mirror of
https://github.com/mgeeky/ShellcodeFluctuation
synced 2026-06-06 16:14:31 +00:00
Generalised memory protection revert to reuse protection originally met after locating shellcode for the first time.
This commit is contained in:
@@ -31,6 +31,7 @@ struct FluctuationMetadata
|
||||
SIZE_T shellcodeSize;
|
||||
bool currentlyEncrypted;
|
||||
DWORD encodeKey;
|
||||
DWORD protect;
|
||||
};
|
||||
|
||||
struct HookedSleep
|
||||
|
||||
@@ -291,7 +291,7 @@ void shellcodeEncryptDecrypt(LPVOID callerAddress)
|
||||
g_fluctuationData.shellcodeAddr,
|
||||
g_fluctuationData.shellcodeSize,
|
||||
PAGE_READWRITE,
|
||||
&oldProt
|
||||
&g_fluctuationData.protect
|
||||
);
|
||||
|
||||
log("[>] Flipped to RW.");
|
||||
@@ -330,11 +330,11 @@ void shellcodeEncryptDecrypt(LPVOID callerAddress)
|
||||
::VirtualProtect(
|
||||
g_fluctuationData.shellcodeAddr,
|
||||
g_fluctuationData.shellcodeSize,
|
||||
Shellcode_Memory_Protection,
|
||||
g_fluctuationData.protect,
|
||||
&oldProt
|
||||
);
|
||||
|
||||
log("[<] Flipped to RX.\n");
|
||||
log("[<] Flipped back to RX/RWX.\n");
|
||||
}
|
||||
|
||||
g_fluctuationData.currentlyEncrypted = !g_fluctuationData.currentlyEncrypted;
|
||||
|
||||
Reference in New Issue
Block a user