commit 21450dca414687c616836502201ac88f7d43d1ee Author: Neo Anderson Date: Thu Apr 2 07:31:48 2020 -0700 Blackbox testing tools diff --git a/.gitattributes b/.gitattributes new file mode 100644 index 0000000..1ff0c42 --- /dev/null +++ b/.gitattributes @@ -0,0 +1,63 @@ +############################################################################### +# Set default behavior to automatically normalize line endings. +############################################################################### +* text=auto + +############################################################################### +# Set default behavior for command prompt diff. +# +# This is need for earlier builds of msysgit that does not have it on by +# default for csharp files. +# Note: This is only used by command line +############################################################################### +#*.cs diff=csharp + +############################################################################### +# Set the merge driver for project and solution files +# +# Merging from the command prompt will add diff markers to the files if there +# are conflicts (Merging from VS is not affected by the settings below, in VS +# the diff markers are never inserted). Diff markers may cause the following +# file extensions to fail to load in VS. An alternative would be to treat +# these files as binary and thus will always conflict and require user +# intervention with every merge. To do so, just uncomment the entries below +############################################################################### +#*.sln merge=binary +#*.csproj merge=binary +#*.vbproj merge=binary +#*.vcxproj merge=binary +#*.vcproj merge=binary +#*.dbproj merge=binary +#*.fsproj merge=binary +#*.lsproj merge=binary +#*.wixproj merge=binary +#*.modelproj merge=binary +#*.sqlproj merge=binary +#*.wwaproj merge=binary + +############################################################################### +# behavior for image files +# +# image files are treated as binary by default. +############################################################################### +#*.jpg binary +#*.png binary +#*.gif binary + +############################################################################### +# diff behavior for common document formats +# +# Convert binary document formats to text before diffing them. This feature +# is only available from the command line. Turn it on by uncommenting the +# entries below. +############################################################################### +#*.doc diff=astextplain +#*.DOC diff=astextplain +#*.docx diff=astextplain +#*.DOCX diff=astextplain +#*.dot diff=astextplain +#*.DOT diff=astextplain +#*.pdf diff=astextplain +#*.PDF diff=astextplain +#*.rtf diff=astextplain +#*.RTF diff=astextplain diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..48bf02b --- /dev/null +++ b/.gitignore @@ -0,0 +1,352 @@ +## Ignore Visual Studio temporary files, build results, and +## files generated by popular Visual Studio add-ons. +## +## Get latest from https://github.com/github/gitignore/blob/master/VisualStudio.gitignore + +# User-specific files +*.rsuser +*.suo +*.user +*.userosscache +*.sln.docstates + +# User-specific files (MonoDevelop/Xamarin Studio) +*.userprefs + +# Mono auto generated files +mono_crash.* + +# Build results +[Dd]ebug/ +[Dd]ebugPublic/ +[Rr]elease/ +[Rr]eleases/ +x64/ +x86/ +[Aa][Rr][Mm]/ +[Aa][Rr][Mm]64/ +bld/ +[Bb]in/ +[Oo]bj/ +[Ll]og/ +[Ll]ogs/ + +# Visual Studio 2015/2017 cache/options directory +.vs/ +# Uncomment if you have tasks that create the project's static files in wwwroot +#wwwroot/ + +# Visual Studio 2017 auto generated files +Generated\ Files/ + +# MSTest test Results +[Tt]est[Rr]esult*/ +[Bb]uild[Ll]og.* + +# NUnit +*.VisualState.xml +TestResult.xml +nunit-*.xml + +# Build Results of an ATL Project +[Dd]ebugPS/ +[Rr]eleasePS/ +dlldata.c + +# Benchmark Results +BenchmarkDotNet.Artifacts/ + +# .NET Core +project.lock.json +project.fragment.lock.json +artifacts/ + +# StyleCop +StyleCopReport.xml + +# Files built by Visual Studio +*_i.c +*_p.c +*_h.h +*.ilk +*.meta +*.obj +*.iobj +*.pch +*.pdb +*.ipdb +*.pgc +*.pgd +*.rsp +*.sbr +*.tlb +*.tli +*.tlh +*.tmp +*.tmp_proj +*_wpftmp.csproj +*.log +*.vspscc +*.vssscc +.builds +*.pidb +*.svclog +*.scc + +# Chutzpah Test files +_Chutzpah* + +# Visual C++ cache files +ipch/ +*.aps +*.ncb +*.opendb +*.opensdf +*.sdf +*.cachefile +*.VC.db +*.VC.VC.opendb + +# Visual Studio profiler +*.psess +*.vsp +*.vspx +*.sap + +# Visual Studio Trace Files +*.e2e + +# TFS 2012 Local Workspace +$tf/ + +# Guidance Automation Toolkit +*.gpState + +# ReSharper is a .NET coding add-in +_ReSharper*/ +*.[Rr]e[Ss]harper +*.DotSettings.user + +# TeamCity is a build add-in +_TeamCity* + +# DotCover is a Code Coverage Tool +*.dotCover + +# AxoCover is a Code Coverage Tool +.axoCover/* +!.axoCover/settings.json + +# Visual Studio code coverage results +*.coverage +*.coveragexml + +# NCrunch +_NCrunch_* +.*crunch*.local.xml +nCrunchTemp_* + +# MightyMoose +*.mm.* +AutoTest.Net/ + +# Web workbench (sass) +.sass-cache/ + +# Installshield output folder +[Ee]xpress/ + +# DocProject is a documentation generator add-in +DocProject/buildhelp/ +DocProject/Help/*.HxT +DocProject/Help/*.HxC +DocProject/Help/*.hhc +DocProject/Help/*.hhk +DocProject/Help/*.hhp +DocProject/Help/Html2 +DocProject/Help/html + +# Click-Once directory +publish/ + +# Publish Web Output +*.[Pp]ublish.xml +*.azurePubxml +# Note: Comment the next line if you want to checkin your web deploy settings, +# but database connection strings (with potential passwords) will be unencrypted +*.pubxml +*.publishproj + +# Microsoft Azure Web App publish settings. Comment the next line if you want to +# checkin your Azure Web App publish settings, but sensitive information contained +# in these scripts will be unencrypted +PublishScripts/ + +# NuGet Packages +*.nupkg +# NuGet Symbol Packages +*.snupkg +# The packages folder can be ignored because of Package Restore +**/[Pp]ackages/* +# except build/, which is used as an MSBuild target. +!**/[Pp]ackages/build/ +# Uncomment if necessary however generally it will be regenerated when needed +#!**/[Pp]ackages/repositories.config +# NuGet v3's project.json files produces more ignorable files +*.nuget.props +*.nuget.targets + +# Microsoft Azure Build Output +csx/ +*.build.csdef + +# Microsoft Azure Emulator +ecf/ +rcf/ + +# Windows Store app package directories and files +AppPackages/ +BundleArtifacts/ +Package.StoreAssociation.xml +_pkginfo.txt +*.appx +*.appxbundle +*.appxupload + +# Visual Studio cache files +# files ending in .cache can be ignored +*.[Cc]ache +# but keep track of directories ending in .cache +!?*.[Cc]ache/ + +# Others +ClientBin/ +~$* +*~ +*.dbmdl +*.dbproj.schemaview +*.jfm +*.pfx +*.publishsettings +orleans.codegen.cs + +# Including strong name files can present a security risk +# (https://github.com/github/gitignore/pull/2483#issue-259490424) +#*.snk + +# Since there are multiple workflows, uncomment next line to ignore bower_components +# (https://github.com/github/gitignore/pull/1529#issuecomment-104372622) +#bower_components/ + +# RIA/Silverlight projects +Generated_Code/ + +# Backup & report files from converting an old project file +# to a newer Visual Studio version. Backup files are not needed, +# because we have git ;-) +_UpgradeReport_Files/ +Backup*/ +UpgradeLog*.XML +UpgradeLog*.htm +ServiceFabricBackup/ +*.rptproj.bak + +# SQL Server files +*.mdf +*.ldf +*.ndf + +# Business Intelligence projects +*.rdl.data +*.bim.layout +*.bim_*.settings +*.rptproj.rsuser +*- [Bb]ackup.rdl +*- [Bb]ackup ([0-9]).rdl +*- [Bb]ackup ([0-9][0-9]).rdl + +# Microsoft Fakes +FakesAssemblies/ + +# GhostDoc plugin setting file +*.GhostDoc.xml + +# Node.js Tools for Visual Studio +.ntvs_analysis.dat +node_modules/ + +# Visual Studio 6 build log +*.plg + +# Visual Studio 6 workspace options file +*.opt + +# Visual Studio 6 auto-generated workspace file (contains which files were open etc.) +*.vbw + +# Visual Studio LightSwitch build output +**/*.HTMLClient/GeneratedArtifacts +**/*.DesktopClient/GeneratedArtifacts +**/*.DesktopClient/ModelManifest.xml +**/*.Server/GeneratedArtifacts +**/*.Server/ModelManifest.xml +_Pvt_Extensions + +# Paket dependency manager +.paket/paket.exe +paket-files/ + +# FAKE - F# Make +.fake/ + +# CodeRush personal settings +.cr/personal + +# Python Tools for Visual Studio (PTVS) +__pycache__/ +*.pyc + +# Cake - Uncomment if you are using it +# tools/** +# !tools/packages.config + +# Tabs Studio +*.tss + +# Telerik's JustMock configuration file +*.jmconfig + +# BizTalk build output +*.btp.cs +*.btm.cs +*.odx.cs +*.xsd.cs + +# OpenCover UI analysis results +OpenCover/ + +# Azure Stream Analytics local run output +ASALocalRun/ + +# MSBuild Binary and Structured Log +*.binlog + +# NVidia Nsight GPU debugger configuration file +*.nvuser + +# MFractors (Xamarin productivity tool) working folder +.mfractor/ + +# Local History for Visual Studio +.localhistory/ + +# BeatPulse healthcheck temp database +healthchecksdb + +# Backup folder for Package Reference Convert tool in Visual Studio 2017 +MigrationBackup/ + +# Ionide (cross platform F# VS Code tools) working folder +.ionide/ + +cpp/test \ No newline at end of file diff --git a/README.md b/README.md new file mode 100644 index 0000000..8a3f626 --- /dev/null +++ b/README.md @@ -0,0 +1,2 @@ +# Longhorn-TN3270 +Generates keys for an aptly named 3270 terminal emulator diff --git a/cpp/licensegen.cpp b/cpp/licensegen.cpp new file mode 100644 index 0000000..01dc5ab --- /dev/null +++ b/cpp/licensegen.cpp @@ -0,0 +1,40 @@ +#include +#include +#include +#pragma GCC diagnostic ignored "-Wwrite-strings" + +int LicenseCalc(char *sInput); +int strtoupper(char *sInput); +char input [40]; + +int main () +{ + while(true) { + printf("Please enter a User Name or ^C to cancel:\n >"); + fgets(input, 40, stdin); + strtoupper(input); + + if ((strlen(input) > 0) && (input[strlen(input) - 1] == '\n')) + input[strlen(input) - 1] = '\0'; + + int license = LicenseCalc(input); + printf("Input: %s\tLicense: %05u\tHex: 0x%x\n", input, license, license); + } + return 0; +} + +int LicenseCalc(char *sInput) +{ + int salt = 0x5217; + for (int i = 0; i < strlen(sInput); i++) { + salt += sInput[i] * 0xa3; + } + return salt & 0xffff; +} + +int strtoupper(char *input) +{ + for (int i = 0; input[i] != 0; i++) { + input[i] = toupper(input[i]); + } +} \ No newline at end of file diff --git a/frida/licensegen.py b/frida/licensegen.py new file mode 100644 index 0000000..14d4b1e --- /dev/null +++ b/frida/licensegen.py @@ -0,0 +1,75 @@ +############################################################################### +# Generate keys based on black box discovery +############################################################################### + +import frida +import sys + +def on_message(message, data): + print("[on_message] message:", message, "data:", data) + +# vistatn3270!LicenceCalc@00432CF0 +# vistatn3270!SanitizeString@00430830 + +session = frida.attach("vistatn3270.exe") + +script = session.create_script(""" + +var santitizeString = new NativeFunction(ptr(0x00430830), 'int', ['pointer']); +var strToUpper = new NativeFunction(ptr(0x0044F046), 'void', ['pointer']); +var iLicenseCalc = new NativeFunction(ptr(0x00432CF0), 'uint', ['pointer', 'pointer', 'uint', 'char']); + +Interceptor.attach(iLicenseCalc, { + + // When function is called, print out its parameters + onEnter: function (args) { + this.inptr = args[0]; + this.outptr = args[1]; + this.inint = args[2]; + this.inchar = args[3]; + console.log(''); + console.log('[+] Called iLicenseCalc@' + iLicenseCalc); + console.log('Input:' + this.inptr.readAnsiString()); + console.log('Output:' + this.outptr.readAnsiString()); + console.log('IntVal:' + this.inint); + console.log('CharVal:' + this.inchar); + }, + + // When function is finished + onLeave: function (retval) { + console.log('Output:' + this.outptr.readAnsiString()); + console.log('[+] Returned from iLicenseCalc: ' + retval); + } +}); + +Interceptor.attach(santitizeString, { + + // When function is called, print out its parameters + onEnter: function (args) { + this.outptr = args[0]; // Store arg0 in order to see when we leave the function + console.log(''); + console.log('[+] Called santitizeString@' + santitizeString); + console.log('Input:' + this.outptr.readAnsiString()); + }, + + // When function is finished + onLeave: function (retval) { + console.log('Output:' + this.outptr.readAnsiString()); // Print out data array, which will contain some data as output + console.log('[+] Returned from santitizeString: ' + retval); + } +}); + +var jst = " Longhorn 3270"; +var jsts = Memory.allocAnsiString(jst); +var buf = Memory.alloc(8); + +strToUpper(jsts); +iLicenseCalc(buf, jsts, jst.length, 0x1); + +""") + +script.on('message', on_message) +script.load() +print("[!] Ctrl+D on UNIX, Ctrl+Z on Windows/cmd.exe to detach from instrumented program.\n\n") +sys.stdin.read() +session.detach() diff --git a/frida/licensehooks.py b/frida/licensehooks.py new file mode 100644 index 0000000..2d19d93 --- /dev/null +++ b/frida/licensehooks.py @@ -0,0 +1,83 @@ +############################################################################### +# Hook into Licence related functions for black-box testing +############################################################################### + +import frida +import sys + +def on_message(message, data): + print("[on_message] message:", message, "data:", data) + +session = frida.attach("vista32.exe") + +script = session.create_script(""" + +var santitizeString = new NativeFunction(ptr(0x00421f90), 'int', ['pointer']); +var sPrepRegCode = new NativeFunction(ptr(0x00421df0), 'void', ['pointer', 'pointer']); +var iLicenseCalc = new NativeFunction(ptr(0x0042a570), 'uint', ['pointer', 'pointer', 'uint', 'char']); + +Interceptor.attach(iLicenseCalc, { + + // When function is called, print out its parameters + onEnter: function (args) { + this.inptr = args[0]; + this.outptr = args[1]; + this.inint = args[2]; + this.inchar = args[3]; + console.log(''); + console.log('[+] Called iLicenseCalc@' + iLicenseCalc); + console.log('Input:' + this.inptr.readAnsiString()); + console.log('Output:' + this.outptr.readAnsiString()); + console.log('IntVal:' + this.inint); + console.log('CharVal:' + this.inchar); + }, + + // When function is finished + onLeave: function (retval) { + console.log('Output:' + this.outptr.readAnsiString()); + console.log('[+] Returned from iLicenseCalc: ' + retval); + } +}); + +Interceptor.attach(sPrepRegCode, { + + // When function is called, print out its parameters + onEnter: function (args) { + this.outptr = args[0]; // Store arg0 in order to see when we leave the function + this.inptr = args[1]; // Store arg0 in order to see when we leave the function + console.log(''); + console.log('[+] Called sPrepRegCode@' + sPrepRegCode); + console.log('Input:' + this.inptr.readAnsiString()); + }, + + // When function is finished + onLeave: function (retval) { + console.log('Output:' + this.outptr.readAnsiString()); // Print out data array, which will contain some data as output + console.log('[+] Returned from sPrepRegCode: ' + retval); + } +}); + +Interceptor.attach(santitizeString, { + + // When function is called, print out its parameters + onEnter: function (args) { + this.outptr = args[0]; // Store arg0 in order to see when we leave the function + console.log(''); + console.log('[+] Called santitizeString@' + santitizeString); + console.log('Input:' + this.outptr.readAnsiString()); + }, + + // When function is finished + onLeave: function (retval) { + console.log('Output:' + this.outptr.readAnsiString()); // Print out data array, which will contain some data as output + console.log('[+] Returned from santitizeString: ' + retval); + } +}); + +""") + +script.on('message', on_message) +script.load() +print("[!] Ctrl+D on UNIX, Ctrl+Z on Windows/cmd.exe to detach from instrumented program.\n\n") +sys.stdin.read() +session.detach()