From fc0c8a612d7c4749ecc9354ce80154227d8fe3ee Mon Sep 17 00:00:00 2001 From: Paolo 'VoidSec' Stagno Date: Wed, 29 Sep 2021 09:00:34 +0200 Subject: [PATCH] update IDA DB --- .../DispatchDeviceControl.cpp | 392 +++++++++--------- .../Reverse Engineering/MODAPI.sys.i64 | Bin 447176 -> 447176 bytes 2 files changed, 196 insertions(+), 196 deletions(-) diff --git a/windows/x64/kernel/crucial_Ballistix_MOD_Utility_v.2.0.2.5/Reverse Engineering/DispatchDeviceControl.cpp b/windows/x64/kernel/crucial_Ballistix_MOD_Utility_v.2.0.2.5/Reverse Engineering/DispatchDeviceControl.cpp index 727c764..82fffc1 100644 --- a/windows/x64/kernel/crucial_Ballistix_MOD_Utility_v.2.0.2.5/Reverse Engineering/DispatchDeviceControl.cpp +++ b/windows/x64/kernel/crucial_Ballistix_MOD_Utility_v.2.0.2.5/Reverse Engineering/DispatchDeviceControl.cpp @@ -1,212 +1,212 @@ __int64 __fastcall DispatchDeviceControl(__int64 a1, IRP *a2) { - unsigned int *p_Information; // rdi - _IO_STACK_LOCATION *CurrentStackLocation; // rdx - unsigned int status; // ebx - unsigned int IOCTL_Code; // eax - _IRP *v7; // rcx - unsigned int v8; // er8 - int v9; // edx - unsigned __int32 v10; // eax - unsigned int v11; // eax - CSHORT v12; // ax - unsigned __int8 v13; // al - unsigned int Options; // ebx - _IRP *v15; // r9 - _IRP *v16; // rcx - int v17; // edx - unsigned int Length; // ebp - ULONG *MasterIrp; // r9 - ULONG BusDataByOffset; // eax - int v21; // eax + unsigned int *p_Information; // rdi + _IO_STACK_LOCATION *CurrentStackLocation; // rdx + unsigned int status; // ebx + unsigned int IOCTL_Code; // eax + _IRP *v7; // rcx + unsigned int v8; // er8 + int v9; // edx + unsigned __int32 v10; // eax + unsigned int v11; // eax + CSHORT v12; // ax + unsigned __int8 v13; // al + unsigned int Options; // ebx + _IRP *v15; // r9 + _IRP *v16; // rcx + int v17; // edx + unsigned int Length; // ebp + ULONG *MasterIrp; // r9 + ULONG BusDataByOffset; // eax + int v21; // eax - p_Information = (unsigned int *)&a2->IoStatus.Information; - CurrentStackLocation = a2->Tail.Overlay.CurrentStackLocation; - *(_QWORD *)p_Information = 0i64; - status = 0xC0000002; // STATUS_NOT_IMPLEMENTED - if (!CurrentStackLocation->MajorFunction) + p_Information = (unsigned int *)&a2->IoStatus.Information; + CurrentStackLocation = a2->Tail.Overlay.CurrentStackLocation; + *(_QWORD *)p_Information = 0i64; + status = 0xC0000002; // STATUS_NOT_IMPLEMENTED + if (!CurrentStackLocation->MajorFunction) + { + if (dword_13110 == -1) + goto exit_ok; + v21 = dword_13110 + 1; + goto pre_exit_ok; + } + if (CurrentStackLocation->MajorFunction == 2) + { + if (dword_13110 == -1) + goto exit_ok; + v21 = dword_13110 - 1; + pre_exit_ok: + dword_13110 = v21; + goto exit_ok; + } + if (CurrentStackLocation->MajorFunction != 14) + goto exit; + IOCTL_Code = CurrentStackLocation->Parameters.Read.ByteOffset.LowPart; + if (IOCTL_Code > 0x9C4060D4) + { + if (IOCTL_Code != 0x9C406104) { - if (dword_13110 == -1) - goto exit_ok; - v21 = dword_13110 + 1; - goto pre_exit_ok; - } - if (CurrentStackLocation->MajorFunction == 2) - { - if (dword_13110 == -1) - goto exit_ok; - v21 = dword_13110 - 1; - pre_exit_ok: - dword_13110 = v21; - goto exit_ok; - } - if (CurrentStackLocation->MajorFunction != 14) - goto exit; - IOCTL_Code = CurrentStackLocation->Parameters.Read.ByteOffset.LowPart; - if (IOCTL_Code > 0x9C4060D4) - { - if (IOCTL_Code != 0x9C406104) + switch (IOCTL_Code) + { + case 0x9C406144: + Length = CurrentStackLocation->Parameters.Read.Length; + if (CurrentStackLocation->Parameters.Create.Options != 8) + goto invalid_parameter; + MasterIrp = (ULONG *)a2->AssociatedIrp.MasterIrp; + BusDataByOffset = HalGetBusDataByOffset( + PCIConfiguration, + (unsigned __int8)BYTE1(*MasterIrp), + (32 * (*MasterIrp & 7)) | ((unsigned __int8)*MasterIrp >> 3), + MasterIrp, + MasterIrp[1], + CurrentStackLocation->Parameters.Read.Length); + if (BusDataByOffset) { - switch (IOCTL_Code) + if (Length == 2 || BusDataByOffset != 2) + { + if (Length == BusDataByOffset) { - case 0x9C406144: - Length = CurrentStackLocation->Parameters.Read.Length; - if (CurrentStackLocation->Parameters.Create.Options != 8) - goto invalid_parameter; - MasterIrp = (ULONG *)a2->AssociatedIrp.MasterIrp; - BusDataByOffset = HalGetBusDataByOffset( - PCIConfiguration, - (unsigned __int8)BYTE1(*MasterIrp), - (32 * (*MasterIrp & 7)) | ((unsigned __int8)*MasterIrp >> 3), - MasterIrp, - MasterIrp[1], - CurrentStackLocation->Parameters.Read.Length); - if (BusDataByOffset) - { - if (Length == 2 || BusDataByOffset != 2) - { - if (Length == BusDataByOffset) - { - *p_Information = Length; - goto exit_ok; - } - status = 0xE0000004; - } - else - { - status = 0xE0000002; - } - } - else - { - status = 0xE0000001; - } - *p_Information = 0; - break; - case 0x9C40A0C8: - case 0x9C40A0D8: - case 0x9C40A0DC: - case 0x9C40A0E0: - v16 = a2->AssociatedIrp.MasterIrp; - v17 = *(_DWORD *)&v16->Type; - switch (IOCTL_Code) - { - case 0x9C40A0D8: - __outbyte(v17, *((_BYTE *)&v16->Size + 2)); - goto exit_ok; - case 0x9C40A0DC: - __outword(v17, *(&v16->Size + 1)); - goto exit_ok; - case 0x9C40A0E0: - __outdword(v17, *(_DWORD *)(&v16->Size + 1)); - goto exit_ok; - } - goto invalid_parameter; - case 0x9C40A108: - goto pre_invalid_param; - case 0x9C40A148: - Options = CurrentStackLocation->Parameters.Create.Options; - if (Options < 8) - { - invalid_parameter: - status = 0xC000000D; // STATUS_INVALID_PARAMETER - goto exit; - } - v15 = a2->AssociatedIrp.MasterIrp; - *p_Information = 0; - status = Options - 8 != HalSetBusDataByOffset( - PCIConfiguration, - (unsigned __int8)BYTE1(*(_DWORD *)&v15->Type), - (32 * (*(_DWORD *)&v15->Type & 7)) | ((unsigned __int8)*(_DWORD *)&v15->Type >> 3), - &v15->MdlAddress, - *(_DWORD *)(&v15->Size + 1), - Options - 8) - ? 0xE0000003 - : 0; - break; + *p_Information = Length; + goto exit_ok; } - goto exit; + status = 0xE0000004; + } + else + { + status = 0xE0000002; + } } - v11 = vuln_MmMapIoSpace( - (__int64)a2->AssociatedIrp.MasterIrp, - CurrentStackLocation->Parameters.Create.Options, - a2->AssociatedIrp.MasterIrp, - CurrentStackLocation->Parameters.Read.Length, - p_Information); - pre_exit: - status = v11; - goto exit; - } - switch (IOCTL_Code) - { - case 0x9C4060D4: - write_B_W_DW: - v7 = a2->AssociatedIrp.MasterIrp; - v8 = CurrentStackLocation->Parameters.Create.Options; - v9 = *(_DWORD *)&v7->Type; + else + { + status = 0xE0000001; + } + *p_Information = 0; + break; + case 0x9C40A0C8: + case 0x9C40A0D8: + case 0x9C40A0DC: + case 0x9C40A0E0: + v16 = a2->AssociatedIrp.MasterIrp; + v17 = *(_DWORD *)&v16->Type; switch (IOCTL_Code) { - case 0x9C4060CC: - v13 = __inbyte(v9); - LOBYTE(v7->Type) = v13; - goto pre_exit2; - case 0x9C4060D0: - v12 = __inword(v9); - v7->Type = v12; - goto pre_exit2; - case 0x9C4060D4: - v10 = __indword(v9); - *(_DWORD *)&v7->Type = v10; - pre_exit2: - *p_Information = v8; - goto exit_ok; + case 0x9C40A0D8: + __outbyte(v17, *((_BYTE *)&v16->Size + 2)); + goto exit_ok; + case 0x9C40A0DC: + __outword(v17, *(&v16->Size + 1)); + goto exit_ok; + case 0x9C40A0E0: + __outdword(v17, *(_DWORD *)(&v16->Size + 1)); + goto exit_ok; } - pre_invalid_param: - *p_Information = 0; goto invalid_parameter; - case 0x9C402000: - *(_DWORD *)a2->AssociatedIrp.MasterIrp = 16908293; - goto LABEL1; - case 0x9C402004: - *(_DWORD *)a2->AssociatedIrp.MasterIrp = dword_13110; - LABEL1: - *(_QWORD *)p_Information = 4i64; - exit_ok: - status = 0; + case 0x9C40A108: + goto pre_invalid_param; + case 0x9C40A148: + Options = CurrentStackLocation->Parameters.Create.Options; + if (Options < 8) + { + invalid_parameter: + status = 0xC000000D; // STATUS_INVALID_PARAMETER + goto exit; + } + v15 = a2->AssociatedIrp.MasterIrp; + *p_Information = 0; + status = Options - 8 != HalSetBusDataByOffset( + PCIConfiguration, + (unsigned __int8)BYTE1(*(_DWORD *)&v15->Type), + (32 * (*(_DWORD *)&v15->Type & 7)) | ((unsigned __int8)*(_DWORD *)&v15->Type >> 3), + &v15->MdlAddress, + *(_DWORD *)(&v15->Size + 1), + Options - 8) + ? 0xE0000003 + : 0; break; - case 0x9C402084: - v11 = readmsr( - (unsigned int *)a2->AssociatedIrp.MasterIrp, - CurrentStackLocation->Parameters.Create.Options, - (unsigned __int64 *)a2->AssociatedIrp.MasterIrp, - CurrentStackLocation->Parameters.Read.Length, - p_Information); - goto pre_exit; - case 0x9C402088: - v11 = writemsr( - (__int64)a2->AssociatedIrp.MasterIrp, - CurrentStackLocation->Parameters.Create.Options, - (__int64)a2->AssociatedIrp.MasterIrp, - CurrentStackLocation->Parameters.Read.Length, - p_Information); - goto pre_exit; - case 0x9C40208C: - v11 = readpmc( - (unsigned int *)a2->AssociatedIrp.MasterIrp, - CurrentStackLocation->Parameters.Create.Options, - (unsigned __int64 *)a2->AssociatedIrp.MasterIrp, - CurrentStackLocation->Parameters.Read.Length, - p_Information); - goto pre_exit; - case 0x9C402090: - __halt(); - case 0x9C4060C4: - case 0x9C4060CC: - case 0x9C4060D0: - goto write_B_W_DW; + } + goto exit; } + v11 = MapPhisicalMemory( + (__int64)a2->AssociatedIrp.MasterIrp, + CurrentStackLocation->Parameters.Create.Options, + a2->AssociatedIrp.MasterIrp, + CurrentStackLocation->Parameters.Read.Length, + p_Information); + pre_exit: + status = v11; + goto exit; + } + switch (IOCTL_Code) + { + case 0x9C4060D4: + read_write_B_W_DW: + v7 = a2->AssociatedIrp.MasterIrp; + v8 = CurrentStackLocation->Parameters.Create.Options; + v9 = *(_DWORD *)&v7->Type; + switch (IOCTL_Code) + { + case 0x9C4060CC: + v13 = __inbyte(v9); + LOBYTE(v7->Type) = v13; + goto pre_exit2; + case 0x9C4060D0: + v12 = __inword(v9); + v7->Type = v12; + goto pre_exit2; + case 0x9C4060D4: + v10 = __indword(v9); + *(_DWORD *)&v7->Type = v10; + pre_exit2: + *p_Information = v8; + goto exit_ok; + } + pre_invalid_param: + *p_Information = 0; + goto invalid_parameter; + case 0x9C402000: + *(_DWORD *)a2->AssociatedIrp.MasterIrp = 16908293; + goto LABEL1; + case 0x9C402004: + *(_DWORD *)a2->AssociatedIrp.MasterIrp = dword_13110; + LABEL1: + *(_QWORD *)p_Information = 4i64; + exit_ok: + status = 0; + break; + case 0x9C402084: + v11 = readmsr( + (unsigned int *)a2->AssociatedIrp.MasterIrp, + CurrentStackLocation->Parameters.Create.Options, + (unsigned __int64 *)a2->AssociatedIrp.MasterIrp, + CurrentStackLocation->Parameters.Read.Length, + p_Information); + goto pre_exit; + case 0x9C402088: + v11 = writemsr( + (__int64)a2->AssociatedIrp.MasterIrp, + CurrentStackLocation->Parameters.Create.Options, + (__int64)a2->AssociatedIrp.MasterIrp, + CurrentStackLocation->Parameters.Read.Length, + p_Information); + goto pre_exit; + case 0x9C40208C: + v11 = readpmc( + (unsigned int *)a2->AssociatedIrp.MasterIrp, + CurrentStackLocation->Parameters.Create.Options, + (unsigned __int64 *)a2->AssociatedIrp.MasterIrp, + CurrentStackLocation->Parameters.Read.Length, + p_Information); + goto pre_exit; + case 0x9C402090: + __halt(); + case 0x9C4060C4: + case 0x9C4060CC: + case 0x9C4060D0: + goto read_write_B_W_DW; + } exit: - a2->IoStatus.Status = status; - IofCompleteRequest(a2, 0); - return status; + a2->IoStatus.Status = status; + IofCompleteRequest(a2, 0); + return status; } \ No newline at end of file diff --git a/windows/x64/kernel/crucial_Ballistix_MOD_Utility_v.2.0.2.5/Reverse Engineering/MODAPI.sys.i64 b/windows/x64/kernel/crucial_Ballistix_MOD_Utility_v.2.0.2.5/Reverse Engineering/MODAPI.sys.i64 index bb9002144c4ba8f0e233d39dda2bb47c33452680..da89c02c97aca13942d6cc507fa941f8b56567d5 100644 GIT binary patch delta 2221 zcmZXVX>3$g6vxlKZ#tdzy;=IEGt)u=1*%rVDvL;3Qb0hkvMM4vEv2o2wo)W4lA*N$ z30A0}54250wzvi?VT7QTF9;O~Y4`ww7z~1_35IASEW!Ud^pn11e)-SY?!D*U``)o# zdB=9;Z5rvi(c1Sw>zL#I0O9GQfVPg1I?_kQH+T0Ps9$w;3|1=)J47Z;d$7;KnnjgM zDywShY8yOccdYNf<^{F3!`E0~1UPj{l&egMA}22t57X3CeOYx)Lrq0$(bUStbxT%w z$YraJ>Mhay@c(=rZ|(hlvnt6vSE>q>E(xQ^iGXbwRB~|3PMTC&a#On(S1wJ}R~XLR z>8dKOwX!VtsU6=`9WAD8$_^DyC|kEw8JTm_)v|1JW+hLCNYNb+WoKTTt3Gq9_KYv3 zo>A%9Ru)_#GaK$Akm#oA24|T8SjK}y$AfIIg56Ca%S~C-1?{4~&<0%yx=GV}uqfIm zxg#u&Zxp=)xr#1I<%x(V>InK^xenq{X69VEI;4h-4RYTagIVx3$($Bg3c3{}dI@6? zHCO!yJj?{@V`N_Sf@^fN;)db(y= zrH2L@5_T_hHKY&w)o^ELz8>aW&DVniWet_DEvT!gTTuDv_>A34H!J5#Z@t6$sJAY4 zP8Mjtv!OtbbGG%?gEDsuwC57HkZwD^M%9>B)SMT_-?}_6rauoPDuzW<5vV9GUYGEC zk`pf^xm{gJo=_&~0(V0zdRHuOB)P)UB)4l$lDA`IG6ZiSNE8#h5?)WBPMR(yIH5b? z!;qbzqAx(A_Jj#;6gDNKpAxx1yc0Q@Mv3KNvBbsV6U*&5SGX4EnDcS2e?lyW;#}ub zv9yULy&=xStd8?u)k7;P7t1UOogkqjB(#5=`(}&99p}~mnaiuckjtw-3KH!T%lo+| z4q6MSX$`2T0VG-|k!2D&G?%B9pO!y2V}2z30%|%9D*75E+8W~l*2cK>!Wa)fQ!GU> z8!<7E=&tR@3I79h(Rt9IW1yxCsAwlh^p4FH(l%GCwz6xiIZh&b-$ zaOl+>_MXb&IMh#4EKd5MH z)JVg$D#};nl_(E3FUpgcj8KCHftr$%?2+W(BOLQXgiCw}D%uO;)feH?%@Mv#RS^wN zjzqvG#oIf=J@7`j;eUsDqkjzZVLu9D{JmjL{vgcBO<~@rdIV`ofr_R{!Wi*BAl|Gn zpXVzfKF=pZT<%NJ?V_7PHm1G=)HDZFGyx=f95J{B5*bD$rVZ*e{bunn=Rl%wExwAM zi*_tt!RuBCg%*RjoFLIt;vFHnP;|obpqvIZT{At1JOkn|n%s$IlRH#naRU zqJH8{`%P~CjUZ3rB8ZzEL{9``&_y6la*$sRrr7TU zxX#Z3&gzCX=m4mx9aPjJ-qit~TzNXc`#mwhJ5(szLYk)AeqQlq5GDNFmBXU<_&IH* z=n6lttW+$I`FZ=oqHp@}I0zDL^YOi3>Ep4=ecYQ;(fxdBc94&c)nza1BVN`Y zdik(4i7xkY+BneV65V3-kd-_gW7R*( zuxLhR&U$q#;>_<LvB%rjcv%H{zD$qc x%VbPC8y?&%P?Td^c0sSu;6ylTW@Rc?xVmOLAOGYEt{Z*YgZV>l}S0s>N^y=)utijrK1Q zBih$7rsXl!-sfpc8BQM67)H#rK;PPKGe5X#=BbJxzTZLV3jpt-iLzVGFOr@K@| zW=XY5DP0jn?B~9SL6wKQd#R?n@}_pKt$(_kSK0({3@}xO6H@Ic|78YcKAJr zJPQ(CR{qR|mFh!PTIlCauJUKWw?*bO+fvBe2`X9y5>=rR(FO~kLO$b->sbpqF zlZxrwApNhEE^zh?qfLBR3Y>zV9(nOmRZal6Q&PlMVJi&7=N*G{H!T}nv75x@x z<@-3te--CBABuBNUW*6dZ3i(U(Vq~`iF2N55?>5OQxa6<74LAKNtC9me50W}Ud~`1 zr#_m;srTmb;2olD6J?_)4WcX&WtJ#qqTD4)uHeYWfaTGzbzM%jL)eAW=sy zXKoSukz6n0t3XW?K}B(p=z2QJ1ujQu{JSu`levGF}Ng z(g=M94~ptRqWdLiDu!tq4Jz_Wid!M}UJCKi|0JY2MJNRB3UPtwLfnHVL)`HBA>QeG zU}MWf@ypnoK^{94H&$m0`eAsL`{e^Xc?$!HmGQdjLi=O;q{39yM+a$>4FtN&?!*SVUVcT;xgT0 zw~M{Wav|MvP}3|>Q3*(7THJ|CrfieR{dmU=!@C1SZj-%@CO3bc$&}06`Z>{b8C4A1pfIRu*vDnAfH*xq zF5mCt{od>24QdyAjgJ?+1XNU+#*L`h$8E_I+abfwd08Lu^2+vjInhgA-oGZX7mGa^ zwxXygH$40{pYw3Beh>F%kJxF^mwEW;Rf;`A?AvZWD?{#u?C5v%u-$I9x4Jn|gV-~n zD=HGN$IVHvxU%sQo(2ti7sNLiRJ0x>TFfCJzQ!+TheZokXNFzIa46}f1?=Gq%W7>K zP~j7#{^o1;2)j1l7&qQSV=M1Okm3!#b1D3;5V-~vzm*bS;IaqujYB%8(YBICBGZ{P zo;5P=J?gDm{ey+dBh3JQE9zBg$&^V|rDc^fC(p|K6wn`gRf)YfU*D}}+NbjM^h_+N z+mwAKr6<`3Q#xty9HD#c?I~Stx2Ck$C@+~}SElsH%