add a module stomping check to the alias and update README.

This commit is contained in:
root
2021-01-13 13:32:05 -05:00
parent 537390be67
commit 45586bc1ba
2 changed files with 10 additions and 2 deletions
+1 -1
View File
@@ -10,7 +10,7 @@ Run 'unhook' from Beacon
Known issues:
This alias will crash your Beacon if module stomping is enabled in your profile. There's no detection for this in the CNA script or work-around in the BOF.
Unhook refreshes "everything". If you're module stomping--this would include that module. The unhook alias does detect if module stomping is enabled and report an error. Future improvements could limit which DLLs are refreshed to a list of high-interest DLLs or explicitly exclude our stomped module.
To build:
+9 -1
View File
@@ -1,9 +1,17 @@
alias unhook {
local('$barch $handle $data');
local('$barch $handle $data $stomp');
# figure out the arch of this session
$barch = barch($1);
# if we're module stomping; don't run the unhook as-is because we'll walk over
# everything. We don't want that. A nice improvement would ask unhooker to skip stomped module.
$stomp = [data_query("metadata")["c2profile"] getString: ".stage.module_ $+ $barch"];
if ($stomp ne "") {
berror($1, "Can't unhook when .stage.module_ $+ $barch is set. :(");
return;
}
# read in the right BOF file
$handle = openf(script_resource("unhook. $+ $barch $+ .o"));
$data = readb($handle, -1);