mirror of
https://github.com/fortra/No-Consolation
synced 2026-06-06 15:44:28 +00:00
allow users to run 'noconsolation --close-handles'
This commit is contained in:
+30
-26
@@ -115,45 +115,49 @@ alias noconsolation
|
||||
}
|
||||
}
|
||||
|
||||
if ($path_set == 0)
|
||||
# allow users to close all handles without having to run a PE
|
||||
if ($path_set == 0 && $close_handles == 0)
|
||||
{
|
||||
berror($1, "PE path not provided");
|
||||
return;
|
||||
}
|
||||
|
||||
if (!-exists $path && $local == 0)
|
||||
if ($path_set && !-exists $path && $local == 0)
|
||||
{
|
||||
berror($bid, "Specified executable ". $path ." does not exist");
|
||||
return;
|
||||
}
|
||||
|
||||
if ($local == 0)
|
||||
if ($path_set)
|
||||
{
|
||||
$pename = split("/", $path, 50)[-1];
|
||||
|
||||
$handle = openf($path);
|
||||
$pebytes = readb($handle, -1);
|
||||
closef($handle);
|
||||
if(strlen($pebytes) == 0)
|
||||
if ($local == 0)
|
||||
{
|
||||
berror($1, "could not read PE");
|
||||
return;
|
||||
}
|
||||
$path = '';
|
||||
}
|
||||
else
|
||||
{
|
||||
$pename = split('\\\\', $path, 50)[-1];
|
||||
}
|
||||
$pename = split("/", $path, 50)[-1];
|
||||
|
||||
# Iterate through args given
|
||||
$cmdline = $pename;
|
||||
for ($y = $i + 1; $y < size(@_); $y++)
|
||||
{
|
||||
# We have instructed users to 'escape' double quotes by using a backslash
|
||||
# identify this and replace with a normal double quote.
|
||||
$arg = strrep(@_[$y], '\\"', '"');
|
||||
$cmdline = $cmdline . " " . $arg;
|
||||
$handle = openf($path);
|
||||
$pebytes = readb($handle, -1);
|
||||
closef($handle);
|
||||
if(strlen($pebytes) == 0)
|
||||
{
|
||||
berror($1, "could not read PE");
|
||||
return;
|
||||
}
|
||||
$path = '';
|
||||
}
|
||||
else
|
||||
{
|
||||
$pename = split('\\\\', $path, 50)[-1];
|
||||
}
|
||||
|
||||
# Iterate through args given
|
||||
$cmdline = $pename;
|
||||
for ($y = $i + 1; $y < size(@_); $y++)
|
||||
{
|
||||
# We have instructed users to 'escape' double quotes by using a backslash
|
||||
# identify this and replace with a normal double quote.
|
||||
$arg = strrep(@_[$y], '\\"', '"');
|
||||
$cmdline = $cmdline . " " . $arg;
|
||||
}
|
||||
}
|
||||
|
||||
runpe($bid, $pebytes, $path, $local, $timeout, $headers, $cmdline, $method, $use_unicode, $nooutput, $alloc_console, $close_handles, $free_libs);
|
||||
|
||||
Vendored
BIN
Binary file not shown.
Vendored
BIN
Binary file not shown.
@@ -33,6 +33,7 @@ int go(IN PCHAR Buffer, IN ULONG Length)
|
||||
BeaconDataParse(&parser, Buffer, Length);
|
||||
pe_bytes = BeaconDataExtract(&parser, &pe_length);
|
||||
pe_path = BeaconDataExtract(&parser, NULL);
|
||||
pe_path = pe_path[0] ? pe_path : NULL;
|
||||
local = BeaconDataInt(&parser);
|
||||
timeout = BeaconDataInt(&parser);
|
||||
headers = BeaconDataInt(&parser);
|
||||
@@ -57,6 +58,9 @@ int go(IN PCHAR Buffer, IN ULONG Length)
|
||||
peinfo->alloc_console = alloc_console;
|
||||
peinfo->unload_libs = unload_libs;
|
||||
|
||||
if (!pe_path && !pe_length)
|
||||
goto Cleanup;
|
||||
|
||||
if (local)
|
||||
{
|
||||
if (!read_local_pe(pe_path, &pe_bytes, &pe_length))
|
||||
@@ -105,6 +109,7 @@ Cleanup:
|
||||
|
||||
if (close_handles)
|
||||
{
|
||||
DPRINT("Freeing handles");
|
||||
if (peinfo && peinfo->Handles && peinfo->Handles->fo_msvc)
|
||||
{
|
||||
void ( WINAPI *msvcrt_close ) ( int ) = xGetProcAddress(xGetLibAddress("msvcrt", TRUE, NULL), "_close", 0);
|
||||
|
||||
Reference in New Issue
Block a user