HackingScripts/util.py

119 lines
3.1 KiB
Python
Raw Normal View History

2020-06-02 14:15:03 +02:00
import random
import socket
import netifaces as ni
2020-06-08 14:28:22 +02:00
import sys
2020-07-12 20:36:14 +02:00
from pwn import *
2020-06-02 14:15:03 +02:00
def getAddress(interface="tun0"):
if not interface in ni.interfaces():
interfaces = ni.interfaces()
interfaces.remove('lo')
interface = interfaces[0]
addresses = ni.ifaddresses(interface)
address = addresses[ni.AF_INET][0]["addr"]
return address
def openServer(address, ports=None):
listenPort = None
retry = True
sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
while retry:
if isinstance(ports, int):
listenPort = ports
retry = False
elif isinstance(ports, range):
listenPort = random.randint(ports[0],ports[-1])
elif ports is None:
listenPort = random.randint(10000,65535)
try:
sock.bind((address, listenPort))
sock.listen(1)
return sock
except Exception as e:
if not retry:
print("Unable to listen on port %d: %s" % (listenPort, str(e)))
raise e
2020-06-08 14:28:22 +02:00
2020-07-12 20:36:14 +02:00
class Stack:
def __init__(self, startAddress):
self.buffer = b""
self.address = startAddress
def pushString(self, data):
addr = self.address
data = pad(data.encode() + b"\x00", 8)
self.buffer += data
self.address += len(data)
return addr
def pushAddr(self, addr):
ptr = self.address
data = p64(addr)
self.buffer += data
self.address += len(data)
return ptr
def pushArray(self, arr):
addresses = []
for arg in arr:
arg_addr = self.pushString(arg)
addresses.append(arg_addr)
addresses.append(0x0)
addr = self.address
for arg_addr in addresses:
self.pushAddr(arg_addr)
return addr
2020-08-06 18:38:40 +02:00
def setRegisters(elf, registers):
2020-07-12 20:36:14 +02:00
rop = ROP(elf)
for t in rop.setRegisters(registers):
value = t[0]
gadget = t[1]
if type(gadget) == pwnlib.rop.gadgets.Gadget:
rop.raw(gadget.address)
for reg in gadget.regs:
if reg in registers:
rop.raw(registers[reg])
else:
rop.raw(0)
2020-08-06 18:38:40 +02:00
return rop
2020-07-12 20:36:14 +02:00
2020-08-06 18:38:40 +02:00
def genSyscall(elf, syscall, registers):
registers["rax"] = syscall
rop = setRegisters(elf, registers)
2020-07-12 20:36:14 +02:00
syscall_gadget = "syscall" if elf.arch == "amd64" else "int 0x80"
rop.raw(rop.find_gadget([syscall_gadget]).address)
return rop
def pad(x, n):
if len(x) % n != 0:
x += (n-(len(x)%n))*b"\x00"
return x
2020-06-08 14:28:22 +02:00
if __name__ == "__main__":
2020-07-12 20:36:14 +02:00
bin = sys.argv[0]
2020-06-08 14:28:22 +02:00
if len(sys.argv) < 2:
2020-07-12 20:36:14 +02:00
print("Usage: %s [command]" % bin)
2020-06-08 14:28:22 +02:00
exit(1)
2020-07-12 20:36:14 +02:00
command = sys.argv[1]
if command == "getAddress":
2020-08-04 14:33:49 +02:00
if len(sys.argv) >= 3:
2020-06-08 14:28:22 +02:00
print(getAddress(sys.argv[2]))
else:
print(getAddress())
2020-07-12 20:36:14 +02:00
elif command == "pad":
if len(sys.argv) >= 3:
n = 8
if len(sys.argv) >= 4:
n = int(sys.argv[3])
print(pad(sys.argv[2].encode(), n))
else:
print("Usage: %s pad <str> [n=8]" % bin)