mirror of
https://github.com/rsmudge/unhook-bof
synced 2026-06-06 16:44:26 +00:00
add a module stomping check to the alias and update README.
This commit is contained in:
@@ -10,7 +10,7 @@ Run 'unhook' from Beacon
|
||||
|
||||
Known issues:
|
||||
|
||||
This alias will crash your Beacon if module stomping is enabled in your profile. There's no detection for this in the CNA script or work-around in the BOF.
|
||||
Unhook refreshes "everything". If you're module stomping--this would include that module. The unhook alias does detect if module stomping is enabled and report an error. Future improvements could limit which DLLs are refreshed to a list of high-interest DLLs or explicitly exclude our stomped module.
|
||||
|
||||
To build:
|
||||
|
||||
|
||||
+9
-1
@@ -1,9 +1,17 @@
|
||||
alias unhook {
|
||||
local('$barch $handle $data');
|
||||
local('$barch $handle $data $stomp');
|
||||
|
||||
# figure out the arch of this session
|
||||
$barch = barch($1);
|
||||
|
||||
# if we're module stomping; don't run the unhook as-is because we'll walk over
|
||||
# everything. We don't want that. A nice improvement would ask unhooker to skip stomped module.
|
||||
$stomp = [data_query("metadata")["c2profile"] getString: ".stage.module_ $+ $barch"];
|
||||
if ($stomp ne "") {
|
||||
berror($1, "Can't unhook when .stage.module_ $+ $barch is set. :(");
|
||||
return;
|
||||
}
|
||||
|
||||
# read in the right BOF file
|
||||
$handle = openf(script_resource("unhook. $+ $barch $+ .o"));
|
||||
$data = readb($handle, -1);
|
||||
|
||||
Reference in New Issue
Block a user