mirror of
https://github.com/Print3M/DllShimmer
synced 2026-06-06 16:34:32 +00:00
Current directory path bug fixed, +better logging
This commit is contained in:
Vendored
+1
@@ -2,5 +2,6 @@
|
||||
"files.associations": {
|
||||
"*.cpp.template": "cpp",
|
||||
"*.sh.template": "shellscript",
|
||||
"functional": "cpp"
|
||||
}
|
||||
}
|
||||
@@ -101,4 +101,6 @@ In case of static linking, we really only have one option:
|
||||
|
||||
## TODO
|
||||
|
||||
- Auto-generate compilation script to output folder
|
||||
- Cache LoadLibraryA() and GetProcAddress() pointers not to call WinAPI every time (better performance and more stealthy).
|
||||
- Improve the shim template code (leave as little code in the macro as possible. Is the macro actually required now when we use args/params trick?)
|
||||
- Maybe move boilerplate code into header file?
|
||||
|
||||
+1
-1
@@ -63,7 +63,7 @@ func ParseCli() *CliFlags {
|
||||
fmt.Println()
|
||||
fmt.Println("Example:")
|
||||
fmt.Println()
|
||||
fmt.Println(" DllShimmer -i version.dll -o ./project -p 'C:\\Windows\\System32\\version.dll' -m")
|
||||
fmt.Println(" DllShimmer -i version.dll -o ./project -x 'C:\\Windows\\System32\\version.dll' -m")
|
||||
fmt.Println()
|
||||
fmt.Println("Created by Print3M (print3m.github.io)")
|
||||
fmt.Println()
|
||||
|
||||
@@ -32,7 +32,7 @@ func main() {
|
||||
}
|
||||
|
||||
fmt.Println()
|
||||
fmt.Println("What to do next?")
|
||||
fmt.Println("Success! What to do next?")
|
||||
fmt.Println()
|
||||
fmt.Printf(" 1. Jump into the '%s/' directory.\n", out.OutputDir)
|
||||
fmt.Printf(" 2. Add your backdoor to the '%s' file.\n", out.GetCodeFileName())
|
||||
|
||||
@@ -28,17 +28,24 @@ typedef uint64_t (*Func12)(
|
||||
#define PARAMS T a1, T a2, T a3, T a4, T a5, T a6, T a7, T a8, T a9, T a10, T a11, T a12
|
||||
#define ARGS a1, a2, a3, a4, a5, a6, a7, a8, a9, a10, a11, a12
|
||||
|
||||
void PrintCurrentDirectoryA() {
|
||||
char buf[MAX_PATH];
|
||||
DWORD len = GetCurrentDirectoryA(MAX_PATH, buf);
|
||||
if (len == 0 || len >= MAX_PATH) {
|
||||
printf("\tGetCurrentDirectoryA failed\n");
|
||||
return;
|
||||
}
|
||||
printf("\tCurrent directory: '%s'\n", buf);
|
||||
}
|
||||
|
||||
#define PROXY_FUNCTION(function) \
|
||||
\
|
||||
HMODULE hModule = LoadLibraryA("{{.OriginalPath}}"); \
|
||||
if (hModule == NULL) { \
|
||||
printf("[!] {{.DllName}}: LoadLibraryA({{.OriginalPath}}) failed\n"); \
|
||||
printf("[!] DismCore.dll: LoadLibraryA(DismCore2.dll) failed\n"); \
|
||||
printf("\tError code: %lu\n", GetLastError()); \
|
||||
\
|
||||
WCHAR buf[MAX_PATH]; \
|
||||
DWORD len = GetCurrentDirectoryW(MAX_PATH, buf); \
|
||||
wprintf(L"\tCurrent search directory: %s\n", buf); \
|
||||
} \
|
||||
PrintCurrentDirectoryA(); \
|
||||
} \
|
||||
\
|
||||
Func12 pFunction = (Func12) GetProcAddress(hModule, function); \
|
||||
if (pFunction == NULL) { \
|
||||
|
||||
@@ -20,6 +20,17 @@
|
||||
{{- end}}
|
||||
{{ $r := . }}
|
||||
|
||||
void PrintCurrentDirectoryA() {
|
||||
char buf[MAX_PATH];
|
||||
DWORD len = GetCurrentDirectoryA(MAX_PATH, buf);
|
||||
if (len == 0 || len >= MAX_PATH) {
|
||||
printf("\tGetCurrentDirectoryA failed\n");
|
||||
return;
|
||||
}
|
||||
printf("\tCurrent directory: '%s'\n", buf);
|
||||
}
|
||||
|
||||
|
||||
#define MUTEX(name) \
|
||||
(CreateMutexA(NULL, TRUE, name) && GetLastError() != ERROR_ALREADY_EXISTS)
|
||||
|
||||
@@ -61,9 +72,7 @@ BOOL WINAPI DllMain(HINSTANCE hinstDLL, DWORD fdwReason, LPVOID lpvReserved) {
|
||||
case DLL_PROCESS_ATTACH: {
|
||||
#ifdef DEBUG
|
||||
printf("[+] {{.DllName}}: DLL_PROCESS_ATTACH event\n");
|
||||
WCHAR buf[MAX_PATH];
|
||||
DWORD len = GetCurrentDirectoryW(MAX_PATH, buf);
|
||||
wprintf(L"\tCurrent search directory: %s\n", buf);
|
||||
PrintCurrentDirectoryA();
|
||||
#endif
|
||||
}
|
||||
case DLL_THREAD_ATTACH:
|
||||
|
||||
Reference in New Issue
Block a user