Skip to content

Commit

Permalink
Added the python/base64_encode encoder (closes #170).
Browse files Browse the repository at this point in the history
  • Loading branch information
postmodern committed Aug 14, 2024
1 parent c05d54b commit c3cc8c1
Show file tree
Hide file tree
Showing 3 changed files with 89 additions and 0 deletions.
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -208,6 +208,7 @@ $ ronin-payloads encoders
js/hex_encode
js/node/base64_encode
powershell/hex_encode
python/base64_encode
shell/base64_encode
shell/hex_encode
shell/hex_escape
Expand Down
71 changes: 71 additions & 0 deletions lib/ronin/payloads/encoders/builtin/python/base64_encode.rb
Original file line number Diff line number Diff line change
@@ -0,0 +1,71 @@
# frozen_string_literal: true
#
# ronin-payloads - A Ruby micro-framework for writing and running exploit
# payloads.
#
# Copyright (c) 2007-2024 Hal Brodigan (postmodern.mod3 at gmail.com)
#
# ronin-payloads is free software: you can redistribute it and/or modify
# it under the terms of the GNU Lesser General Public License as published
# by the Free Software Foundation, either version 3 of the License, or
# (at your option) any later version.
#
# ronin-payloads is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU Lesser General Public License for more details.
#
# You should have received a copy of the GNU Lesser General Public License
# along with ronin-payloads. If not, see <https://www.gnu.org/licenses/>.
#

require 'ronin/payloads/encoders/python_encoder'
require 'ronin/support/encoding/base64'

module Ronin
module Payloads
module Encoders
module Python
#
# Encodes the given Python code as a Base64 string, then decodes it
# using `base64.b64decode()`, and then evaluates the decoded Python code
# using `eval()`.
#
# print('PWNED') -> import base64; eval(base64.b64decode(bytes("cHJpbnQoJ1BXTkVEJyk=","utf-8")))
#
# @since 0.3.0
#
class Base64Encode < PythonEncoder

register 'python/base64_encode'

summary 'Encodes Python as base64'

description <<~DESC
Encodes the given Python code as a Base64 string, then decodes it
using `base64.b64decode()`, and then evaluates the decoded Python
code using `eval()`.
print('PWNED') -> import base64; eval(base64.b64decode(bytes("cHJpbnQoJ1BXTkVEJyk=","utf-8")))
DESC

#
# Encodes Python code as Base64.
#
# @param [String] python
# The Python code to encode.
#
# @return [String]
#
def encode(python)
base64 = Support::Encoding::Base64.encode(python, mode: :strict)

%{import base64; eval(base64.b64decode(bytes("#{base64}","utf-8")))}
end

end
end
end
end
end
17 changes: 17 additions & 0 deletions spec/encoders/builtin/python/base64_encode_spec.rb
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
require 'spec_helper'
require 'ronin/payloads/encoders/builtin/python/base64_encode'

describe Ronin::Payloads::Encoders::Python::Base64Encode do
it "must inherit from Ronin::Payloads::Encoders::PythonEncoder" do
expect(described_class).to be < Ronin::Payloads::Encoders::PythonEncoder
end

describe "#encode" do
let(:python) { "print('PWNED')" }
let(:encoded) { %{import base64; eval(base64.b64decode(bytes("cHJpbnQoJ1BXTkVEJyk=","utf-8")))} }

it "must encode the given Python code as a Base64 string and embed it into the 'import base64; eval(base64.b64decode(bytes(\"...\",\"utf-8\")))'" do
expect(subject.encode(python)).to eq(encoded)
end
end
end

0 comments on commit c3cc8c1

Please sign in to comment.