64 bit/windows 8 done
@@ -4,10 +4,29 @@
|
||||
#include "stdafx.h"
|
||||
#include <stdlib.h>
|
||||
#include <Windows.h>
|
||||
#include <intrin.h>
|
||||
|
||||
extern "C" void get_idtr(unsigned char *out);
|
||||
extern "C" BYTE get_tss_selector(void);
|
||||
|
||||
int main()
|
||||
{
|
||||
|
||||
#ifdef _WIN64
|
||||
unsigned char idtr[10] = { 0 };
|
||||
get_idtr(idtr);
|
||||
unsigned long long idtrBase = (unsigned long long)idtr[0] << 56 |
|
||||
(unsigned long long)idtr[1] << 48 |
|
||||
(unsigned long long)idtr[2] << 40 |
|
||||
(unsigned long long)idtr[3] << 32 |
|
||||
(unsigned long long)idtr[4] << 24 |
|
||||
(unsigned long long)idtr[5] << 16 |
|
||||
(unsigned long long)idtr[6] << 8 |
|
||||
(unsigned long long)idtr[7];
|
||||
unsigned short idtrLimit = (unsigned int)idtr[8] << 8 |
|
||||
(unsigned int)idtr[9];
|
||||
printf("Interrupt Descriptor Table Register base: 0x%llx, limit: 0x%X\r\n", idtrBase, idtrLimit);
|
||||
#else
|
||||
unsigned char idtr[6] = { 0 };
|
||||
__asm {
|
||||
sidt idtr;
|
||||
@@ -16,9 +35,28 @@ int main()
|
||||
(unsigned int)idtr[1] << 16 |
|
||||
(unsigned int)idtr[2] << 8 |
|
||||
(unsigned int)idtr[3];
|
||||
unsigned short idtrLimit = (unsigned int) idtr[4] << 8 |
|
||||
unsigned short idtrLimit = (unsigned int)idtr[4] << 8 |
|
||||
(unsigned int)idtr[5];
|
||||
printf("Interrupt Descriptor Table Register base: 0x%X, limit: 0x%X\r\n", idtrBase, idtrLimit);
|
||||
#endif
|
||||
|
||||
|
||||
|
||||
#ifdef _WIN64
|
||||
unsigned char gdtr[10] = { 0 };
|
||||
_sgdt(gdtr);
|
||||
unsigned long long gdtrBase = (unsigned long long)gdtr[0] << 56 |
|
||||
(unsigned long long)gdtr[1] << 48 |
|
||||
(unsigned long long)gdtr[2] << 40 |
|
||||
(unsigned long long)gdtr[3] << 32 |
|
||||
(unsigned long long)gdtr[4] << 24 |
|
||||
(unsigned long long)gdtr[5] << 16 |
|
||||
(unsigned long long)gdtr[6] << 8 |
|
||||
(unsigned long long)gdtr[7];
|
||||
unsigned short gdtrLimit = (unsigned int)gdtr[8] << 8 |
|
||||
(unsigned int)gdtr[9];
|
||||
printf("Global Descriptor Table Register base: 0x%llx, limit: 0x%X\r\n", gdtrBase, gdtrLimit);
|
||||
#else
|
||||
unsigned char gdtr[6] = { 0 };
|
||||
__asm {
|
||||
sgdt gdtr;
|
||||
@@ -30,14 +68,22 @@ int main()
|
||||
unsigned short gdtrLimit = (unsigned int)gdtr[4] << 8 |
|
||||
(unsigned int)gdtr[5];
|
||||
printf("Global Descriptor Table Register base: 0x%X, limit: 0x%X\r\n", gdtrBase, gdtrLimit);
|
||||
|
||||
LDT_ENTRY tss;
|
||||
#endif
|
||||
|
||||
WORD tr;
|
||||
|
||||
#ifdef _WIN64
|
||||
tr = get_tss_selector();
|
||||
#else
|
||||
__asm str tr
|
||||
#endif
|
||||
|
||||
#ifdef _WIN64
|
||||
WOW64_LDT_ENTRY tss;
|
||||
Wow64GetThreadSelectorEntry(GetCurrentThread(), tr, &tss);
|
||||
#else
|
||||
LDT_ENTRY tss;
|
||||
GetThreadSelectorEntry(GetCurrentThread(), tr, &tss);
|
||||
|
||||
#endif
|
||||
unsigned int tssBase = (tss.HighWord.Bits.BaseHi << 24) +
|
||||
(tss.HighWord.Bits.BaseMid << 16) +
|
||||
tss.BaseLow;
|
||||
|
||||
@@ -53,6 +53,7 @@
|
||||
</PropertyGroup>
|
||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.props" />
|
||||
<ImportGroup Label="ExtensionSettings">
|
||||
<Import Project="$(VCTargetsPath)\BuildCustomizations\masm.props" />
|
||||
</ImportGroup>
|
||||
<ImportGroup Label="Shared">
|
||||
</ImportGroup>
|
||||
@@ -157,7 +158,13 @@
|
||||
<PrecompiledHeader Condition="'$(Configuration)|$(Platform)'=='Release|x64'">Create</PrecompiledHeader>
|
||||
</ClCompile>
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<MASM Include="asm_funcs.asm">
|
||||
<FileType>Document</FileType>
|
||||
</MASM>
|
||||
</ItemGroup>
|
||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
|
||||
<ImportGroup Label="ExtensionTargets">
|
||||
<Import Project="$(VCTargetsPath)\BuildCustomizations\masm.targets" />
|
||||
</ImportGroup>
|
||||
</Project>
|
||||
@@ -33,4 +33,9 @@
|
||||
<Filter>Source Files</Filter>
|
||||
</ClCompile>
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<MASM Include="asm_funcs.asm">
|
||||
<Filter>Source Files</Filter>
|
||||
</MASM>
|
||||
</ItemGroup>
|
||||
</Project>
|
||||
@@ -0,0 +1,18 @@
|
||||
_DATA SEGMENT
|
||||
_DATA ENDS
|
||||
_TEXT SEGMENT
|
||||
|
||||
PUBLIC get_idtr
|
||||
get_idtr PROC
|
||||
sidt [rcx]
|
||||
ret
|
||||
get_idtr ENDP
|
||||
|
||||
PUBLIC get_tss_selector
|
||||
get_tss_selector PROC
|
||||
str eax
|
||||
ret
|
||||
get_tss_selector ENDP
|
||||
|
||||
_TEXT ENDS
|
||||
END
|
||||
@@ -59,8 +59,12 @@ int main()
|
||||
HANDLE handle = pHandleInfo->Handles[i].HandleValue;
|
||||
HANDLE pid = pHandleInfo->Handles[i].UniqueProcessId;
|
||||
printf("PID: %d\t", pid);
|
||||
#ifdef _WIN64
|
||||
printf("Object 0x%llx\t", object);
|
||||
#else
|
||||
printf("Object 0x%X\t", object);
|
||||
printf("Handle 0x%X\r\n", handle);
|
||||
#endif
|
||||
printf("Handle 0x%x\r\n", handle);
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -12,6 +12,9 @@ typedef struct _SYSTEM_LOCK {
|
||||
ULONG ActiveCount;
|
||||
ULONG ContentionCount;
|
||||
ULONG Reserved2[2];
|
||||
#ifdef _WIN64
|
||||
ULONG Reserved3;
|
||||
#endif
|
||||
ULONG NumberOfSharedWaiters;
|
||||
ULONG NumberOfExclusiveWaiters;
|
||||
} SYSTEM_LOCK, *PSYSTEM_LOCK;
|
||||
@@ -51,10 +54,14 @@ int main()
|
||||
status = query(SystemLockInformation, pLockInfo, len, &len);
|
||||
} while (status == (NTSTATUS)0xc0000004);
|
||||
|
||||
for (int i = 0; i < pLockInfo->LocksCount; i++) {
|
||||
for (unsigned int i = 0; i < pLockInfo->LocksCount; i++) {
|
||||
PVOID lockAddress = pLockInfo->Locks[i].Address;
|
||||
USHORT lockType = (USHORT)pLockInfo->Locks[i].Type;
|
||||
#ifdef _WIN64
|
||||
printf("Lock Address 0x%llx\t", lockAddress);
|
||||
#else
|
||||
printf("Lock Address 0x%X\t", lockAddress);
|
||||
#endif
|
||||
printf("Lock Type 0x%X\r\n", lockType);
|
||||
}
|
||||
return 0;
|
||||
|
||||
@@ -9,6 +9,9 @@
|
||||
typedef struct SYSTEM_MODULE {
|
||||
ULONG Reserved1;
|
||||
ULONG Reserved2;
|
||||
#ifdef _WIN64
|
||||
ULONG Reserved3;
|
||||
#endif
|
||||
PVOID ImageBaseAddress;
|
||||
ULONG ImageSize;
|
||||
ULONG Flags;
|
||||
@@ -16,7 +19,7 @@ typedef struct SYSTEM_MODULE {
|
||||
WORD Rank;
|
||||
WORD w018;
|
||||
WORD NameOffset;
|
||||
BYTE Name[MAXIMUM_FILENAME_LENGTH];
|
||||
CHAR Name[MAXIMUM_FILENAME_LENGTH];
|
||||
}SYSTEM_MODULE, *PSYSTEM_MODULE;
|
||||
|
||||
typedef struct SYSTEM_MODULE_INFORMATION {
|
||||
@@ -56,11 +59,15 @@ int main()
|
||||
printf("Failed to retrieve system module information.\r\n");
|
||||
return 1;
|
||||
}
|
||||
for (int i = 0; i < pModuleInfo->ModulesCount; i++) {
|
||||
for (unsigned int i = 0; i < pModuleInfo->ModulesCount; i++) {
|
||||
PVOID kernelImageBase = pModuleInfo->Modules[i].ImageBaseAddress;
|
||||
PCHAR kernelImage = (PCHAR)pModuleInfo->Modules[i].Name;
|
||||
printf("Module name %s\t", kernelImage);
|
||||
printf("Base Address 0x%X\r\n", kernelImageBase);
|
||||
printf("Mod name %s ", kernelImage);
|
||||
#ifdef _WIN64
|
||||
printf("Base Addr 0x%llx\r\n", kernelImageBase);
|
||||
#else
|
||||
printf("Base Addr 0x%X\r\n", kernelImageBase);
|
||||
#endif
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -0,0 +1,40 @@
|
||||
========================================================================
|
||||
CONSOLE APPLICATION : NtQuerySysInfo_SystemModuleInformation Project Overview
|
||||
========================================================================
|
||||
|
||||
AppWizard has created this NtQuerySysInfo_SystemModuleInformation application for you.
|
||||
|
||||
This file contains a summary of what you will find in each of the files that
|
||||
make up your NtQuerySysInfo_SystemModuleInformation application.
|
||||
|
||||
|
||||
NtQuerySysInfo_SystemModuleInformation.vcxproj
|
||||
This is the main project file for VC++ projects generated using an Application Wizard.
|
||||
It contains information about the version of Visual C++ that generated the file, and
|
||||
information about the platforms, configurations, and project features selected with the
|
||||
Application Wizard.
|
||||
|
||||
NtQuerySysInfo_SystemModuleInformation.vcxproj.filters
|
||||
This is the filters file for VC++ projects generated using an Application Wizard.
|
||||
It contains information about the association between the files in your project
|
||||
and the filters. This association is used in the IDE to show grouping of files with
|
||||
similar extensions under a specific node (for e.g. ".cpp" files are associated with the
|
||||
"Source Files" filter).
|
||||
|
||||
NtQuerySysInfo_SystemModuleInformation.cpp
|
||||
This is the main application source file.
|
||||
|
||||
/////////////////////////////////////////////////////////////////////////////
|
||||
Other standard files:
|
||||
|
||||
StdAfx.h, StdAfx.cpp
|
||||
These files are used to build a precompiled header (PCH) file
|
||||
named NtQuerySysInfo_SystemModuleInformation.pch and a precompiled types file named StdAfx.obj.
|
||||
|
||||
/////////////////////////////////////////////////////////////////////////////
|
||||
Other notes:
|
||||
|
||||
AppWizard uses "TODO:" comments to indicate parts of the source code you
|
||||
should add to or customize.
|
||||
|
||||
/////////////////////////////////////////////////////////////////////////////
|
||||
@@ -86,8 +86,7 @@ typedef enum _KWAIT_REASON
|
||||
MaximumWaitReason = 37
|
||||
} KWAIT_REASON;
|
||||
|
||||
|
||||
typedef struct _SYSTEM_THREAD_INFORMATION{
|
||||
typedef struct _SYSTEM_THREAD_INFORMATION {
|
||||
LARGE_INTEGER KernelTime;
|
||||
LARGE_INTEGER UserTime;
|
||||
LARGE_INTEGER CreateTime;
|
||||
@@ -96,10 +95,13 @@ typedef struct _SYSTEM_THREAD_INFORMATION{
|
||||
CLIENT_ID ClientId;
|
||||
KPRIORITY Priority;
|
||||
LONG BasePriority;
|
||||
ULONG ContextSwitches;
|
||||
ULONG ContextSwitchCount;
|
||||
ULONG ThreadState;
|
||||
KWAIT_REASON WaitReason;
|
||||
} SYSTEM_THREAD_INFORMATION, *PSYSTEM_THREAD_INFORMATION;
|
||||
#ifdef _WIN64
|
||||
ULONG Reserved[4];
|
||||
#endif
|
||||
}SYSTEM_THREAD_INFORMATION, *PSYSTEM_THREAD_INFORMATION;
|
||||
|
||||
typedef struct _SYSTEM_EXTENDED_THREAD_INFORMATION
|
||||
{
|
||||
@@ -107,13 +109,11 @@ typedef struct _SYSTEM_EXTENDED_THREAD_INFORMATION
|
||||
PVOID StackBase;
|
||||
PVOID StackLimit;
|
||||
PVOID Win32StartAddress;
|
||||
PVOID TebAddress;
|
||||
PVOID TebAddress; /* This is only filled in on Vista and above */
|
||||
ULONG Reserved1;
|
||||
ULONG Reserved2;
|
||||
ULONG Reserved3;
|
||||
} SYSTEM_EXTENDED_THREAD_INFORMATION, *
|
||||
PSYSTEM_EXTENDED_THREAD_INFORMATION;
|
||||
|
||||
} SYSTEM_EXTENDED_THREAD_INFORMATION, *PSYSTEM_EXTENDED_THREAD_INFORMATION;
|
||||
typedef struct _SYSTEM_EXTENDED_PROCESS_INFORMATION
|
||||
{
|
||||
ULONG NextEntryOffset;
|
||||
@@ -126,7 +126,7 @@ typedef struct _SYSTEM_EXTENDED_PROCESS_INFORMATION
|
||||
LARGE_INTEGER KernelTime;
|
||||
UNICODE_STRING ImageName;
|
||||
KPRIORITY BasePriority;
|
||||
ULONG UniqueProcessId;
|
||||
ULONG ProcessId;
|
||||
ULONG InheritedFromUniqueProcessId;
|
||||
ULONG HandleCount;
|
||||
ULONG SessionId;
|
||||
@@ -137,9 +137,8 @@ typedef struct _SYSTEM_EXTENDED_PROCESS_INFORMATION
|
||||
SYSTEM_EXTENDED_THREAD_INFORMATION Threads[1];
|
||||
} SYSTEM_EXTENDED_PROCESS_INFORMATION, *PSYSTEM_EXTENDED_PROCESS_INFORMATION;
|
||||
|
||||
|
||||
typedef enum _SYSTEM_INFORMATION_CLASS {
|
||||
SystemSessionProcessInformation = 57
|
||||
SystemExtendedProcessInformation = 57
|
||||
} SYSTEM_INFORMATION_CLASS;
|
||||
|
||||
typedef NTSTATUS(WINAPI *PNtQuerySystemInformation)(
|
||||
@@ -157,20 +156,29 @@ int main()
|
||||
printf("GetProcAddress() failed.\n");
|
||||
return 1;
|
||||
}
|
||||
ULONG len = 20;
|
||||
ULONG len = 2000;
|
||||
NTSTATUS status = NULL;
|
||||
PSYSTEM_EXTENDED_PROCESS_INFORMATION pProcessInfo = NULL;
|
||||
do {
|
||||
len *= 2;
|
||||
len *= 2;
|
||||
pProcessInfo = (PSYSTEM_EXTENDED_PROCESS_INFORMATION)GlobalAlloc(GMEM_ZEROINIT, len);
|
||||
status = query(SystemSessionProcessInformation, pProcessInfo, len, &len);
|
||||
status = query(SystemExtendedProcessInformation, pProcessInfo, len, &len);
|
||||
} while (status == (NTSTATUS)0xc0000004);
|
||||
|
||||
for (unsigned int i = 0; i < pProcessInfo->NumberOfThreads; i++) {
|
||||
PVOID stackBase = pProcessInfo->Threads[i].StackBase;
|
||||
PVOID stackLimit = pProcessInfo->Threads[i].StackLimit;
|
||||
printf("Stack base 0x%X\t", stackBase);
|
||||
printf("Stack limit 0x%X\r\n", stackLimit);
|
||||
|
||||
while (pProcessInfo->NextEntryOffset != NULL) {
|
||||
for (unsigned int i = 0; i < pProcessInfo->NumberOfThreads; i++) {
|
||||
PVOID stackBase = pProcessInfo->Threads[i].StackBase;
|
||||
PVOID stackLimit = pProcessInfo->Threads[i].StackLimit;
|
||||
#ifdef _WIN64
|
||||
printf("Stack base 0x%llx\t", stackBase);
|
||||
printf("Stack limit 0x%llx\r\n", stackLimit);
|
||||
#else
|
||||
printf("Stack base 0x%X\t", stackBase);
|
||||
printf("Stack limit 0x%X\r\n", stackLimit);
|
||||
#endif
|
||||
}
|
||||
pProcessInfo = (PSYSTEM_EXTENDED_PROCESS_INFORMATION)((ULONG_PTR)pProcessInfo + pProcessInfo->NextEntryOffset);
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -4,13 +4,13 @@ This repository aims to provide functioning code that demonstrated usage of vari
|
||||
|
||||
| Technique | Windows 7 | Windows 8 | Windows 8.1 | Windows 10|
|
||||
|---------------------------------------------------|-----------|-----------|-------------|-----------|
|
||||
|[NtQuerySystemInformation (SystemHandleInformation)](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/NtQuerySysInfo_SystemHandleInformation/NtQuerySysInfo_SystemHandleInformation/NtQuerySysInfo_SystemHandleInformation.cpp) |  | | | |
|
||||
|[NtQuerySystemInformation (SystemLockInformation)](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/NtQuerySysInfo_SystemLockInformation/NtQuerySysInfo_SystemLockInformation/NtQuerySysInfo_SystemLockInformation.cpp) | | | | |
|
||||
|[NtQuerySystemInformation (SystemModuleInformation)](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/NtQuerySysInfo_SystemModuleInformation/NtQuerySysInfo_SystemModuleInformation/NtQuerySysInfo_SystemModuleInformation.cpp) | | | | |
|
||||
|[NtQuerySystemInformation (SystemProcessInformation)](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/NtQuerySysInfo_SystemProcessInformation/NtQuerySysInfo_SystemProcessInformation/NtQuerySysInfo_SystemProcessInformation.cpp)| | | | |
|
||||
|[NtQuerySystemInformation (SystemHandleInformation)](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/NtQuerySysInfo_SystemHandleInformation/NtQuerySysInfo_SystemHandleInformation/NtQuerySysInfo_SystemHandleInformation.cpp) |  | | | |
|
||||
|[NtQuerySystemInformation (SystemLockInformation)](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/NtQuerySysInfo_SystemLockInformation/NtQuerySysInfo_SystemLockInformation/NtQuerySysInfo_SystemLockInformation.cpp) | | | | |
|
||||
|[NtQuerySystemInformation (SystemModuleInformation)](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/NtQuerySysInfo_SystemModuleInformation/NtQuerySysInfo_SystemModuleInformation/NtQuerySysInfo_SystemModuleInformation.cpp) | | | | |
|
||||
|[NtQuerySystemInformation (SystemProcessInformation)](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/NtQuerySysInfo_SystemProcessInformation/NtQuerySysInfo_SystemProcessInformation/NtQuerySysInfo_SystemProcessInformation.cpp)| | | | |
|
||||
|[System Call Return Values](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/Syscalls/Syscalls/Syscalls.cpp) | | | | |
|
||||
|[Win32k Shared Info Handle Table](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/SharedInfoHandleTable/SharedInfoHandleTable/SharedInfoHandleTable.cpp) | | | | |
|
||||
|[Descriptor Tables](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/DescriptorTables/DescriptorTables/DescriptorTables.cpp) | | | | |
|
||||
|[Win32k Shared Info Handle Table](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/SharedInfoHandleTable/SharedInfoHandleTable/SharedInfoHandleTable.cpp) | | | | |
|
||||
|[Descriptor Tables](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/DescriptorTables/DescriptorTables/DescriptorTables.cpp) | | | | |
|
||||
|
||||
|
||||
|
||||
|
||||
@@ -7,15 +7,20 @@
|
||||
|
||||
typedef struct _HANDLEENTRY {
|
||||
PVOID phead;
|
||||
ULONG pOwner;
|
||||
PVOID pOwner;
|
||||
BYTE bType;
|
||||
BYTE bFlags;
|
||||
WORD wUniq;
|
||||
}HANDLEENTRY, *PHANDLEENTRY;
|
||||
|
||||
typedef struct _SERVERINFO {
|
||||
DWORD dwSRVIFlags;
|
||||
DWORD cHandleEntries;
|
||||
#ifdef _WIN64
|
||||
UINT64 dwSRVIFlags;
|
||||
UINT64 cHandleEntries;
|
||||
#else
|
||||
DWORD dwSRVIFlags;
|
||||
DWORD cHandleEntries;
|
||||
#endif
|
||||
WORD wSRVIFlags;
|
||||
WORD wRIPPID;
|
||||
WORD wRIPError;
|
||||
@@ -39,7 +44,11 @@ int main()
|
||||
for (unsigned int i = 0; i < gSharedInfo->psi->cHandleEntries; i++) {
|
||||
HANDLEENTRY entry = gSharedInfo->aheList[i];
|
||||
if (entry.bType != 0) { //ignore free entries
|
||||
#ifdef _WIN64
|
||||
printf("Head: 0x%llx, Owner: 0x%llx, Type: 0x%X\r\n", entry.phead, entry.pOwner, entry.bType);
|
||||
#else
|
||||
printf("Head: 0x%X, Owner: 0x%X, Type: 0x%X\r\n", entry.phead, entry.pOwner, entry.bType);
|
||||
#endif
|
||||
}
|
||||
}
|
||||
return 0;
|
||||
|
||||
@@ -5,16 +5,28 @@
|
||||
#include <Windows.h>
|
||||
#include <Winddi.h>
|
||||
|
||||
//0x64D4B - NtUserModifyUserStartupInfoFlags
|
||||
typedef DWORD(NTAPI * lNtUserModifyUserStartupInfoFlags)(DWORD Set, DWORD Flags);
|
||||
//0xA2F4 - NtUserGetAsyncKeyState
|
||||
typedef DWORD(NTAPI *lNtUserGetAsyncKeyState)(DWORD key);
|
||||
#ifdef _WIN64
|
||||
//win8, 64bit
|
||||
#define NtUserModifyUserStartupInfoFlagsAddress 0x263F0
|
||||
#define NtUserGetAsyncKeyStateAddress 0x3B30
|
||||
#define NtGdiPATHOBJ_vEnumStartClipLinesAddress 0x67590
|
||||
|
||||
//0x47123 - NtGdiFONTOBJ_vGetInfo
|
||||
#else
|
||||
//win7, 32bit
|
||||
#define NtUserModifyUserStartupInfoFlagsAddress 0x64D4B
|
||||
#define NtUserGetAsyncKeyStateAddress 0xA2F4
|
||||
#define NtGdiFONTOBJ_vGetInfoAddress 0x47123
|
||||
#define NtGdiPATHOBJ_vEnumStartClipLinesAddress 0x47263
|
||||
|
||||
#endif
|
||||
|
||||
typedef DWORD(NTAPI * lNtUserModifyUserStartupInfoFlags)(DWORD Set, DWORD Flags);
|
||||
typedef DWORD(NTAPI *lNtUserGetAsyncKeyState)(DWORD key);
|
||||
typedef VOID(NTAPI * lNtGdiFONTOBJ_vGetInfo)(FONTOBJ *pfo,ULONG cjSize,FONTINFO *pfi);
|
||||
//0x47263 - NtGdiPATHOBJ_vEnumStartClipLines
|
||||
typedef VOID(NTAPI * lNtGdiPATHOBJ_vEnumStartClipLines)(PATHOBJ *ppo, CLIPOBJ *pco, SURFOBJ *pso, LINEATTRS *pla);
|
||||
|
||||
extern "C" unsigned long long get_rax();
|
||||
|
||||
int main()
|
||||
{
|
||||
HMODULE hUser32 = LoadLibraryA("user32.dll");
|
||||
@@ -23,49 +35,70 @@ int main()
|
||||
return 1;
|
||||
}
|
||||
|
||||
lNtUserGetAsyncKeyState pNtUserGetAsyncKeyState = (lNtUserGetAsyncKeyState)((DWORD_PTR)hUser32 + 0xA2F4);
|
||||
lNtUserGetAsyncKeyState pNtUserGetAsyncKeyState = (lNtUserGetAsyncKeyState)((DWORD_PTR)hUser32 + NtUserGetAsyncKeyStateAddress);
|
||||
|
||||
pNtUserGetAsyncKeyState(20);
|
||||
#ifdef _WIN64
|
||||
unsigned long long ethread = get_rax();
|
||||
#else
|
||||
unsigned int ethread = 0;
|
||||
|
||||
__asm {
|
||||
mov ethread, eax;
|
||||
}
|
||||
#endif
|
||||
printf("NtUserGetAsyncKeyState ETHREAD partial disclosure: 0x%X\r\n", ethread);
|
||||
lNtUserModifyUserStartupInfoFlags pNtUserModifyUserStartupInfoFlags = (lNtUserModifyUserStartupInfoFlags)((DWORD_PTR)hUser32 + 0x64D4B);
|
||||
lNtUserModifyUserStartupInfoFlags pNtUserModifyUserStartupInfoFlags = (lNtUserModifyUserStartupInfoFlags)((DWORD_PTR)hUser32 + NtUserModifyUserStartupInfoFlagsAddress);
|
||||
|
||||
pNtUserModifyUserStartupInfoFlags(20, 12);
|
||||
#ifdef _WIN64
|
||||
unsigned long long ethread_full = get_rax();
|
||||
#else
|
||||
unsigned ethread_full = 0;
|
||||
__asm {
|
||||
mov ethread_full, eax;
|
||||
}
|
||||
printf("NtUserModifyUserStartupInfoFlags ETHREAD full disclosure: 0x%X\r\n", ethread_full);
|
||||
|
||||
#endif
|
||||
printf("NtUserModifyUserStartupInfoFlags ETHREAD full disclosure: 0x%X\r\n", ethread_full);
|
||||
|
||||
HMODULE hGDI32 = LoadLibraryA("gdi32.dll");
|
||||
if (hGDI32 == NULL) {
|
||||
printf("Failed to load gdi32");
|
||||
return 1;
|
||||
}
|
||||
#ifdef _WIN64
|
||||
//unsigned long long w32thread = get_rax();
|
||||
#else
|
||||
|
||||
|
||||
lNtGdiFONTOBJ_vGetInfo pNtGdiEngUnLockSurface = (lNtGdiFONTOBJ_vGetInfo)((DWORD_PTR)hGDI32 + 0x47123);
|
||||
lNtGdiFONTOBJ_vGetInfo pNtGdiFONTOBJ_vGetInfo = (lNtGdiFONTOBJ_vGetInfo)((DWORD_PTR)hGDI32 + NtGdiFONTOBJ_vGetInfoAddress);
|
||||
FONTOBJ surf = { 0 };
|
||||
FONTINFO finfo = { 0 };
|
||||
pNtGdiEngUnLockSurface(&surf,123, &finfo);
|
||||
pNtGdiFONTOBJ_vGetInfo(&surf,123, &finfo);
|
||||
|
||||
long int w32thread = 0;
|
||||
__asm {
|
||||
mov w32thread, eax;
|
||||
}
|
||||
|
||||
#endif
|
||||
printf("NtGdiEngUnLockSurface W32THREAD full disclosure: 0x%X\r\n", ethread);
|
||||
|
||||
lNtGdiPATHOBJ_vEnumStartClipLines pNtGdiPATHOBJ_vEnumStartClipLines = (lNtGdiPATHOBJ_vEnumStartClipLines)((DWORD_PTR)hGDI32 + 0x47263);
|
||||
lNtGdiPATHOBJ_vEnumStartClipLines pNtGdiPATHOBJ_vEnumStartClipLines = (lNtGdiPATHOBJ_vEnumStartClipLines)((DWORD_PTR)hGDI32 + NtGdiPATHOBJ_vEnumStartClipLinesAddress);
|
||||
PATHOBJ pathobj = { 0 };
|
||||
CLIPOBJ pco = { 0 };
|
||||
SURFOBJ pso = { 0 };
|
||||
LINEATTRS pla = { 0 };
|
||||
pNtGdiPATHOBJ_vEnumStartClipLines(&pathobj, &pco, &pso, &pla);
|
||||
#ifdef _WIN64
|
||||
unsigned long long w32thread = get_rax();
|
||||
#else
|
||||
w32thread = 0;
|
||||
__asm {
|
||||
mov w32thread, eax;
|
||||
}
|
||||
|
||||
#endif
|
||||
printf("NtGdiPATHOBJ_vEnumStartClipLines W32THREAD full disclosure: 0x%X\r\n", ethread);
|
||||
|
||||
return 0;
|
||||
|
||||
@@ -53,6 +53,7 @@
|
||||
</PropertyGroup>
|
||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.props" />
|
||||
<ImportGroup Label="ExtensionSettings">
|
||||
<Import Project="$(VCTargetsPath)\BuildCustomizations\masm.props" />
|
||||
</ImportGroup>
|
||||
<ImportGroup Label="Shared">
|
||||
</ImportGroup>
|
||||
@@ -157,7 +158,11 @@
|
||||
</ClCompile>
|
||||
<ClCompile Include="Syscalls.cpp" />
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<MASM Include="asm_funcs.asm" />
|
||||
</ItemGroup>
|
||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
|
||||
<ImportGroup Label="ExtensionTargets">
|
||||
<Import Project="$(VCTargetsPath)\BuildCustomizations\masm.targets" />
|
||||
</ImportGroup>
|
||||
</Project>
|
||||
@@ -26,11 +26,14 @@
|
||||
</ClInclude>
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<ClCompile Include="stdafx.cpp">
|
||||
<Filter>Source Files</Filter>
|
||||
</ClCompile>
|
||||
<ClCompile Include="Syscalls.cpp">
|
||||
<Filter>Source Files</Filter>
|
||||
</ClCompile>
|
||||
<ClCompile Include="stdafx.cpp" />
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<MASM Include="asm_funcs.asm">
|
||||
<Filter>Source Files</Filter>
|
||||
</MASM>
|
||||
</ItemGroup>
|
||||
</Project>
|
||||
@@ -0,0 +1,11 @@
|
||||
_DATA SEGMENT
|
||||
_DATA ENDS
|
||||
_TEXT SEGMENT
|
||||
|
||||
PUBLIC get_rax
|
||||
|
||||
get_rax PROC
|
||||
ret
|
||||
get_rax ENDP
|
||||
_TEXT ENDS
|
||||
END
|
||||
|
After Width: | Height: | Size: 19 KiB |
|
After Width: | Height: | Size: 19 KiB |
|
After Width: | Height: | Size: 27 KiB |
|
After Width: | Height: | Size: 20 KiB |
|
After Width: | Height: | Size: 23 KiB |
|
Before Width: | Height: | Size: 11 KiB After Width: | Height: | Size: 11 KiB |
|
After Width: | Height: | Size: 24 KiB |
|
Before Width: | Height: | Size: 14 KiB After Width: | Height: | Size: 14 KiB |
|
Before Width: | Height: | Size: 13 KiB After Width: | Height: | Size: 13 KiB |
|
Before Width: | Height: | Size: 15 KiB After Width: | Height: | Size: 15 KiB |
|
Before Width: | Height: | Size: 6.0 KiB |
|
Before Width: | Height: | Size: 5.0 KiB After Width: | Height: | Size: 5.0 KiB |
|
Before Width: | Height: | Size: 18 KiB After Width: | Height: | Size: 18 KiB |