Samples of code =============== .. _sample_current_process: ``windows.current_process`` """"""""""""""""""""""""""" .. literalinclude:: ..\..\samples\current_process.py Output:: (cmd λ) python32.exe current_process.py current process is current process is a <32> bits process current process is a SysWow64 process ? current process pid <8264> and ppid <4100> Here are the current process threads: <[]> Let's execute some native code ! (0x41 + 1) Native code returned <0x42> Allocating memory in current process Allocated memory is at <0xd60000> Writing 'SOME STUFF' in allocation memory Reading memory : <'SOME STUFF\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'> .. _sample_remote_process: Remote process : :class:`WinProcess` """""""""""""""""""""""""""""""""""" .. literalinclude:: ..\..\samples\remote_calc.py Output:: (cmd λ) python.exe remote_calc.py Creating a calc Looking for calcs in the processes They are currently <1> calcs running on the system Let's play with our calc: <> Our calc pid is 8052 Our calc is a <32> bits process Our calc is a SysWow64 process ? Our calc have threads ! <[, , ]> Exploring our calc PEB ! Command line is Here are 3 loaded modules: [, , ] Allocating memory in our calc Allocated memory is at <0x5c90000> Writing 'SOME STUFF' in allocated memory Reading allocated memory : <'SOME STUFF\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'> Execution some native code in our calc (write 0x424242 at allocated address + return 0x1337 Executing native code ! Return code = 0x1337L Reading allocated memory : <'BBBB STUFF\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00'> Executing python code ! Reading allocated memory : <'HELLO FROM CALC\x00\x00\x00\x00\x00'> Trying to import in remote module 'FAKE_MODULE' Remote ERROR ! Traceback (most recent call last): File "", line 3, in File "", line 2, in func ImportError: No module named FAKE_MODULE That's all ! killing the calc .. _sample_peb_exploration: :class:`PEB` exploration """""""""""""""""""""""" .. literalinclude:: ..\..\samples\peb.py Output:: (cmd λ) python.exe peb.py Exploring the current process PEB PEB is <> Commandline object is Commandline string is u'python.exe peb.py ' Imagepath Printing some modules: === K32 === Looking for kernel32.dll Kernel32 module: Module name = | Fullname = Kernel32 is loaded at address 0x774c0000 === K32 PE === PE Representation of k32: Here are some exports {0: 2001566688L, u'CreateFileA': 2001635616L, 42: 2001647872L, u'VirtualAlloc': 2001570704L} Import DLL dependancies are (without api-*): [u'ntdll.dll', u'kernelbase.dll'] IAT Entry for ntdll!NtCreateFile = | addr = 0x77541128L Sections: [, , , , ] .. _sample_system: ``windows.system`` """""""""""""""""" .. literalinclude:: ..\..\samples\system.py Output:: (cmd λ) python system.py Basic system infos: version = (6, 3) bitness = 64 computer_name = HAKRIL-PC product_type = VER_NT_WORKSTATION(0x1L) version_name = Windows 8.1 There is 117 processes There is 1246 threads Dumping first logical drive: name = C:\ type = DRIVE_FIXED(0x3L) path = \Device\HarddiskVolume2 Dumping first service: name = ACPI description = Microsoft ACPI Driver status = ServiceStatus(type=SERVICE_KERNEL_DRIVER(0x1L), state=SERVICE_RUNNING(0x4L), control_accepted=1L, flags=0L) process = None Finding a service in a user process: name = Appinfo description = Application Information status = ServiceStatus(type=SERVICE_WIN32_SHARE_PROCESS(0x20L), state=SERVICE_RUNNING(0x4L), control_accepted=129L, flags=0L) process = Enumerating handles: There are 40664 handles: First handle is: in process pid=4> Enumerating handles of the current process: There are 255 handles for this process Looking for a File handle: Handle is in process pid=14340> Name is <\Device\ConDrv> .. _sample_iat_hook: IAT hooking """"""""""" .. literalinclude:: ..\..\samples\iat_hook.py Output:: (cmd λ) python iat_hook.py Asking for Hook called | hKey = 0x12d687 | lpSubKey = Secret key asked, returning magic handle 0x12345678 Result = 0x12345678 Asking for Hook called | hKey = 0x12d687 | lpSubKey = Asked for a failing key: returning 0x2a WindowsError(42, 'Windows Error 0x2A') Asking for Hook called | hKey = 0x80000001L | lpSubKey = Non-secret key : calling normal function Result = 0x108 .. _sample_network_exploration: :class:`Network` - socket exploration """"""""""""""""""""""""""""""""""""" .. literalinclude:: ..\..\samples\network.py Output:: (cmd λ) python.exe network.py Working on ipv4 == Listening == Some listening connections: [, , ] Listening ports are : [80, 135, 443, 445, 902, 912, 5357, 49152, 49153, 49154, 49155, 49157, 49159, 8307, 25340, 139, 139] == Established == Some established connections: [ 127.0.0.1:49472>, 127.0.0.1:49174>, 127.0.0.1:49173>] == connection to localhost:80 == Our connection is [ 127.0.0.1:80>] Sending YOP Closing socket Sending LAIT Traceback (most recent call last): File ".\network.py", line 45, in s.send("LAIT") socket.error: [Errno 10054] An existing connection was forcibly closed by the remote host .. _sample_registry: :class:`Registry` """"""""""""""""" .. literalinclude:: ..\..\samples\registry.py Output:: (cmd λ) python.exe registry.py Registry is <> HKEY_CURRENT_USER is <> HKEY_CURRENT_USER subkeys names are: ['AppEvents', 'AppXBackupContentType', 'Console', 'Control Panel', 'Environment', 'EUDC', 'Identities', 'Keyboard Layout', 'Network', 'Printers', 'Software', 'System', 'Volatile Environment'] Opening 'Software' in HKEY_CURRENT_USER: We can also open it in one access: Looking at CurrentVersion Key is values are: [KeyValue(name='SoftwareType', value=u'System', type=1), KeyValue(name='RegisteredOwner', value=u'hakril', type=1), KeyValue(name='InstallDate', value=0, type=4), ... KeyValue(name='PathName', value=u'C:\\Windows', type=1)] registered owner = .. _sample_wintrust: ``windows.wintrust`` """""""""""""""""""" .. literalinclude:: ..\..\samples\wintrust.py Output:: (cmd λ) python .\wintrust.py Checking signature of is_signed: check_signature: <0> full_signature_information: * signed * catalog * catalogsigned * additionalinfo <0> Checking signature of some loaded DLL : False (TRUST_E_NOSIGNATURE(0x800b0100L)) : True : True : True : False (TRUST_E_NOSIGNATURE(0x800b0100L)) .. _sample_vectoredexception: :func:`VectoredException` """"""""""""""""""""""""" In local process '''''''''''''''' .. literalinclude:: ..\..\samples\veh_segv.py Output:: (cmd λ) python.exe veh_segv.py Protected page is at <0x1db0000> Setting page protection to ==Entry of VEH handler== Instr at 0x1d1ab574 accessed to addr 0x1db0000 Resetting page protection to ==Entry of VEH handler== Exception of type EXCEPTION_SINGLE_STEP(0x80000004L) Resetting page protection to Value 1 read ==Entry of VEH handler== Instr at 0x1d1ab574 accessed to addr 0x1db0010 Resetting page protection to ==Entry of VEH handler== Exception of type EXCEPTION_SINGLE_STEP(0x80000004L) Resetting page protection to Value 2 read In remote process ''''''''''''''''' .. literalinclude:: ..\..\samples\remote_veh_segv.py Output:: (cmd λ) python .exe.\samples\remote_veh_segv.py (In another console) Tracing execution in module: Protected page is at 0x7ffa3c700000L Instr at 0x7ffa3c70f0f0L accessed to addr 0x7ffa3c70f0f0L (gdi32.dll) Exception of type EXCEPTION_SINGLE_STEP(0x80000004L) Resetting page protection to Instr at 0x7ffa3c70f0f5L accessed to addr 0x7ffa3c70f0f5L (gdi32.dll) Exception of type EXCEPTION_SINGLE_STEP(0x80000004L) Resetting page protection to Instr at 0x7ffa3c70f0faL accessed to addr 0x7ffa3c70f0faL (gdi32.dll) Exception of type EXCEPTION_SINGLE_STEP(0x80000004L) Resetting page protection to Instr at 0x7ffa3c70f0ffL accessed to addr 0x7ffa3c70f0ffL (gdi32.dll) Exception of type EXCEPTION_SINGLE_STEP(0x80000004L) Resetting page protection to Instr at 0x7ffa3c70f100L accessed to addr 0x7ffa3c70f100L (gdi32.dll) No more tracing ! .. _sample_debugger: Debugging """"""""" :class:`Debugger` ''''''''''''''''' .. literalinclude:: ..\..\samples\debugger_print_LdrLoaddll.py Ouput:: (cmd λ) python.exe .\samples\debugger_print_LdrLoaddll.py Loading Got exception EXCEPTION_BREAKPOINT(0x80000003L) at 0x77a73bad Loading Loading Loading Loading Loading Loading Loading Loading Loading Loading Loading Loading Loading Ask to load : exiting process Single stepping ~~~~~~~~~~~~~~~ .. literalinclude:: ..\..\samples\debugger_membp_singlestep.py Ouput:: (cmd λ) python.exe .\samples\debugger_membp_singlestep.py Got exception EXCEPTION_BREAKPOINT(0x80000003L) at 0x77ae3c7d Instruction at <0x8d0006> wrote at <0x8e0000> Got single_step EXCEPTION_SINGLE_STEP(0x80000004L) at 0x8d000c Got single_step EXCEPTION_SINGLE_STEP(0x80000004L) at 0x8d0011 Instruction at <0x8d0011> wrote at <0x8e0004> Got single_step EXCEPTION_SINGLE_STEP(0x80000004L) at 0x8d0017 Got single_step EXCEPTION_SINGLE_STEP(0x80000004L) at 0x8d001c Got single_step EXCEPTION_SINGLE_STEP(0x80000004L) at 0x8d0022 Got single_step EXCEPTION_SINGLE_STEP(0x80000004L) at 0x8d0023 No more single step: exiting :class:`windows.debug.FunctionBP` ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ .. literalinclude:: ..\..\samples\debug_functionbp.py Ouput:: (cmd λ) python.exe .\samples\debug_functionbp.py NtCreateFile of <\??\C:\Windows\syswow64\en-US\calc.exe.mui>: handle = 0xac Handle manually found! typename=, name=<\Device\HarddiskVolume2\Windows\SysWOW64\en-US\calc.exe.mui> NtCreateFile of <\Device\DeviceApi\CMApi>: handle = 0x108 Handle manually found! typename=, name=<\Device\DeviceApi> NtCreateFile of <\??\C:\Windows\Fonts\staticcache.dat>: handle = 0x154 Handle manually found! typename=, name=<\Device\HarddiskVolume2\Windows\Fonts\StaticCache.dat> Exiting process .. _sample_local_debugger: :class:`LocalDebugger` '''''''''''''''''''''' In current process ~~~~~~~~~~~~~~~~~~ .. literalinclude:: ..\..\samples\local_debugger.py Ouput:: (cmd λ) python.exe .\samples\local_debugger.py Code addr = 0xcf0002 GOT AN HXBP at 0xcf0002 EXCEPTION !!!! Got a EXCEPTION_SINGLE_STEP(0x80000004L) at 0xcf0003 EXCEPTION !!!! Got a EXCEPTION_SINGLE_STEP(0x80000004L) at 0xcf0004 EXCEPTION !!!! Got a EXCEPTION_SINGLE_STEP(0x80000004L) at 0xcf0005 EXCEPTION !!!! Got a EXCEPTION_SINGLE_STEP(0x80000004L) at 0x770d7c04 Done! In remote process ~~~~~~~~~~~~~~~~~ .. literalinclude:: ..\..\samples\local_debugger_remote_process.py Ouput:: (cmd λ) python.exe .\samples\local_debugger_remote_process.py (In another console) I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING I AM LOADING .. _wmi_request: Make WMI requests ''''''''''''''''' .. literalinclude:: ..\..\samples\wmi_request.py Ouput:: (cmd λ) python .\samples\wmi_request.py WMI requester is Selecting * from 'Win32_Process' They are <92> processes Looking for ourself via pid Some info about our process: * Name -> python.exe * ProcessId -> 7968 * OSName -> Microsoft Windows 8.1 Pro|C:\Windows|\Device\Harddisk0\Partition2 * UserModeTime -> 2812500 * WindowsVersion -> 6.3.9600 * CommandLine -> python.exe .\samples\wmi_request.py