From 12cd5ee6076953fa34db6c4ef13a9718f862b665 Mon Sep 17 00:00:00 2001 From: kento <37926134+kkent030315@users.noreply.github.com> Date: Fri, 23 Oct 2020 19:44:07 +0900 Subject: [PATCH] cleanup repo --- README.md | 16 ++++++++-------- image01.png => images/image01.png | Bin image02.png => images/image02.png | Bin image03.png => images/image03.png | Bin image04.png => images/image04.png | Bin image05.png => images/image05.png | Bin image06.png => images/image06.png | Bin image07.png => images/image07.png | Bin image08.png => images/image08.png | Bin image09.png => images/image09.png | Bin 10 files changed, 8 insertions(+), 8 deletions(-) rename image01.png => images/image01.png (100%) rename image02.png => images/image02.png (100%) rename image03.png => images/image03.png (100%) rename image04.png => images/image04.png (100%) rename image05.png => images/image05.png (100%) rename image06.png => images/image06.png (100%) rename image07.png => images/image07.png (100%) rename image08.png => images/image08.png (100%) rename image09.png => images/image09.png (100%) diff --git a/README.md b/README.md index a535fb8..be81cdf 100644 --- a/README.md +++ b/README.md @@ -1,8 +1,8 @@ ![LOGO](logo.png) -![IMAGE](image01.png) -![IMAGE](image04.png) -![IMAGE](image05.png) +![IMAGE](images/image01.png) +![IMAGE](images/image04.png) +![IMAGE](images/image05.png) # evil-mhyprot-cli A PoC for vulnerable driver "mhyprot" that allows us to read/write memory in kernel/user from usermode. @@ -87,7 +87,7 @@ Since around ioctl functions and its functionalities are packed, to reverse engi but I can still easily find the function that registered at `DriverObject->MajorFunction[IRP_MJ_DEVICE_CONTROL]` since the IOCTL handler must have an `IoCompleteRequest` or like `IofCompleteRequest` that exported by `ntoskrnl`. (Btw `IoCompleteRequest` is just a wrapper of `IofCompleteRequest`) -![IMAGE](image03.png) +![IMAGE](images/image03.png) As mhyprot imports `IofCompleteRequest` then go xrefs, and we will see there are many ioctl handlers. Concretely, I found two big subroutine in packed segment. @@ -271,13 +271,13 @@ PAGE:FFFFF800188CD31B jmp loc_FFFFF800188CD21C Call map: -![IMAGE](image06.png) +![IMAGE](images/image06.png) ### Proof I have confirmed that by simply hooking mhyprot kernel module: -![IMAGE](image08.png) +![IMAGE](images/image08.png) ## A Way of Read Kernel Memory @@ -329,14 +329,14 @@ And the `sub_FFFFF800188C63A8` is like: Here is the ioctl handlers, found the `0x83064000`(`MHYPROT_IOCTL_READ_KERNEL_MEMORY`) as `cmp ecx, 83064000h` and some another ioctl codes as follows: -![IMAGE](image02.png) +![IMAGE](images/image02.png) Call map: As I defined as `DWORD result` in [mhyprot.hpp#L40](https://github.com/kkent030315/evil-mhyprot-cli/blob/main/src/mhyprot.hpp#L40) the first 4bytes is result. I can guess it's a `NTSTATUS` as it typedef'ed as `typedef LONG NTSTATUS` natively and the dispathers return types are `NTSTATUS` and the result will directly be got stored from it. -![IMAGE](image07.png) +![IMAGE](images/image07.png) ## Enumerate Modules diff --git a/image01.png b/images/image01.png similarity index 100% rename from image01.png rename to images/image01.png diff --git a/image02.png b/images/image02.png similarity index 100% rename from image02.png rename to images/image02.png diff --git a/image03.png b/images/image03.png similarity index 100% rename from image03.png rename to images/image03.png diff --git a/image04.png b/images/image04.png similarity index 100% rename from image04.png rename to images/image04.png diff --git a/image05.png b/images/image05.png similarity index 100% rename from image05.png rename to images/image05.png diff --git a/image06.png b/images/image06.png similarity index 100% rename from image06.png rename to images/image06.png diff --git a/image07.png b/images/image07.png similarity index 100% rename from image07.png rename to images/image07.png diff --git a/image08.png b/images/image08.png similarity index 100% rename from image08.png rename to images/image08.png diff --git a/image09.png b/images/image09.png similarity index 100% rename from image09.png rename to images/image09.png