fix disable fail
This commit is contained in:
@@ -152,13 +152,20 @@
|
|||||||
<ClCompile Include="comm_win7.cpp" />
|
<ClCompile Include="comm_win7.cpp" />
|
||||||
<ClCompile Include="create_thread_callback.cpp" />
|
<ClCompile Include="create_thread_callback.cpp" />
|
||||||
<ClCompile Include="driver_main.cpp" />
|
<ClCompile Include="driver_main.cpp" />
|
||||||
|
<ClCompile Include="hde\hde64.cpp" />
|
||||||
|
<ClCompile Include="inline_hooks.cpp" />
|
||||||
<ClCompile Include="io_ctl.cpp" />
|
<ClCompile Include="io_ctl.cpp" />
|
||||||
<ClCompile Include="kernel_api.cpp" />
|
<ClCompile Include="kernel_api.cpp" />
|
||||||
<ClCompile Include="kernel_function.cpp" />
|
<ClCompile Include="kernel_function.cpp" />
|
||||||
<ClCompile Include="load_Image_callback.cpp" />
|
<ClCompile Include="load_Image_callback.cpp" />
|
||||||
|
<ClCompile Include="mouse_keybord_hook.cpp" />
|
||||||
|
<ClCompile Include="mouse_key_win10.cpp" />
|
||||||
|
<ClCompile Include="mouse_key_win7.cpp" />
|
||||||
<ClCompile Include="ob_reg_callback.cpp" />
|
<ClCompile Include="ob_reg_callback.cpp" />
|
||||||
<ClCompile Include="process_func.cpp" />
|
<ClCompile Include="process_func.cpp" />
|
||||||
|
<ClCompile Include="process_notify_callback.cpp" />
|
||||||
<ClCompile Include="protect_filter.cpp" />
|
<ClCompile Include="protect_filter.cpp" />
|
||||||
|
<ClCompile Include="shadow_ssdt.cpp" />
|
||||||
<ClCompile Include="utils.cpp" />
|
<ClCompile Include="utils.cpp" />
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
<ItemGroup>
|
<ItemGroup>
|
||||||
@@ -169,13 +176,23 @@
|
|||||||
<ClInclude Include="comm_win10.h" />
|
<ClInclude Include="comm_win10.h" />
|
||||||
<ClInclude Include="comm_win7.h" />
|
<ClInclude Include="comm_win7.h" />
|
||||||
<ClInclude Include="create_thread_callback.h" />
|
<ClInclude Include="create_thread_callback.h" />
|
||||||
|
<ClInclude Include="hde\hde64.h" />
|
||||||
|
<ClInclude Include="hde\headers.hpp" />
|
||||||
|
<ClInclude Include="hde\pstdint.h" />
|
||||||
|
<ClInclude Include="hde\table64.h" />
|
||||||
|
<ClInclude Include="inline_hooks.h" />
|
||||||
<ClInclude Include="io_ctl.h" />
|
<ClInclude Include="io_ctl.h" />
|
||||||
<ClInclude Include="kernel_api.h" />
|
<ClInclude Include="kernel_api.h" />
|
||||||
<ClInclude Include="kernel_function.h" />
|
<ClInclude Include="kernel_function.h" />
|
||||||
<ClInclude Include="load_Image_callback.h" />
|
<ClInclude Include="load_Image_callback.h" />
|
||||||
|
<ClInclude Include="mouse_keybord_hook.h" />
|
||||||
|
<ClInclude Include="mouse_key_win10.h" />
|
||||||
|
<ClInclude Include="mouse_key_win7.h" />
|
||||||
<ClInclude Include="ob_reg_callback.h" />
|
<ClInclude Include="ob_reg_callback.h" />
|
||||||
<ClInclude Include="process_func.h" />
|
<ClInclude Include="process_func.h" />
|
||||||
|
<ClInclude Include="process_notify_callback.h" />
|
||||||
<ClInclude Include="protect_filter.h" />
|
<ClInclude Include="protect_filter.h" />
|
||||||
|
<ClInclude Include="shadow_ssdt.h" />
|
||||||
<ClInclude Include="utils.h" />
|
<ClInclude Include="utils.h" />
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
|
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
|
||||||
|
|||||||
@@ -19,9 +19,6 @@
|
|||||||
<Filter Include="kernel_extern_api">
|
<Filter Include="kernel_extern_api">
|
||||||
<UniqueIdentifier>{b3f98251-c1bf-4bd0-a5bd-d5425c272a5e}</UniqueIdentifier>
|
<UniqueIdentifier>{b3f98251-c1bf-4bd0-a5bd-d5425c272a5e}</UniqueIdentifier>
|
||||||
</Filter>
|
</Filter>
|
||||||
<Filter Include="Iocontrol">
|
|
||||||
<UniqueIdentifier>{1373c16e-e769-4553-b7b9-0f87b2f6ab0e}</UniqueIdentifier>
|
|
||||||
</Filter>
|
|
||||||
<Filter Include="Resource Files">
|
<Filter Include="Resource Files">
|
||||||
<UniqueIdentifier>{67DA6AB6-F800-4c08-8B7A-83BB121AAD01}</UniqueIdentifier>
|
<UniqueIdentifier>{67DA6AB6-F800-4c08-8B7A-83BB121AAD01}</UniqueIdentifier>
|
||||||
<Extensions>rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms</Extensions>
|
<Extensions>rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms</Extensions>
|
||||||
@@ -41,6 +38,27 @@
|
|||||||
<Filter Include="comm">
|
<Filter Include="comm">
|
||||||
<UniqueIdentifier>{39d8ef92-d541-4aee-9850-0a3d878333dc}</UniqueIdentifier>
|
<UniqueIdentifier>{39d8ef92-d541-4aee-9850-0a3d878333dc}</UniqueIdentifier>
|
||||||
</Filter>
|
</Filter>
|
||||||
|
<Filter Include="comm\Iocontrol">
|
||||||
|
<UniqueIdentifier>{1373c16e-e769-4553-b7b9-0f87b2f6ab0e}</UniqueIdentifier>
|
||||||
|
</Filter>
|
||||||
|
<Filter Include="utils\hde">
|
||||||
|
<UniqueIdentifier>{eb37b22e-76b8-4afe-9adb-bc5b6842ee98}</UniqueIdentifier>
|
||||||
|
</Filter>
|
||||||
|
<Filter Include="Hooks">
|
||||||
|
<UniqueIdentifier>{ea698d6c-d13f-4cc1-9129-3f8e935ee10d}</UniqueIdentifier>
|
||||||
|
</Filter>
|
||||||
|
<Filter Include="Hooks\InlineHook">
|
||||||
|
<UniqueIdentifier>{c6d3ba67-35ff-487d-b42b-beaf95752ea6}</UniqueIdentifier>
|
||||||
|
</Filter>
|
||||||
|
<Filter Include="mouse_keyboard">
|
||||||
|
<UniqueIdentifier>{d29bdd3e-0035-4cad-a658-7b272bd7d199}</UniqueIdentifier>
|
||||||
|
</Filter>
|
||||||
|
<Filter Include="kernel_extern_api\SSDT">
|
||||||
|
<UniqueIdentifier>{14cf9a07-d604-4163-8bfc-ded4b6e62df5}</UniqueIdentifier>
|
||||||
|
</Filter>
|
||||||
|
<Filter Include="kernel_extern_api\ShadowSSDT">
|
||||||
|
<UniqueIdentifier>{4f8c4f4e-0ff6-4cfa-804b-27bd50fca679}</UniqueIdentifier>
|
||||||
|
</Filter>
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
<ItemGroup>
|
<ItemGroup>
|
||||||
<ClCompile Include="driver_main.cpp">
|
<ClCompile Include="driver_main.cpp">
|
||||||
@@ -53,7 +71,7 @@
|
|||||||
<Filter>kernel_extern_api</Filter>
|
<Filter>kernel_extern_api</Filter>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
<ClCompile Include="io_ctl.cpp">
|
<ClCompile Include="io_ctl.cpp">
|
||||||
<Filter>Iocontrol</Filter>
|
<Filter>comm\Iocontrol</Filter>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
<ClCompile Include="utils.cpp">
|
<ClCompile Include="utils.cpp">
|
||||||
<Filter>utils</Filter>
|
<Filter>utils</Filter>
|
||||||
@@ -88,6 +106,27 @@
|
|||||||
<ClCompile Include="comm.cpp">
|
<ClCompile Include="comm.cpp">
|
||||||
<Filter>comm</Filter>
|
<Filter>comm</Filter>
|
||||||
</ClCompile>
|
</ClCompile>
|
||||||
|
<ClCompile Include="process_notify_callback.cpp">
|
||||||
|
<Filter>kernel_callback</Filter>
|
||||||
|
</ClCompile>
|
||||||
|
<ClCompile Include="hde\hde64.cpp">
|
||||||
|
<Filter>utils\hde</Filter>
|
||||||
|
</ClCompile>
|
||||||
|
<ClCompile Include="inline_hooks.cpp">
|
||||||
|
<Filter>Hooks\InlineHook</Filter>
|
||||||
|
</ClCompile>
|
||||||
|
<ClCompile Include="mouse_keybord_hook.cpp">
|
||||||
|
<Filter>mouse_keyboard</Filter>
|
||||||
|
</ClCompile>
|
||||||
|
<ClCompile Include="shadow_ssdt.cpp">
|
||||||
|
<Filter>kernel_extern_api\ShadowSSDT</Filter>
|
||||||
|
</ClCompile>
|
||||||
|
<ClCompile Include="mouse_key_win10.cpp">
|
||||||
|
<Filter>mouse_keyboard</Filter>
|
||||||
|
</ClCompile>
|
||||||
|
<ClCompile Include="mouse_key_win7.cpp">
|
||||||
|
<Filter>mouse_keyboard</Filter>
|
||||||
|
</ClCompile>
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
<ItemGroup>
|
<ItemGroup>
|
||||||
<ClInclude Include="Base.h">
|
<ClInclude Include="Base.h">
|
||||||
@@ -100,7 +139,7 @@
|
|||||||
<Filter>kernel_extern_api</Filter>
|
<Filter>kernel_extern_api</Filter>
|
||||||
</ClInclude>
|
</ClInclude>
|
||||||
<ClInclude Include="io_ctl.h">
|
<ClInclude Include="io_ctl.h">
|
||||||
<Filter>Iocontrol</Filter>
|
<Filter>comm\Iocontrol</Filter>
|
||||||
</ClInclude>
|
</ClInclude>
|
||||||
<ClInclude Include="utils.h">
|
<ClInclude Include="utils.h">
|
||||||
<Filter>utils</Filter>
|
<Filter>utils</Filter>
|
||||||
@@ -135,5 +174,35 @@
|
|||||||
<ClInclude Include="comm.h">
|
<ClInclude Include="comm.h">
|
||||||
<Filter>comm</Filter>
|
<Filter>comm</Filter>
|
||||||
</ClInclude>
|
</ClInclude>
|
||||||
|
<ClInclude Include="process_notify_callback.h">
|
||||||
|
<Filter>kernel_callback</Filter>
|
||||||
|
</ClInclude>
|
||||||
|
<ClInclude Include="hde\hde64.h">
|
||||||
|
<Filter>utils\hde</Filter>
|
||||||
|
</ClInclude>
|
||||||
|
<ClInclude Include="hde\headers.hpp">
|
||||||
|
<Filter>utils\hde</Filter>
|
||||||
|
</ClInclude>
|
||||||
|
<ClInclude Include="hde\pstdint.h">
|
||||||
|
<Filter>utils\hde</Filter>
|
||||||
|
</ClInclude>
|
||||||
|
<ClInclude Include="hde\table64.h">
|
||||||
|
<Filter>utils\hde</Filter>
|
||||||
|
</ClInclude>
|
||||||
|
<ClInclude Include="inline_hooks.h">
|
||||||
|
<Filter>Hooks\InlineHook</Filter>
|
||||||
|
</ClInclude>
|
||||||
|
<ClInclude Include="mouse_keybord_hook.h">
|
||||||
|
<Filter>mouse_keyboard</Filter>
|
||||||
|
</ClInclude>
|
||||||
|
<ClInclude Include="shadow_ssdt.h">
|
||||||
|
<Filter>kernel_extern_api\ShadowSSDT</Filter>
|
||||||
|
</ClInclude>
|
||||||
|
<ClInclude Include="mouse_key_win10.h">
|
||||||
|
<Filter>mouse_keyboard</Filter>
|
||||||
|
</ClInclude>
|
||||||
|
<ClInclude Include="mouse_key_win7.h">
|
||||||
|
<Filter>mouse_keyboard</Filter>
|
||||||
|
</ClInclude>
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
</Project>
|
</Project>
|
||||||
@@ -2,8 +2,7 @@
|
|||||||
#include "comm_dispatch.h"
|
#include "comm_dispatch.h"
|
||||||
#include "utils.h"
|
#include "utils.h"
|
||||||
#include "kernel_function.h"
|
#include "kernel_function.h"
|
||||||
#pragma warning(disable : 4309)
|
#pragma warning(disable : 4309 4838)
|
||||||
#pragma warning(disable : 4838)
|
|
||||||
|
|
||||||
typedef NTSTATUS(__fastcall* fnHalpTimerConvertAuxiliaryCounterToPerformanceCounter)(PVOID, PVOID, PVOID);
|
typedef NTSTATUS(__fastcall* fnHalpTimerConvertAuxiliaryCounterToPerformanceCounter)(PVOID, PVOID, PVOID);
|
||||||
fnHalpTimerConvertAuxiliaryCounterToPerformanceCounter _HalpTimerConvertAuxiliaryCounterToPerformanceCounter = 0;
|
fnHalpTimerConvertAuxiliaryCounterToPerformanceCounter _HalpTimerConvertAuxiliaryCounterToPerformanceCounter = 0;
|
||||||
@@ -33,6 +32,7 @@ namespace comm_win10
|
|||||||
|
|
||||||
// mov rax,comm_callback
|
// mov rax,comm_callback
|
||||||
// jmp rax
|
// jmp rax
|
||||||
|
|
||||||
char jmprax[] = { 0x48, 0xB8, 0x13, 0x09, 0xFC, 0xD6, 0xFC, 0x7F, 0x00, 0x00, 0xFF, 0xE0 };
|
char jmprax[] = { 0x48, 0xB8, 0x13, 0x09, 0xFC, 0xD6, 0xFC, 0x7F, 0x00, 0x00, 0xFF, 0xE0 };
|
||||||
*(uintptr_t*)&jmprax[2] = (uintptr_t)comm_callback;
|
*(uintptr_t*)&jmprax[2] = (uintptr_t)comm_callback;
|
||||||
|
|
||||||
@@ -62,7 +62,6 @@ namespace comm_win10
|
|||||||
if (!beep_trampoline_ptr)
|
if (!beep_trampoline_ptr)
|
||||||
return FALSE;
|
return FALSE;
|
||||||
|
|
||||||
|
|
||||||
char nullcode[12]{ 0 };
|
char nullcode[12]{ 0 };
|
||||||
auto status = kernel_function::MmMDLPagesCopy((PVOID)beep_trampoline_ptr, &nullcode, sizeof(nullcode), 0x0000002, KernelMode);
|
auto status = kernel_function::MmMDLPagesCopy((PVOID)beep_trampoline_ptr, &nullcode, sizeof(nullcode), 0x0000002, KernelMode);
|
||||||
if (!NT_SUCCESS(status))
|
if (!NT_SUCCESS(status))
|
||||||
|
|||||||
@@ -1,8 +1,72 @@
|
|||||||
#include "ob_reg_callback.h"
|
#include "ob_reg_callback.h"
|
||||||
#include "create_thread_callback.h"
|
#include "create_thread_callback.h"
|
||||||
|
#include "process_notify_callback.h"
|
||||||
#include "protect_filter.h"
|
#include "protect_filter.h"
|
||||||
#include "comm.h"
|
#include "comm.h"
|
||||||
|
#include "inline_hooks.h"
|
||||||
|
#include "mouse_keybord_hook.h"
|
||||||
|
|
||||||
|
typedef NTSTATUS (NTAPI* fnNtOpenProcess)(
|
||||||
|
_Out_ PHANDLE ProcessHandle,
|
||||||
|
_In_ ACCESS_MASK DesiredAccess,
|
||||||
|
_In_ POBJECT_ATTRIBUTES ObjectAttributes,
|
||||||
|
_In_opt_ PCLIENT_ID ClientId);
|
||||||
|
|
||||||
|
typedef NTSTATUS(NTAPI* fnNtCreateFile)(
|
||||||
|
_Out_ PHANDLE FileHandle,
|
||||||
|
_In_ ACCESS_MASK DesiredAccess,
|
||||||
|
_In_ POBJECT_ATTRIBUTES ObjectAttributes,
|
||||||
|
_Out_ PIO_STATUS_BLOCK IoStatusBlock,
|
||||||
|
_In_opt_ PLARGE_INTEGER AllocationSize,
|
||||||
|
_In_ ULONG FileAttributes,
|
||||||
|
_In_ ULONG ShareAccess,
|
||||||
|
_In_ ULONG CreateDisposition,
|
||||||
|
_In_ ULONG CreateOptions,
|
||||||
|
_In_reads_bytes_opt_(EaLength) PVOID EaBuffer,
|
||||||
|
_In_ ULONG EaLength
|
||||||
|
);
|
||||||
|
|
||||||
|
|
||||||
|
fnNtOpenProcess origon_ntOpenProcess;
|
||||||
|
fnNtCreateFile origon_ntCreatFile;
|
||||||
|
|
||||||
|
NTSTATUS NTAPI hkNtOpenProcess(
|
||||||
|
_Out_ PHANDLE ProcessHandle,
|
||||||
|
_In_ ACCESS_MASK DesiredAccess,
|
||||||
|
_In_ POBJECT_ATTRIBUTES ObjectAttributes,
|
||||||
|
_In_opt_ PCLIENT_ID ClientId
|
||||||
|
)
|
||||||
|
{
|
||||||
|
|
||||||
|
DbgPrintEx(77, 0, "NtOpenProcess\n");
|
||||||
|
|
||||||
|
return origon_ntOpenProcess(ProcessHandle, DesiredAccess, ObjectAttributes, ClientId);
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
NTSTATUS
|
||||||
|
NTAPI
|
||||||
|
hkNtCreateFile(
|
||||||
|
_Out_ PHANDLE FileHandle,
|
||||||
|
_In_ ACCESS_MASK DesiredAccess,
|
||||||
|
_In_ POBJECT_ATTRIBUTES ObjectAttributes,
|
||||||
|
_Out_ PIO_STATUS_BLOCK IoStatusBlock,
|
||||||
|
_In_opt_ PLARGE_INTEGER AllocationSize,
|
||||||
|
_In_ ULONG FileAttributes,
|
||||||
|
_In_ ULONG ShareAccess,
|
||||||
|
_In_ ULONG CreateDisposition,
|
||||||
|
_In_ ULONG CreateOptions,
|
||||||
|
_In_reads_bytes_opt_(EaLength) PVOID EaBuffer,
|
||||||
|
_In_ ULONG EaLength
|
||||||
|
)
|
||||||
|
|
||||||
|
{
|
||||||
|
|
||||||
|
DbgPrintEx(77, 0, "NtCreateFile\n");
|
||||||
|
|
||||||
|
|
||||||
|
return origon_ntCreatFile(FileHandle, DesiredAccess, ObjectAttributes, IoStatusBlock, AllocationSize, FileAttributes, ShareAccess, CreateDisposition, CreateOptions, EaBuffer, EaLength);
|
||||||
|
}
|
||||||
|
|
||||||
EXTERN_C NTSTATUS DriverEntry(PDRIVER_OBJECT drv_obj, PUNICODE_STRING)
|
EXTERN_C NTSTATUS DriverEntry(PDRIVER_OBJECT drv_obj, PUNICODE_STRING)
|
||||||
{
|
{
|
||||||
@@ -12,16 +76,31 @@ EXTERN_C NTSTATUS DriverEntry(PDRIVER_OBJECT drv_obj, PUNICODE_STRING)
|
|||||||
{
|
{
|
||||||
kernel_comm_create::remove();
|
kernel_comm_create::remove();
|
||||||
ob_call_back::uninstall_ob_callback();
|
ob_call_back::uninstall_ob_callback();
|
||||||
//DbgPrintEx(77,0,"%x\n", thread_notify_routine::unload_thread_routine());
|
process_notify_callback::remov_process_notify();
|
||||||
|
thread_notify_routine::unload_thread_routine();
|
||||||
|
|
||||||
|
inline_hooks_manager::fn_get_instance()->inline_remov_hook((void**)NtOpenProcess);
|
||||||
|
inline_hooks_manager::fn_get_instance()->inline_remov_hook((void**)NtCreateFile);
|
||||||
|
|
||||||
|
mouse_keybord_hook::remove_mouse_keybord_hook();
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
kernel_api::kernel_api_init();
|
|
||||||
protect_filter::Init();
|
protect_filter::Init();
|
||||||
|
kernel_api::kernel_api_init();
|
||||||
kernel_comm_create::Init();
|
kernel_comm_create::Init();
|
||||||
|
|
||||||
|
|
||||||
|
//inline_hooks_manager::fn_get_instance()->inline_install_hook(NtOpenProcess, hkNtOpenProcess, (void**)&origon_ntOpenProcess);
|
||||||
|
//inline_hooks_manager::fn_get_instance()->inline_install_hook(NtCreateFile, hkNtCreateFile, (void**)&origon_ntCreatFile);
|
||||||
|
|
||||||
|
|
||||||
|
mouse_keybord_hook::install_mouse_keybord_hook();
|
||||||
DbgPrintEx(77, 0, "[+]ob_reg_callback status:%x\n", ob_call_back::register_ob_reg_callback());
|
DbgPrintEx(77, 0, "[+]ob_reg_callback status:%x\n", ob_call_back::register_ob_reg_callback());
|
||||||
//DbgPrintEx(77, 0, "[+]create_thread_routine status:%x\n", thread_notify_routine::create_thread_routine());
|
DbgPrintEx(77, 0, "[+]process_notify_callback status:%x\n", process_notify_callback::install_process_notify());
|
||||||
|
DbgPrintEx(77, 0, "[+]create_thread_routine status:%x\n", thread_notify_routine::create_thread_routine());
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
return STATUS_SUCCESS;
|
return STATUS_SUCCESS;
|
||||||
}
|
}
|
||||||
@@ -1,9 +1,9 @@
|
|||||||
#include "kernel_api.h"
|
#include "kernel_api.h"
|
||||||
|
struct imported_ imported { 0 };
|
||||||
|
|
||||||
|
|
||||||
namespace kernel_api
|
namespace kernel_api
|
||||||
{
|
{
|
||||||
struct imported_ imported { 0 };
|
|
||||||
|
|
||||||
auto kernel_api_init() -> void
|
auto kernel_api_init() -> void
|
||||||
{
|
{
|
||||||
UNICODE_STRING unFuncName{ 0 };
|
UNICODE_STRING unFuncName{ 0 };
|
||||||
@@ -19,6 +19,9 @@ namespace kernel_api
|
|||||||
|
|
||||||
RtlInitUnicodeString(&unFuncName, L"SeLocateProcessImageName");
|
RtlInitUnicodeString(&unFuncName, L"SeLocateProcessImageName");
|
||||||
imported.se_locateprocess_imagename = (ULONG64)MmGetSystemRoutineAddress(&unFuncName);
|
imported.se_locateprocess_imagename = (ULONG64)MmGetSystemRoutineAddress(&unFuncName);
|
||||||
|
|
||||||
|
RtlInitUnicodeString(&unFuncName, L"RtlFindExportedRoutineByName");
|
||||||
|
imported.rtl_findexported_routinebyname = (ULONG64)MmGetSystemRoutineAddress(&unFuncName);
|
||||||
}
|
}
|
||||||
|
|
||||||
NTSTATUS ntquerysysteminformation(ULONG SystemInformationClass, PVOID SystemInformation, ULONG SystemInformationLength, PULONG ReturnLength)
|
NTSTATUS ntquerysysteminformation(ULONG SystemInformationClass, PVOID SystemInformation, ULONG SystemInformationLength, PULONG ReturnLength)
|
||||||
@@ -43,4 +46,11 @@ namespace kernel_api
|
|||||||
return reinterpret_cast<NTSTATUS(*)(PEPROCESS, PUNICODE_STRING*)>
|
return reinterpret_cast<NTSTATUS(*)(PEPROCESS, PUNICODE_STRING*)>
|
||||||
(imported.se_locateprocess_imagename)(Process, pImageFileName);
|
(imported.se_locateprocess_imagename)(Process, pImageFileName);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
PVOID rtlfindexportedroutinebyname(PVOID ImageBase, PCCH RoutineName)
|
||||||
|
{
|
||||||
|
return reinterpret_cast<PVOID(*)(PVOID, PCCH)>(imported.rtl_findexported_routinebyname)
|
||||||
|
(ImageBase, RoutineName);
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
@@ -23,7 +23,7 @@ struct imported_
|
|||||||
|
|
||||||
namespace kernel_api
|
namespace kernel_api
|
||||||
{
|
{
|
||||||
extern struct imported_ imported;
|
//extern struct imported_ imported;
|
||||||
|
|
||||||
auto kernel_api_init() -> void;
|
auto kernel_api_init() -> void;
|
||||||
|
|
||||||
@@ -38,4 +38,5 @@ namespace kernel_api
|
|||||||
|
|
||||||
NTSTATUS selocate_process_imagename(PEPROCESS Process, PUNICODE_STRING* pImageFileName);
|
NTSTATUS selocate_process_imagename(PEPROCESS Process, PUNICODE_STRING* pImageFileName);
|
||||||
|
|
||||||
|
PVOID rtlfindexportedroutinebyname(PVOID ImageBase, PCCH RoutineName);
|
||||||
}
|
}
|
||||||
@@ -5,10 +5,9 @@
|
|||||||
#pragma warning(disable : 4838)
|
#pragma warning(disable : 4838)
|
||||||
namespace kernel_function
|
namespace kernel_function
|
||||||
{
|
{
|
||||||
PEPROCESS process{ 0 };
|
|
||||||
|
|
||||||
auto FindProcess(const CHAR* ProcessName) -> PEPROCESS
|
auto FindProcess(const CHAR* ProcessName) -> PEPROCESS
|
||||||
{
|
{
|
||||||
|
PEPROCESS process{ 0 };
|
||||||
for (ULONG i = 4; i < 0x401000; i += 4)
|
for (ULONG i = 4; i < 0x401000; i += 4)
|
||||||
{
|
{
|
||||||
auto status = PsLookupProcessByProcessId(ULongToHandle(i), &process);
|
auto status = PsLookupProcessByProcessId(ULongToHandle(i), &process);
|
||||||
@@ -68,6 +67,65 @@ namespace kernel_function
|
|||||||
return base;
|
return base;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
auto GetProcessModule(HANDLE Pid, UNICODE_STRING ModuleName, PVOID Buffer) -> NTSTATUS
|
||||||
|
{
|
||||||
|
NTSTATUS status = STATUS_SUCCESS;
|
||||||
|
PEPROCESS process = NULL;
|
||||||
|
UNICODE_STRING UniCodeName{ 0 };
|
||||||
|
uintptr_t ModuleBase = 0;
|
||||||
|
|
||||||
|
status = PsLookupProcessByProcessId(Pid, &process);
|
||||||
|
if (!NT_SUCCESS(status))
|
||||||
|
{
|
||||||
|
DbgPrintEx(77, 0, "[drv_memory] PsLookupProcessByProcessId failed with status %x\n", status);
|
||||||
|
return status;
|
||||||
|
}
|
||||||
|
BOOLEAN Is64 = (utils::PsGetProcessWow64Process(process) != NULL) ? TRUE : FALSE;
|
||||||
|
|
||||||
|
KAPC_STATE ApcState;
|
||||||
|
KeStackAttachProcess(process, &ApcState);
|
||||||
|
if (Is64)
|
||||||
|
{
|
||||||
|
PPEB32 Peb32 = (PPEB32)utils::PsGetProcessWow64Process(process);
|
||||||
|
PLIST_ENTRY32 LdrEntry32 = (PLIST_ENTRY32)((PPEB_LDR_DATA32)Peb32->Ldr)->InLoadOrderModuleList.Flink;
|
||||||
|
while (LdrEntry32 != &((PPEB_LDR_DATA32)Peb32->Ldr)->InLoadOrderModuleList)
|
||||||
|
{
|
||||||
|
PLDR_DATA_TABLE_ENTRY32 LdrDataTableEntry32 = (PLDR_DATA_TABLE_ENTRY32)LdrEntry32;
|
||||||
|
if (LdrDataTableEntry32->BaseDllName.Buffer == NULL) continue;
|
||||||
|
|
||||||
|
RtlInitUnicodeString(&UniCodeName, (PWCHAR)LdrDataTableEntry32->BaseDllName.Buffer);
|
||||||
|
if (RtlEqualUnicodeString(&ModuleName, &UniCodeName, TRUE))
|
||||||
|
{
|
||||||
|
ModuleBase = (uintptr_t)LdrDataTableEntry32->DllBase;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
LdrEntry32 = (PLIST_ENTRY32)LdrEntry32->Flink;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
PPEB64 Peb64 = (PPEB64)utils::PsGetProcessPeb(process);
|
||||||
|
PLIST_ENTRY64 LdrEntry64 = (PLIST_ENTRY64)((PPEB_LDR_DATA64)Peb64->Ldr)->InLoadOrderModuleList.Flink;
|
||||||
|
while (LdrEntry64 != &((PPEB_LDR_DATA64)Peb64->Ldr)->InLoadOrderModuleList)
|
||||||
|
{
|
||||||
|
PLDR_DATA_TABLE_ENTRY64 LdrDataTableEntry64 = (PLDR_DATA_TABLE_ENTRY64)LdrEntry64;
|
||||||
|
if (LdrDataTableEntry64->BaseDllName.Buffer == NULL) continue;
|
||||||
|
|
||||||
|
RtlInitUnicodeString(&UniCodeName, LdrDataTableEntry64->BaseDllName.Buffer);
|
||||||
|
if (RtlEqualUnicodeString(&UniCodeName, &ModuleName, TRUE))
|
||||||
|
{
|
||||||
|
ModuleBase = (uintptr_t)LdrDataTableEntry64->DllBase;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
LdrEntry64 = (PLIST_ENTRY64)LdrEntry64->Flink;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
KeUnstackDetachProcess(&ApcState);
|
||||||
|
ObDereferenceObject(process);
|
||||||
|
RtlCopyMemory(Buffer, &ModuleBase, sizeof(uintptr_t));
|
||||||
|
return status;
|
||||||
|
}
|
||||||
|
|
||||||
auto MmMDLPagesCopy(IN PVOID Address, PVOID Buff, SIZE_T Size, BYTE Type, CHAR AccessMode) -> NTSTATUS
|
auto MmMDLPagesCopy(IN PVOID Address, PVOID Buff, SIZE_T Size, BYTE Type, CHAR AccessMode) -> NTSTATUS
|
||||||
{
|
{
|
||||||
PMDL pMDL = IoAllocateMdl(Address, (ULONG)Size, FALSE, FALSE, NULL);
|
PMDL pMDL = IoAllocateMdl(Address, (ULONG)Size, FALSE, FALSE, NULL);
|
||||||
@@ -169,5 +227,33 @@ namespace kernel_function
|
|||||||
return TRUE;
|
return TRUE;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
auto ke_stack_attch_process(PEPROCESS PROCESS) -> KAPC_STATE
|
||||||
|
{
|
||||||
|
KAPC_STATE apc_state{ 0 };
|
||||||
|
KeStackAttachProcess(PROCESS, &apc_state);
|
||||||
|
return apc_state;
|
||||||
|
}
|
||||||
|
|
||||||
|
auto ke_unstack_detach_process(KAPC_STATE apc_state) -> void
|
||||||
|
{
|
||||||
|
KeUnstackDetachProcess(&apc_state);
|
||||||
|
}
|
||||||
|
|
||||||
|
auto GetgSessionGlobalSlots() -> uintptr_t {
|
||||||
|
|
||||||
|
static uintptr_t gSessionGlobalSlots;
|
||||||
|
if (gSessionGlobalSlots == NULL) {
|
||||||
|
auto win32k = GetKernelModule("win32k.sys");
|
||||||
|
if (!win32k)
|
||||||
|
return NULL;
|
||||||
|
|
||||||
|
auto W32GetSessionStateForSession = utils::FindSectionsCode(win32k, "\x48\x8b\x05\x00\x00\x00\x00\xff\xc9\x48\x8b\x04\xc8", "xxx????xxxxxx", ".text");
|
||||||
|
if (!W32GetSessionStateForSession)
|
||||||
|
return NULL;
|
||||||
|
|
||||||
|
gSessionGlobalSlots = (*(ULONG*)(W32GetSessionStateForSession + 3)) + (W32GetSessionStateForSession + 7);
|
||||||
|
}
|
||||||
|
|
||||||
|
return gSessionGlobalSlots;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -37,11 +37,119 @@ namespace kernel_function
|
|||||||
RTL_PROCESS_MODULE_INFORMATION Modules[1];
|
RTL_PROCESS_MODULE_INFORMATION Modules[1];
|
||||||
} RTL_PROCESS_MODULES, * PRTL_PROCESS_MODULES;
|
} RTL_PROCESS_MODULES, * PRTL_PROCESS_MODULES;
|
||||||
|
|
||||||
|
typedef struct _PEB32
|
||||||
|
{
|
||||||
|
UCHAR InheritedAddressSpace;
|
||||||
|
UCHAR ReadImageFileExecOptions;
|
||||||
|
UCHAR BeingDebugged;
|
||||||
|
UCHAR BitField;
|
||||||
|
ULONG Mutant;
|
||||||
|
ULONG ImageBaseAddress;
|
||||||
|
ULONG Ldr;
|
||||||
|
ULONG ProcessParameters;
|
||||||
|
ULONG SubSystemData;
|
||||||
|
ULONG ProcessHeap;
|
||||||
|
ULONG FastPebLock;
|
||||||
|
ULONG AtlThunkSListPtr;
|
||||||
|
ULONG IFEOKey;
|
||||||
|
ULONG CrossProcessFlags;
|
||||||
|
ULONG UserSharedInfoPtr;
|
||||||
|
ULONG SystemReserved;
|
||||||
|
ULONG AtlThunkSListPtr32;
|
||||||
|
ULONG ApiSetMap;
|
||||||
|
} PEB32, * PPEB32; ////32 PEB½á¹¹
|
||||||
|
|
||||||
|
typedef struct _LDR_DATA_TABLE_ENTRY32
|
||||||
|
{
|
||||||
|
LIST_ENTRY32 InLoadOrderLinks;
|
||||||
|
LIST_ENTRY32 InMemoryOrderLinks;
|
||||||
|
LIST_ENTRY32 InInitializationOrderLinks;
|
||||||
|
ULONG DllBase;
|
||||||
|
ULONG EntryPoint;
|
||||||
|
ULONG SizeOfImage;
|
||||||
|
UNICODE_STRING32 FullDllName;
|
||||||
|
UNICODE_STRING32 BaseDllName;
|
||||||
|
ULONG Flags;
|
||||||
|
USHORT LoadCount;
|
||||||
|
USHORT TlsIndex;
|
||||||
|
LIST_ENTRY32 HashLinks;
|
||||||
|
ULONG TimeDateStamp;
|
||||||
|
} LDR_DATA_TABLE_ENTRY32, * PLDR_DATA_TABLE_ENTRY32;//32 PEB½á¹¹
|
||||||
|
typedef struct _PEB_LDR_DATA32
|
||||||
|
{
|
||||||
|
ULONG Length;
|
||||||
|
UCHAR Initialized;
|
||||||
|
ULONG SsHandle;
|
||||||
|
LIST_ENTRY32 InLoadOrderModuleList;
|
||||||
|
LIST_ENTRY32 InMemoryOrderModuleList;
|
||||||
|
LIST_ENTRY32 InInitializationOrderModuleList;
|
||||||
|
} PEB_LDR_DATA32, * PPEB_LDR_DATA32;//32 PEB½á¹¹
|
||||||
|
|
||||||
|
typedef struct _PEB64
|
||||||
|
{
|
||||||
|
UCHAR InheritedAddressSpace;
|
||||||
|
UCHAR ReadImageFileExecOptions;
|
||||||
|
UCHAR BeingDebugged;
|
||||||
|
UCHAR BitField;
|
||||||
|
ULONG64 Mutant;
|
||||||
|
ULONG64 ImageBaseAddress;
|
||||||
|
ULONG64 Ldr;
|
||||||
|
ULONG64 ProcessParameters;
|
||||||
|
ULONG64 SubSystemData;
|
||||||
|
ULONG64 ProcessHeap;
|
||||||
|
ULONG64 FastPebLock;
|
||||||
|
ULONG64 AtlThunkSListPtr;
|
||||||
|
ULONG64 IFEOKey;
|
||||||
|
ULONG64 CrossProcessFlags;
|
||||||
|
ULONG64 UserSharedInfoPtr;
|
||||||
|
ULONG SystemReserved;
|
||||||
|
ULONG AtlThunkSListPtr32;
|
||||||
|
ULONG64 ApiSetMap;
|
||||||
|
} PEB64, * PPEB64;
|
||||||
|
typedef struct _PEB_LDR_DATA64
|
||||||
|
{
|
||||||
|
ULONG Length;
|
||||||
|
BOOLEAN Initialized;
|
||||||
|
ULONG64 SsHandle;
|
||||||
|
LIST_ENTRY64 InLoadOrderModuleList;
|
||||||
|
LIST_ENTRY64 InMemoryOrderModuleList;
|
||||||
|
LIST_ENTRY64 InInitializationOrderModuleList;
|
||||||
|
ULONG64 EntryInProgress;
|
||||||
|
} PEB_LDR_DATA64, * PPEB_LDR_DATA64;
|
||||||
|
typedef struct _LDR_DATA_TABLE_ENTRY64
|
||||||
|
{
|
||||||
|
LIST_ENTRY64 InLoadOrderLinks;
|
||||||
|
LIST_ENTRY64 InMemoryOrderLinks;
|
||||||
|
LIST_ENTRY64 InInitializationOrderLinks;
|
||||||
|
PVOID DllBase;
|
||||||
|
ULONG64 EntryPoint;
|
||||||
|
ULONG64 SizeOfImage;
|
||||||
|
UNICODE_STRING FullDllName;
|
||||||
|
UNICODE_STRING BaseDllName;
|
||||||
|
ULONG Flags;
|
||||||
|
USHORT LoadCount;
|
||||||
|
USHORT TlsIndex;
|
||||||
|
LIST_ENTRY64 HashLinks;
|
||||||
|
ULONG64 SectionPointer;
|
||||||
|
ULONG64 CheckSum;
|
||||||
|
ULONG64 TimeDateStamp;
|
||||||
|
ULONG64 LoadedImports;
|
||||||
|
ULONG64 EntryPointActivationContext;
|
||||||
|
ULONG64 PatchInformation;
|
||||||
|
LIST_ENTRY64 ForwarderLinks;
|
||||||
|
LIST_ENTRY64 ServiceTagLinks;
|
||||||
|
LIST_ENTRY64 StaticLinks;
|
||||||
|
ULONG64 ContextInformation;
|
||||||
|
ULONG64 OriginalBase;
|
||||||
|
LARGE_INTEGER LoadTime;
|
||||||
|
} LDR_DATA_TABLE_ENTRY64, * PLDR_DATA_TABLE_ENTRY64;
|
||||||
|
|
||||||
auto FindProcess(CONST CHAR* ProcessName)->PEPROCESS;
|
auto FindProcess(CONST CHAR* ProcessName)->PEPROCESS;
|
||||||
|
|
||||||
auto GetKernelModule(CONST CHAR* Module)->uintptr_t;
|
auto GetKernelModule(CONST CHAR* Module)->uintptr_t;
|
||||||
|
|
||||||
|
auto GetProcessModule(HANDLE Pid, UNICODE_STRING ModuleName, PVOID Buffer) -> NTSTATUS;
|
||||||
|
|
||||||
auto MmMDLPagesCopy(IN PVOID Address, PVOID Buff, SIZE_T Size, BYTE Type, CHAR AccessMode)->NTSTATUS;
|
auto MmMDLPagesCopy(IN PVOID Address, PVOID Buff, SIZE_T Size, BYTE Type, CHAR AccessMode)->NTSTATUS;
|
||||||
|
|
||||||
auto GetMmverifyCallBackFlags()->uintptr_t;
|
auto GetMmverifyCallBackFlags()->uintptr_t;
|
||||||
@@ -49,4 +157,10 @@ namespace kernel_function
|
|||||||
auto Mack_MmVerifyCallBackFlags(BYTE** orgin_byte)->BOOL;
|
auto Mack_MmVerifyCallBackFlags(BYTE** orgin_byte)->BOOL;
|
||||||
|
|
||||||
auto Orgin_MmVerifyCallBackFlags(BYTE* orgin_byte)->BOOL;
|
auto Orgin_MmVerifyCallBackFlags(BYTE* orgin_byte)->BOOL;
|
||||||
|
|
||||||
|
auto ke_stack_attch_process(PEPROCESS PROCESS) ->KAPC_STATE;
|
||||||
|
|
||||||
|
auto ke_unstack_detach_process(KAPC_STATE apc_state) -> void;
|
||||||
|
|
||||||
|
auto GetgSessionGlobalSlots()->uintptr_t;
|
||||||
}
|
}
|
||||||
Reference in New Issue
Block a user