[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fW77iGqIfS2i-j5uXai0uaNqMlI0wp1opW7riMbm6P7k":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},507,"What is the Boolang language and why is it useful for executing shellcode?","Boolang is an object-oriented language that combines Python's syntax with C#'s speed and security, running on the .NET Framework. It is useful for executing shellcode because it allows dynamic compilation of scripts in memory, enabling attackers to load and execute malicious payloads without writing traditional malicious files. This technique, detailed in the [Exploitation Analysis of Executing Shellcode via Boolang Language](\u002Fnews\u002Fexploitation-analysis-of-executing-shellcode-via-boolang-language), leverages the .NET DLR to bypass signature-based defenses.","\u003Cp>Boolang is an object-oriented language that combines Python&#39;s syntax with C#&#39;s speed and security, running on the .NET Framework. It is useful for executing shellcode because it allows dynamic compilation of scripts in memory, enabling attackers to load and execute malicious payloads without writing traditional malicious files. This technique, detailed in the [Exploitation Analysis of Executing Shellcode via Boolang Language](\u002Fnews\u002Fexploitation-analysis-of-executing-shellcode-via-boolang-language), leverages the .NET DLR to bypass signature-based defenses.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fexploitation-analysis-of-executing-shellcode-via-boolang-language\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-boolang-language-and-why-is-it-useful-for-executing-shellcode-1777483245176","Boolang, shellcode, .NET, DLR, memory execution, dynamic compilation",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},126,"Exploitation Analysis of Executing Shellcode via Boolang Language","exploitation-analysis-of-executing-shellcode-via-boolang-language","Learn how attackers use Boolang language to execute shellcode, analyze exploitation techniques, and discover defensive detection strategies.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Exploitation Analysis of SILENTTRINITY', I learned the method of loading payloads from memory using the C# IronPython engine. On byt3bl33d3r's GitHub, I came across code that executes shellcode using the Boolang language, prompting me to research this technique.\u003C\u002Fp>\u003Cp>This article will introduce the characteristics and usage of the Boolang language, analyze the advantages of executing shellcode via Boolang, and provide recommendations for defensive detection.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to the Boolang Language\u003C\u002Fli>\u003Cli>Usage of the Boolang Language\u003C\u002Fli>\u003Cli>Implementation Code for Executing Shellcode via Boolang Language\u003C\u002Fli>\u003Cli>Exploitation Analysis\u003C\u002Fli>\u003Cli>Defensive Detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Boolang Language\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Learning Materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fboo-lang\u002Fboo\u003C\u002Fp>\u003Cp>Boolang is an object-oriented language that combines Python's syntax, Ruby's functionality, and C#'s speed and security\u003C\u002Fp>\u003Cp>Features include:\u003C\u002Fp>\u003Cul>\u003Cli>Syntax is very close to Python, user-friendly\u003C\u002Fli>\u003Cli>Statically typed, more secure compared to dynamically typed Python\u003C\u002Fli>\u003Cli>Extensible compiler, can run on .NET Framework or Mono\u003C\u002Fli>\u003Cli>Open source code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Usage of Boolang Language\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>First, you need to download the compiled Boolang files from the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fboo-lang\u002Fboo\u002Freleases\u003C\u002Fp>\u003Cp>The files include the following three executable programs:\u003C\u002Fp>\u003Col>\u003Cli>booi.exe, used for executing scripts\u003C\u002Fli>\u003Cli>booish.exe, a real-time compiler program, convenient for testing code\u003C\u002Fli>\u003Cli>booc.exe, used for compiling scripts\u003C\u002Fli>\u003C\u002Fol>\u003Cp>The specific usage is as follows:\u003C\u002Fp>\u003Ch3>1. Use booi.exe to execute Boolang scripts\u003C\u002Fh3>\u003Cp>The content of test.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>print \"Hello, World!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>booi.exe test.boo\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017955039_0_215513d0e8.jpeg\">\u003C\u002Fp>\u003Ch3>2. Use booish.exe for real-time compilation\u003C\u002Fh3>\u003Cp>Start booish.exe, enter the following code in the command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>print \"Hello, World!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017966004_1_e478de3f93.jpeg\">\u003C\u002Fp>\u003Ch3>3. Use booc.exe to compile Boolang scripts\u003C\u002Fh3>\u003Cp>The content of test.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>print \"Hello, World!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Cp>enter code herebooc -output:test.exe test.boo\u003C\u002Fp>\u003Cp>Generate the file test.exe\u003C\u002Fp>\u003Ch3>4. Compile Boolang script using booc.exe (using Boo.Lang.Compiler API)\u003C\u002Fh3>\u003Cp>The content of test.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import Boo.Lang.Compiler\u003Cbr>import Boo.Lang.Compiler.IO\u003Cbr>import Boo.Lang.Compiler.Pipelines\u003Cbr>\u003Cbr>compiler = BooCompiler()\u003Cbr>compiler.Parameters.Input.Add(StringInput(\"\u003Cscript>\", \"print('Hello!')\"))\u003Cbr>compiler.Parameters.Pipeline = Run()\u003Cbr>\u003Cbr>compiler.Run()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>booc -output:test.exe test.boo\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate file test.exe\u003C\u002Fp>\u003Ch3>5. Using C# to call BooLang script\u003C\u002Fh3>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fboo-lang\u002Fboo\u002Fwiki\u002FScripting-with-the-Boo.Lang.Compiler-API\u003C\u002Fp>\u003Cp>The content of script.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>static def stringManip(item as string): \u002F\u002Fstatic lets us invoke this method without needing to instantiate a class.\u003Cbr>\treturn \"'${item}'? What the hell are you talking about?\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The content of runBoo.cs is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Text;\u003Cbr>using System.Reflection;\u003Cbr>\u003Cbr>using Boo.Lang.Compiler;\u003Cbr>using Boo.Lang.Compiler.IO;\u003Cbr>using Boo.Lang.Compiler.Pipelines;\u003Cbr>namespace ConsoleApplication1\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        static void Main(string[] args)\u003Cbr>        {\u003Cbr>            BooCompiler compiler = new BooCompiler();\u003Cbr>            compiler.Parameters.Input.Add(new FileInput(\"script.boo\"));\u003Cbr>            compiler.Parameters.Pipeline = new CompileToMemory();\u003Cbr>            compiler.Parameters.Ducky = true;\u003Cbr>\u003Cbr>            CompilerContext context = compiler.Run();\u003Cbr>            \u002F\u002FNote that the following code might throw an error if the Boo script had bugs.\u003Cbr>            \u002F\u002FPoke context.Errors to make sure.\u003Cbr>            if (context.GeneratedAssembly != null)\u003Cbr>    {\u003Cbr>                Type scriptModule = context.GeneratedAssembly.GetType(\"ScriptModule\");\u003Cbr>                MethodInfo stringManip = scriptModule.GetMethod(\"stringManip\");\u003Cbr>                string output = (string)stringManip.Invoke(null, new object[] { \"Tag\" } );\u003Cbr>                Console.WriteLine(output);\u003Cbr>            }\u003Cbr>            else\u003Cbr>            {\u003Cbr>                foreach (CompilerError error in context.Errors)\u003Cbr>                    Console.WriteLine(error);\u003Cbr>            }\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile runBoo.cs using csc.exe with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe \u002Fr:Boo.Lang.dll,Boo.Lang.Compiler.dll,Boo.Lang.Parser.dll \u002Ft:exe runBoo.cs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate the file runBoo.exe, the command to invoke script.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>runBoo.exe script.boo\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017969465_2_a1e1c3379a.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The following three DLLs must exist in the same directory as runBoo.exe:\u003C\u002Fp>\u003Cul>\u003Cli>Boo.Lang.dll\u003C\u002Fli>\u003Cli>Boo.Lang.Compiler.dll\u003C\u002Fli>\u003Cli>Boo.Lang.Parser.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The advantage of this method is that it can compile and run the Boolang script in memory. Corresponding to the example above, runBoo.exe compiles and runs script.boo in memory.\u003C\u002Fp>\u003Ch2>0x04 Implementation code for executing shellcode via the Boolang language\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Code from https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002F\u003C\u002Fp>\u003Ch3>1. Using C# to invoke Boolang scripts\u003C\u002Fh3>\u003Cp>The following two code files are required:\u003C\u002Fp>\u003Ch4>(1) runBoo.cs\u003C\u002Fh4>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002Fblob\u002Fmaster\u002FrunBoo.cs\u003C\u002Fp>\u003Cp>The structure is basically the same as runBoo.cs in 0x04-5\u003C\u002Fp>\u003Cp>Stores 32-bit and 64-bit shellcode separately in arrays\u003C\u002Fp>\u003Cp>The first command-line argument is the passed Boolang script file\u003C\u002Fp>\u003Cp>The second command-line argument is the method for injecting shellcode\u003C\u002Fp>\u003Ch4>(2) shellcode.boo\u003C\u002Fh4>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002Fblob\u002Fmaster\u002Fshellcode.boo\u003C\u002Fp>\u003Cp>Boolang script, supporting the following three injection methods:\u003C\u002Fp>\u003Cul>\u003Cli>InjectQueueUserAPC, injects into the explorer.exe process via QueueUserAPC\u003C\u002Fli>\u003Cli>InjectSelf, injects into the current process via CreateThread\u003C\u002Fli>\u003Cli>InjectRemote, injects into the explorer.exe process via CreateRemoteThread\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Specific usage is as follows:\u003C\u002Fp>\u003Ch4>(1) Compile runBoo.cs using csc.exe\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe \u002Fr:Boo.Lang.Compiler.dll,Boo.Lang.dll,Boo.Lang.Parser.dll \u002Ft:exe runBoo.cs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate the file runBoo.exe\u003C\u002Fp>\u003Ch4>(2) Test functionality\u003C\u002Fh4>\u003Cp>Available commands are as follows:\u003C\u002Fp>\u003Col>\u003Cli>runBoo.exe shellcode.boo InjectQueueUserAPC\u003C\u002Fli>\u003Cli>runBoo.exe shellcode.boo InjectSelf\u003C\u002Fli>\u003Cli>runBoo.exe shellcode.boo InjectRemote\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The following three DLLs must exist in the same directory as runBoo.exe:\u003C\u002Fp>\u003Cul>\u003Cli>Boo.Lang.dll\u003C\u002Fli>\u003Cli>Boo.Lang.Compiler.dll\u003C\u002Fli>\u003Cli>Boo.Lang.Parser.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Solution 1:\u003C\u002Fp>\u003Cp>Using ILMerge\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fboo-lang\u002Fboo\u002Fwiki\u002FMerge-Boo.Lang.dll-into-your-exe-or-dll\u003C\u002Fp>\u003Ch3>2. Using PowerShell to invoke Boo language scripts\u003C\u002Fh3>\u003Cp>Requires the following two code files:\u003C\u002Fp>\u003Ch4>(1) Invoke-JumpScare.ps1\u003C\u002Fh4>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002Fblob\u002Fmaster\u002FInvoke-JumpScare.ps1\u003C\u002Fp>\u003Cp>Functionally equivalent to runBoo.cs, but loads the required three DLLs (Boo.Lang.dll, Boo.Lang.Compiler.dll, Boo.Lang.Parser.dll) via reflection, eliminating the need for these three DLL files in the same directory\u003C\u002Fp>\u003Cp>No need to use csc.exe for compilation, no intermediate files generated\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Boo language script content can be stored in a variable, eliminating the need for an additional Boo script file; all functionality can be contained within a single PowerShell file\u003C\u002Fp>\u003Ch4>(2) shellcode.boo\u003C\u002Fh4>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002Fblob\u002Fmaster\u002Fshellcode.boo\u003C\u002Fp>\u003Cp>Content as above\u003C\u002Fp>\u003Cp>Actual test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017975943_3_db12d09d3f.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Compared to the open-source Boolang code, the code open-sourced by byt3bl33d3r adds the following features:\u003C\u002Fp>\u003Cul>\u003Cli>Supports PowerShell invocation, eliminating the need to compile with csc.exe. The Boolang script is dynamically compiled and executed just-in-time, using reflection to load the required three DLLs without dependency on them.\u003C\u002Fli>\u003Cli>Added functionality to execute shellcode.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>This exploitation method has the following advantages:\u003C\u002Fp>\u003Cp>Using the Boolang language to execute shellcode, the startup code (PowerShell script) does not include malicious functionality; the payload can be stored in another script file.\u003C\u002Fp>\u003Cp>Simple understanding:\u003C\u002Fp>\u003Cp>Developed a PowerShell-format script interpreter via the Boolang language, capable of dynamically loading code from another script file in memory.\u003C\u002Fp>\u003Ch2>0x06 Defense and Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A similar method was introduced in a previous article, 'Penetration Techniques – Use AutoIt script to create a keylogger,' which also involves launching code from another script file via a script interpreter, so the defense and detection methods are similar.\u003C\u002Fp>\u003Cp>Given the exploitation methods, we typically encounter the following scenarios during detection: the launcher and payload are separated, making static detection difficult.\u003C\u002Fp>\u003Cp>However, this technique cannot bypass detection of program behavior, so defense can be achieved by monitoring process behavior.\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the characteristics and usage of the Boolang language, analyzes the advantages of executing shellcode via Boolang based on byt3bl33d3r's open-source code, and provides recommendations for defensive detection.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>\u003C\u002Fscript>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Exploitation Analysis of SILENTTRINITY', I learned the method of loading payloads from memory using the C# IronPython engine. On byt3bl33d3r's GitHub, I came across code that executes shellcode using the Boolang language, prompting me to research this technique.\u003C\u002Fp>\u003Cp>This article will introduce the characteristics and usage of the Boolang language, analyze the advantages of executing shellcode via Boolang, and provide recommendations for defensive detection.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to the Boolang Language\u003C\u002Fli>\u003Cli>Usage of the Boolang Language\u003C\u002Fli>\u003Cli>Implementation Code for Executing Shellcode via Boolang Language\u003C\u002Fli>\u003Cli>Exploitation Analysis\u003C\u002Fli>\u003Cli>Defensive Detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Boolang Language\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Learning Materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fboo-lang\u002Fboo\u003C\u002Fp>\u003Cp>Boolang is an object-oriented language that combines Python's syntax, Ruby's functionality, and C#'s speed and security\u003C\u002Fp>\u003Cp>Features include:\u003C\u002Fp>\u003Cul>\u003Cli>Syntax is very close to Python, user-friendly\u003C\u002Fli>\u003Cli>Statically typed, more secure compared to dynamically typed Python\u003C\u002Fli>\u003Cli>Extensible compiler, can run on .NET Framework or Mono\u003C\u002Fli>\u003Cli>Open source code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Usage of Boolang Language\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>First, you need to download the compiled Boolang files from the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fboo-lang\u002Fboo\u002Freleases\u003C\u002Fp>\u003Cp>The files include the following three executable programs:\u003C\u002Fp>\u003Col>\u003Cli>booi.exe, used for executing scripts\u003C\u002Fli>\u003Cli>booish.exe, a real-time compiler program, convenient for testing code\u003C\u002Fli>\u003Cli>booc.exe, used for compiling scripts\u003C\u002Fli>\u003C\u002Fol>\u003Cp>The specific usage is as follows:\u003C\u002Fp>\u003Ch3>1. Use booi.exe to execute Boolang scripts\u003C\u002Fh3>\u003Cp>The content of test.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>print \"Hello, World!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>booi.exe test.boo\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017955039_0_215513d0e8-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Use booish.exe for real-time compilation\u003C\u002Fh3>\u003Cp>Start booish.exe, enter the following code in the command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>print \"Hello, World!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017966004_1_e478de3f93-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Use booc.exe to compile Boolang scripts\u003C\u002Fh3>\u003Cp>The content of test.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>print \"Hello, World!\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Cp>enter code herebooc -output:test.exe test.boo\u003C\u002Fp>\u003Cp>Generate the file test.exe\u003C\u002Fp>\u003Ch3>4. Compile Boolang script using booc.exe (using Boo.Lang.Compiler API)\u003C\u002Fh3>\u003Cp>The content of test.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import Boo.Lang.Compiler\u003Cbr>import Boo.Lang.Compiler.IO\u003Cbr>import Boo.Lang.Compiler.Pipelines\u003Cbr>\u003Cbr>compiler = BooCompiler()\u003Cbr>compiler.Parameters.Input.Add(StringInput(\"\u003Cscript>\", \"print('Hello!')\"))\u003Cbr>compiler.Parameters.Pipeline = Run()\u003Cbr>\u003Cbr>compiler.Run()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>booc -output:test.exe test.boo\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate file test.exe\u003C\u002Fp>\u003Ch3>5. Using C# to call BooLang script\u003C\u002Fh3>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fboo-lang\u002Fboo\u002Fwiki\u002FScripting-with-the-Boo.Lang.Compiler-API\u003C\u002Fp>\u003Cp>The content of script.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>static def stringManip(item as string): \u002F\u002Fstatic lets us invoke this method without needing to instantiate a class.\u003Cbr>\treturn \"'${item}'? What the hell are you talking about?\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The content of runBoo.cs is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>using System;\u003Cbr>using System.Text;\u003Cbr>using System.Reflection;\u003Cbr>\u003Cbr>using Boo.Lang.Compiler;\u003Cbr>using Boo.Lang.Compiler.IO;\u003Cbr>using Boo.Lang.Compiler.Pipelines;\u003Cbr>namespace ConsoleApplication1\u003Cbr>{\u003Cbr>    class Program\u003Cbr>    {\u003Cbr>        static void Main(string[] args)\u003Cbr>        {\u003Cbr>            BooCompiler compiler = new BooCompiler();\u003Cbr>            compiler.Parameters.Input.Add(new FileInput(\"script.boo\"));\u003Cbr>            compiler.Parameters.Pipeline = new CompileToMemory();\u003Cbr>            compiler.Parameters.Ducky = true;\u003Cbr>\u003Cbr>            CompilerContext context = compiler.Run();\u003Cbr>            \u002F\u002FNote that the following code might throw an error if the Boo script had bugs.\u003Cbr>            \u002F\u002FPoke context.Errors to make sure.\u003Cbr>            if (context.GeneratedAssembly != null)\u003Cbr>    {\u003Cbr>                Type scriptModule = context.GeneratedAssembly.GetType(\"ScriptModule\");\u003Cbr>                MethodInfo stringManip = scriptModule.GetMethod(\"stringManip\");\u003Cbr>                string output = (string)stringManip.Invoke(null, new object[] { \"Tag\" } );\u003Cbr>                Console.WriteLine(output);\u003Cbr>            }\u003Cbr>            else\u003Cbr>            {\u003Cbr>                foreach (CompilerError error in context.Errors)\u003Cbr>                    Console.WriteLine(error);\u003Cbr>            }\u003Cbr>        }\u003Cbr>    }\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile runBoo.cs using csc.exe with the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe \u002Fr:Boo.Lang.dll,Boo.Lang.Compiler.dll,Boo.Lang.Parser.dll \u002Ft:exe runBoo.cs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate the file runBoo.exe, the command to invoke script.boo is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>runBoo.exe script.boo\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017969465_2_a1e1c3379a-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The following three DLLs must exist in the same directory as runBoo.exe:\u003C\u002Fp>\u003Cul>\u003Cli>Boo.Lang.dll\u003C\u002Fli>\u003Cli>Boo.Lang.Compiler.dll\u003C\u002Fli>\u003Cli>Boo.Lang.Parser.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The advantage of this method is that it can compile and run the Boolang script in memory. Corresponding to the example above, runBoo.exe compiles and runs script.boo in memory.\u003C\u002Fp>\u003Ch2>0x04 Implementation code for executing shellcode via the Boolang language\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Code from https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002F\u003C\u002Fp>\u003Ch3>1. Using C# to invoke Boolang scripts\u003C\u002Fh3>\u003Cp>The following two code files are required:\u003C\u002Fp>\u003Ch4>(1) runBoo.cs\u003C\u002Fh4>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002Fblob\u002Fmaster\u002FrunBoo.cs\u003C\u002Fp>\u003Cp>The structure is basically the same as runBoo.cs in 0x04-5\u003C\u002Fp>\u003Cp>Stores 32-bit and 64-bit shellcode separately in arrays\u003C\u002Fp>\u003Cp>The first command-line argument is the passed Boolang script file\u003C\u002Fp>\u003Cp>The second command-line argument is the method for injecting shellcode\u003C\u002Fp>\u003Ch4>(2) shellcode.boo\u003C\u002Fh4>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002Fblob\u002Fmaster\u002Fshellcode.boo\u003C\u002Fp>\u003Cp>Boolang script, supporting the following three injection methods:\u003C\u002Fp>\u003Cul>\u003Cli>InjectQueueUserAPC, injects into the explorer.exe process via QueueUserAPC\u003C\u002Fli>\u003Cli>InjectSelf, injects into the current process via CreateThread\u003C\u002Fli>\u003Cli>InjectRemote, injects into the explorer.exe process via CreateRemoteThread\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Specific usage is as follows:\u003C\u002Fp>\u003Ch4>(1) Compile runBoo.cs using csc.exe\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe \u002Fr:Boo.Lang.Compiler.dll,Boo.Lang.dll,Boo.Lang.Parser.dll \u002Ft:exe runBoo.cs\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate the file runBoo.exe\u003C\u002Fp>\u003Ch4>(2) Test functionality\u003C\u002Fh4>\u003Cp>Available commands are as follows:\u003C\u002Fp>\u003Col>\u003Cli>runBoo.exe shellcode.boo InjectQueueUserAPC\u003C\u002Fli>\u003Cli>runBoo.exe shellcode.boo InjectSelf\u003C\u002Fli>\u003Cli>runBoo.exe shellcode.boo InjectRemote\u003C\u002Fli>\u003C\u002Fol>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The following three DLLs must exist in the same directory as runBoo.exe:\u003C\u002Fp>\u003Cul>\u003Cli>Boo.Lang.dll\u003C\u002Fli>\u003Cli>Boo.Lang.Compiler.dll\u003C\u002Fli>\u003Cli>Boo.Lang.Parser.dll\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Solution 1:\u003C\u002Fp>\u003Cp>Using ILMerge\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fboo-lang\u002Fboo\u002Fwiki\u002FMerge-Boo.Lang.dll-into-your-exe-or-dll\u003C\u002Fp>\u003Ch3>2. Using PowerShell to invoke Boo language scripts\u003C\u002Fh3>\u003Cp>Requires the following two code files:\u003C\u002Fp>\u003Ch4>(1) Invoke-JumpScare.ps1\u003C\u002Fh4>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002Fblob\u002Fmaster\u002FInvoke-JumpScare.ps1\u003C\u002Fp>\u003Cp>Functionally equivalent to runBoo.cs, but loads the required three DLLs (Boo.Lang.dll, Boo.Lang.Compiler.dll, Boo.Lang.Parser.dll) via reflection, eliminating the need for these three DLL files in the same directory\u003C\u002Fp>\u003Cp>No need to use csc.exe for compilation, no intermediate files generated\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The Boo language script content can be stored in a variable, eliminating the need for an additional Boo script file; all functionality can be contained within a single PowerShell file\u003C\u002Fp>\u003Ch4>(2) shellcode.boo\u003C\u002Fh4>\u003Cp>Code location:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fbyt3bl33d3r\u002FOffensiveDLR\u002Fblob\u002Fmaster\u002Fshellcode.boo\u003C\u002Fp>\u003Cp>Content as above\u003C\u002Fp>\u003Cp>Actual test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017975943_3_db12d09d3f-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Compared to the open-source Boolang code, the code open-sourced by byt3bl33d3r adds the following features:\u003C\u002Fp>\u003Cul>\u003Cli>Supports PowerShell invocation, eliminating the need to compile with csc.exe. The Boolang script is dynamically compiled and executed just-in-time, using reflection to load the required three DLLs without dependency on them.\u003C\u002Fli>\u003Cli>Added functionality to execute shellcode.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>This exploitation method has the following advantages:\u003C\u002Fp>\u003Cp>Using the Boolang language to execute shellcode, the startup code (PowerShell script) does not include malicious functionality; the payload can be stored in another script file.\u003C\u002Fp>\u003Cp>Simple understanding:\u003C\u002Fp>\u003Cp>Developed a PowerShell-format script interpreter via the Boolang language, capable of dynamically loading code from another script file in memory.\u003C\u002Fp>\u003Ch2>0x06 Defense and Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A similar method was introduced in a previous article, 'Penetration Techniques – Use AutoIt script to create a keylogger,' which also involves launching code from another script file via a script interpreter, so the defense and detection methods are similar.\u003C\u002Fp>\u003Cp>Given the exploitation methods, we typically encounter the following scenarios during detection: the launcher and payload are separated, making static detection difficult.\u003C\u002Fp>\u003Cp>However, this technique cannot bypass detection of program behavior, so defense can be achieved by monitoring process behavior.\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the characteristics and usage of the Boolang language, analyzes the advantages of executing shellcode via Boolang based on byt3bl33d3r's open-source code, and provides recommendations for defensive detection.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>\u003C\u002Fscript>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fbody>\u003C\u002Fhtml>",1074,"Onedaysec",5,"published","2026-02-02T07:51:00.064Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Exploiting Shellcode via Boolang Language: Analysis & Defense","Boolang language, shellcode execution, exploitation analysis, defensive detection, C# IronPython, memory loading, cybersecurity",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],510,509,508,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.974Z","2026-07-23T16:01:40.435Z","draft","2026-07-23T16:12:50.841Z"]