IAT hook GetModuleHandleW

otherwise, GetModuleHandleW(NULL) would return an invalid address
This commit is contained in:
S4ntiagoP
2024-05-08 15:48:24 -03:00
parent 3a7be6cff7
commit 98401cb893
7 changed files with 56 additions and 9 deletions
BIN
View File
Binary file not shown.
BIN
View File
Binary file not shown.
+2 -1
View File
@@ -8,7 +8,8 @@
#include "utils.h"
#define NC_HANDLE_INFO_KEY "NoConsolationHandleKey"
#define NC_PE_INFO_KEY "NoConsolationPeKey"
#define NC_SAVED_PE_KEY "NoConsolationSavedPeKey"
#define NC_PE_INFO_KEY "NoConsolationPeInfoKey"
#define STATUS_SUCCESS 0x00000000
//#define STATUS_INVALID_HANDLE 0xc0000008
+3
View File
@@ -15,6 +15,9 @@ FARPROC my_get_proc_address(
IN HMODULE hModule,
IN LPSTR lpProcName);
HMODULE my_get_module_handle_w(
IN LPCWSTR lpModuleName);
#ifdef _WIN64
BOOL insert_inverted_function_table_entry(
IN PVOID base_address,
+5
View File
@@ -75,6 +75,9 @@ int go(IN PCHAR Buffer, IN ULONG Length)
peinfo->alloc_console = alloc_console;
peinfo->unload_libs = unload_libs;
// save a reference to peinfo
BeaconAddValue(NC_PE_INFO_KEY, peinfo);
if (list_pes)
{
list_saved_pes();
@@ -284,5 +287,7 @@ Cleanup:
intFree(peinfo);
}
BeaconRemoveValue(NC_PE_INFO_KEY);
return 0;
}
+7 -1
View File
@@ -237,13 +237,19 @@ BOOL load_pe(
// if this is an exit-related API, replace it with RtlExitUserThread
if (IsExitAPI(ibn->Name))
{
DPRINT("Replacing %s!%s with ntdll!RtlExitUserThread", name, ibn->Name);
DPRINT("IAT hooking %s!%s with ntdll!RtlExitUserThread", name, ibn->Name);
ft->u1.Function = (ULONG_PTR)xGetProcAddress(xGetLibAddress("ntdll", TRUE, NULL), "RtlExitUserThread", 0);
}
else if (!_stricmp(ibn->Name, "GetProcAddress"))
{
DPRINT("IAT hooking %s!%s with my_get_proc_address", name, ibn->Name);
ft->u1.Function = (ULONG_PTR)my_get_proc_address;
}
else if (!_stricmp(ibn->Name, "GetModuleHandleW"))
{
DPRINT("IAT hooking %s!%s with my_get_module_handle_w", name, ibn->Name);
ft->u1.Function = (ULONG_PTR)my_get_module_handle_w;
}
else
{
ft->u1.Function = (ULONG_PTR)xGetProcAddress(dll, ibn->Name, 0);
+39 -7
View File
@@ -111,6 +111,38 @@ FARPROC my_get_proc_address(
}
}
/*
* If the PE calls GetModuleHandleW(NULL), we need to return
* the base of our module, instead of the base of the host process
*/
HMODULE my_get_module_handle_w(
IN LPCWSTR lpModuleName)
{
PLOADED_PE_INFO peinfo = NULL;
if (!lpModuleName)
{
peinfo = BeaconGetValue(NC_PE_INFO_KEY);
if (peinfo)
{
DPRINT("GetModuleHandleW(NULL) was called, returning 0x%p", peinfo->pe_base);
return peinfo->pe_base;
}
}
// call the original GetModuleHandleW
HMODULE ( WINAPI *GetModuleHandleW ) ( LPCWSTR ) = xGetProcAddress(xGetLibAddress("kernelbase", TRUE, NULL), "GetModuleHandleW", 0);
if (GetModuleHandleW)
{
return GetModuleHandleW(lpModuleName);
}
else
{
api_not_found("GetModuleHandleW");
return NULL;
}
}
HANDLE get_console_handle(VOID)
{
uPRTL_USER_PROCESS_PARAMETERS ProcessParameters = (uPRTL_USER_PROCESS_PARAMETERS)NtCurrentTeb()->ProcessEnvironmentBlock->ProcessParameters;
@@ -276,7 +308,7 @@ PSAVED_PE find_pe_by_name(
{
PSAVED_PE saved_pe = NULL;
saved_pe = BeaconGetValue(NC_PE_INFO_KEY);
saved_pe = BeaconGetValue(NC_SAVED_PE_KEY);
while (saved_pe)
{
if (!_stricmp(saved_pe->pe_name, pe_name))
@@ -413,11 +445,11 @@ BOOL save_pe_info(
memcpy(saved_pe->loadtime, loadtime, MAX_PATH);
// add PE to linked list
tmp = BeaconGetValue(NC_PE_INFO_KEY);
tmp = BeaconGetValue(NC_SAVED_PE_KEY);
if (!tmp)
{
// save the PE linked list
if (!BeaconAddValue(NC_PE_INFO_KEY, saved_pe))
if (!BeaconAddValue(NC_SAVED_PE_KEY, saved_pe))
{
function_failed("BeaconAddValue");
return FALSE;
@@ -491,7 +523,7 @@ VOID list_saved_pes()
{
PSAVED_PE saved_pe = NULL;
saved_pe = BeaconGetValue(NC_PE_INFO_KEY);
saved_pe = BeaconGetValue(NC_SAVED_PE_KEY);
if (!saved_pe)
{
PRINT("There are no saved PEs in memory");
@@ -514,7 +546,7 @@ BOOL remove_saved_pe(
PSAVED_PE tmp = NULL;
// look for the PE by name
saved_pe = BeaconGetValue(NC_PE_INFO_KEY);
saved_pe = BeaconGetValue(NC_SAVED_PE_KEY);
while (saved_pe)
{
if (!_stricmp(saved_pe->pe_name, pe_name))
@@ -522,7 +554,7 @@ BOOL remove_saved_pe(
// remove PE from linked list
if (!tmp)
{
if (!BeaconRemoveValue(NC_PE_INFO_KEY))
if (!BeaconRemoveValue(NC_SAVED_PE_KEY))
{
function_failed("BeaconRemoveValue");
return FALSE;
@@ -530,7 +562,7 @@ BOOL remove_saved_pe(
if (saved_pe->next)
{
if (!BeaconAddValue(NC_PE_INFO_KEY, saved_pe->next))
if (!BeaconAddValue(NC_SAVED_PE_KEY, saved_pe->next))
{
function_failed("BeaconAddValue");
return FALSE;