Samples of code =============== .. _sample_current_process: ``windows.current_process`` """"""""""""""""""""""""""" .. literalinclude:: ..\..\samples\current_process.py Output:: (cmd λ) python32.exe current_process.py current process is current process is a <32> bits process current process is a SysWow64 process ? current process pid <7432> and ppid <5412> Here are the current process threads: <[]> Let's execute some native code ! (0x41 + 1) Waiting for execution to finish ! Native code returned <0x42L> Allocating memory in current process Allocated memory is at <0x3f0000> Writing 'SOME STUFF' in allocation memory Reading memory : <'SOME STUFF\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'> .. _sample_remote_process: Remote process : :class:`WinProcess` """""""""""""""""""""""""""""""""""" .. literalinclude:: ..\..\samples\remote_calc.py Output:: (cmd λ) python.exe remote_calc.py Creating a calc Looking for calcs in the processes They are currently <1> calcs running on the system Let's play with our calc: <> Our calc pid is 8052 Our calc is a <32> bits process Our calc is a SysWow64 process ? Our calc have threads ! <[, , ]> Exploring our calc PEB ! Command line is Here are 3 loaded modules: [, , ] Allocating memory in our calc Allocated memory is at <0x5c90000> Writing 'SOME STUFF' in allocated memory Reading allocated memory : <'SOME STUFF\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'> Execution some native code in our calc (write 0x424242 at allocated address + return 0x1337 Executing native code ! Return code = 0x1337L Reading allocated memory : <'BBBB STUFF\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'> Executing python code ! Reading allocated memory : <'HELLO FROM CALC\x00\x00\x00\x00\x00'> Trying to import in remote module 'FAKE_MODULE' Remote ERROR ! Traceback (most recent call last): File "", line 3, in File "", line 2, in func ImportError: No module named FAKE_MODULE That's all ! killing the calc .. _sample_peb_exploration: :class:`PEB` exploration """""""""""""""""""""""" .. literalinclude:: ..\..\samples\peb.py Output:: (cmd λ) python.exe peb.py Exploring the current process PEB PEB is <> Commandline object is Commandline string is u'python.exe peb.py ' Imagepath Printing some modules: === K32 === Looking for kernel32.dll Kernel32 module: Module name = | Fullname = Kernel32 is loaded at address 0x774c0000 === K32 PE === PE Representation of k32: Here are some exports {0: 2001566688L, u'CreateFileA': 2001635616L, 42: 2001647872L, u'VirtualAlloc': 2001570704L} Import DLL dependancies are (without api-*): [u'ntdll.dll', u'kernelbase.dll'] IAT Entry for ntdll!NtCreateFile = | addr = 0x77541128L Sections: [, , , , ] .. _sample_iat_hook: IAT hooking """"""""""" .. literalinclude:: ..\..\samples\iat_hook.py Output:: (cmd λ) python iat_hook.py Asking for Hook called | hKey = 0x12d687 | lpSubKey = Secret key asked, returning magic handle 0x12345678 Result = 0x12345678 Asking for Hook called | hKey = 0x12d687 | lpSubKey = Asked for a failing key: returning 0x2a WindowsError(42, 'Windows Error 0x2A') Asking for Hook called | hKey = 0x80000001L | lpSubKey = Non-secret key : calling normal function Result = 0x108 .. _sample_network_exploration: :class:`Network` - socket exploration """"""""""""""""""""""""""""""""""""" .. literalinclude:: ..\..\samples\network.py Output:: (cmd λ) python.exe network.py Working on ipv4 == Listening == Some listening connections: [, , ] Listening ports are : [80, 135, 443, 445, 902, 912, 5357, 49152, 49153, 49154, 49155, 49157, 49159, 8307, 25340, 139, 139] == Established == Some established connections: [ 127.0.0.1:49472>, 127.0.0.1:49174>, 127.0.0.1:49173>] == connection to localhost:80 == Our connection is [ 127.0.0.1:80>] Sending YOP Closing socket Sending LAIT Traceback (most recent call last): File ".\network.py", line 45, in s.send("LAIT") socket.error: [Errno 10054] An existing connection was forcibly closed by the remote host .. _sample_registry: :class:`Registry` """"""""""""""""" .. literalinclude:: ..\..\samples\registry.py Output:: (cmd λ) python.exe registry.py Registry is <> HKEY_CURRENT_USER is <> HKEY_CURRENT_USER subkeys names are: ['AppEvents', 'AppXBackupContentType', 'Console', 'Control Panel', 'Environment', 'EUDC', 'Identities', 'Keyboard Layout', 'Network', 'Printers', 'Software', 'System', 'Volatile Environment'] Opening 'Software' in HKEY_CURRENT_USER: We can also open it in one access: Looking at CurrentVersion Key is values are: [KeyValue(name='SoftwareType', value=u'System', type=1), KeyValue(name='RegisteredOwner', value=u'hakril', type=1), KeyValue(name='InstallDate', value=0, type=4), ... KeyValue(name='PathName', value=u'C:\\Windows', type=1)] registered owner =