2013-03-11 22:04:47 +00:00
|
|
|
#!/usr/bin/env sh
|
|
|
|
#
|
2013-03-12 22:29:25 +00:00
|
|
|
# Creates shell_bind_tcp shellcode with specific port
|
2013-03-11 22:04:47 +00:00
|
|
|
#
|
|
|
|
# Example
|
|
|
|
# ./compile_all.sh shell_bind_tcp 50123
|
|
|
|
#
|
|
|
|
# If no port specified, the default one will be used 43775
|
|
|
|
#
|
|
|
|
# Port is stored in last two bytes in HEX
|
|
|
|
#
|
|
|
|
|
|
|
|
ARG1=$1 # Specify program
|
|
|
|
ARG2=$2 # Specify port
|
|
|
|
|
|
|
|
|
2013-03-12 22:29:25 +00:00
|
|
|
|
2013-03-11 22:39:04 +00:00
|
|
|
#
|
|
|
|
# Check script usage and file existence
|
|
|
|
#
|
2013-03-11 22:04:47 +00:00
|
|
|
if [ -z "$ARG1" ]; then
|
|
|
|
echo " [I] Please specify program you would like to assemble!"
|
2013-03-11 22:06:57 +00:00
|
|
|
echo " [I] Usage example: ./compile_all.sh shell_bind_tcp 50123"
|
2013-03-11 22:04:47 +00:00
|
|
|
exit 1;
|
2013-03-12 22:29:25 +00:00
|
|
|
elif [ -e "$ARG1" ]; then
|
|
|
|
if [[ $ARG1 == *nasm* ]]; then
|
|
|
|
ARG1=$(echo -ne $ARG1 |sed 's/.....$//g');
|
|
|
|
echo $ARG1
|
|
|
|
fi
|
|
|
|
elif [ ! -e "$ARG1".nasm ]; then
|
2013-03-11 22:04:47 +00:00
|
|
|
ARG1_GUESS=$(echo $ARG1 |sed 's/.nasm//g')
|
|
|
|
if [ -e "$ARG1_GUESS" ]; then
|
|
|
|
ARG1=$ARG1_GUESS
|
|
|
|
else
|
2013-03-12 22:29:25 +00:00
|
|
|
echo " [E] File "$ARG1" does not exist!"
|
2013-03-11 22:04:47 +00:00
|
|
|
exit 1;
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
|
2013-03-12 22:29:25 +00:00
|
|
|
|
2013-03-11 22:39:04 +00:00
|
|
|
#
|
|
|
|
# Validate nasm source file
|
|
|
|
#
|
2013-03-11 22:04:47 +00:00
|
|
|
if ! $(grep -qi ^global $ARG1.nasm 2>/dev/null); then
|
|
|
|
echo " [E] The file "$ARG1.nasm" does not appear to be a correct NASM source!"
|
|
|
|
exit 1;
|
|
|
|
fi
|
|
|
|
|
2013-03-11 22:39:04 +00:00
|
|
|
#
|
|
|
|
# Port range check
|
|
|
|
#
|
2013-03-11 22:19:53 +00:00
|
|
|
if [ -z "$ARG2" ]; then
|
|
|
|
echo " [I] Default port will be used."
|
2013-03-11 22:34:58 +00:00
|
|
|
elif ! [[ $ARG2 -ge 1024 && $ARG2 -le 65535 ]]; then
|
|
|
|
echo " [E] The port must be in range 1024..65535 !"
|
2013-03-11 22:19:53 +00:00
|
|
|
exit 1;
|
2013-03-11 22:34:58 +00:00
|
|
|
else
|
|
|
|
echo " [I] Using custom port: "$ARG2
|
2013-03-11 22:19:53 +00:00
|
|
|
fi
|
2013-03-11 22:04:47 +00:00
|
|
|
|
2013-03-11 22:39:04 +00:00
|
|
|
#
|
|
|
|
# Assemble and link
|
|
|
|
#
|
2013-03-12 22:29:25 +00:00
|
|
|
echo " [+] Assembling "$ARG1".nasm with NASM ..."
|
2013-03-11 22:04:47 +00:00
|
|
|
nasm -f elf32 -o $ARG1.o $ARG1.nasm && \
|
2013-03-12 22:29:25 +00:00
|
|
|
echo " [+] Linking "$ARG1".o ..." && \
|
2013-03-11 22:04:47 +00:00
|
|
|
ld -m elf_i386 -o $ARG1 $ARG1.o && \
|
|
|
|
echo -e " [+] Generating shellcode with objdump ..." && \
|
|
|
|
SHELLCODE=$(objdump -d ./$ARG1 |grep '[0-9a-f]:'|grep -v 'file'|cut -f2 -d:|cut -f1-7 -d' '|tr -s ' '|tr '\t' ' '|sed 's/ $//g'|sed 's/ /\\x/g'|paste -d '' -s |sed 's/^/"/' |sed 's/$/"/g')
|
|
|
|
|
2013-03-11 22:39:04 +00:00
|
|
|
#
|
|
|
|
# Set the custom port (if any was specified) for the shellcode
|
|
|
|
#
|
2013-03-11 22:04:47 +00:00
|
|
|
if [ -z "$ARG2" ]; then
|
|
|
|
FULL_SHELLCODE=$(echo $SHELLCODE)
|
|
|
|
else
|
|
|
|
PORT_HEX=$(printf '%.4x' $ARG2 | sed 's/../\\x&/g')
|
|
|
|
FULL_SHELLCODE=$(echo -n $SHELLCODE | sed 's/.........$//' ; echo $PORT_HEX"\"")
|
|
|
|
fi
|
|
|
|
|
2013-03-11 22:39:04 +00:00
|
|
|
#
|
|
|
|
# Check shellcode for NULLs
|
|
|
|
#
|
2013-03-11 22:40:41 +00:00
|
|
|
echo " [+] Checking shellcode for NULLs ..."
|
2013-03-11 22:34:58 +00:00
|
|
|
if [[ $FULL_SHELLCODE == *00* ]]; then
|
|
|
|
echo " [E] Your shellcode contains 00 (NULL) ! Most likely you need to change your port."
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
|
2013-03-11 22:04:47 +00:00
|
|
|
echo -ne " [+] Shellcode size is "$(echo -ne $FULL_SHELLCODE|sed 's/\"//g'|wc -c)" bytes\n"
|
|
|
|
echo $FULL_SHELLCODE
|
|
|
|
|
2013-03-27 14:04:39 +00:00
|
|
|
if [ -z "$FULL_SHELLCODE" ]; then
|
|
|
|
exit 1;
|
|
|
|
fi
|
2013-03-11 22:04:47 +00:00
|
|
|
|
2013-03-11 22:39:04 +00:00
|
|
|
#
|
|
|
|
# Generate shellcode.c
|
|
|
|
#
|
2013-03-11 22:04:47 +00:00
|
|
|
echo " [+] Generating shellcode.c file with the "$ARG1" shellcode ..."
|
|
|
|
cat > shellcode.c << EOF
|
|
|
|
#include <stdio.h>
|
|
|
|
#include <string.h>
|
|
|
|
|
|
|
|
unsigned char code[] = \
|
|
|
|
$FULL_SHELLCODE;
|
|
|
|
|
|
|
|
main()
|
|
|
|
{
|
|
|
|
printf("Shellcode Length: %d\n", strlen(code));
|
|
|
|
int (*ret)() = (int(*)())code;
|
|
|
|
ret();
|
|
|
|
}
|
|
|
|
EOF
|
|
|
|
|
2013-03-11 22:39:04 +00:00
|
|
|
#
|
|
|
|
# Compile C code with GCC
|
|
|
|
#
|
2013-03-11 22:04:47 +00:00
|
|
|
echo " [+] Compiling shellcode.c with GCC ..."
|
|
|
|
gcc -m32 -fno-stack-protector -z execstack shellcode.c -o shellcode
|
|
|
|
|
|
|
|
echo -e " [+] All done! You can run the shellcode now: \n$ ./shellcode"
|