From 89cd524acb99a108f4e98d97c90aef5384630181 Mon Sep 17 00:00:00 2001 From: adfoster-r7 Date: Wed, 2 Aug 2023 01:26:18 +0100 Subject: [PATCH] Update osx templates makefile and compile binaries --- data/meterpreter/aarch64_osx_stage | Bin 0 -> 34062 bytes data/meterpreter/x64_osx_stage | Bin 33640 -> 33640 bytes data/templates/template_aarch64_darwin.bin | Bin 50072 -> 50072 bytes .../shellcode/osx/aarch64/stage_mettle.s | 4 ++-- .../source/shellcode/osx/stager/.gitignore | 4 ++++ .../source/shellcode/osx/template/.gitignore | 1 + .../source/shellcode/osx/template/Makefile | 20 ++++++++++++++++-- 7 files changed, 25 insertions(+), 4 deletions(-) create mode 100755 data/meterpreter/aarch64_osx_stage create mode 100644 external/source/shellcode/osx/stager/.gitignore create mode 100644 external/source/shellcode/osx/template/.gitignore diff --git a/data/meterpreter/aarch64_osx_stage b/data/meterpreter/aarch64_osx_stage new file mode 100755 index 0000000000000000000000000000000000000000..806160894830ddc2737e1211878a3dea8536d676 GIT binary patch literal 34062 zcmeHQdvp|4n!nXepgSQvBn|>PNrPxN42C8TlA|%*B!M)qKpuj+TGL6Iq)GZgcL$C5 z2r#aXj4S2nFs`e@QCDEsHFD$}dgkcB;LPA_5uDL+cXT_TXRCwms=Mx5Gh*-WyH%Bb zgfJfcbF0p&+`9LE-*><7_kH)Pd%L?TC;s%w*OM6&7!DK8X*dTaFm^X9!4+e(a5mx; z#dYo#4L3A2H&JW$!I`t0#?(m8y&x3D)`pF(+1;GqmEFd)dLEkTgi8Dn#hCBbm{viN zEARLm)tEiART`?3U8BbYHZXdP3sLNd#v=Y;m)4joue(x}x5BCtP(Aa=l8p|?3k9QT z1#{&M)vEF=nh>g+GX>^ci(+5!7Jsl)^anSExcqGV4r}trM|4m|sM9fpf(!@6VrD$g1;=9Q7+{QSv7jtLnS0m=R9p$4 zOK{q^Gd3NiYX`0&umIQVaMD4sOeeKX#YsHl9aZ4Z)JLbAf{PNIn7gdBFB&QB^|zOH z_V;$8P6xuC>(N>_IQ!YgrR5KGUjOJnt(zHGg7y-es!V7gOy<`rmcKPEKp**6KkTra z?4fy-dC<63IH^z7zZeJ#X-k{Ht>SkEpqvsO+Ez4EWeIFQTf*9!_;?^f{j!CSUHv!pgNd-w=+Bs=Y( zvj`~r1SOxbqS3bPOtNDfUdI@gJk&AfnN(^fZ-X5Rych$#79szveT$$h*y4s9l9xY7 z^6;HV5$VJFY3v=%*I``ZEkPgAV3utv5J~5?bQ9Jzp8NP~Y z)%|f)w>d}tgiQIm&6zY0&yoJD%U%SV9fFcd6;xXm!QYx5R`{26cfj{a^yS)cR_BKe zS$&sZCVi;)L9U!yRgLfID#^BD8!)*WwqE~a^S<|g89{8ssb3b<{wz82_oY*i!(((7 zVsw^UDFN^Bu>$GzFAF3l)V_o78H>0-)3y!ShKi+EbiRwhckx(0;z@}G)y0KrpISb1 zE65ex=iFwkpJ?+7frX9Y0C@s7B+UgtlfqKLHqv#anZw?HM#9 zu%%IPDK5gX&MJZDEsAZ=N#ftvoV?K#Pl={D+IKm&S4p1txZJlKHYR!AXNm`L>KR6f zdEog7r4?loCFFTNK?y&2K0}FE_k6)HPio&G{|(QxO0{n?#WHQ+l>Jqv*k5%ia;+&o zYCGz>?L42o32ct4wjaNORq{5BX`wv$68K-jJh6f%j_ae8^90F$2-k;P3VuRys#s93 z@vSd!D|WMLy8}2wh7CH;10B8>9$NP4d}#qNx8j^Hu#1-Cyb@>9%%oa@^^f}E1>o?4 zOR+x3l>Fyhu-m0Ll+6!0gr0*QYr4-0xemc9jhHQxbwAqoyA;Sl?m+Amx|9Oc{m_Zp z7YY-k!8a=`%2K|@5S|Aj7zeh2frpcXmg<7`Z%s1 z$5?r+nwN#FIv;h4W6yN;+H)C7&=;V6GjyhY&mxvNuZL`3&X>Lrv^n=Eumg=nm?haC z!Sy4UzZl>CDDD~1!G`)=*fkF{I!+d}@%xuHkE}022Vj*SCq47eS|#X7ZLpEI6=FU; zfVKx*igi0m3FX~dc^^|OsPCJu&dH42Fl5_!rS!V4=N-`L4(J43hL26;d4c8+&(-IS zR`1j9KUw@A+NEFU{QcnXAIqObf9nG2d7Zuw^cc$?z#67*Vs+{sAx`lr-?KgLfWCC^ zcbQl#k6G9?f_6*)<}d9&@bzIFUmCkJ^Cn8W1)#qPd^f3lG-j$x)4waNKbxqnT}XdwhyKOE>8}9`Ja;vqp^{3u70-_APq_b?mIM zK3ps{>3j{~Yf$yKX}ofmh8t{o^L)7d!AbL3)zuAtx5od1I`$aMhL%WWI(-f3YgGEo z_{!4n(sBuTLzQ0*`fAWawvGjl1=Jl!UC8-NnSZ`qy|F_29%N9Cc2zK?u>vK<^gMGq zPZwftP@aC9#Z&Jx%F{!R=}humOzp_!dvQGr`4@bc?}`WGd2A?gU-!&MN%`7=lJfK- zl$58P@R4@UDYoLClc(KtOk?iJL$-lyq)(V;C+x5bs!b&*DTmthIED@QVVp7vc5>UH zM?Prm$OV?X`~!9xgJ?42sk}ydN0Xh{fc_1@P(Z$Z6M5#=#;Gv^E{Gy;U=s4-%_#c;p)C=ftxDJS)JnDm@0n8gQfTqs(#2ua%x7 zo;vWK(>I@w9y&cj^jCxa>TLSu8kP%iua##FG&c&YnyxJZ zt_xZG^izVAS_+?F?M>?>+jeyxS|+e90~u?^avB%9Czfg$byrHKanGa}NR(mRvg~oO zb}J&?6KK!GG*JrL(rjA%KB|cHPM}?nDZ_keWi46n|uFPp*W1dCzF1(?x%KnCR2b>kz9;^v*iHCQLqlm z81EzKmO_7Grb{`ut!{tHET}rwnV^$pKgHEBV&pXZoFZI-eG0gf&uDEW183CX3&=*B z1AAi{du|@ao~P;r9k*~@P$%Euw~R%jeLm!G-212wUn#sDYe&K`0nB*(#IBWomP+kL zOjc0*kpIb^(f&QxO1seiL%pB$gS;e8tQ$z5LDG|Sgiod;ZsNZqpDe^$fz}naJ1hLvjx8p;HIqD?hpYZHIsJVXnU!c$ndT%)vI;S|R`o&?P}Us$CB5t4VQWhY#T=1o17VHN9O7Po+{J|vTo;F(#)FCI;n|3tk zv4M*wYB`wvKt8l)@X)?<1UytGVH4#Je8$CNnd7t26&Gk;aJiNP_&MyuB!}6s&zY~y zyP?aaufI<1CSCP>L$O~1{b*gN>vRTrh39Uvk>U+lBLAz`!16ix{oJ+{$SqpT9Yf4v zehef3oQ8iW=6QU;UU?GgnDI3e&!G!YAA!ww+|&LW@+p6% za4%4EdEUvdLPhxe@Z$a0mmMHE$tQ6>26|x3^VV*Rvm4j&uly6V!!Ftr$`7Lb!StSx zuKD_gO4<_w;}XcQ0n0OJ!=7;0GTaa8UP1f9^X&<-$5QWYQ-R|k^cVzo_b{yUU1Roz zdS4Q<)qNrMd^^FjQ`;9}Y|2GvQTIbGwX6F=vvl?@rkuS?-4~9)Hrf~RI_O5wPW!@< zZMfcsaRpTmeob=FM*G6#Ex5i#-52r_`@#{_Y0u%ozL2gx*cTGtSzOb;khjskFdaL) zXkQqj*dd#vz!bE!FO);L4ypS>IZAjSmQbGyyUu`y#}VrAvtp;5yj%5A@+Z`W`P>73 zYJ+XOtq?KXg|;r2BHxIz2c@W$9ctM~`$6cDrC)EQv_jW!1L!uWejPq$QrCZ=w?HS0 zz8}ox-?LO&s`Iyizhx|c)_B+tE(AU4L2FKuEw4bXsWV|ei1~64@(pw+8~I)kbY#;A z+G#H+*J6w&@FIVY;x*5dvlrCn9OUV1jw~JiSS97_I$sTWSEqFz-3#X0`DL|q?wsmJ zn)8%1<)tbg`6|@~-MiAdC+NNp8A;L|?X(X}mLmQ$V*~p@S(BMq2zd)3w-j>^~|!X^=j#$PCpa$Gt>C$c4g6H5BT>w{S43}|IvKVaiF;)qfR*&c@FpO zHmp}$_osH|rSIKSkw*)_D-4{nxb}Qb`7>okeG+^C{*eNg@+sDQ3EVq|@jVIFQ@@ju z6LIqO#OQtam~gUjmL{VN@rk@>IR+kSm@# zrmb&xvXjRz*X)Jv$vP&bbp4^Tj#;K|bPv_>8hu73${z}$$5rTQm8;Z8L&UW$brGL8 z=4)!-?CXdv_xJid0dJRYc_b8A;|qi${dnN$hP4&MQeM$jkD`IMtWukt6?oR9!`s_i z@9Xt-K~8xf;0-sd+Zyou{ecW#XXVPiXv`CA^#^>bL*7nbq&(p5@ijEBZ4sSIn)`w= zbhN}Ep<&%Bb-XfX*&1(0cauBl?d`wK7ePly^D59+ay9E4`rF&vW8ZO%YCZ%BJimA- zQyG93VyJSpw?EVu%QU|%&Ar6wRn=_qbp?FESX85K?r(0-04&$03$twvh=4ZK0aTdC zwTOA6Jz~_?yGgvD-A?B%{#bXjugi~T;?jVo)oo~VmbF82j~EX5gE3!Z`Bs9~DOR{6 z5pTbTP*&YksY+?U@ok38_2IW3cf5eB3WOt}7-E+P9oy=xbk#1tc^fyQX_E#)&CT1? zt2@@OzoUw|Gc3`}be8ubD(ih=U$B$h*U;>A*89C(!B8~j?}(l!ObM^WqSHw*HHBjw z=?uBqLG7#xhGPCr{q?@~zOF7`gqRvgLaa;_o#oN6H|RmAjiTPLI^e7-FRxr$UcPu~ z+0w<;6&21(XGOLXbk!@pot+ze-ky5jrf6$u4d&lC>ShfF^HVm_5FFZ_Haq&u6ao-qzpJ5eoY{H$?o1y9RZ3XxSty5jdAz;fMr_d%t9_JXX+E_ zn@-mpv6!z};&OBwGg)%jGyHi0F@Jeld@HfeoItstkgZk7;2BO>?X2wf20MHCqC|CJ zc6=g*;7-};OW!NkwyX|?diugGd^&rAYeJoUz5E{P4>GKIv!+jJ>yGH`%c3--l0FEya6A&oR3QH zpRGN2KAs$--9W%Vz(Bx2z(Bx2z(Bx2z(Bx2z(Bx2z(Bx2z(Bx2z(Bx2z(Bx2z(Bx2 zz(Bx2z(Bx2z(Bx2z(Bx2z(Bx2z(Bx2z(Bx2z(Bx2z(Bx2z(Bx2z(Bx2z(Bx2z(Bx2 zz(Bx2z(Bx2z(Bx2z(Bx2z(Bx2z(Bx2z(Bx2;F}{beeNaUOV;CmmAgcG2~#N85%I<7 z4M-h5%jm^CY<-07B5{I<*9}h;1KpzUR$oV7%qMo^wIIF-TNYr;qwK~_^iS&9wg}$a z(b*Pe&j_86(-9M+eji@t!`>C>%>>Nk#hVYV^94G>{Y%&Z!OV^?MPn?2cb|wIp+MLh z@v*JytDHpkJo*o};=Kj*&Y=+dsSxGwQDBb=>RY4sp#Q}-yw>3Ob@(%M1O2%Xf1Va0 zv!go@>SU*cXg6ebiV^-2A`$O^!OMn%VfIJxe(VSF;m!E7ua}ggy$rQVJt^D5pfMQ_CjXu%=skt9a5!$ZUy#OPID@FjV8v^tKX#|djF(+SCa?IOK? z2VpG24k#e1ucPt@w}yJ~rjGM8ic6?jCF}G>J0kvYEEExAf$(_kSCzrZ+VQ6kCLaNk zPoSz}TZA@*hj2eLO`w;1P^fIiiPvNE!^+ssaES@8?)XNBOQ#aN-bhDxWw{uN-U?Ik zIyLsjN9#|9cTADLe>k$NRAKmR|AThTl&=wBoU{DZgp@s(WK;;f%^H zFHWw$xS;rd@4Mj-{kF+dcgvQ+=kIhlf4*wv&vrK+pSEjXsP&b|!RD=RpO{_Kc+Fo` zeXyXpJJyWW^| zukicR9m_YxCJ*=D^!V2Nqow~7e7W}PRnI?n*FPTI82U|e(~$}9o;=xOYTB5Wy8Xr5 zZ@c?nUK(t??+4F**Z#KIiI=YWxA}iQ{NulVVcF)zpZ#LiTmMmf^M74b`uXDrCkjP3 F{U5m52X+7e literal 0 HcmV?d00001 diff --git a/data/meterpreter/x64_osx_stage b/data/meterpreter/x64_osx_stage index cb20b82afb30177957d533c3c17a92aa44ccf6db..39640cd5b8670767fc66f271140b5fe188441795 100755 GIT binary patch literal 33640 zcmeHQeQ;b?b$=_{@tQcS2u=~H+bH1?6znEi>mzbw!YYx>Q?j;YO9=u}o>$V^TCDxZ z?#f6;3^FTeC?b*NiDY9JllkC}Q}Pf$`ftYc5?WN4!>ov8;XC`_l_rG}~>BmxTR z?|1IqPpu4-^w0NT_uO;uIp?1HyXStqEAP!qKmFk^HX4R&onaU?_;~QitT&7kMm^!iKx#f?moUO{y&Q%E7c5i22Z@Gx*`^xhS&2K<<{zD1dP6kJl zOsS{Rp6_Nf21T#lp~}glImKtaF;Qe_Zy=G3ha!h{W~IH>7G>{!o0I_g(ubIpKCl;! zB#I7J+MBpv*>h_p^2C0v$F@fz9}PtY?NH=U6hf8urnJ4&+5q`VpGs}pc5ui(6c2=h zD!0;J!+Vu~SG5xP>-ooi&EjL*9qqmC_JjNO_Nd;fr{1Ao`vhdVpER4WZeQ(63i=QE^@u}sP( z*D&sYMkCV`hQYSDLF+*)pN0vAYYhtO@M$=17;gdfeG+LHyb z+Mr+RPhRfLNYvxA8J~Mb67hS6L;d#*jtvij=kx3M(2o~?cJUh{&oqDgnTdz~cJtr; z%a?Z`uO1&|6CSuWOIkJma?QI@#{SJe4QM&-a9ox?thWsxmMQ;l!?1T1eStqcV~J!i zeD?!)!>>@k(!LXf_G^zT-MchTyqw2Dz(K%4z(K%4z(K%4z(K%4z(K%4z(L^u4*~1= zwJUhnyF6)L(r>)e=gka~*7P}Zo)krAbrI8NblN|CQu6)NPfA{P$L)qOJ!w8kop~HW z*(;x*l}Ymya#H7|!0=3d4sV*-);m@=Zk#4H0`TH&Y&_$vdUyenPgc(X+|`(xjvQvhHh%(p%l}o zmp)oMuXs`uI$yPJ#-vWVt4>?6D3(5N3Y~3v9I#~{#oKgh8Q$>qnI@&0w7@q9`P^@n z=BG0CY?+c#)my2Ii+OY{lJ}l~2n5@td`c>xG=;94G-;fAQpvqi$$9CpXZcp1 zy&rz%i)m5BpDuLnU4pRKLI<-DP2k(S4kv(VundX%MXcW zY|rJ}(4H@9`)o&Un{>mfhF_rIh!$*P!+};K8&0p$ROVrz+=?R|`Y0kQ6dEXvEJa7% z77#F&RulsN^;Q(3ZS^8_UZ^S=rN=0#)9OOO*J??Xe^T+YEj#GoKWZH}W#ANPMbCuj zFFID#OZ&oIS|4;NfbK+YSzuT=>ni92NO5PjS>fk73U1ee2K@w( z%j)pScz)7+jY;~>G6d#9vOsT&qPqE7%vHsYZ8ZP)^bxWGL%yv=U!S1NpJ^FZ{i>?g z<(ZV=MUCQBR(r+j&!YOv#!EQ2FA6^_u4yQX=D$kw4{7sPVT1aLo)^YORt=W_2 zzk#kS)lV%^Kr)SKAq?pttBEb)7zCowi0=&5qXN`k%yRM zL#+YXMbuxp!7#j;_UTNg_k}`?>2h`mOW6X^JoQYpO1O9I!`DjM(w6zee#C~ znkN6euU33s7M1gQLd{3Zj50NQOKvNAWWC9-x!hrj1yIgoI*i=9N}+JU(7d8nt#$mB zm6h+USjS&5jCyn*a^OLww0O9|M_t%hMs<`DT5N{&Z`!IW6ir+1LV5$w?5Vs&Iy+M^ zBK))nD)^L=$}UM43}m$dk$@M%(*Pn)H%?_KWl0y57q#o8&-+}`43%D2l3tJ5cG6V& z80VkdR~ z&xlh9dblErsWz;`#fco*3Pi-x!;RmkCx9pBG+Pr}umrEg}>uXEZOW;Lld@ z^W?E|u^cY^r?|Uno_z9F;IM6zYVm1pLQx&k7{{ziHHi`AdDiy{ZZs$Fhv6#I+&P-O zibyAjr?g2$SDRer(6_1m$69+%YpaO~dwlR%B&I+(&5e`du?AGyx=$hLne1mSuokce zW<=6Tua~`MOdD0k&zp*`=t#srD{Ci;Xgf@?GVGAiCZ=*z)i)GVbpP8MRpW;sNG}xq z6&n9lYJWj%AJp24R%)a9k3oPBo6mHy`76vVX}*-|=68$PRk;5VtG+{5ZRx5NJ#Q+V za}wif@$*%;@@ZQ6jvhd5+KQssnS)$SF`l^s+? zdx+Z4YVA6$t!QyRVXU+6;$+#tp*!u)y&}E3%BKLW4$KrX#XEQ}Q+wv7!m17Uc%xSBN;$50N-gY6Q+@Gp$WSmB9?b?JkqUd>( zI!e0{61lHQC#-t0^wY#vG0|a;TB&h!w94!FH>)du7ym#a`#m;&y2Ff7IaWpaiR#K< zr}CGz@(`7Wswnq~GT?-Z&l@iZvPfR`ZFaN0*jXI}m2UO175S|(W{flBXM4?qD+`=` zCTk&w__~B_7&US~7d^H*J#HQZ-h19=7|&or6xceU00_#a z&@{pVH=$dBGN6GXD&M-YfRG~!ut;JZzjOuU;-R}ew@p$5rpC=>YdUEzc{5hpZ!UYD z-IV%?G1X!Ihi6j$Q4DM$6E^+k5(;sEbuz=^&)`!yg}GhVx~vYGph6#(^4wDHi?XEB z)Kl8jQ=9I(a&gW|U2C8Zb#P$|&IOks_X)VQv%{?Oq&}q0*0G(~IE|a`XIIdp*(dPt zNv!Ghrj^=d)_6|TYdQDvHoiD}PT-wbP;d)W+@~AxXN$ECW|>u&o1;SjjH)79Z>26Z zT*P^&j6k?FN?2mnbT4`mf<6&MqA#E5mIUl#F!9I@prd#@bCJ27h>hOYUh7HaqsU6N z!P&fT7BzgiPeNQeEYMa|fx>m%B?0 zD8Ug5-kKN0x*-*bV7G)@@k`YNkF9jqdfAmSgwP5uy&$=F6E8JNCJ}9cUON<6x)ZS9iiLjoPo?hpW_V<6y5>yuf8^r{lKcB~CB z^GreYDYfov-|R^xb!|}en{C!WFFO3f_tBb{)0?!WiXkhFj?KD$t`U5f)`N(%) z3X5#(Vm^AYvS$0wu zb5A~AM0Gj$fYw;@zA*iw^%?~c@r#sRTrEx1>FN?I&sy8)Ih|r2>qIDA!??lfz^__X z3;;3bqQ@Q+e~?h)1__HfpdC^&fCPJP$dW;G4C9<;F^ysu>_=I?W8BuXpV5I1Lfvf? zYP2q7@3&HmE*TR1hjQ?L7yRFVWbQVang>RFHd^nXya?7R!N&~Gr$q2o@N}V;lcBPD zAFOUfH5ktA^;UX+gOxspD0;lndRp0|LAvAm2Pp2Ee(`C}!0q!l!*;ufSU4g;mMk?F zXcn;eIe%M?)-y#Ly|nRiy4TzVLJ3Qa_jIhyT9-7tq1a}*o(I`A{akiXJf*GlsLx7w zTbLK#gt3^t?`J&RM-zyR3@&_i!Rs-2jm1SdiSO-r^FgPmKz$~*+k1uJ!7g?=N__y)O6dw5k9;m-?x^Xg~dgv88qR_Zxq zA=0MYIietzu^t@1Ci{TtpHRNBaOQ)(XE%Fs`Xz=_gN46BSrQ=V6nzfl6CNi>Le)7? zo04gOjE@6Zy=rKBnZ07jYD=-p#WNs^sWYH<#Mv17>T!hGj8dPy#e*?~PKD5_b04k% zoF0q4-N=2mdI`}Ke7*RUr~7db^nG;@^rB(Zqm{_vuAEXO(&GK`3$g=6wtBnJ^fJ9c zV=OqkA6>4qr}qPKoj!iS&<1NsaVDI%ApG=OD5=m>S}MCFU9{lV7DNPU!qWl{OITFM zQrc2n)D}M=Li&6=4}$V(9t7pnJP69Cc@T6`)uQwAASoL>2r3MOo=q4CJC@Zz0REFE zCq{O(R9rX(TGF{fi_xHj@hT+^Ij3KG_SfgVQM-OoT73fK6D4&5B+-Z3v$`H#COsl$ z#S@@KEg}>uS2QoG;1??RtK_kvWH|<#ypLgIHI$(65l#o&UsEVx#9$vuC7_@v!WwU8 ztcVQ~U0;3S0BD!UmRk(c;8X zf6jn#@BVpGJly{>%>xiN)-yRk4igyKI*B!kA}5tddi??|&51zqEl=?!{Wv=#wYATq zuh4jyVGW%AR4VsrJt39C`8BL6*?<0VN#mz0%OV4u~#rQ zOJm7WV-`j5MPoRqLa!AfwxIPCwzt{)OSOE|!dEG{m393!>vETBVV;*gMSl1TT*yKw zF;wLU8d9$_a01Ksb>N! zXokk-nZ>aN7w`(DUFd}i@F>ID=jrzuuJfm9>=ae!s5-^cGgLcGwNn;0D06;%P3`e! z_IO`V-k#-l@hrAmGB%OEQsep5`%$0gSu`)T?Dd?$365|tr6`>(qSMlJlqi+4jzV`=5RO=>+C)n4uwMD z5?ycWLnDb~SEM%-4*H{k!C<^O95@o}Jg~RN_ULW78Au$l6T#s__I2Cs^?o#z z96As@9KtWWihvf~?R>=B)DO!?>{v7uNe1J)j}lt1-O?V92gbUHvg)Q*Wu+6(>#4G` z4_|k^YXw|eI2Mm45xWv}#!+vp@4by5{+Kjl-ysdbdp`UzmHPPp{U2{L+DlrZo9S&H zMpSkLW5LKEyRY+r*V_>a9F9a2$)!S0u33=CB z1A~L_4+f5O1P>*8qkAy^)^NA1GB|(zN;Km6TD*Z+Y!9?fLHA8G?BA9$6*6V+?WWZOBzBQG-O`*s@$MAvRp$DUwi#cT!V{vV* zM%6=aFq+FDYif&+M7koOWGFBk!nB`wAeu}@!;i$eher~R#6B8`5BfuqBWt5sEtYmP zazdn^Fes4+T#r!G;T^sw{jPT zry}g`)j7x;j+tjO zTaERxTa9&%w;MGRw;QgrcNhjyprwK8SexL?32nTU!HwW_3}!2hj$Qg5O5H1 z5O5H15O5H15O5H15O5H15O5H15O5H15O5H15O5H15O5H15O5H15O5H15O5H15O5H1 z5O5H15O5H15O5H15O5H15O5H15O5H15O5H15O5H15O5H15O5H15O5H15O5H15O5H1 z5O5H15O5H15O5H15cuT?yycF%Slxd7x5a%nudRwk2I9da?~EEa@&Ke8g>16PcnDM8sLD(5c+KEsQ zmmeAbZMoj>BMLZe|55&fH7=P|sXJl~oX-zVY+hXj2XgCaTiZ@+;f;E0mwc zHMr||OHT3A2fiY=^*Wp3&|OV3}x z=gqhfA@*){@4$9E}@i|gd6$F&}-V*>Yvly<%?!J#@$rB#orwC+{h#l?F>!a6wYd?eY4 z^6;>6=Nd0ZLtnCo3+x&ly+&BWnL$_{>9=`d5yIF;JK%t=F7OIPjz*8*Zj&mR_6}w% YvB6+sARdY(qj5VKj;)n{cT6SfgoL15OvtxwV>hRP&&w zX}94taGGYQ?f2Th+}^R5t+j`vmRyyhp37h~&Cd3&&RP~B@2_ps6ul13)=3W2%*KYY ztjVKZpZ~WJ47zUlE!j^R;Z%;b+GvHKzDOpUj`tr{jrIBt_@utOuaOL-s}EvUeL!Eb zKT~nAUf<{=QlC=^ktX(6J4|z+|LJ&t)QtD{B*9d#Z&K--Q3^=c`&6ylG-JJHPdc24 z$<}&(O<$D$T~hn|?dtk0 z+^DbGFEu>SB#)KjQ0t%5Fa1Ly4${^7RCBqg%!A;rJ&(5scF8C;W>Zc6g67eyl(A3r zi&jnh93+}qAJsI*;za2|S${N*N?aSz(TKBYOw(>e>Hj9`P`Cm05KbPj{|Q%8~L-r=6^r?Lg63(>e{b< zumx=%oI~_!aL46OOxaQonml%HFGJ;$2Id#@Ll1d|z>4LeKJR3mmyKdJ0t|cUtddiLOJci}fy5 z59W@G_F(SMMO(20Uoqt-^iImWiZ5Z!<>#p7m~NnD{EX<(ToZqRZ&!*3ev@4jdNY~x zss!DnXqI{7b_nZIn1$v#dNZ!%7yXlOK$T*#8jbuh*}2c1yJR@#X{51QX{Zr?Z<0z` ztWY{9m9o!L3Y{c#ZyAmSDs-|BP*`77k&kuo(NFMgUvP~-uY8p;9urdeeT`+emSD)p zpV37*)tUo*#k1D}swMcuuaT%$n92*R{7_x;R=2P7kg^<7P8jQ;SG3Zl(xK($Wh)MX zBfz-NK`9^l*(J&~6FLpBT^RbjFmy%?-dTP_Rs37{W_43cuvZ59UV*jHg~4Vg!r(Vs zDz)fU=?D1AkTDC{{Bdb|s`W1sZt>?z{~~dL3YMDdkLFsIPdZ#j`5k)cEH0Hy!dG#^ zf1zw0eKc|xq_5ZD>p08TlK<*_@6sO?@~<1y68`*Pm6(2fD`NUgRZOLO#89jV{t_8K zP>vKCJP<1|c>0ZS*@lTT1PJJ(V38@oKS*GcEd5RcEQ`x!6h`rNCZk&rY-dC%@%cCU zjGlSbBg^BGo@x!zrEcXCCj{MKSvMX>=ppP2@!AoXsI~xUvS1kN6XNgjy*I(DbKv4F zaNs?qf`&`aDDdhSucN24igA{n0=!f7RJgW6@qbY9q~f0;KiofrWWAtW#9xw-lC5V% zt1)$2Xfvjc>)!|W^1}HE{d-hTJJV%5$J7w)avI~W7Wmzqdv+y!mxlIA|DKp&&Zz^JVq|7H^P*W@6;PD41o{+)ByP0$;p?0_(@R2gMvXA zbg~3Z!$GXam#Gjq&A}jS&!fOWoPHpy=sm43pw2iivjk33>bPD|G_|t7sOULGFDlx? zZAsDds$XM?u;$Pn%w1$KfXCei^x(lPT6qu%VF9boxq`#kAiG53itZK3%0H1Peinbz zL7tOJg)GnLLo^Bu2?>KC-W)FEBRLVqjMD1o@ST9#*| z;8bf97-c?BudeBOFcim>l1ZgRmS=RzNa+GRD+w%D-n0IdE6*cJ#VA!^m1DWeZSP0W zv&tCOMd8#c!e0@>a)~>yT`aG5{*6v}YFr5D zy>yxFi^`6eQy88u>YnP{>2LiFP5V2n zt^&V+eu!=zTE(q5gbag*;2{VOVrCNafZj!!u2p2@PzLlAWx6T@MBF)0tBCwQT1z+) zM^mYTqT{DD%FT!xQ9=;LH!m+B_Xq?uvM|Qp z7((&7>kcR%(U-U~EPCgRd{AFbyJ&Mmc=HqSBb(DXm zML{P8J*Cfp1hpx5&R7$qHe5>Ip>x2F!h+djjK9(Jde8lqZ>~H1fbNQzcW`ltu%(O~ zQmza=D_ue!m5`-q$XMs0PS_^HX12rpW&%F+V4K@DKF@A68RI^4olybos z61iBpNL%pP$nRUL-V5L|BN?A_K=bC(-NaB%hzYD&7|s#oq-%nIZpL~DSU3L1xM+#yxi^!`hwYk6O8s9@s zM7l^k3ak~Z>}EQPhVh||*HqG{K+YvA*{{fChj>t5EPYoc`w~Qj>=MieP^En)c9FwX z#Bf=;BkV4fc35tB-^7dKhh)SID3H6blAG8|rvXpVxR0LGDYnrf=hF%D;E_Tsn0R=Q z^XrU0igpa&2nwsgZE9i-e1~}YgL_qO%QOJrJ^%_@B04!SYAb{bDmWRtp5JFvusFu2^Zx*QWSZ~}(2{E_al5s?HJueuy3&T?3 zgT`IFyTC?}nbu_Fhdr1)oS^T*K=H4CwY=Q!oeN-Sz~iSMxO9>+jq@8$l+C+dl}4A> z2k(T}LC4zx@I4vGz1B91RUFs_bq`du&E5oG+61?8VXclXb&v8wt$c_?B<|ur zeT0PoH8DAHsfj78`-H}~a1Aam;5ssX&VevS;Ad1$muTr8tX`NJOpmJj1BQD^+^^_w zQRETr6j&1}dYLsOuPGZ!&Mi!+!3+#YabC><@a3vDZ9g#dx&vihqIbKzr&5bg8=nuPcVPb7tFsX`2bC`k^3;1dnY(`^Fvt5 z2~krp_d}5(!Q4M1DPV?EM<_(e-FVG_V7pY-*jQp-f1}b=Rk0IglnGbD_ozqz0^D;Nf zDb);CLFcX`r=MMUyv3HAr3S%L(I8$1pg}Z)RnSs{jMr+C(xST}E&PBnmgn0XFlg1+ zRMpoyD(&k!NBE zr3IkHEZ*vo#n@DE6DCIEaaqrgviir@RCL}8Bn@LHBw z-Nd?y&o*d?0SQ^d6L6hvd#+7PZTxIvh0dQ)=i^G}tkNmVvQE6ivqQds*ShpR#WyPP zQx*M4T4d!68t`$+Nfdm|c#$OzKBu#8JSdTLO+-i`n1bj%CVTU1=ZW>S>XX{lEwE}N z5jbxa(puXrMhM|U7cFp^l(o{g)G`J3GN9k3_j^8&fKDnqvMdK*2WVOLBxP?>vZG2? zmMdh-cWB&#M=DXjqofKfaqk^5M9AWGs21iIXzZn5&`~}?VQg{1+aYh52kWB!*U2M_(;Zj zf*X;yq><9C09rKGJCmfo!hgvi4EEwu)^}PgkmbZJ<1D0JR#JXS;bKYEr+ZoI8?=>G zQa(!IVyyxd%#bE>aT87Znv7fn?xtPHp{iG!>B{>b-%N^l*lS>g!=_Pnk{t}f zFR09WXb-yQsBD&foD;$YC#}PUPPhPrbIguevYn*B43(YW6M=|jl1`r_%M6)MP;8nv zxXIn#x!vA3rMIW}xOxhYc4Bg(KHuPa{vhnR&IWXReBgB*<-0GbOXEx1TvK?x^mY(6w~8L!!P27V)TC6cunUNo)bA zf*)-KMt4~Tg5g2e>*Ze%WyDW*_+ujemPq|@$K133(R3`FjqUCJYAll78SjhjN`w!` zcBYew-LXV6J&d1|eR)qSMOs=92T-(EwRpEZHjv5g>hFvvV!>oM8cVk%!bf859eehh z-Yp#i{aJME&q9BD=y9oKt9R?}aHMx{TYtE3_?cK59g&X5!M{xy53~<=cXwxDBNI=g z`eJ4@g`WgwdxX))g&*}Aws^x**Z$byM65rX35JK01KIYD;f`+2988$uzP@AxK4@kF zmd$K9bHvQV`g+VyjKu4GI-c$Ah#ijOSA0~GsF8M$y6*VU{ALrY0LQ5 z;jl&FkWGgpm}Q?Dfm$_NeCb#>e#p8zp2^_nwmbX6(uv_jcd`$Wd$Zk}ceKAe@eeyZd69_Q9({ussvYK9TAS z9{7YQc~xQW)_8v;(AN>`c{GW&iIcjLGFO*smZ*Q~tg8iQt1ms!zpFojEL4aWPAtd85D4^vt!V$oP-8QZfzm`olSNbMIRwyS@4GCI&F zmbZAnh9zB%#NHmsz$ThdY+O{zznrc5(J}8ryy>#Mop%`=)g}A*ThSJjJP-PC!NK|( zoE!1qL*iGf+J?{u?YhDS?b^|enzL|&w*HVyyJo?KpO4?9tsT8dTNAoXYnZuBb1dMm zC-B(47XLS#5as5EAyIB>=tAie^_yV&nubPE4>gE8E$lg->ChZQZijp0dgnBprmsAW z5+22Hd<*sJgMAO-oV_CZpRMjho&8VZZ2Xz*Ppr~Eg0>Uy%YOJ-b5Q<8obz}u;IX%+ zSL#25wx%W7zq78tp7g5*{}<$#)b|^zVH195&M~tO8vz>u8vz>u8vz>u8vz>u8vz>u z8vz>u8vz>u8vz>u8vz>u8vz>u8vz>u8vz>u8vz>u8vz>u8vz>u8vz>u8vz>u8vz>u z8vz>u8vz>u8vz>u8vz>u8vz>u8vz>u8vz>u8vz>u8vz>u8vz>u8vz>u8vz>u8vz@E z|33mZey%aqxDWrfxZmWqJjwn@I+o?`IgukfxWkOLFRgJ`FwJ3NBZX_sM6VeeibV#p zF|!w2XvEUmj)b-|qkW}^|46;|Y#Mu9M4w1$FFB&n6Ukynof!6{(SGdUP7Yc_7@I{L zh$SMa;Vs(Bjy2jG_8Dl%Vz-^cW+a(Nh0`%@P;O0QYTrlyG<;jb9dwe~A3HK)>j~{o z9M~BM{{Z+5`e!<@4aD4jTxPm>`4Y*epfl2&NJh0EIx@Y`88y>lOC1w?pkUXW{*?AF z)SUoxftTqNo#Qe0g@s$D9W#!?+EGX96fO(bhfcxuH_>+kHau|uuH5(FT}975An6ZC zV>>CQU((lumvob&8NJKl##Q#;B4|x3VDl#Kqi~m^J=lzwG`EIyq2jq$(hnzlGbvdH4u0|F6Byl5=gh~$6$|N&Wn;s_il;YM!7)y?DnY_wCUnQ;K zOca_2x=n6MgETe~2OKcvzDn`_!Q>HaZn8?FxrNP=EgH*2((zO_nKrYD)YaPW-|~6w F{{TorsHy+} diff --git a/data/templates/template_aarch64_darwin.bin b/data/templates/template_aarch64_darwin.bin index 7b9b008d23eb050f1f128d3f7b3847f733cb35ae..fe4ddfe32b43fe8b2365fc2ab2af184b7b4e5653 100755 GIT binary patch delta 1230 zcmZWoZD?C%6h8O8H#Vj1OxAX-boM6e*s>{GTe3>GX+mMN6-U?F>7AhOZayU2lI@zL zbhWJsimN{=_Vz8a^UuNrp<{!M{;G&ey0KP4HpdLiAEOn91ra;MVg@yylcYoNz~MaS zIUn!2hjXXL z*E~gXdyxZ8v`Eg*SbV_8L&2~Sj3Uo@{~@ivlz?WWRCBOIkx!346$O$7EV`uy$tvvZ z1!+aR%nsCTWN{wWd2A@+I}_$cJSsfwIcNPwIo8S>7;PDXSkYL~KJAOX1AU4gLF+|J^H6*`4e$)%4B!S1%c`VMPs`uP zmzllQA|<=J@4C<3UyrrFG%@n*<&MDzU$$a_1GTVps6bFzz{TMg*lvv3P&dSd!_i}l z!mgRJ)>J0j6ZxC)K6V4EvOMb0B%L*dsBwq83gWhBQxzSt8(q?4 zV%gI;dqLs*XH&{0OYKzYE>k6Yh3xEKiQhaSdlS4)UF_b#P&mK~_w74zI)L}x8-)po zVT5xY2}b(fxb(?rUpt?{m{pJ$YD}#@nP{k~Tn6 zgB+d=vjM|@ffWwdKwc|E0jdBphJ!&R4zQ!cTVg?q2O~yU#|d>k>JPQKc|ea2o;VG@ z-Mym^n%HNFaqWAzzH9Z?+7Cy+xv6Rc2j6b|*z?7$Y>Re>AMbg8v^M)t zRFD7s>T4HM7f*hjb@hE({-&6mKQ3D59gffEZ^Ww3T}bJ!kp@?y+xctz$L}qDFy7L0 w{p{G~e6vQ0+jGmHy1IPlAGM0);en$)FK&Bx@bQAx8ve?1b$IRDw`k^n0c2Y~82|tP delta 1085 zcmYjQZ%7nT5TD(5dsVkU>M~WZBGj#uG}1*}0&V5G zxmYUksaz91&1X{^Z=iEYB5mQrr;3(Ps7!N&c)E|Q$;<$dBbir41(ziuTSi+%n=y(- z^r-*>t~M{g8X6=Pj$n;BLM+-wWkWR0Hzeoo`qFj(on()?7W2KjvcK!eVob0iw7UUb zl9)7|pby|TpMqcQaLoot#>3fRe(E(?c;ccXhO{JA1qesyLIewDOqk3=Fk40jv3y64 zP?tsXg-=KS^nx!~$$Nsepxo=VbYjE+H(EQe1LT7FP*Y$4d8U9qD?sDWGzg4N69eG_ z+^Pm}AW<{R!5Nr`(4PR%j!<~aA0ZGRAUDjwykQ~+*nTV4j6$2$7!AW(VIsBLg%zv@ ztJTu$>p7^PuqjRoYxbmQx@gqL9&)lg4iDnu z5jZWH?zQCUdz=$15od9c(|yprv!dMXEOJXOcNwGi*hC5$Hle-&Wk zvRY(38|Jpb9ZKlS3f ztt7WB;=}o`f~PYsCpzt;_fd79ulZW?f z(baSEM&r^Q$9%c;?#WZ|_)={$3rcGBO`M;#`9x7f)^bn(ovYclA1}je&MC!b>K*G+ Kj=XT_?EeA|&>PYK diff --git a/external/source/shellcode/osx/aarch64/stage_mettle.s b/external/source/shellcode/osx/aarch64/stage_mettle.s index 203bbe57bd..b3c7d05f04 100644 --- a/external/source/shellcode/osx/aarch64/stage_mettle.s +++ b/external/source/shellcode/osx/aarch64/stage_mettle.s @@ -1,5 +1,5 @@ // Compile: clang stage_mettle.s -// Shellcode: objdump -d a.out | cut -d ' ' -f 2-5 | grep -Ev ':|o|^$' | rev | awk '{print "0x"$1$2$3$4","}' +// Shellcode: objdump -d a.out | cut -d ' ' -f 2-5 | cut -d ' ' -f 2- | ruby tools/payloads/format_aarch64.rb .equ SYS_RECVFROM, 0x200001d .equ SYS_MPROTECT, 0x200004a .equ SYS_MMAP, 0x20000c5 @@ -72,7 +72,7 @@ _main: ldr x10, [x10] mov x12, x11 mov x15, x0 - + /* make stack space */ /* mmap(addr=0, length=0x40000, prot=3 (PROT_READ | PROT_WRITE), flags=0x1002 (MAP_PRIVATE | MAP_ANON), fd=0, offset=0) */ mov x0, xzr diff --git a/external/source/shellcode/osx/stager/.gitignore b/external/source/shellcode/osx/stager/.gitignore new file mode 100644 index 0000000000..1d086c3bd3 --- /dev/null +++ b/external/source/shellcode/osx/stager/.gitignore @@ -0,0 +1,4 @@ +x64_osx_stage +x64_osx_stage_debug +aarch64_osx_stage +aarch64_osx_stage_debug diff --git a/external/source/shellcode/osx/template/.gitignore b/external/source/shellcode/osx/template/.gitignore new file mode 100644 index 0000000000..8377e15bc3 --- /dev/null +++ b/external/source/shellcode/osx/template/.gitignore @@ -0,0 +1 @@ +template_aarch64_darwin diff --git a/external/source/shellcode/osx/template/Makefile b/external/source/shellcode/osx/template/Makefile index aabb8e5419..3283781d93 100644 --- a/external/source/shellcode/osx/template/Makefile +++ b/external/source/shellcode/osx/template/Makefile @@ -1,4 +1,20 @@ .PHONY: templates +CFLAGS=-fno-stack-protector -fomit-frame-pointer -fno-exceptions -fPIC -Os -O0 +GCC_BIN_OSX=`xcrun --sdk macosx -f gcc` +GCC_BASE_OSX=$(GCC_BIN_OSX) $(CFLAGS) +GCC_OSX_X64=$(GCC_BASE_OSX) -arch x86_64 +GCC_OSX_AARCH64=$(GCC_BASE_OSX) -arch arm64 + +all: templates + +template_aarch64_darwin: template_aarch64_darwin.c + $(GCC_OSX_AARCH64) -o $@ $^ + strip $@ + templates: template_aarch64_darwin - strip $^ - cp $^ ../../../../../data/$@/$^.bin + +install: templates + cp template_aarch64_darwin ../../../../../data/templates/template_aarch64_darwin.bin + +clean: + rm -f template_aarch64_darwin