GithubHelp home page GithubHelp logo

r00t-3xp10it / backdoorppt Goto Github PK

View Code? Open in Web Editor NEW
460.0 31.0 186.0 3.46 MB

transform your payload.exe into one fake word doc (.ppt)

Shell 100.00%
office-word-doc spoof-extensions fake-doc-builder payload rtlo

backdoorppt's Introduction

Version Stage Build

backdoorppt - 'Office spoof extensions tool'

Version release: v1.7-Stable
Author: pedro ubuntu  [ r00t-3xp10it ]
Distros Supported: Linux Kali, Ubuntu, Mint
Suspicious-Shell-Activity© (SSA) RedTeam develop @2017

backdoorppt


Transform your payload.exe into one fake word doc (.ppt)

Simple script that allow users to add a ms-word icon to one
existing executable.exe (using resource-hacker as backend appl)
and a ruby one-liner command that will hidde the .exe extension
and add the word doc .ppt extension to the end of the file name.

Spoof extension methods

backdoorppt tool uses 2 diferent extension spoof methods:
'Right to Left Override' & 'Hide Extensions for Known File Types'
Edit the 'settings' file to chose what method should be used..

cd backdoorppt && nano settings

backdoorppt

Dependencies (backend applications required)

xterm, wine, ruby, ResourceHacker(wine)

'backdoorppt script will work on wine 32 or 64 bits'
'it also installs ResourceHacker under .../.wine/Program Files/.. directorys'

Tool Limitations

1º - backdoorppt only supports windows binarys to be transformed (.exe -> .ppt)
2º - backdoorppt requires ResourceHacker installed (wine) to change the icons
3º - backdoorppt present you 6 available diferent icons (.ico) to chose from
4º - backdoorppt does not build real ms-word doc files, but it will transform
     your payload.exe to look like one word doc file (social engineering).



Backdoorppt working (Kali distros)

backdoorppt

transformed files on-target system (windows)

backdoorppt



Final notes

Target user thinks they are opening a word document file,
but in fact they are executing one binary payload insted.

Video tutorials:

backdoorppt: https://www.youtube.com/watch?v=k4UJW4p1E3w&t=1s


Special thanks:

@Damon Mohammadbagher | Article: goo.gl/hKHesk

backdoorppt's People

Contributors

r00t-3xp10it avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

backdoorppt's Issues

Asking

use for android.apk run in android phone

Resource Hacker

Resource hacker is installed on my system, but is not detected. The program then "install" it again just to repeat the whole process the next time because it is not detecting resource hacker

Kali 2018.4 - (64)

Infinite Loop

Stays on infinite loop: Kali Linux

[x] ResourceHacker.exe -> not found!
Installing ResourceHacker under .wine directorys...
Version:windows7 Arch:x64 Path:drive_c/Program Files (x86)
/home/jinx/.wine/drive_c/Program Files (x86)/Resource Hacker/ResourceHacker.exe

[⊶] Please wait, restarting tool!
[⊶] For proper ResourceHacker.exe Instalation!

Not executing :( Here is the issue.

┌─[root@parrot]─[/home/user/backdoorppt]
└──╼ # ./backdoorppt.sh

+-+-+-+-+-+-+-+-+-+-+-+-+---+
|b|a|c|k|d|o|o|r|p|p|t|:|1.7|
+-+-+-+-+-+-+-+-+-+-+-+-+---+
'Office spoof extensions tool'
Credits: Damon Mohammadbagher

[☆] Checking backend applications ..
[☆] Ruby installation : found!
[☆] Wine installation : found!
[☆] Zenity installation : found!
[☆] Xterm installation : found!
[☆] Wine Program Files (x86) : found!
[x] Aborting all tasks : done!

Codename::ghost-in-a-shell
Author::pedr0 ubuntu::[r00t-3xp10it]
backdoorppt::v1.7::SuspiciousShellActivity©::RedTeam::2017
┌─[root@parrot]─[/home/user/backdoorppt]
└──╼ #

error while compiling..

[☆] ResourceHacker.exe -> found!
[⊶] Working on backdoor agent!
[☆] Transforming backdoor agent -> done...
[☆] Change backdoor agent icons -> done...
[☆] Adding agent hidden extensions -> done...
[☆] Word doc builder (backdoorppt) -> done...
-e:1:in rename': No such file or directory @ rb_file_s_rename - (backdoor_ppt.exe, resume‮tpp.exe) (Errno::ENOENT) from -e:1:in

'
[⊶] Task over, Writing reports!

debian too ?

first off, thank you for a great script, using it on debian-testing but keep getting this 👍

selection_003

BTW .. wine ver is 32bit.
thx in adv.

Directory Path issue

-e:1:in rename': No such file or directory @ rb_file_s_rename - (backdoor_ppt.exe, resume‮tpp.exe) (Errno::ENOENT) from -e:1:in

'

hasn't copied the file.

While it says everything is OK and file has been copied in .../output folder, but nothing is there!
Thanks.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.