2007-02-18 00:10:39 +00:00
|
|
|
##
|
2008-10-02 05:23:59 +00:00
|
|
|
# $Id$
|
2007-02-18 00:10:39 +00:00
|
|
|
##
|
|
|
|
|
|
|
|
##
|
2010-04-30 08:40:19 +00:00
|
|
|
# This file is part of the Metasploit Framework and may be subject to
|
2007-02-18 00:10:39 +00:00
|
|
|
# redistribution and commercial restrictions. Please see the Metasploit
|
|
|
|
# Framework web site for more information on licensing and terms of use.
|
2009-04-13 14:33:26 +00:00
|
|
|
# http://metasploit.com/framework/
|
2007-02-18 00:10:39 +00:00
|
|
|
##
|
|
|
|
|
|
|
|
|
2005-10-31 19:37:25 +00:00
|
|
|
require 'msf/core'
|
|
|
|
|
|
|
|
|
2008-10-02 05:23:59 +00:00
|
|
|
class Metasploit3 < Msf::Encoder::Xor
|
2005-10-31 19:37:25 +00:00
|
|
|
|
|
|
|
def initialize
|
|
|
|
super(
|
|
|
|
'Name' => 'PPC LongXOR Encoder',
|
|
|
|
'Version' => '$Revision$',
|
|
|
|
'Description' => %q{
|
|
|
|
This encoder is ghandi's PPC dword xor encoder with some size tweaks
|
|
|
|
by HDM.
|
|
|
|
},
|
2009-09-27 21:30:45 +00:00
|
|
|
'Author' => [ 'ddz', 'hdm' ],
|
2005-10-31 19:37:25 +00:00
|
|
|
'Arch' => ARCH_PPC,
|
2006-01-21 22:10:20 +00:00
|
|
|
'License' => MSF_LICENSE,
|
2005-10-31 19:37:25 +00:00
|
|
|
'Decoder' =>
|
|
|
|
{
|
|
|
|
'KeySize' => 4,
|
|
|
|
'BlockSize' => 4,
|
2005-12-30 06:05:23 +00:00
|
|
|
'KeyPack' => 'N',
|
2005-10-31 19:37:25 +00:00
|
|
|
})
|
|
|
|
end
|
|
|
|
|
|
|
|
#
|
|
|
|
# Returns the decoder stub that is adjusted for the size of
|
|
|
|
# the buffer being encoded
|
|
|
|
#
|
|
|
|
def decoder_stub(state)
|
|
|
|
[
|
|
|
|
0x7ca52a79, # 0x1da8 <main>: xor. r5,r5,r5
|
|
|
|
0x4082fffd, # 0x1dac <main+4>: bnel+ 0x1da8 <main>
|
|
|
|
0x7fe802a6, # 0x1db0 <main+8>: mflr r31
|
|
|
|
0x3bff07fa, # 0x1db4 <main+12>: addi r31,r31,2042
|
|
|
|
0x38a5f84a, # 0x1db8 <main+16>: addi r5,r5,-1974
|
|
|
|
0x3cc09999, # 0x1dbc <main+20>: lis r6, hi16(key)
|
|
|
|
0x60c69999, # 0x1dc0 <main+24>: ori r6,r6, lo16(key)
|
|
|
|
0x388507ba, # 0x1dc4 <main+28>: addi r4,r5,1978
|
|
|
|
0x7c8903a6, # 0x1dc8 <main+32>: mtctr r4
|
|
|
|
0x809ff84a, # 0x1dcc <main+36>: lwz r4,-1974(r31)
|
|
|
|
0x7c843278, # 0x1dd0 <main+40>: xor r4,r4,r6
|
|
|
|
0x909ff84a, # 0x1dd4 <main+44>: stw r4,-1974(r31)
|
|
|
|
0x7c05f8ac, # 0x1dd8 <main+48>: dcbf r5,r31
|
|
|
|
0x7cff04ac, # 0x1ddc <main+52>: sync
|
|
|
|
0x7c05ffac, # 0x1de0 <main+56>: icbi r5,r31
|
|
|
|
0x3bc507ba, # 0x1de4 <main+60>: addi r30,r5,1978
|
|
|
|
0x7ffff215, # 0x1de8 <main+64>: add. r31,r31,r30
|
|
|
|
0x4220ffe0, # 0x1dec <main+68>: bdnz- 0x1dcc <main+36>
|
|
|
|
0x4cff012c, # 0x1df0 <main+72>: isync
|
|
|
|
].pack("N*")
|
|
|
|
end
|
|
|
|
|
|
|
|
#
|
2010-04-30 08:40:19 +00:00
|
|
|
# Fix up the decoder stub now
|
2005-10-31 19:37:25 +00:00
|
|
|
#
|
|
|
|
def encode_finalize_stub(state, stub)
|
|
|
|
icount = state.buf.length / 4
|
|
|
|
|
|
|
|
stub[30, 2] = [ 1974 + icount ].pack('n')
|
2005-12-30 06:05:23 +00:00
|
|
|
stub[22, 2] = [ state.key.to_i ].pack('N')[0, 2]
|
|
|
|
stub[26, 2] = [ state.key.to_i ].pack('N')[2, 2]
|
2005-10-31 19:37:25 +00:00
|
|
|
|
|
|
|
stub
|
|
|
|
end
|
|
|
|
|
2010-04-30 08:40:19 +00:00
|
|
|
end
|