mirror of
https://github.com/EgeBalci/crc32_api
synced 2026-06-08 10:55:29 +00:00
Added CRC32 seed value for randomizing the API hashes.
This commit is contained in:
+5
-2
@@ -2,7 +2,7 @@
|
||||
; Author: Ege Balcı (egebalci[at]pm[dot]me)
|
||||
; Version: 1.1 (29 April 2023)
|
||||
; Architecture: x64
|
||||
; Size: 186 bytes
|
||||
; Size: 192 bytes
|
||||
;-----------------------------------------------------------------------------;
|
||||
|
||||
[BITS 64]
|
||||
@@ -13,9 +13,11 @@
|
||||
; Input: The CRC32 hash of the module and function name.
|
||||
; Output: The address of the function will be in RAX.
|
||||
; Clobbers: R10
|
||||
; Un-Clobbered: RAX, RCX, RDX, R8, R9, RBX, RSI, RDI, RBP, R12, R13, R14, R15.
|
||||
; Un-Clobbered: RCX, RDX, R8, R9, RBX, RSI, RDI, RBP, R12, R13, R14, R15.
|
||||
; Note: This function assumes the direction flag has allready been cleared via a CLD instruction.
|
||||
|
||||
%define CRC32_SEED 0x00
|
||||
|
||||
api_call:
|
||||
push r9 ; Save R9
|
||||
push r8 ; Save R8
|
||||
@@ -30,6 +32,7 @@ next_mod: ;
|
||||
mov rsi, [rdx+80] ; Get pointer to modules name (unicode string)
|
||||
movzx rcx, word [rdx+74] ; Set rcx to the length we want to check
|
||||
xor r9, r9 ; Clear r9 which will store the hash of the module name
|
||||
mov r9, CRC32_SEED ; Set the initial CRC32 seed value
|
||||
loop_modname: ;
|
||||
xor rax, rax ; Clear RAX
|
||||
lodsb ; Read in the next byte of the name
|
||||
|
||||
+4
-1
@@ -2,7 +2,7 @@
|
||||
; Author: Ege Balcı (egebalci[at]pm[dot]me)
|
||||
; Version: 1.1 (29 April 2023)
|
||||
; Architecture: x86
|
||||
; Size: 124 bytes
|
||||
; Size: 129 bytes
|
||||
;-----------------------------------------------------------------------------;
|
||||
|
||||
[BITS 32]
|
||||
@@ -13,6 +13,8 @@
|
||||
; Un-Clobbered: EBX, ESI, EDI, ESP and EBP can be expected to remain un-clobbered.
|
||||
; Note: This function assumes the direction flag has allready been cleared via a CLD instruction.
|
||||
|
||||
%define CRC32_SEED 0x00
|
||||
|
||||
api_call:
|
||||
pushad ; We preserve all the registers for the caller, bar EAX and ECX.
|
||||
mov ebp, esp ; Create a new stack frame
|
||||
@@ -24,6 +26,7 @@ next_mod: ;
|
||||
mov esi, [edx+40] ; Get pointer to modules name (unicode string)
|
||||
movzx ecx, word [edx+38] ; Set ECX to the length we want to check
|
||||
xor edi, edi ; Clear EDI which will store the hash of the module name
|
||||
mov edi, CRC32_SEED ; Set the initial CRC32 seed value
|
||||
loop_modname: ;
|
||||
lodsb ; Read in the next byte of the name
|
||||
cmp al, 'a' ; Some versions of Windows use lower case module names
|
||||
|
||||
+3
-1
@@ -9,6 +9,8 @@
|
||||
from sys import path
|
||||
import os, time, sys, crcmod
|
||||
|
||||
CRC32_SEED=0
|
||||
|
||||
def unicode( string, uppercase=True ):
|
||||
result = "";
|
||||
if uppercase:
|
||||
@@ -18,7 +20,7 @@ def unicode( string, uppercase=True ):
|
||||
return result
|
||||
#=============================================================================#
|
||||
def hash( module, function, bits=13, print_hash=True ):
|
||||
crc32_func = crcmod.mkCrcFun(0x11EDC6F41, initCrc=0, xorOut=0)
|
||||
crc32_func = crcmod.mkCrcFun(0x11EDC6F41, initCrc=CRC32_SEED, xorOut=0)
|
||||
h = crc32_func((unicode(module)+function+"\x00").encode('utf-8'))
|
||||
print("[+] 0x%08X = %s!%s" % ( h, module.lower(), function ))
|
||||
return h
|
||||
|
||||
Reference in New Issue
Block a user