fix bug on insert_inverted_function_table_entry

This commit is contained in:
S4ntiagoP
2024-05-09 23:34:36 -03:00
parent 2d1c27a7b9
commit 85378e4772
3 changed files with 4 additions and 3 deletions
+1 -1
View File
@@ -9,7 +9,7 @@ This is a Beacon Object File (BOF) that executes unmanaged PEs inline and retrie
- Supports EXEs and DLLs
- Does not create new processes
- Saves binaries in memory
- Supports C++ exceptions (experimental)
- Supports C++ exceptions (x64 only)
## Usage
```
BIN
View File
Binary file not shown.
+3 -2
View File
@@ -770,7 +770,8 @@ BOOL insert_inverted_function_table_entry(
{
if (ift->CurrentSize > 1)
{
fte = &ift->TableEntry[0];
// ntdll is always at 0, so we start at 1
fte = &ift->TableEntry[1];
do
{
if (base_address < fte->FunctionTable)
@@ -822,7 +823,7 @@ BOOL remove_inverted_function_table_entry(
if (!ift)
goto Cleanup;
for (DWORD i = 0; i < ift->CurrentSize; ++i)
for (DWORD i = 1; i < ift->CurrentSize; ++i)
{
fte = &ift->TableEntry[i];