Improvements & Bug Fixes

[+] Implemented LdrpCallTlsInitializers, LdrpFindTlsEntry & ImageTlsCallbackCaller.
[+] Changed DllMain calling convention back to __fastcall again.
This commit is contained in:
paskalian
2023-04-05 03:30:59 +03:00
parent c6c5f1bb7a
commit a675ee0203
6 changed files with 79 additions and 4 deletions
+21
View File
@@ -42,6 +42,8 @@ UINT_PTR*** qword_1843B8 = nullptr;
UINT_PTR* qword_1843B0 = nullptr;
UINT_PTR* LdrpCurrentDllInitializer = nullptr;
LPVOID** LdrpProcessInitContextRecord = nullptr;
PRTL_SRWLOCK LdrpTlsLock = nullptr;
TLS_ENTRY** LdrpTlsList = nullptr;
tLdrpManifestProberRoutine LdrpManifestProberRoutine = nullptr;
tLdrpRedirectionCalloutFunc LdrpRedirectionCalloutFunc = nullptr;
@@ -592,6 +594,23 @@ BOOL __fastcall LdrpIsExecutableRelocatedImage(PIMAGE_DOS_HEADER DllBase)
&& (MemoryInformation.ImageFlags & 1) == 0;
}
TLS_ENTRY* __fastcall LdrpFindTlsEntry(LDR_DATA_TABLE_ENTRY* LdrEntry)
{
TLS_ENTRY* TlsEntry;
for (TlsEntry = *LdrpTlsList; TlsEntry != (TLS_ENTRY*)LdrpTlsList; TlsEntry = (TLS_ENTRY*)TlsEntry->TlsEntry.Flink)
{
if ((LDR_DATA_TABLE_ENTRY*)TlsEntry->ModuleEntry == LdrEntry)
return TlsEntry;
}
return nullptr;
}
BOOL __fastcall ImageTlsCallbackCaller(HINSTANCE hInstDll, DWORD fdwReason, LPVOID lpvReserved)
{
((void(__fastcall*)(HINSTANCE, DWORD, LPVOID))lpvReserved)(hInstDll, fdwReason, 0);
return 1;
}
// Implemented inside LOADLIBRARY class to use WID_HIDDEN
NTSTATUS __fastcall WID::Loader::LOADLIBRARY::LdrpThreadTokenSetMainThreadToken() // CHECKED.
@@ -809,6 +828,8 @@ tRtlReleaseActivationContext RtlReleaseActivationContext = nullpt
tRtlCharToInteger RtlCharToInteger = nullptr;
tRtlActivateActivationContextUnsafeFast RtlActivateActivationContextUnsafeFast = nullptr;
tRtlDeactivateActivationContextUnsafeFast RtlDeactivateActivationContextUnsafeFast = nullptr;
tRtlAcquireSRWLockShared RtlAcquireSRWLockShared = nullptr;
tRtlReleaseSRWLockShared RtlReleaseSRWLockShared = nullptr;
// Signatured
tLdrpLogInternal LdrpLogInternal = nullptr;
+10
View File
@@ -79,6 +79,8 @@ extern UINT_PTR*** qword_1843B8;
extern UINT_PTR* qword_1843B0;
extern UINT_PTR* LdrpCurrentDllInitializer;
extern LPVOID** LdrpProcessInitContextRecord;
extern PRTL_SRWLOCK LdrpTlsLock;
extern TLS_ENTRY** LdrpTlsList;
typedef NTSTATUS(__fastcall** tLdrpManifestProberRoutine)(PIMAGE_DOS_HEADER Base, PWCHAR, PVOID);
extern tLdrpManifestProberRoutine LdrpManifestProberRoutine;
@@ -112,6 +114,8 @@ PIMAGE_SECTION_HEADER __fastcall RtlSectionTableFromVirtualAddress(PIMAGE_NT_HEA
PIMAGE_SECTION_HEADER __fastcall RtlAddressInSectionTable(PIMAGE_NT_HEADERS NtHeader, PVOID Base, UINT_PTR Address);
BOOLEAN __fastcall LdrpValidateEntrySection(LDR_DATA_TABLE_ENTRY* DllEntry);
BOOL __fastcall LdrpIsExecutableRelocatedImage(PIMAGE_DOS_HEADER DllBase);
TLS_ENTRY* __fastcall LdrpFindTlsEntry(LDR_DATA_TABLE_ENTRY* LdrEntry);
BOOL __fastcall ImageTlsCallbackCaller(HINSTANCE hInstDll, DWORD fdwReason, LPVOID lpvReserved);
extern "C" NTSTATUS __fastcall ZwSystemDebugControl();
extern "C" NTSTATUS __fastcall NtCreateSection(PHANDLE SectionHandle, ACCESS_MASK DesiredAccess, OBJECT_ATTRIBUTES * ObjectAttributes, PLARGE_INTEGER MaximumSize, ULONG SectionPageProtection, ULONG AllocationAttributes, HANDLE FileHandle);
@@ -198,6 +202,12 @@ extern tRtlActivateActivationContextUnsafeFast RtlActivateActivationContextUnsaf
typedef VOID(__fastcall* tRtlDeactivateActivationContextUnsafeFast)(RTL_CALLER_ALLOCATED_ACTIVATION_CONTEXT_STACK_FRAME_EXTENDED* StackFrameExtended);
extern tRtlDeactivateActivationContextUnsafeFast RtlDeactivateActivationContextUnsafeFast;
typedef NTSTATUS(__fastcall* tRtlAcquireSRWLockShared)(PRTL_SRWLOCK SrwLock);
extern tRtlAcquireSRWLockShared RtlAcquireSRWLockShared;
typedef NTSTATUS(__fastcall* tRtlReleaseSRWLockShared)(PRTL_SRWLOCK SrwLock);
extern tRtlReleaseSRWLockShared RtlReleaseSRWLockShared;
// Signatured
#define LDRP_LOG_INTERNAL_PATTERN "\x89\x54\x24\x10\x4C\x8B\xDC\x49\x89\x4B\x08"
typedef NTSTATUS(__fastcall* tLdrpLogInternal)(PCHAR, ULONG, PCHAR, ULONG, PCHAR, ...);
+8
View File
@@ -930,6 +930,14 @@ typedef struct _MEMORY_IMAGE_INFORMATION
};
} MEMORY_IMAGE_INFORMATION, * PMEMORY_IMAGE_INFORMATION;
typedef struct _TLS_ENTRY
{
LIST_ENTRY TlsEntry;
IMAGE_TLS_DIRECTORY TlsDirectory;
PLDR_DATA_TABLE_ENTRY ModuleEntry;
SIZE_T Index;
} TLS_ENTRY, *PTLS_ENTRY;
enum SECTION_INHERIT
{
ViewShare = 1,
+34 -3
View File
@@ -1673,7 +1673,7 @@ NTSTATUS __fastcall LOADLIBRARY::fLdrpMapDllNtFileName(PLDRP_LOAD_CONTEXT LoadCo
// SYSTEM_FLAGS_INFORMATION
if ((NtCurrentPeb()->NtGlobalFlag & FLG_ENABLE_KDEBUG_SYMBOL_LOAD))
{
ZwSystemDebugControl();
WID_HIDDEN( ZwSystemDebugControl(); )
}
HANDLE FileHandle;
@@ -2857,7 +2857,7 @@ NTSTATUS __fastcall LOADLIBRARY::fLdrpInitializeNode(_LDR_DDAG_NODE* DdagNode)
v20 = 0;
RtlActivateActivationContextUnsafeFast(&StackFrameExtended, LdrEntry_2->EntryPointActivationContext);
if (LdrEntry_2->TlsIndex)
LdrpCallTlsInitializers(1i64, (LDR_DATA_TABLE_ENTRY*)&i[-1].DdagNode);
fLdrpCallTlsInitializers(1i64, (LDR_DATA_TABLE_ENTRY*)&i[-1].DdagNode);
//LdrpCallTlsInitializers(1, CONTAINING_RECORD(i, LDR_DATA_TABLE_ENTRY, DdagNode));
if (EntryPoint)
@@ -2889,7 +2889,38 @@ NTSTATUS __fastcall LOADLIBRARY::fLdrpInitializeNode(_LDR_DDAG_NODE* DdagNode)
return Status;
}
BOOLEAN __fastcall LOADLIBRARY::fLdrpCallInitRoutine(BOOL(__stdcall* DllMain)(HINSTANCE hInstDll, DWORD fdwReason, LPVOID lpvReserved), PIMAGE_DOS_HEADER DllBase, unsigned int One, LPVOID ContextRecord)
BOOL __fastcall LOADLIBRARY::fLdrpCallTlsInitializers(DWORD fdwReason, LDR_DATA_TABLE_ENTRY* LdrEntry)
{
BOOL Result = FALSE;
RtlAcquireSRWLockShared(LdrpTlsLock);
TLS_ENTRY* TlsEntry = LdrpFindTlsEntry(LdrEntry);
RtlReleaseSRWLockShared(LdrpTlsLock);
if (TlsEntry)
{
LPVOID* AddressOfCallBacks = (LPVOID*)TlsEntry->TlsDirectory.AddressOfCallBacks;
if (AddressOfCallBacks)
{
while (TRUE)
{
LPVOID ContextRecord = *AddressOfCallBacks;
if (!ContextRecord)
break;
++AddressOfCallBacks;
WID_HIDDEN( LdrpLogInternal("minkernel\\ntdll\\ldrtls.c", 1180, "LdrpCallTlsInitializers", 2u, "Calling TLS callback %p for DLL \"%wZ\" at %p\n", ContextRecord, &LdrEntry->FullDllName, LdrEntry->DllBase); )
Result = fLdrpCallInitRoutine(ImageTlsCallbackCaller, LdrEntry->DllBase, fdwReason, ContextRecord);
}
}
}
return Result;
}
BOOLEAN __fastcall LOADLIBRARY::fLdrpCallInitRoutine(BOOL(__fastcall* DllMain)(HINSTANCE hInstDll, DWORD fdwReason, LPVOID lpvReserved), PIMAGE_DOS_HEADER DllBase, unsigned int One, LPVOID ContextRecord)
{
BOOLEAN ReturnVal = TRUE;
+2 -1
View File
@@ -130,7 +130,8 @@ namespace WID
NTSTATUS __fastcall fLdrpPrepareModuleForExecution(PLDR_DATA_TABLE_ENTRY LdrEntry, NTSTATUS* pStatus);
NTSTATUS __fastcall fLdrpInitializeGraphRecurse(LDR_DDAG_NODE* DdagNode, NTSTATUS* pStatus, char* Unknown);
NTSTATUS __fastcall fLdrpInitializeNode(_LDR_DDAG_NODE* DdagNode);
BOOLEAN __fastcall fLdrpCallInitRoutine(BOOL(__stdcall* DllMain)(HINSTANCE hInstDll, DWORD fdwReason, LPVOID lpvReserved), PIMAGE_DOS_HEADER DllBase, unsigned int One, LPVOID ContextRecord);
BOOL __fastcall fLdrpCallTlsInitializers(DWORD fdwReason, LDR_DATA_TABLE_ENTRY* LdrEntry);
BOOLEAN __fastcall fLdrpCallInitRoutine(BOOL(__fastcall* DllMain)(HINSTANCE hInstDll, DWORD fdwReason, LPVOID lpvReserved), PIMAGE_DOS_HEADER DllBase, unsigned int One, LPVOID ContextRecord);
NTSTATUS __fastcall fBasepLoadLibraryAsDataFileInternal(PUNICODE_STRING DllName, PWSTR Path, PWSTR Unknown, DWORD dwFlags, HMODULE* pBaseOfLoadedModule);
public:
+4
View File
@@ -74,6 +74,8 @@ NTSTATUS WID::Init()
(qword_1843B0 = (UINT_PTR*) ((PCHAR)NtdllModule + 0x1843B0) ,assert(qword_1843B0));
(LdrpCurrentDllInitializer = (UINT_PTR*) ((PCHAR)NtdllModule + 0x184A88) ,assert(LdrpCurrentDllInitializer));
(LdrpProcessInitContextRecord = (LPVOID**) ((PCHAR)NtdllModule + 0x184358) ,assert(LdrpProcessInitContextRecord));
(LdrpTlsLock = (PRTL_SRWLOCK) ((PCHAR)NtdllModule + 0x184EF8) ,assert(LdrpTlsLock));
(LdrpTlsList = (TLS_ENTRY**) ((PCHAR)NtdllModule + 0x17E2B0) ,assert(LdrpTlsList));
// Exported functions
(NtOpenThreadToken = (tNtOpenThreadToken) GetProcAddress(NtdllModule, "NtOpenThreadToken") ,assert(NtOpenThreadToken));
@@ -101,6 +103,8 @@ NTSTATUS WID::Init()
(RtlCharToInteger = (tRtlCharToInteger) GetProcAddress(NtdllModule, "RtlCharToInteger") ,assert(RtlCharToInteger));
(RtlActivateActivationContextUnsafeFast = (tRtlActivateActivationContextUnsafeFast)GetProcAddress(NtdllModule, "RtlActivateActivationContextUnsafeFast"),assert(RtlActivateActivationContextUnsafeFast));
(RtlDeactivateActivationContextUnsafeFast = (tRtlDeactivateActivationContextUnsafeFast)GetProcAddress(NtdllModule, "RtlDeactivateActivationContextUnsafeFast"),assert(RtlDeactivateActivationContextUnsafeFast));
(RtlAcquireSRWLockShared = (tRtlAcquireSRWLockShared) GetProcAddress(NtdllModule, "RtlAcquireSRWLockShared") ,assert(RtlAcquireSRWLockShared));
(RtlReleaseSRWLockShared = (tRtlReleaseSRWLockShared) GetProcAddress(NtdllModule, "RtlReleaseSRWLockShared") ,assert(RtlReleaseSRWLockShared));
// Signatured.
// I don't think the signatures will ever change, you can go with the offsets though.