2007-10-19 06:48:26 +00:00
|
|
|
module Rex
|
|
|
|
module PeScan
|
|
|
|
module Analyze
|
|
|
|
|
|
|
|
require "rex/ui/text/table"
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
class Fingerprint
|
|
|
|
attr_accessor :pe
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
def initialize(pe)
|
|
|
|
self.pe = pe
|
|
|
|
end
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
def config(param)
|
|
|
|
@sigs = {}
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
name = nil
|
|
|
|
regx = ''
|
|
|
|
epon = 0
|
|
|
|
sidx = 0
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
fd = File.open(param['database'], 'rb')
|
|
|
|
fd.each_line do |line|
|
|
|
|
case line
|
|
|
|
when /^\s*#/
|
|
|
|
next
|
|
|
|
when /\[\s*(.*)\s*\]/
|
|
|
|
if (name)
|
|
|
|
@sigs[ name ] = [regx, epon]
|
|
|
|
end
|
|
|
|
name = $1 + " [#{ sidx+=1 }]"
|
|
|
|
epon = 0
|
|
|
|
next
|
|
|
|
when /signature\s*=\s*(.*)/
|
|
|
|
pat = $1.strip
|
|
|
|
regx = ''
|
|
|
|
pat.split(/\s+/).each do |c|
|
|
|
|
next if c.length != 2
|
|
|
|
regx << (c.index('?') ? '.' : "\\x#{c}")
|
|
|
|
end
|
|
|
|
when /ep_only\s*=\s*(.*)/
|
|
|
|
epon = ($1 =~ /^T/i) ? 1 : 0
|
|
|
|
end
|
|
|
|
end
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
if (name and ! @sigs[name])
|
|
|
|
@sigs[ name ] = [regx, epon]
|
|
|
|
end
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
fd.close
|
|
|
|
end
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
def scan(param)
|
|
|
|
config(param)
|
|
|
|
|
|
|
|
epa = pe.hdr.opt.AddressOfEntryPoint
|
|
|
|
buf = pe.read_rva(epa, 256)
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
@sigs.each_pair do |name, data|
|
|
|
|
begin
|
2009-11-02 17:09:13 +00:00
|
|
|
if (buf.match(Regexp.new('^' + data[0], nil, 'n')))
|
2007-10-19 06:48:26 +00:00
|
|
|
$stdout.puts param['file'] + ": " + name
|
|
|
|
end
|
|
|
|
rescue RegexpError
|
|
|
|
$stderr.puts "Invalid signature: #{name} #{data[0]}"
|
|
|
|
end
|
|
|
|
end
|
2009-11-02 17:09:13 +00:00
|
|
|
end
|
2007-10-19 06:48:26 +00:00
|
|
|
end
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
class Information
|
|
|
|
attr_accessor :pe
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
def initialize(pe)
|
|
|
|
self.pe = pe
|
|
|
|
end
|
|
|
|
|
|
|
|
def add_fields(tbl, obj, fields)
|
|
|
|
fields.each do |name|
|
|
|
|
begin
|
|
|
|
tbl << [name, "0x%.8x" % obj.send(name)]
|
|
|
|
rescue ::NoMethodError => e
|
|
|
|
$stderr.puts "Invalid field #{name}"
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def scan(param)
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
$stdout.puts "\n\n"
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
tbl = table("Image Headers", ['Name', 'Value'])
|
|
|
|
add_fields(tbl, pe.hdr.file, %W{
|
|
|
|
Characteristics
|
|
|
|
SizeOfOptionalHeader
|
|
|
|
PointerToSymbolTable
|
|
|
|
TimeDateStamp
|
|
|
|
NumberOfSections
|
|
|
|
Machine
|
|
|
|
})
|
|
|
|
$stdout.puts tbl.to_s
|
|
|
|
$stdout.puts "\n\n"
|
|
|
|
|
|
|
|
tbl = table("Optional Image Headers", ['Name', 'Value'])
|
|
|
|
add_fields(tbl, pe.hdr.opt, %W{
|
|
|
|
ImageBase
|
|
|
|
Magic
|
|
|
|
MajorLinkerVersion
|
|
|
|
MinorLinkerVersion
|
|
|
|
SizeOfCode
|
|
|
|
SizeOfInitializeData
|
|
|
|
SizeOfUninitializeData
|
|
|
|
AddressOfEntryPoint
|
|
|
|
BaseOfCode
|
|
|
|
BaseOfData
|
|
|
|
SectionAlignment
|
|
|
|
FileAlignment
|
|
|
|
MajorOperatingSystemVersion
|
|
|
|
MinorOperatingSystemVersion
|
|
|
|
MajorImageVersion
|
|
|
|
MinorImageVersion
|
|
|
|
MajorSubsystemVersion
|
|
|
|
MinorSubsystemVersion
|
|
|
|
Win32VersionValue
|
|
|
|
SizeOfImage
|
|
|
|
SizeOfHeaders
|
|
|
|
CheckSum
|
|
|
|
Subsystem
|
|
|
|
DllCharacteristics
|
|
|
|
SizeOfStackReserve
|
|
|
|
SizeOfStackCommit
|
|
|
|
SizeOfHeapReserve
|
|
|
|
SizeOfHeapCommit
|
|
|
|
LoaderFlags
|
|
|
|
NumberOfRvaAndSizes
|
|
|
|
})
|
|
|
|
$stdout.puts tbl.to_s
|
|
|
|
$stdout.puts "\n\n"
|
|
|
|
|
2009-11-02 17:09:13 +00:00
|
|
|
if (pe.exports)
|
2007-10-19 06:48:26 +00:00
|
|
|
tbl = table("Exported Functions", ['Ordinal', 'Name', 'Address'])
|
|
|
|
pe.exports.entries.each do |ent|
|
|
|
|
tbl << [ent.ordinal, ent.name, "0x%.8x" % pe.rva_to_vma(ent.rva)]
|
|
|
|
end
|
|
|
|
$stdout.puts tbl.to_s
|
|
|
|
$stdout.puts "\n\n"
|
|
|
|
end
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
if (pe.imports)
|
|
|
|
tbl = table("Imported Functions", ['Library', 'Ordinal', 'Name'])
|
|
|
|
pe.imports.each do |lib|
|
|
|
|
lib.entries.each do |ent|
|
|
|
|
tbl << [lib.name, ent.ordinal, ent.name]
|
|
|
|
end
|
|
|
|
end
|
|
|
|
$stdout.puts tbl.to_s
|
|
|
|
$stdout.puts "\n\n"
|
|
|
|
end
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
if(pe.config)
|
|
|
|
tbl = table("Configuration Header", ['Name', 'Value'])
|
2009-11-02 17:09:13 +00:00
|
|
|
add_fields(tbl, pe.config, %W{
|
2007-10-19 06:48:26 +00:00
|
|
|
Size
|
|
|
|
TimeDateStamp
|
|
|
|
MajorVersion
|
|
|
|
MinorVersion
|
|
|
|
GlobalFlagsClear
|
|
|
|
GlobalFlagsSet
|
|
|
|
CriticalSectionDefaultTimeout
|
|
|
|
DeCommitFreeBlockThreshold
|
|
|
|
DeCommitTotalFreeThreshold
|
|
|
|
LockPrefixTable
|
|
|
|
MaximumAllocationSize
|
|
|
|
VirtualMemoryThreshold
|
|
|
|
ProcessAffinityMask
|
|
|
|
ProcessHeapFlags
|
|
|
|
CSDVersion
|
|
|
|
Reserved1
|
|
|
|
EditList
|
|
|
|
SecurityCookie
|
|
|
|
SEHandlerTable
|
|
|
|
SEHandlerCount
|
|
|
|
})
|
|
|
|
$stdout.puts tbl.to_s
|
|
|
|
$stdout.puts "\n\n"
|
|
|
|
end
|
|
|
|
|
|
|
|
|
2009-06-02 23:40:36 +00:00
|
|
|
if(pe.resources)
|
|
|
|
tbl = table("Resources", ['ID', 'Language', 'Code Page', 'Size', 'Name'])
|
|
|
|
pe.resources.keys.sort.each do |rkey|
|
|
|
|
res = pe.resources[rkey]
|
|
|
|
tbl << [rkey, res.lang, res.code, res.size, res.file]
|
|
|
|
end
|
|
|
|
$stdout.puts tbl.to_s
|
|
|
|
$stdout.puts "\n\n"
|
2009-06-20 17:53:53 +00:00
|
|
|
end
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2009-06-20 17:53:53 +00:00
|
|
|
tbl = table("Section Header", ["Name", "VirtualAddress", "SizeOfRawData", "Characteristics"])
|
|
|
|
pe.sections.each do |sec|
|
2009-11-02 17:09:13 +00:00
|
|
|
tbl << [ sec.name, *[sec.vma, sec.raw_size, sec.flags].map{|x| "0x%.8x" % x} ]
|
2009-06-20 17:53:53 +00:00
|
|
|
end
|
|
|
|
$stdout.puts tbl.to_s
|
2009-11-02 17:09:13 +00:00
|
|
|
$stdout.puts "\n\n"
|
|
|
|
|
|
|
|
end
|
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
def table(name, cols)
|
|
|
|
Rex::Ui::Text::Table.new(
|
|
|
|
'Header' => name,
|
|
|
|
'Columns' => cols
|
|
|
|
)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
|
|
|
|
class Ripper
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
require "fileutils"
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
attr_accessor :pe
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
def initialize(pe)
|
|
|
|
self.pe = pe
|
|
|
|
end
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
def scan(param)
|
|
|
|
dest = param['dir']
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
if (param['file'])
|
|
|
|
dest = File.join(dest, File.basename(param['file']))
|
|
|
|
end
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2009-04-02 18:58:36 +00:00
|
|
|
::FileUtils.mkdir_p(dest)
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
pe.resources.keys.sort.each do |rkey|
|
|
|
|
res = pe.resources[rkey]
|
|
|
|
path = File.join(dest, rkey.split('/')[1] + '_' + res.file)
|
2009-11-02 17:09:13 +00:00
|
|
|
|
|
|
|
fd = File.new(path, 'wb')
|
2007-10-19 06:48:26 +00:00
|
|
|
fd.write(res.data)
|
|
|
|
fd.close
|
2009-11-02 17:09:13 +00:00
|
|
|
end
|
2007-10-19 06:48:26 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
class ContextMapDumper
|
|
|
|
|
|
|
|
attr_accessor :pe
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
def initialize(pe)
|
|
|
|
self.pe = pe
|
|
|
|
end
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
def scan(param)
|
|
|
|
dest = param['dir']
|
|
|
|
path = ''
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2009-04-02 18:58:36 +00:00
|
|
|
::FileUtils.mkdir_p(dest)
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
if(not (param['dir'] and param['file']))
|
|
|
|
$stderr.puts "No directory or file specified"
|
|
|
|
return
|
|
|
|
end
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
if (param['file'])
|
|
|
|
path = File.join(dest, File.basename(param['file']) + ".map")
|
|
|
|
end
|
|
|
|
|
2009-11-02 17:09:13 +00:00
|
|
|
fd = File.new(path, "wb")
|
2007-10-19 06:48:26 +00:00
|
|
|
pe.all_sections.each do |section|
|
|
|
|
|
|
|
|
# Skip over known bad sections
|
|
|
|
next if section.name == ".data"
|
|
|
|
next if section.name == ".reloc"
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 14:26:56 +00:00
|
|
|
offset = 0
|
|
|
|
while offset < section.size
|
2007-10-19 06:48:26 +00:00
|
|
|
byte = section.read(offset, 1)[0]
|
|
|
|
if byte != 0
|
2009-11-02 17:09:13 +00:00
|
|
|
chunkbase = pe.rva_to_vma(section.base_rva) + offset
|
2007-10-19 06:48:26 +00:00
|
|
|
data = ''
|
|
|
|
while byte != 0
|
|
|
|
data << byte
|
|
|
|
offset += 1
|
|
|
|
byte = 0
|
|
|
|
byte = section.read(offset, 1)[0] if offset < section.size
|
|
|
|
end
|
|
|
|
buff = nil
|
|
|
|
buff = [ 0x01, chunkbase, data.length, data].pack("CNNA*") if data.length > 0
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
fd.write(buff) if buff
|
|
|
|
end
|
2007-10-19 14:26:56 +00:00
|
|
|
offset += 1
|
2007-10-19 06:48:26 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
end
|
2009-11-02 17:09:13 +00:00
|
|
|
|
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
fd.close
|
|
|
|
end
|
|
|
|
end
|
2009-11-02 17:09:13 +00:00
|
|
|
|
2007-10-19 06:48:26 +00:00
|
|
|
# EOC
|
|
|
|
|
|
|
|
end
|
|
|
|
end
|
2009-04-02 18:58:36 +00:00
|
|
|
end
|
2009-11-02 17:09:13 +00:00
|
|
|
|