b
xor %ecx,%ecx # .byte 0x31,0xc9
Example with the .ascii notation:
das # .ascii "/"
je 0xac # .ascii "tm"
jo 0x70 # .ascii "p/"
jae 0xa8 # .ascii "se"
arpl %si,0x65(%edx) # .ascii "cre"
je 0xa0 # .ascii "tX
ShellNoob 以 MIT 许可证发布。请查看 COPYRIGHT 文件。