Skip to main content

Convert standard elf files to standalone shellcodes. Please read the following documentation view the examples for this project to work

How does this work ?

The python library parses the elf and create a simple relocatable file format Then the mini loader is inserted as the entry point of the elf the mini loader will load the relocatable format and execute it. There are no special requirements, the library contain the compiled mini loaders

Supported architectures

  • mips

  • x32

Installation:

# Unfortunately only python2 is supported for now
python2 -m pip install elf_to_shellcode

Creating a shellcode

Some compilation flags are required for this to work properly. You must compile the binary with -fPIE and -static take a look at the provided examples below

Examples:

Makefile

Main.c

Compiling with libc

Libc has destructors and constructors this project doesn’t fully support libc. take a look at the provided example (which uses libc) and note that some function won’t work properly.

eg…

printf is using fwrite which uses the FILE * struct for stdout. this file is opened post libc initialization (in one of the libc constructors). __start is responsible for calling libc constructors and we don’t use __start (for other reasons). therefor you can’t use printf in the shellcode, but you can implement it using snprintf and write

Converting the elf to shellcode:

from elf_to_shellcode.relocate import make_shellcode

shellcode = make_shellcode(
    binary_path="/tmp/binary.out",
    arch="mips",
    endian="big"
)

with open("myshellcode.out", 'wb') as fp:
    fp.write(shellcode)

Testing your shellcode

You can use the provided shellcode Loader to test you shellcodes

qemu-mips ./shellcode_loader ./myshellcode.out

Output example

Shellcode size = 66620
Allocating shellcode buffer, size = 69632
Mapping new memory, size = 69632
Jumping to shellcode, address = 0x7f7ee000
Hello from shellcode !

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

elf_to_shellcode-1.3.tar.gz (5.9 kB view details)

Uploaded Source

File details

Details for the file elf_to_shellcode-1.3.tar.gz.

File metadata

  • Download URL: elf_to_shellcode-1.3.tar.gz
  • Upload date:
  • Size: 5.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/1.15.0 pkginfo/1.8.2 requests/2.27.1 setuptools/44.1.1 requests-toolbelt/0.9.1 tqdm/4.63.0 CPython/2.7.18

File hashes

Hashes for elf_to_shellcode-1.3.tar.gz
Algorithm Hash digest
SHA256 2d727be5c7fe667e8395e7947c3fd88c6bdda8c554d2e9fcd68107a27ecd994d
MD5 2515f2fe39b1b4219673a78686a3e87a
BLAKE2b-256 43aabaf32516fcd2cb7544a5304fddfa424f233229659e2c76217eb8506ff43c

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page