Samples of code =============== .. _sample_current_process: ``windows.current_process`` """"""""""""""""""""""""""" .. literalinclude:: ..\..\samples\current_process.py Output:: (cmd λ) python32.exe current_process.py current process is current process is a <32> bits process current process is a SysWow64 process ? current process pid <7432> and ppid <5412> Here are the current process threads: <[]> Let's execute some native code ! (0x41 + 1) Waiting for execution to finish ! Native code returned <0x42L> Allocating memory in current process Allocated memory is at <0x3f0000> Writing 'SOME STUFF' in allocation memory Reading memory : <'SOME STUFF\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'> .. _sample_remote_process: Remote process : :class:`WinProcess` """""""""""""""""""""""""""""""""""" .. literalinclude:: ..\..\samples\remote_calc.py Output:: (cmd λ) python.exe remote_calc.py Creating a calc Looking for calcs in the processes They are currently <1> calcs running on the system Let's play with our calc: <> Our calc pid is 8052 Our calc is a <32> bits process Our calc is a SysWow64 process ? Our calc have threads ! <[, , ]> Exploring our calc PEB ! Command line is Here are 3 loaded modules: [, , ] Allocating memory in our calc Allocated memory is at <0x5c90000> Writing 'SOME STUFF' in allocated memory Reading allocated memory : <'SOME STUFF\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'> Execution some native code in our calc (write 0x424242 at allocated address + return 0x1337 Executing native code ! Return code = 0x1337L Reading allocated memory : <'BBBB STUFF\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'> Executing python code ! Reading allocated memory : <'HELLO FROM CALC\x00\x00\x00\x00\x00'> Trying to import in remote module 'FAKE_MODULE' Remote ERROR ! Traceback (most recent call last): File "", line 3, in File "", line 2, in func ImportError: No module named FAKE_MODULE That's all ! killing the calc .. _sample_peb_exploration: :class:`PEB` exploration """""""""""""""""""""""" .. literalinclude:: ..\..\samples\peb.py Output:: (cmd λ) python.exe peb.py Exploring the current process PEB PEB is <> Commandline object is Commandline string is u'python.exe peb.py ' Imagepath Printing some modules: === K32 === Looking for kernel32.dll Kernel32 module: Module name = | Fullname = Kernel32 is loaded at address 0x774c0000 === K32 PE === PE Representation of k32: Here are some exports {0: 2001566688L, u'CreateFileA': 2001635616L, 42: 2001647872L, u'VirtualAlloc': 2001570704L} Import DLL dependancies are (without api-*): [u'ntdll.dll', u'kernelbase.dll'] IAT Entry for ntdll!NtCreateFile = | addr = 0x77541128L Sections: [, , , , ] .. _sample_system: ``windows.system`` """""""""""""""""" .. literalinclude:: ..\..\samples\system.py Output:: (cmd λ) python system.py Basic system infos: version = (6, 3) bitness = 64 computer_name = HAKRIL-PC product_type = VER_NT_WORKSTATION(0x1L) version_name = Windows 8.1 There is 95 processes There is 1021 threads Dumping first logical drive: name = C:\ type = DRIVE_FIXED(0x3L) path = \Device\HarddiskVolume2 Dumping first service: name = ACPI description = Microsoft ACPI Driver status = ServiceStatus(type=SERVICE_KERNEL_DRIVER(0x1L), state=SERVICE_RUNNING(0x4L), control_accepted=1L, flags=0L) process = None Finding a service in a user process: name = Appinfo description = Application Information status = ServiceStatus(type=SERVICE_WIN32_SHARE_PROCESS(0x20L), state=SERVICE_RUNNING(0x4L), control_accepted=129L, flags=0L) process = .. _sample_iat_hook: IAT hooking """"""""""" .. literalinclude:: ..\..\samples\iat_hook.py Output:: (cmd λ) python iat_hook.py Asking for Hook called | hKey = 0x12d687 | lpSubKey = Secret key asked, returning magic handle 0x12345678 Result = 0x12345678 Asking for Hook called | hKey = 0x12d687 | lpSubKey = Asked for a failing key: returning 0x2a WindowsError(42, 'Windows Error 0x2A') Asking for Hook called | hKey = 0x80000001L | lpSubKey = Non-secret key : calling normal function Result = 0x108 .. _sample_network_exploration: :class:`Network` - socket exploration """"""""""""""""""""""""""""""""""""" .. literalinclude:: ..\..\samples\network.py Output:: (cmd λ) python.exe network.py Working on ipv4 == Listening == Some listening connections: [, , ] Listening ports are : [80, 135, 443, 445, 902, 912, 5357, 49152, 49153, 49154, 49155, 49157, 49159, 8307, 25340, 139, 139] == Established == Some established connections: [ 127.0.0.1:49472>, 127.0.0.1:49174>, 127.0.0.1:49173>] == connection to localhost:80 == Our connection is [ 127.0.0.1:80>] Sending YOP Closing socket Sending LAIT Traceback (most recent call last): File ".\network.py", line 45, in s.send("LAIT") socket.error: [Errno 10054] An existing connection was forcibly closed by the remote host .. _sample_registry: :class:`Registry` """"""""""""""""" .. literalinclude:: ..\..\samples\registry.py Output:: (cmd λ) python.exe registry.py Registry is <> HKEY_CURRENT_USER is <> HKEY_CURRENT_USER subkeys names are: ['AppEvents', 'AppXBackupContentType', 'Console', 'Control Panel', 'Environment', 'EUDC', 'Identities', 'Keyboard Layout', 'Network', 'Printers', 'Software', 'System', 'Volatile Environment'] Opening 'Software' in HKEY_CURRENT_USER: We can also open it in one access: Looking at CurrentVersion Key is values are: [KeyValue(name='SoftwareType', value=u'System', type=1), KeyValue(name='RegisteredOwner', value=u'hakril', type=1), KeyValue(name='InstallDate', value=0, type=4), ... KeyValue(name='PathName', value=u'C:\\Windows', type=1)] registered owner = .. _sample_wintrust: ``windows.wintrust`` """""""""""""""""""" .. literalinclude:: ..\..\samples\wintrust.py Output:: (cmd λ) python .\wintrust.py Checking signature of is_signed: check_signature: <0> full_signature_information: * signed * catalog * catalogsigned * additionalinfo <0> Checking signature of some loaded DLL : False (TRUST_E_NOSIGNATURE(0x800b0100L)) : True : True : True : False (TRUST_E_NOSIGNATURE(0x800b0100L)) .. _sample_vectoredexception: :func:`VectoredException` """"""""""""""""""""""""" In local process '''''''''''''''' .. literalinclude:: ..\..\samples\veh_segv.py Output:: (cmd λ) python.exe veh_segv.py Protected page is at <0x1db0000> Setting page protection to ==Entry of VEH handler== Instr at 0x1d1ab574 accessed to addr 0x1db0000 Resetting page protection to ==Entry of VEH handler== Exception of type EXCEPTION_SINGLE_STEP(0x80000004L) Resetting page protection to Value 1 read ==Entry of VEH handler== Instr at 0x1d1ab574 accessed to addr 0x1db0010 Resetting page protection to ==Entry of VEH handler== Exception of type EXCEPTION_SINGLE_STEP(0x80000004L) Resetting page protection to Value 2 read In remote process ''''''''''''''''' .. literalinclude:: ..\..\samples\remote_veh_segv.py Output:: (cmd λ) python .exe.\samples\remote_veh_segv.py (In another console) Tracing execution in module: Protected page is at 0x7ffa3c700000L Instr at 0x7ffa3c70f0f0L accessed to addr 0x7ffa3c70f0f0L (gdi32.dll) Exception of type EXCEPTION_SINGLE_STEP(0x80000004L) Resetting page protection to Instr at 0x7ffa3c70f0f5L accessed to addr 0x7ffa3c70f0f5L (gdi32.dll) Exception of type EXCEPTION_SINGLE_STEP(0x80000004L) Resetting page protection to Instr at 0x7ffa3c70f0faL accessed to addr 0x7ffa3c70f0faL (gdi32.dll) Exception of type EXCEPTION_SINGLE_STEP(0x80000004L) Resetting page protection to Instr at 0x7ffa3c70f0ffL accessed to addr 0x7ffa3c70f0ffL (gdi32.dll) Exception of type EXCEPTION_SINGLE_STEP(0x80000004L) Resetting page protection to Instr at 0x7ffa3c70f100L accessed to addr 0x7ffa3c70f100L (gdi32.dll) No more tracing ! .. _sample_debugger: Debugging """"""""" :class:`Debugger` ''''''''''''''''' .. literalinclude:: ..\..\samples\debugger.py Ouput:: (cmd λ) python.exe .\samples\debugger.py Loading Got exception EXCEPTION_BREAKPOINT(0x80000003L) at 0x77a73bad Loading Loading Loading Loading Loading Loading Loading Loading Loading Loading Loading Loading Loading Ask to load : exiting process .. _sample_local_debugger: :class:`LocalDebugger` '''''''''''''''''''''' In current process ^^^^^^^^^^^^^^^^^^ .. literalinclude:: ..\..\samples\local_debugger.py Ouput:: (cmd λ) python.exe .\samples\local_debugger.py Your main thread is 3864 Code addr = 0x46000b GOT AN HXBP <3 at 0x46000b EXCEPTION !!!! Got a EXCEPTION_SINGLE_STEP(0x80000004L) at 0x46000c EXCEPTION !!!! Got a EXCEPTION_SINGLE_STEP(0x80000004L) at 0x46000d EXCEPTION !!!! Got a EXCEPTION_SINGLE_STEP(0x80000004L) at 0x46000e EXCEPTION !!!! Got a EXCEPTION_SINGLE_STEP(0x80000004L) at 0x46000f EXCEPTION !!!! Got a EXCEPTION_SINGLE_STEP(0x80000004L) at 0x460010 EXCEPTION !!!! Got a EXCEPTION_SINGLE_STEP(0x80000004L) at 0x460011 In remote process ^^^^^^^^^^^^^^^^^ .. literalinclude:: ..\..\samples\local_debugger_remote_process.py Ouput:: (cmd λ) python.exe .\samples\local_debugger_remote_process.py (In another console) I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING .. _wmi_request: Make WMI requests ''''''''''''''''' .. literalinclude:: ..\..\samples\wmi_request.py Ouput:: (cmd λ) python .\samples\wmi_request.py WMI requester is Selecting * from 'Win32_Process' They are <92> processes Looking for ourself via pid Some info about our process: * Name -> python.exe * ProcessId -> 7968 * OSName -> Microsoft Windows 8.1 Pro|C:\Windows|\Device\Harddisk0\Partition2 * UserModeTime -> 2812500 * WindowsVersion -> 6.3.9600 * CommandLine -> python.exe .\samples\wmi_request.py