4.2 KiB
4.2 KiB
-
Help
!mona help assemble- manual : https://www.corelan.be/index.php/2011/07/14/mona-py-the-manual/
-
Update Mona
!mona update- Switch between stable and trunk release:
!mona update -t release!mona update -t trunk
-
Configure working folder
!mona config -set workingfolder c:\mona%p
-
Global options
-o- ignore OS module from search operations.-m- specify the modules to perform the search operation on (ex: -m "gtk*,win,shell32.dll")-m *searches all modules
-cm- set criteria (c) a module (m) should comply with to get included in search operations.- Available:
- aslr
- rebase
- safeseh
- nx
- os
- Example of including aslr and rebase modules, but excluding safeseh modules:
-cm aslr=true,rebase=true,safeseh=false
- Available:
-cp- specify what criteria (c) a pointer (p) should match.- Available:
- unicode (also includes unicode transforms)
- ascii
- asciiprint
- upper
- lower
- uppernum
- lowernum
- numeric
- alphanum
- nonull
- startswithnull
- Example : only show pointers that contain ascii printable bytes
-cp asciiprint
- Example : only show pointers that don’t contain null bytes
-cp nonull
- Available:
-cpb- specify bad characters for pointers, so pointers containing them are skipped- Example with null byte, carriage return, and line feet:
-cpb '\x00\x0a\x0d'
- Example with null byte, carriage return, and line feet:
-
Analyze crash
!mona findmsp
-
Locate EIP - pattern_create / pattern_offset :
!mona pattern_create 5000!mona pattern_offset <EIP_VALUE>- Get value on stack (ascii):
!mona pattern_offset 5Ai6
-
Find bad characters:
- 1 - generate array of all possible characters:
!mona bytearray -cpb "\x00"
- 2 - Put array of all hex chars into overflow
- 3 - run the program until EIP gets overwritten. Then enter the following (0012FD6C is the address of first byte of the badchars array):
!mona compare -f C:\mona\<app>\bytearray.bin -a 0012FD6C
- 4 - mona gives 1 or multiple badchars. Remove these badchars from array.
- 5 - repeat above until all bad chars are removed
- Example:
!mona bytearray -cpb "\x00\x09"!mona compare -f C:\mona\<app>\bytearray.bin -a 0012FD6C!mona bytearray -cpb "\x00\x09\x0a"!mona compare -f C:\mona\<app>\bytearray.bin -a 0012FD6C!mona bytearray -cpb "\x00\x09\x0a\x0d"!mona compare -f C:\mona\<app>\bytearray.bin -a 0012FD6C
- 1 - generate array of all possible characters:
-
SEH
- Find SEH offset (nseh / seh + jump code):
- 1 - Replace A's by unique pattern (pattern_create)
- 2 -
!mona sehchain
- Find pop pop ret (for SEH Bypass):
!mona seh- Note: this will create seh.txt in working folder
- Find SEH offset (nseh / seh + jump code):
-
Egg Hunter:
- Find eggs occurrences in memory:
!mona find -s "W00TW00T"
- Generate egghunter:
- mona can create an egghunter with checksum check :
- -t : tag (ex: w00t). Default value is w00t
- -c : enable checksum routine. Only works in conjunction with parameter -f
- -f : file containing the shellcode
- Example:
!mona egg -t W00T!mona egg -t W00T -c -f shellcode.bin
- mona can create an egghunter with checksum check :
- Find eggs occurrences in memory:
-
Find jump or call or push/ret to a register:
!mona jmp -r edi- Note: this creates jmp.txt in working folder.
-
Find arbitrary instructions in dll:
/usr/share/metasploit-framework/tools/exploit/nasm_shell.rbjmp esp ==> FF E4!mona modules!mona find -s "\xff\xe4" -m <module>
-
Find shellcode occurrences in memory (and integrity check):
- 1 - Create raw shellcode.bin file using Python or anything you'd like
- 2 - Search memory for the shellcode with mona:
!mona compare -f C:\Users\administrator\Desktop\WORK\tmp\shellcode.bin
-
Asm instructions to opcodes:
!mona assemble -s "xor eax,eax # pop EBX # ret"
-
Set breakpoint on addr when the program read or write it:
- Mandatory arguments:
- -a
- -t : where is either “READ” or “WRITE”
- Note : the address should exist when setting the breakpoint. If not, you’ll get an error.
- Example : set a breakpoint when the application reads from 0012C431:
!mona bp -a 0x0012C431 -t READ
- Mandatory arguments:
-
Generate msfmodule based on crash:
- 1 - Replace A's by unique pattern (pattern_create)
- 2 - When crash occurs:
!mona suggest