feat comm init win10-win11
This commit is contained in:
@@ -0,0 +1,45 @@
|
||||
#include "comm.h"
|
||||
#include "utils.h"
|
||||
#include "comm_win10.h"
|
||||
#include "comm_win7.h"
|
||||
|
||||
namespace kernel_comm_create
|
||||
{
|
||||
auto Init() -> BOOL
|
||||
{
|
||||
auto version = utils::GetVersion();
|
||||
if (version.dwBuildNumber == 7600 || version.dwBuildNumber == 7601)
|
||||
{
|
||||
//win7
|
||||
if (comm_win7::comm_init())
|
||||
{
|
||||
return comm_win7::comm_install_hook();
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
//win10
|
||||
if (comm_win10::comm_init())
|
||||
{
|
||||
return comm_win10::comm_install_hook();
|
||||
}
|
||||
}
|
||||
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
auto remove() -> BOOL
|
||||
{
|
||||
auto version = utils::GetVersion();
|
||||
if (version.dwBuildNumber == 7600 || version.dwBuildNumber == 7601)
|
||||
{
|
||||
//win7
|
||||
return comm_win7::comm_remov_hook();
|
||||
}
|
||||
else
|
||||
{
|
||||
return comm_win10::comm_remov_hook();
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,10 @@
|
||||
#pragma once
|
||||
#include "Base.h"
|
||||
|
||||
namespace kernel_comm_create
|
||||
{
|
||||
auto Init()->BOOL;
|
||||
|
||||
auto remove()->BOOL;
|
||||
|
||||
}
|
||||
@@ -0,0 +1,29 @@
|
||||
#include "comm_dispatch.h"
|
||||
#include "protect_filter.h"
|
||||
|
||||
namespace comm_dispatch
|
||||
{
|
||||
auto dispatch(CMD_COMM* data) -> NTSTATUS
|
||||
{
|
||||
auto status = STATUS_UNSUCCESSFUL;
|
||||
switch (data->CommID)
|
||||
{
|
||||
case CMD::DRIVER_COMM_TEST:
|
||||
{
|
||||
status = STATUS_SUCCESS;
|
||||
break;
|
||||
}
|
||||
case CMD::DRIVER_PROTECT_PROCESS:
|
||||
{
|
||||
status = protect_filter::add_list((ULONG)data->Pid, NULL);
|
||||
break;
|
||||
}
|
||||
default:
|
||||
break;
|
||||
}
|
||||
|
||||
*(NTSTATUS*)data->status = status;
|
||||
return status;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,21 @@
|
||||
#pragma once
|
||||
#include "Base.h"
|
||||
|
||||
struct CMD_COMM
|
||||
{
|
||||
DWORD64 CommID;
|
||||
DWORD64 Pid;
|
||||
DWORD64 status;
|
||||
};
|
||||
|
||||
enum CMD
|
||||
{
|
||||
MSG_BASE = 0x10000,
|
||||
DRIVER_COMM_TEST,
|
||||
DRIVER_PROTECT_PROCESS
|
||||
};
|
||||
|
||||
namespace comm_dispatch
|
||||
{
|
||||
auto dispatch(CMD_COMM* data)->NTSTATUS;
|
||||
}
|
||||
@@ -0,0 +1,75 @@
|
||||
#include "comm_win10.h"
|
||||
#include "comm_dispatch.h"
|
||||
#include "utils.h"
|
||||
#include "kernel_function.h"
|
||||
#pragma warning(disable : 4309)
|
||||
#pragma warning(disable : 4838)
|
||||
|
||||
typedef NTSTATUS(__fastcall* fnHalpTimerConvertAuxiliaryCounterToPerformanceCounter)(PVOID, PVOID, PVOID);
|
||||
fnHalpTimerConvertAuxiliaryCounterToPerformanceCounter _HalpTimerConvertAuxiliaryCounterToPerformanceCounter = 0;
|
||||
|
||||
uintptr_t beep_trampoline_ptr;
|
||||
uintptr_t func_call_address;
|
||||
|
||||
namespace comm_win10
|
||||
{
|
||||
auto comm_callback(PVOID a1, PVOID a2, PVOID a3) -> NTSTATUS
|
||||
{
|
||||
comm_dispatch::dispatch((CMD_COMM*)a1);
|
||||
return _HalpTimerConvertAuxiliaryCounterToPerformanceCounter(a1, a2, a3);
|
||||
}
|
||||
|
||||
auto comm_init() -> BOOL
|
||||
{
|
||||
beep_trampoline_ptr = utils::get_beep_trampoline_ptr();
|
||||
return !beep_trampoline_ptr ? FALSE : TRUE;
|
||||
}
|
||||
|
||||
auto comm_install_hook() -> BOOL
|
||||
{
|
||||
auto ntoskrnl = kernel_function::GetKernelModule("ntoskrnl.exe");
|
||||
if (!ntoskrnl)
|
||||
return FALSE;
|
||||
|
||||
// mov rax,comm_callback
|
||||
// jmp rax
|
||||
char jmprax[] = { 0x48, 0xB8, 0x13, 0x09, 0xFC, 0xD6, 0xFC, 0x7F, 0x00, 0x00, 0xFF, 0xE0 };
|
||||
*(uintptr_t*)&jmprax[2] = (uintptr_t)comm_callback;
|
||||
|
||||
auto status = kernel_function::MmMDLPagesCopy((PVOID)beep_trampoline_ptr, &jmprax, sizeof(jmprax), 0x0000002, KernelMode);
|
||||
if (!NT_SUCCESS(status))
|
||||
return FALSE;
|
||||
|
||||
auto code_addr = utils::FindSectionsCode(ntoskrnl, "\x48\x8B\x05\x00\x00\x00\x00\x00\x00\x48\x8B\x05\x00\x00\x00\x00\xE8\x00\x00\x00\x00\x8B\xC8",
|
||||
"xxx??????xxx????x????xx", "PAGE");
|
||||
|
||||
func_call_address = (*(long*)(code_addr + 3)) + (code_addr + 7);
|
||||
_HalpTimerConvertAuxiliaryCounterToPerformanceCounter =
|
||||
*(fnHalpTimerConvertAuxiliaryCounterToPerformanceCounter*)(func_call_address);
|
||||
|
||||
*(uintptr_t*)func_call_address = beep_trampoline_ptr;
|
||||
|
||||
return TRUE;
|
||||
}
|
||||
auto comm_remov_hook() -> BOOL
|
||||
{
|
||||
if (!func_call_address)
|
||||
return FALSE;
|
||||
|
||||
*(uintptr_t*)func_call_address =
|
||||
(uintptr_t)_HalpTimerConvertAuxiliaryCounterToPerformanceCounter;
|
||||
|
||||
if (!beep_trampoline_ptr)
|
||||
return FALSE;
|
||||
|
||||
|
||||
char nullcode[12]{ 0 };
|
||||
auto status = kernel_function::MmMDLPagesCopy((PVOID)beep_trampoline_ptr, &nullcode, sizeof(nullcode), 0x0000002, KernelMode);
|
||||
if (!NT_SUCCESS(status))
|
||||
return FALSE;
|
||||
|
||||
return TRUE;
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -0,0 +1,9 @@
|
||||
#pragma once
|
||||
#include "Base.h"
|
||||
|
||||
namespace comm_win10
|
||||
{
|
||||
auto comm_init()->BOOL;
|
||||
auto comm_install_hook()->BOOL;
|
||||
auto comm_remov_hook()->BOOL;
|
||||
}
|
||||
@@ -0,0 +1,81 @@
|
||||
#include "comm_win7.h"
|
||||
#include "comm_dispatch.h"
|
||||
#include "utils.h"
|
||||
#include "kernel_function.h"
|
||||
|
||||
#pragma warning(disable : 4309)
|
||||
#pragma warning(disable : 4838)
|
||||
|
||||
PFILE_OBJECT file_obj{ 0 };
|
||||
PDEVICE_OBJECT device_obj{ 0 };
|
||||
|
||||
LPVOID orign_maj_function = nullptr;
|
||||
|
||||
namespace comm_win7
|
||||
{
|
||||
auto comm_init() -> BOOL
|
||||
{
|
||||
UNICODE_STRING unName{ 0 };
|
||||
RtlInitUnicodeString(&unName, L"\\Device\\Null");
|
||||
auto status = IoGetDeviceObjectPointer(&unName, FILE_ALL_ACCESS, &file_obj, &device_obj);
|
||||
if (!NT_SUCCESS(status))
|
||||
return FALSE;
|
||||
|
||||
ObDereferenceObject(file_obj);
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
auto dispatch_device_io(PDEVICE_OBJECT drvice_object, PIRP irp)->NTSTATUS
|
||||
{
|
||||
UNREFERENCED_PARAMETER(drvice_object);
|
||||
|
||||
auto comm_buf_data = reinterpret_cast<CMD_COMM*>(irp->AssociatedIrp.SystemBuffer);
|
||||
|
||||
auto status = comm_dispatch::dispatch(comm_buf_data);
|
||||
|
||||
irp->IoStatus.Information = sizeof(CMD_COMM);
|
||||
irp->IoStatus.Status = status;
|
||||
IoCompleteRequest(irp, IO_NO_INCREMENT);
|
||||
return status;
|
||||
};
|
||||
|
||||
auto comm_install_hook() -> BOOL
|
||||
{
|
||||
auto drv_obj = device_obj->DriverObject;
|
||||
if (!drv_obj)
|
||||
return FALSE;
|
||||
|
||||
orign_maj_function = drv_obj->MajorFunction[IRP_MJ_DEVICE_CONTROL];
|
||||
|
||||
auto beep_trampoline = utils::get_beep_trampoline_ptr();
|
||||
if (!beep_trampoline)
|
||||
return FALSE;
|
||||
|
||||
//mov rax,dispatch_device_io
|
||||
//jmp rax
|
||||
char jmprax[] = { 0x48, 0xB8, 0xA0, 0x9A, 0xD5, 0x3E, 0xFE, 0x7F, 0x00, 0x00, 0xFF, 0xE0 };
|
||||
|
||||
*(uintptr_t*)&jmprax[2] = (uintptr_t)dispatch_device_io;
|
||||
kernel_function::MmMDLPagesCopy((PVOID)beep_trampoline, &jmprax, sizeof(jmprax), 0x0000002, KernelMode);
|
||||
|
||||
drv_obj->MajorFunction[IRP_MJ_DEVICE_CONTROL] = (PDRIVER_DISPATCH)beep_trampoline/*Ö±½Ó¾ÍÊÇÄãµÄº¯Êý*/;
|
||||
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
auto comm_remov_hook() -> BOOL
|
||||
{
|
||||
auto drv_obj = device_obj->DriverObject;
|
||||
if (!drv_obj)
|
||||
return FALSE;
|
||||
|
||||
if (drv_obj->MajorFunction[IRP_MJ_DEVICE_CONTROL])
|
||||
{
|
||||
drv_obj->MajorFunction[IRP_MJ_DEVICE_CONTROL] =
|
||||
(PDRIVER_DISPATCH)orign_maj_function;
|
||||
}
|
||||
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,12 @@
|
||||
#pragma once
|
||||
#include "Base.h"
|
||||
|
||||
namespace comm_win7
|
||||
{
|
||||
auto comm_init()->BOOL;
|
||||
|
||||
auto comm_install_hook()->BOOL;
|
||||
|
||||
auto comm_remov_hook()->BOOL;
|
||||
|
||||
}
|
||||
Reference in New Issue
Block a user