mirror of
https://github.com/Print3M/DllShimmer
synced 2026-06-06 16:34:32 +00:00
Header file created
This commit is contained in:
@@ -23,7 +23,7 @@ func main() {
|
||||
TemplatesFS: &templatesFS,
|
||||
}
|
||||
|
||||
out.CreateCodeFile(flags.Mutex, flags.Static)
|
||||
out.CreateCodeFiles(flags.Mutex, flags.Static)
|
||||
out.CreateDefFile()
|
||||
out.CreateCompileScript(flags.Static)
|
||||
|
||||
@@ -35,7 +35,7 @@ func main() {
|
||||
fmt.Println("Success! What to do next?")
|
||||
fmt.Println()
|
||||
fmt.Printf(" 1. Jump into the '%s/' directory.\n", out.OutputDir)
|
||||
fmt.Printf(" 2. Add your backdoor to the '%s' file.\n", out.GetCodeFileName())
|
||||
fmt.Printf(" 2. Add your backdoor to the '%s' file.\n", out.GetCppCodeFileName())
|
||||
fmt.Printf(" 3. Compile project using the '%s' script.\n", out.GetCompileScriptName())
|
||||
fmt.Println()
|
||||
}
|
||||
|
||||
+22
-21
@@ -23,10 +23,14 @@ func (o *Output) GetDefFileName() string {
|
||||
return o.Dll.Name + ".def"
|
||||
}
|
||||
|
||||
func (o *Output) GetCodeFileName() string {
|
||||
func (o *Output) GetCppCodeFileName() string {
|
||||
return o.Dll.Name + ".cpp"
|
||||
}
|
||||
|
||||
func (o *Output) GetHdrCodeFileName() string {
|
||||
return "dllshimmer.h"
|
||||
}
|
||||
|
||||
func (o *Output) GetCompileScriptName() string {
|
||||
return "compile.sh"
|
||||
}
|
||||
@@ -56,21 +60,7 @@ func (o *Output) GetTemplate(filename string) *template.Template {
|
||||
return template.Must(template.New("new").Parse(string(content)))
|
||||
}
|
||||
|
||||
func (o *Output) CreateCodeFile(mutex bool, isStaticLinked bool) {
|
||||
templateFile := "dynamic-shim.cpp.template"
|
||||
if isStaticLinked {
|
||||
templateFile = "static-shim.cpp.template"
|
||||
}
|
||||
|
||||
tmpl := o.GetTemplate(templateFile)
|
||||
outputPath := filepath.Join(o.OutputDir, o.GetCodeFileName())
|
||||
|
||||
f, err := os.Create(outputPath)
|
||||
if err != nil {
|
||||
log.Fatalf("[!] Error while creating '%s' file: %v", outputPath, err)
|
||||
}
|
||||
defer f.Close()
|
||||
|
||||
func (o *Output) CreateCodeFiles(mutex bool, isStaticLinked bool) {
|
||||
params := CodeFileParams{
|
||||
Functions: o.Dll.ExportedFunctions,
|
||||
OriginalPath: sanitizePathForInjection(o.Dll.OriginalPath),
|
||||
@@ -78,12 +68,23 @@ func (o *Output) CreateCodeFile(mutex bool, isStaticLinked bool) {
|
||||
DllName: o.Dll.Name,
|
||||
}
|
||||
|
||||
err = tmpl.Execute(f, params)
|
||||
if err != nil {
|
||||
log.Fatalf("[!] Error of template engine: %v", err)
|
||||
o.createCppCodeFile(params, isStaticLinked)
|
||||
o.createHdrCodeFile(params)
|
||||
}
|
||||
|
||||
func (o *Output) createCppCodeFile(params CodeFileParams, isStaticLinked bool) {
|
||||
templateFile := "dynamic-shim.cpp.template"
|
||||
if isStaticLinked {
|
||||
templateFile = "static-shim.cpp.template"
|
||||
}
|
||||
|
||||
fmt.Printf("[+] '%s' file created\n", outputPath)
|
||||
outputPath := filepath.Join(o.OutputDir, o.GetCppCodeFileName())
|
||||
createFileFromTemplate(o, templateFile, outputPath, params)
|
||||
}
|
||||
|
||||
func (o *Output) createHdrCodeFile(params CodeFileParams) {
|
||||
outputPath := filepath.Join(o.OutputDir, o.GetHdrCodeFileName())
|
||||
createFileFromTemplate(o, "dllshimmer.h.template", outputPath, params)
|
||||
}
|
||||
|
||||
func (o *Output) CreateDefFile() {
|
||||
@@ -166,7 +167,7 @@ func (o *Output) CreateCompileScript(isStaticLinked bool) {
|
||||
defer f.Close()
|
||||
|
||||
params := CompileScriptParams{
|
||||
Code: o.GetCodeFileName(),
|
||||
Code: o.GetCppCodeFileName(),
|
||||
Def: o.GetDefFileName(),
|
||||
Output: o.GetOutputDllName(),
|
||||
IsStaticLinked: isStaticLinked,
|
||||
|
||||
+23
-1
@@ -1,7 +1,29 @@
|
||||
package output
|
||||
|
||||
import "strings"
|
||||
import (
|
||||
"fmt"
|
||||
"log"
|
||||
"os"
|
||||
"strings"
|
||||
)
|
||||
|
||||
func sanitizePathForInjection(path string) string {
|
||||
return strings.ReplaceAll(path, "\\", "\\\\")
|
||||
}
|
||||
|
||||
func createFileFromTemplate[K interface{}](o *Output, template string, outputPath string, params K) {
|
||||
tmpl := o.GetTemplate(template)
|
||||
|
||||
f, err := os.Create(outputPath)
|
||||
if err != nil {
|
||||
log.Fatalf("[!] Error while creating '%s' file: %v", outputPath, err)
|
||||
}
|
||||
defer f.Close()
|
||||
|
||||
err = tmpl.Execute(f, params)
|
||||
if err != nil {
|
||||
log.Fatalf("[!] Error of template engine: %v", err)
|
||||
}
|
||||
|
||||
fmt.Printf("[+] '%s' file created\n", outputPath)
|
||||
}
|
||||
|
||||
@@ -0,0 +1,53 @@
|
||||
#pragma once
|
||||
|
||||
// #------------------------------------------------------------------#
|
||||
// | "DON'T TOUCH" ZONE |
|
||||
// | (auto generated) |
|
||||
// #------------------------------------------------------------------#
|
||||
|
||||
#include <windows.h>
|
||||
#include <stdio.h>
|
||||
|
||||
#define T UINT64
|
||||
#define PARAMS \
|
||||
T a1, T a2, T a3, T a4, T a5, T a6, T a7, T a8, T a9, T a10, T a11, T a12
|
||||
#define ARGS a1, a2, a3, a4, a5, a6, a7, a8, a9, a10, a11, a12
|
||||
|
||||
typedef T (*FuncPtr)(PARAMS);
|
||||
|
||||
|
||||
void PrintCurrentDirectory() {
|
||||
char buf[MAX_PATH];
|
||||
DWORD len = GetCurrentDirectoryA(MAX_PATH, buf);
|
||||
if (len == 0 || len >= MAX_PATH) {
|
||||
printf("\tGetCurrentDirectoryA failed\n");
|
||||
return;
|
||||
}
|
||||
|
||||
printf("\tCurrent directory: '%s'\n", buf);
|
||||
}
|
||||
|
||||
|
||||
FuncPtr getProxyFunc(const char *funcName) {
|
||||
HMODULE hModule = LoadLibraryA("{{.OriginalPath}}");
|
||||
if (hModule == NULL) {
|
||||
printf("[!] {{.DllName}}: LoadLibraryA({{.OriginalPath}}) failed\n");
|
||||
printf("\tError code: %lu\n", GetLastError());
|
||||
PrintCurrentDirectory();
|
||||
}
|
||||
|
||||
FuncPtr pFunc = (FuncPtr)GetProcAddress(hModule, funcName);
|
||||
if (pFunc == NULL) {
|
||||
printf("[!] {{.DllName}}: GetProcAddress(%s, {{.OriginalPath}}) failed\n",
|
||||
funcName);
|
||||
printf("\tError code: %lu\n", GetLastError());
|
||||
}
|
||||
|
||||
return pFunc;
|
||||
}
|
||||
|
||||
|
||||
#define MUTEX(name) \
|
||||
(CreateMutexA(NULL, TRUE, name) && GetLastError() != ERROR_ALREADY_EXISTS)
|
||||
|
||||
#define PROXY_FUNCTION(funcName) getProxyFunc(funcName)(ARGS);
|
||||
@@ -3,63 +3,9 @@
|
||||
// Author: Print3M (print3m.github.io/)
|
||||
|
||||
{{- $r := . }}
|
||||
#include "dllshimmer.h"
|
||||
#include <windows.h>
|
||||
#include <stdio.h>
|
||||
#include <iostream>
|
||||
// Put your imports here...
|
||||
|
||||
// #------------------------------------------------------------------#
|
||||
// | "DON'T TOUCH" ZONE |
|
||||
// | (auto generated) |
|
||||
// #------------------------------------------------------------------#
|
||||
|
||||
#define MUTEX(name) \
|
||||
(CreateMutexA(NULL, TRUE, name) && GetLastError() != ERROR_ALREADY_EXISTS)
|
||||
|
||||
#define ARGS_COUNT 12
|
||||
|
||||
typedef uint64_t (*Func12)(
|
||||
uint64_t, uint64_t, uint64_t, uint64_t,
|
||||
uint64_t, uint64_t, uint64_t, uint64_t,
|
||||
uint64_t, uint64_t, uint64_t, uint64_t
|
||||
);
|
||||
|
||||
#define T UINT64
|
||||
#define PARAMS T a1, T a2, T a3, T a4, T a5, T a6, T a7, T a8, T a9, T a10, T a11, T a12
|
||||
#define ARGS a1, a2, a3, a4, a5, a6, a7, a8, a9, a10, a11, a12
|
||||
|
||||
void PrintCurrentDirectoryA() {
|
||||
char buf[MAX_PATH];
|
||||
DWORD len = GetCurrentDirectoryA(MAX_PATH, buf);
|
||||
if (len == 0 || len >= MAX_PATH) {
|
||||
printf("\tGetCurrentDirectoryA failed\n");
|
||||
return;
|
||||
}
|
||||
printf("\tCurrent directory: '%s'\n", buf);
|
||||
}
|
||||
|
||||
#define PROXY_FUNCTION(function) \
|
||||
\
|
||||
HMODULE hModule = LoadLibraryA("{{.OriginalPath}}"); \
|
||||
if (hModule == NULL) { \
|
||||
printf("[!] DismCore.dll: LoadLibraryA(DismCore2.dll) failed\n"); \
|
||||
printf("\tError code: %lu\n", GetLastError()); \
|
||||
PrintCurrentDirectoryA(); \
|
||||
} \
|
||||
\
|
||||
Func12 pFunction = (Func12) GetProcAddress(hModule, function); \
|
||||
if (pFunction == NULL) { \
|
||||
printf( \
|
||||
"[!] {{.DllName}}: GetProcAddress(%s, {{.OriginalPath}}) failed\n", \
|
||||
function ); \
|
||||
printf("\tError code: %lu\n", GetLastError()); \
|
||||
} \
|
||||
\
|
||||
return pFunction(ARGS); \
|
||||
|
||||
// #------------------------------------------------------------------#
|
||||
// | END OF "DON'T TOUCH" ZONE |
|
||||
// #------------------------------------------------------------------#
|
||||
|
||||
{{- range $i, $v := .Functions }}
|
||||
{{- if eq (len $v.Forwarder) 0 }}
|
||||
@@ -76,7 +22,7 @@ extern "C" UINT64 {{$v.Name}}Fwd(PARAMS) {
|
||||
// Put your code here...
|
||||
{{- end }}
|
||||
|
||||
PROXY_FUNCTION("{{$v.Name}}");
|
||||
return PROXY_FUNCTION("{{$v.Name}}");
|
||||
}
|
||||
|
||||
{{- end }}
|
||||
|
||||
@@ -10,6 +10,7 @@
|
||||
// | "DON'T TOUCH" ZONE |
|
||||
// | (auto generated) |
|
||||
// #------------------------------------------------------------------#
|
||||
#include "dllshimmer.h"
|
||||
|
||||
{{- range .Functions}}
|
||||
#define {{.Name}} {{.Name}}Original
|
||||
@@ -20,24 +21,6 @@
|
||||
{{- end}}
|
||||
{{ $r := . }}
|
||||
|
||||
void PrintCurrentDirectoryA() {
|
||||
char buf[MAX_PATH];
|
||||
DWORD len = GetCurrentDirectoryA(MAX_PATH, buf);
|
||||
if (len == 0 || len >= MAX_PATH) {
|
||||
printf("\tGetCurrentDirectoryA failed\n");
|
||||
return;
|
||||
}
|
||||
printf("\tCurrent directory: '%s'\n", buf);
|
||||
}
|
||||
|
||||
|
||||
#define MUTEX(name) \
|
||||
(CreateMutexA(NULL, TRUE, name) && GetLastError() != ERROR_ALREADY_EXISTS)
|
||||
|
||||
#define T UINT64
|
||||
#define PARAMS T a1, T a2, T a3, T a4, T a5, T a6, T a7, T a8, T a9, T a10, T a11, T a12
|
||||
#define ARGS a1, a2, a3, a4, a5, a6, a7, a8, a9, a10, a11, a12
|
||||
|
||||
// #------------------------------------------------------------------#
|
||||
// | END OF "DON'T TOUCH" ZONE |
|
||||
// #------------------------------------------------------------------#
|
||||
@@ -72,7 +55,7 @@ BOOL WINAPI DllMain(HINSTANCE hinstDLL, DWORD fdwReason, LPVOID lpvReserved) {
|
||||
case DLL_PROCESS_ATTACH: {
|
||||
#ifdef DEBUG
|
||||
printf("[+] {{.DllName}}: DLL_PROCESS_ATTACH event\n");
|
||||
PrintCurrentDirectoryA();
|
||||
PrintCurrentDirectory();
|
||||
#endif
|
||||
}
|
||||
case DLL_THREAD_ATTACH:
|
||||
|
||||
Reference in New Issue
Block a user