2007-02-18 00:10:39 +00:00
|
|
|
##
|
2017-07-24 13:26:21 +00:00
|
|
|
# This module requires Metasploit: https://metasploit.com/download
|
2013-10-15 18:50:46 +00:00
|
|
|
# Current source: https://github.com/rapid7/metasploit-framework
|
2007-02-18 00:10:39 +00:00
|
|
|
##
|
|
|
|
|
2006-05-08 15:04:50 +00:00
|
|
|
require 'rex/encoder/nonupper'
|
|
|
|
|
2016-03-08 13:02:44 +00:00
|
|
|
class MetasploitModule < Msf::Encoder::NonUpper
|
2013-08-30 21:28:54 +00:00
|
|
|
Rank = LowRanking
|
2006-05-08 15:04:50 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
def initialize
|
|
|
|
super(
|
|
|
|
'Name' => "Non-Upper Encoder",
|
|
|
|
'Description' => %q{
|
|
|
|
Encodes payloads as non-alpha based bytes. This allows
|
|
|
|
payloads to bypass tolower() calls, but will fail isalpha().
|
|
|
|
Table based design from Russel Sanford.
|
|
|
|
},
|
|
|
|
'Author' => [ 'pusscat'],
|
|
|
|
'Arch' => ARCH_X86,
|
|
|
|
'License' => BSD_LICENSE,
|
|
|
|
'EncoderType' => Msf::Encoder::Type::NonUpper,
|
|
|
|
'Decoder' =>
|
|
|
|
{
|
|
|
|
'BlockSize' => 1,
|
|
|
|
})
|
|
|
|
end
|
2006-05-08 15:04:50 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
#
|
|
|
|
# Returns the decoder stub that is adjusted for the size of the buffer
|
|
|
|
# being encoded.
|
|
|
|
#
|
|
|
|
def decoder_stub(state)
|
|
|
|
state.key = ""
|
|
|
|
state.decoder_key_size = 0
|
|
|
|
Rex::Encoder::NonUpper::gen_decoder()
|
|
|
|
end
|
2006-05-08 15:04:50 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
#
|
|
|
|
# Encodes a one byte block with the current index of the length of the
|
|
|
|
# payload.
|
|
|
|
#
|
|
|
|
def encode_block(state, block)
|
|
|
|
begin
|
|
|
|
newchar, state.key, state.decoder_key_size =
|
|
|
|
Rex::Encoder::NonUpper::encode_byte(datastore['BadChars'], block.unpack('C')[0], state.key, state.decoder_key_size)
|
|
|
|
rescue RuntimeError => e
|
|
|
|
# This is a bandaid to deal with the fact that, since it's in
|
|
|
|
# the Rex namespace, the encoder itself doesn't have access to the
|
|
|
|
# Msf exception classes. Turn it into an actual EncodingError
|
|
|
|
# exception so the encoder doesn't look broken when it just fails
|
|
|
|
# to encode.
|
|
|
|
raise BadcharError if e.message == "BadChar"
|
|
|
|
end
|
|
|
|
return newchar
|
|
|
|
end
|
2006-05-08 15:04:50 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
#
|
|
|
|
# Fix stuff, and add the table :)
|
|
|
|
#
|
|
|
|
def encode_end(state)
|
|
|
|
state.encoded.gsub!(/A/, state.decoder_key_size.chr)
|
|
|
|
state.encoded.gsub!(/B/, (state.decoder_key_size+5).chr)
|
|
|
|
state.encoded[0x24, 0] = state.key
|
|
|
|
end
|
2009-09-28 05:23:23 +00:00
|
|
|
end
|