[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ftkt5fPGBWtaGUI5iN4C1v4Q7IFOswHdQ7oNg4Epom7Q":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},509,"What are the advantages of using Boolang for shellcode execution compared to traditional methods?","The main advantages include: no need for compiled binaries with malicious imports, dynamic compilation in memory to evade static analysis, and the ability to separate the payload script from the launcher. The launcher (e.g., a PowerShell script) appears benign, while the actual shellcode is loaded from another file. This technique, explored in the article [Exploitation Analysis of Executing Shellcode via Boolang Language](\u002Fnews\u002Fexploitation-analysis-of-executing-shellcode-via-boolang-language), reduces the chance of detection by antivirus and EDR solutions.","\u003Cp>The main advantages include: no need for compiled binaries with malicious imports, dynamic compilation in memory to evade static analysis, and the ability to separate the payload script from the launcher. The launcher (e.g., a PowerShell script) appears benign, while the actual shellcode is loaded from another file. This technique, explored in the article [Exploitation Analysis of Executing Shellcode via Boolang Language](\u002Fnews\u002Fexploitation-analysis-of-executing-shellcode-via-boolang-language), reduces the chance of detection by antivirus and EDR solutions.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fexploitation-analysis-of-executing-shellcode-via-boolang-language\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-advantages-of-using-boolang-for-shellcode-execution-compared-to-tra-1777483245319","Boolang, evasion, static analysis, in-memory execution, PowerShell, EDR bypass",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},126,"Exploitation Analysis of Executing Shellcode via Boolang Language","exploitation-analysis-of-executing-shellcode-via-boolang-language","Learn how attackers use Boolang language to execute shellcode, analyze exploitation techniques, and discover defensive detection strategies.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Exploitation Analysis of SILENTTRINITY', I learned the method of loading payloads from memory using the C# IronPython engine. On byt3bl33d3r's GitHub, I came across code that executes shellcode using the Boolang language, prompting me to research this technique.\u003C\u002Fp>\u003Cp>This article will introduce the characteristics and usage of the Boolang language, analyze the advantages of executing shellcode via Boolang, and provide recommendations for defensive detection.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to the Boolang Language\u003C\u002Fli>\u003Cli>Usage of the Boolang Language\u003C\u002Fli>\u003Cli>Implementation Code for Executing Shellcode via Boolang Language\u003C\u002Fli>\u003Cli>Exploitation Analysis\u003C\u002Fli>\u003Cli>Defensive Detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Boolang Language\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Learning Materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fboo-lang\u002Fboo\u003C\u002Fp>\u003Cp>Boolang is an object-oriented language that combines Python's syntax, Ruby's functionality, and C#'s speed and security\u003C\u002Fp>\u003Cp>Features include:\u003C\u002Fp>\u003Cul>\u003Cli>Syntax is very close to Python, user-friendly\u003C\u002Fli>\u003Cli>Statically typed, more secure compared to dynamically typed Python\u003C\u002Fli>\u003Cli>Extensible compiler, can run on .NET Framework or Mono\u003C\u002Fli>\u003Cli>Open source code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Usage of Boolang Language\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>First, you need to download the compiled Boolang files from the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fboo-lang\u002Fboo\u002Freleases\u003C\u002Fp>\u003Cp>The files include the following three executable programs:\u003C\u002Fp>\u003Col>\u003Cli>booi.exe, used for executing scripts\u003C\u002Fli>\u003Cli>booish.exe, a real-time compiler program, convenient for testing code\u003C\u002Fli>\u003Cli>booc.exe, used for compiling scripts\u003C\u002Fli>\u003C\u002Fol>\u003Cp>The specific usage is as follows:\u003C\u002Fp>\u003Ch3>1. Use booi.exe to execute Boolang scripts\u003C\u002Fh3>\u003Cp>The content of test.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>print \"Hello, World!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>booi.exe test.boo\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017955039_0_215513d0e8.jpeg\">\u003C\u002Fp>\u003Ch3>2. Use booish.exe for real-time compilation\u003C\u002Fh3>\u003Cp>Start booish.exe, enter the following code in the command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>print \"Hello, World!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017966004_1_e478de3f93.jpeg\">\u003C\u002Fp>\u003Ch3>3. Use booc.exe to compile Boolang scripts\u003C\u002Fh3>\u003Cp>The content of test.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>print \"Hello, World!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Cp>enter code herebooc -output:test.exe test.boo\u003C\u002Fp>\u003Cp>Generate the file test.exe\u003C\u002Fp>\u003Ch3>4. Compile Boolang script using booc.exe (using Boo.Lang.Compiler API)\u003C\u002Fh3>\u003Cp>The content of test.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import Boo.Lang.Compiler\u003Cbr>import Boo.Lang.Compiler.IO\u003Cbr>import Boo.Lang.Compiler.Pipelines\u003Cbr>\u003Cbr>compiler = BooCompiler()\u003Cbr>compiler.Parameters.Input.Add(StringInput(\"\u003Cscript>\", \"print('Hello!')\"))\u003Cbr>compiler.Parameters.Pipeline = Run()\u003Cbr>\u003Cbr>compiler.Run()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>booc -output:test.exe test.boo\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate file test.exe\u003C\u002Fp>\u003Ch3>5. Using C# to call BooLang script\u003C\u002Fh3>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fboo-lang\u002Fboo\u002Fwiki\u002FScripting-with-the-Boo.Lang.Compiler-API\u003C\u002Fp>\u003Cp>The content of script.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>static def stringManip(item as string): \u002F\u002Fstatic lets us invoke this method without needing to instantiate a class.\u003Cbr>\treturn \"'${item}'? What the hell are you talking about?\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The content of runBoo.cs is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Text;\u003Cbr>using System.Reflection;\u003Cbr>\u003Cbr>using Boo.Lang.Compiler;\u003Cbr>using Boo.Lang.Compiler.IO;\u003Cbr>using Boo.Lang.Compiler.Pipelines;\u003Cbr>namespace ConsoleApplication1\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        static void Main(string[] args)\u003Cbr>        {\u003Cbr>            BooCompiler compiler = new BooCompiler();\u003Cbr>            compiler.Parameters.Input.Add(new FileInput(\"script.boo\"));\u003Cbr>            compiler.Parameters.Pipeline = new CompileToMemory();\u003Cbr>            compiler.Parameters.Ducky = true;\u003Cbr>\u003Cbr>            CompilerContext context = compiler.Run();\u003Cbr>            \u002F\u002FNote that the following code might throw an error if the Boo script had bugs.\u003Cbr>            \u002F\u002FPoke context.Errors to make sure.\u003Cbr>            if (context.GeneratedAssembly != null)\u003Cbr>    {\u003Cbr>                Type scriptModule = context.GeneratedAssembly.GetType(\"ScriptModule\");\u003Cbr>                MethodInfo stringManip = scriptModule.GetMethod(\"stringManip\");\u003Cbr>                string output = (string)stringManip.Invoke(null, new object[] { \"Tag\" } );\u003Cbr>                Console.WriteLine(output);\u003Cbr>            }\u003Cbr>            else\u003Cbr>            {\u003Cbr>                foreach (CompilerError error in context.Errors)\u003Cbr>                    Console.WriteLine(error);\u003Cbr>            }\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile runBoo.cs using csc.exe with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe \u002Fr:Boo.Lang.dll,Boo.Lang.Compiler.dll,Boo.Lang.Parser.dll \u002Ft:exe runBoo.cs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate the file runBoo.exe, the command to invoke script.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>runBoo.exe script.boo\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017969465_2_a1e1c3379a.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The following three DLLs must exist in the same directory as runBoo.exe:\u003C\u002Fp>\u003Cul>\u003Cli>Boo.Lang.dll\u003C\u002Fli>\u003Cli>Boo.Lang.Compiler.dll\u003C\u002Fli>\u003Cli>Boo.Lang.Parser.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The advantage of this method is that it can compile and run the Boolang script in memory. Corresponding to the example above, runBoo.exe compiles and runs script.boo in memory.\u003C\u002Fp>\u003Ch2>0x04 Implementation code for executing shellcode via the Boolang language\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Code from https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002F\u003C\u002Fp>\u003Ch3>1. Using C# to invoke Boolang scripts\u003C\u002Fh3>\u003Cp>The following two code files are required:\u003C\u002Fp>\u003Ch4>(1) runBoo.cs\u003C\u002Fh4>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002Fblob\u002Fmaster\u002FrunBoo.cs\u003C\u002Fp>\u003Cp>The structure is basically the same as runBoo.cs in 0x04-5\u003C\u002Fp>\u003Cp>Stores 32-bit and 64-bit shellcode separately in arrays\u003C\u002Fp>\u003Cp>The first command-line argument is the passed Boolang script file\u003C\u002Fp>\u003Cp>The second command-line argument is the method for injecting shellcode\u003C\u002Fp>\u003Ch4>(2) shellcode.boo\u003C\u002Fh4>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002Fblob\u002Fmaster\u002Fshellcode.boo\u003C\u002Fp>\u003Cp>Boolang script, supporting the following three injection methods:\u003C\u002Fp>\u003Cul>\u003Cli>InjectQueueUserAPC, injects into the explorer.exe process via QueueUserAPC\u003C\u002Fli>\u003Cli>InjectSelf, injects into the current process via CreateThread\u003C\u002Fli>\u003Cli>InjectRemote, injects into the explorer.exe process via CreateRemoteThread\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Specific usage is as follows:\u003C\u002Fp>\u003Ch4>(1) Compile runBoo.cs using csc.exe\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe \u002Fr:Boo.Lang.Compiler.dll,Boo.Lang.dll,Boo.Lang.Parser.dll \u002Ft:exe runBoo.cs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate the file runBoo.exe\u003C\u002Fp>\u003Ch4>(2) Test functionality\u003C\u002Fh4>\u003Cp>Available commands are as follows:\u003C\u002Fp>\u003Col>\u003Cli>runBoo.exe shellcode.boo InjectQueueUserAPC\u003C\u002Fli>\u003Cli>runBoo.exe shellcode.boo InjectSelf\u003C\u002Fli>\u003Cli>runBoo.exe shellcode.boo InjectRemote\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The following three DLLs must exist in the same directory as runBoo.exe:\u003C\u002Fp>\u003Cul>\u003Cli>Boo.Lang.dll\u003C\u002Fli>\u003Cli>Boo.Lang.Compiler.dll\u003C\u002Fli>\u003Cli>Boo.Lang.Parser.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Solution 1:\u003C\u002Fp>\u003Cp>Using ILMerge\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fboo-lang\u002Fboo\u002Fwiki\u002FMerge-Boo.Lang.dll-into-your-exe-or-dll\u003C\u002Fp>\u003Ch3>2. Using PowerShell to invoke Boo language scripts\u003C\u002Fh3>\u003Cp>Requires the following two code files:\u003C\u002Fp>\u003Ch4>(1) Invoke-JumpScare.ps1\u003C\u002Fh4>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002Fblob\u002Fmaster\u002FInvoke-JumpScare.ps1\u003C\u002Fp>\u003Cp>Functionally equivalent to runBoo.cs, but loads the required three DLLs (Boo.Lang.dll, Boo.Lang.Compiler.dll, Boo.Lang.Parser.dll) via reflection, eliminating the need for these three DLL files in the same directory\u003C\u002Fp>\u003Cp>No need to use csc.exe for compilation, no intermediate files generated\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Boo language script content can be stored in a variable, eliminating the need for an additional Boo script file; all functionality can be contained within a single PowerShell file\u003C\u002Fp>\u003Ch4>(2) shellcode.boo\u003C\u002Fh4>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002Fblob\u002Fmaster\u002Fshellcode.boo\u003C\u002Fp>\u003Cp>Content as above\u003C\u002Fp>\u003Cp>Actual test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017975943_3_db12d09d3f.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Compared to the open-source Boolang code, the code open-sourced by byt3bl33d3r adds the following features:\u003C\u002Fp>\u003Cul>\u003Cli>Supports PowerShell invocation, eliminating the need to compile with csc.exe. The Boolang script is dynamically compiled and executed just-in-time, using reflection to load the required three DLLs without dependency on them.\u003C\u002Fli>\u003Cli>Added functionality to execute shellcode.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>This exploitation method has the following advantages:\u003C\u002Fp>\u003Cp>Using the Boolang language to execute shellcode, the startup code (PowerShell script) does not include malicious functionality; the payload can be stored in another script file.\u003C\u002Fp>\u003Cp>Simple understanding:\u003C\u002Fp>\u003Cp>Developed a PowerShell-format script interpreter via the Boolang language, capable of dynamically loading code from another script file in memory.\u003C\u002Fp>\u003Ch2>0x06 Defense and Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A similar method was introduced in a previous article, 'Penetration Techniques – Use AutoIt script to create a keylogger,' which also involves launching code from another script file via a script interpreter, so the defense and detection methods are similar.\u003C\u002Fp>\u003Cp>Given the exploitation methods, we typically encounter the following scenarios during detection: the launcher and payload are separated, making static detection difficult.\u003C\u002Fp>\u003Cp>However, this technique cannot bypass detection of program behavior, so defense can be achieved by monitoring process behavior.\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the characteristics and usage of the Boolang language, analyzes the advantages of executing shellcode via Boolang based on byt3bl33d3r's open-source code, and provides recommendations for defensive detection.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>\u003C\u002Fscript>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Exploitation Analysis of SILENTTRINITY', I learned the method of loading payloads from memory using the C# IronPython engine. On byt3bl33d3r's GitHub, I came across code that executes shellcode using the Boolang language, prompting me to research this technique.\u003C\u002Fp>\u003Cp>This article will introduce the characteristics and usage of the Boolang language, analyze the advantages of executing shellcode via Boolang, and provide recommendations for defensive detection.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to the Boolang Language\u003C\u002Fli>\u003Cli>Usage of the Boolang Language\u003C\u002Fli>\u003Cli>Implementation Code for Executing Shellcode via Boolang Language\u003C\u002Fli>\u003Cli>Exploitation Analysis\u003C\u002Fli>\u003Cli>Defensive Detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Boolang Language\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Learning Materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fboo-lang\u002Fboo\u003C\u002Fp>\u003Cp>Boolang is an object-oriented language that combines Python's syntax, Ruby's functionality, and C#'s speed and security\u003C\u002Fp>\u003Cp>Features include:\u003C\u002Fp>\u003Cul>\u003Cli>Syntax is very close to Python, user-friendly\u003C\u002Fli>\u003Cli>Statically typed, more secure compared to dynamically typed Python\u003C\u002Fli>\u003Cli>Extensible compiler, can run on .NET Framework or Mono\u003C\u002Fli>\u003Cli>Open source code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Usage of Boolang Language\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>First, you need to download the compiled Boolang files from the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fboo-lang\u002Fboo\u002Freleases\u003C\u002Fp>\u003Cp>The files include the following three executable programs:\u003C\u002Fp>\u003Col>\u003Cli>booi.exe, used for executing scripts\u003C\u002Fli>\u003Cli>booish.exe, a real-time compiler program, convenient for testing code\u003C\u002Fli>\u003Cli>booc.exe, used for compiling scripts\u003C\u002Fli>\u003C\u002Fol>\u003Cp>The specific usage is as follows:\u003C\u002Fp>\u003Ch3>1. Use booi.exe to execute Boolang scripts\u003C\u002Fh3>\u003Cp>The content of test.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>print \"Hello, World!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>booi.exe test.boo\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017955039_0_215513d0e8-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Use booish.exe for real-time compilation\u003C\u002Fh3>\u003Cp>Start booish.exe, enter the following code in the command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>print \"Hello, World!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017966004_1_e478de3f93-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Use booc.exe to compile Boolang scripts\u003C\u002Fh3>\u003Cp>The content of test.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>print \"Hello, World!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Cp>enter code herebooc -output:test.exe test.boo\u003C\u002Fp>\u003Cp>Generate the file test.exe\u003C\u002Fp>\u003Ch3>4. Compile Boolang script using booc.exe (using Boo.Lang.Compiler API)\u003C\u002Fh3>\u003Cp>The content of test.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import Boo.Lang.Compiler\u003Cbr>import Boo.Lang.Compiler.IO\u003Cbr>import Boo.Lang.Compiler.Pipelines\u003Cbr>\u003Cbr>compiler = BooCompiler()\u003Cbr>compiler.Parameters.Input.Add(StringInput(\"\u003Cscript>\", \"print('Hello!')\"))\u003Cbr>compiler.Parameters.Pipeline = Run()\u003Cbr>\u003Cbr>compiler.Run()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>booc -output:test.exe test.boo\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate file test.exe\u003C\u002Fp>\u003Ch3>5. Using C# to call BooLang script\u003C\u002Fh3>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fboo-lang\u002Fboo\u002Fwiki\u002FScripting-with-the-Boo.Lang.Compiler-API\u003C\u002Fp>\u003Cp>The content of script.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>static def stringManip(item as string): \u002F\u002Fstatic lets us invoke this method without needing to instantiate a class.\u003Cbr>\treturn \"'${item}'? What the hell are you talking about?\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The content of runBoo.cs is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Text;\u003Cbr>using System.Reflection;\u003Cbr>\u003Cbr>using Boo.Lang.Compiler;\u003Cbr>using Boo.Lang.Compiler.IO;\u003Cbr>using Boo.Lang.Compiler.Pipelines;\u003Cbr>namespace ConsoleApplication1\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        static void Main(string[] args)\u003Cbr>        {\u003Cbr>            BooCompiler compiler = new BooCompiler();\u003Cbr>            compiler.Parameters.Input.Add(new FileInput(\"script.boo\"));\u003Cbr>            compiler.Parameters.Pipeline = new CompileToMemory();\u003Cbr>            compiler.Parameters.Ducky = true;\u003Cbr>\u003Cbr>            CompilerContext context = compiler.Run();\u003Cbr>            \u002F\u002FNote that the following code might throw an error if the Boo script had bugs.\u003Cbr>            \u002F\u002FPoke context.Errors to make sure.\u003Cbr>            if (context.GeneratedAssembly != null)\u003Cbr>    {\u003Cbr>                Type scriptModule = context.GeneratedAssembly.GetType(\"ScriptModule\");\u003Cbr>                MethodInfo stringManip = scriptModule.GetMethod(\"stringManip\");\u003Cbr>                string output = (string)stringManip.Invoke(null, new object[] { \"Tag\" } );\u003Cbr>                Console.WriteLine(output);\u003Cbr>            }\u003Cbr>            else\u003Cbr>            {\u003Cbr>                foreach (CompilerError error in context.Errors)\u003Cbr>                    Console.WriteLine(error);\u003Cbr>            }\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile runBoo.cs using csc.exe with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe \u002Fr:Boo.Lang.dll,Boo.Lang.Compiler.dll,Boo.Lang.Parser.dll \u002Ft:exe runBoo.cs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate the file runBoo.exe, the command to invoke script.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>runBoo.exe script.boo\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017969465_2_a1e1c3379a-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The following three DLLs must exist in the same directory as runBoo.exe:\u003C\u002Fp>\u003Cul>\u003Cli>Boo.Lang.dll\u003C\u002Fli>\u003Cli>Boo.Lang.Compiler.dll\u003C\u002Fli>\u003Cli>Boo.Lang.Parser.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The advantage of this method is that it can compile and run the Boolang script in memory. Corresponding to the example above, runBoo.exe compiles and runs script.boo in memory.\u003C\u002Fp>\u003Ch2>0x04 Implementation code for executing shellcode via the Boolang language\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Code from https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002F\u003C\u002Fp>\u003Ch3>1. Using C# to invoke Boolang scripts\u003C\u002Fh3>\u003Cp>The following two code files are required:\u003C\u002Fp>\u003Ch4>(1) runBoo.cs\u003C\u002Fh4>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002Fblob\u002Fmaster\u002FrunBoo.cs\u003C\u002Fp>\u003Cp>The structure is basically the same as runBoo.cs in 0x04-5\u003C\u002Fp>\u003Cp>Stores 32-bit and 64-bit shellcode separately in arrays\u003C\u002Fp>\u003Cp>The first command-line argument is the passed Boolang script file\u003C\u002Fp>\u003Cp>The second command-line argument is the method for injecting shellcode\u003C\u002Fp>\u003Ch4>(2) shellcode.boo\u003C\u002Fh4>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002Fblob\u002Fmaster\u002Fshellcode.boo\u003C\u002Fp>\u003Cp>Boolang script, supporting the following three injection methods:\u003C\u002Fp>\u003Cul>\u003Cli>InjectQueueUserAPC, injects into the explorer.exe process via QueueUserAPC\u003C\u002Fli>\u003Cli>InjectSelf, injects into the current process via CreateThread\u003C\u002Fli>\u003Cli>InjectRemote, injects into the explorer.exe process via CreateRemoteThread\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Specific usage is as follows:\u003C\u002Fp>\u003Ch4>(1) Compile runBoo.cs using csc.exe\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe \u002Fr:Boo.Lang.Compiler.dll,Boo.Lang.dll,Boo.Lang.Parser.dll \u002Ft:exe runBoo.cs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate the file runBoo.exe\u003C\u002Fp>\u003Ch4>(2) Test functionality\u003C\u002Fh4>\u003Cp>Available commands are as follows:\u003C\u002Fp>\u003Col>\u003Cli>runBoo.exe shellcode.boo InjectQueueUserAPC\u003C\u002Fli>\u003Cli>runBoo.exe shellcode.boo InjectSelf\u003C\u002Fli>\u003Cli>runBoo.exe shellcode.boo InjectRemote\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The following three DLLs must exist in the same directory as runBoo.exe:\u003C\u002Fp>\u003Cul>\u003Cli>Boo.Lang.dll\u003C\u002Fli>\u003Cli>Boo.Lang.Compiler.dll\u003C\u002Fli>\u003Cli>Boo.Lang.Parser.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Solution 1:\u003C\u002Fp>\u003Cp>Using ILMerge\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fboo-lang\u002Fboo\u002Fwiki\u002FMerge-Boo.Lang.dll-into-your-exe-or-dll\u003C\u002Fp>\u003Ch3>2. Using PowerShell to invoke Boo language scripts\u003C\u002Fh3>\u003Cp>Requires the following two code files:\u003C\u002Fp>\u003Ch4>(1) Invoke-JumpScare.ps1\u003C\u002Fh4>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002Fblob\u002Fmaster\u002FInvoke-JumpScare.ps1\u003C\u002Fp>\u003Cp>Functionally equivalent to runBoo.cs, but loads the required three DLLs (Boo.Lang.dll, Boo.Lang.Compiler.dll, Boo.Lang.Parser.dll) via reflection, eliminating the need for these three DLL files in the same directory\u003C\u002Fp>\u003Cp>No need to use csc.exe for compilation, no intermediate files generated\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Boo language script content can be stored in a variable, eliminating the need for an additional Boo script file; all functionality can be contained within a single PowerShell file\u003C\u002Fp>\u003Ch4>(2) shellcode.boo\u003C\u002Fh4>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002Fblob\u002Fmaster\u002Fshellcode.boo\u003C\u002Fp>\u003Cp>Content as above\u003C\u002Fp>\u003Cp>Actual test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017975943_3_db12d09d3f-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Compared to the open-source Boolang code, the code open-sourced by byt3bl33d3r adds the following features:\u003C\u002Fp>\u003Cul>\u003Cli>Supports PowerShell invocation, eliminating the need to compile with csc.exe. The Boolang script is dynamically compiled and executed just-in-time, using reflection to load the required three DLLs without dependency on them.\u003C\u002Fli>\u003Cli>Added functionality to execute shellcode.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>This exploitation method has the following advantages:\u003C\u002Fp>\u003Cp>Using the Boolang language to execute shellcode, the startup code (PowerShell script) does not include malicious functionality; the payload can be stored in another script file.\u003C\u002Fp>\u003Cp>Simple understanding:\u003C\u002Fp>\u003Cp>Developed a PowerShell-format script interpreter via the Boolang language, capable of dynamically loading code from another script file in memory.\u003C\u002Fp>\u003Ch2>0x06 Defense and Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A similar method was introduced in a previous article, 'Penetration Techniques – Use AutoIt script to create a keylogger,' which also involves launching code from another script file via a script interpreter, so the defense and detection methods are similar.\u003C\u002Fp>\u003Cp>Given the exploitation methods, we typically encounter the following scenarios during detection: the launcher and payload are separated, making static detection difficult.\u003C\u002Fp>\u003Cp>However, this technique cannot bypass detection of program behavior, so defense can be achieved by monitoring process behavior.\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the characteristics and usage of the Boolang language, analyzes the advantages of executing shellcode via Boolang based on byt3bl33d3r's open-source code, and provides recommendations for defensive detection.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>\u003C\u002Fscript>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fbody>\u003C\u002Fhtml>",1074,"Onedaysec",5,"published","2026-02-02T07:51:00.064Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Exploiting Shellcode via Boolang Language: Analysis & Defense","Boolang language, shellcode execution, exploitation analysis, defensive detection, C# IronPython, memory loading, cybersecurity",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],510,508,507,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.974Z","2026-07-23T16:01:40.435Z","draft","2026-07-23T16:12:51.543Z"]