mirror of
https://github.com/mgeeky/ShellcodeFluctuation
synced 2026-06-06 16:14:31 +00:00
Generalised memory protection revert to reuse protection originally met after locating shellcode for the first time.
This commit is contained in:
@@ -31,6 +31,7 @@ struct FluctuationMetadata
|
|||||||
SIZE_T shellcodeSize;
|
SIZE_T shellcodeSize;
|
||||||
bool currentlyEncrypted;
|
bool currentlyEncrypted;
|
||||||
DWORD encodeKey;
|
DWORD encodeKey;
|
||||||
|
DWORD protect;
|
||||||
};
|
};
|
||||||
|
|
||||||
struct HookedSleep
|
struct HookedSleep
|
||||||
|
|||||||
@@ -291,7 +291,7 @@ void shellcodeEncryptDecrypt(LPVOID callerAddress)
|
|||||||
g_fluctuationData.shellcodeAddr,
|
g_fluctuationData.shellcodeAddr,
|
||||||
g_fluctuationData.shellcodeSize,
|
g_fluctuationData.shellcodeSize,
|
||||||
PAGE_READWRITE,
|
PAGE_READWRITE,
|
||||||
&oldProt
|
&g_fluctuationData.protect
|
||||||
);
|
);
|
||||||
|
|
||||||
log("[>] Flipped to RW.");
|
log("[>] Flipped to RW.");
|
||||||
@@ -330,11 +330,11 @@ void shellcodeEncryptDecrypt(LPVOID callerAddress)
|
|||||||
::VirtualProtect(
|
::VirtualProtect(
|
||||||
g_fluctuationData.shellcodeAddr,
|
g_fluctuationData.shellcodeAddr,
|
||||||
g_fluctuationData.shellcodeSize,
|
g_fluctuationData.shellcodeSize,
|
||||||
Shellcode_Memory_Protection,
|
g_fluctuationData.protect,
|
||||||
&oldProt
|
&oldProt
|
||||||
);
|
);
|
||||||
|
|
||||||
log("[<] Flipped to RX.\n");
|
log("[<] Flipped back to RX/RWX.\n");
|
||||||
}
|
}
|
||||||
|
|
||||||
g_fluctuationData.currentlyEncrypted = !g_fluctuationData.currentlyEncrypted;
|
g_fluctuationData.currentlyEncrypted = !g_fluctuationData.currentlyEncrypted;
|
||||||
|
|||||||
Reference in New Issue
Block a user