64 bit/windows 8 done

This commit is contained in:
Sam Brown
2017-02-13 22:10:16 +00:00
parent 308b1c3894
commit a3d6f61a1d
28 changed files with 258 additions and 55 deletions
@@ -4,10 +4,29 @@
#include "stdafx.h"
#include <stdlib.h>
#include <Windows.h>
#include <intrin.h>
extern "C" void get_idtr(unsigned char *out);
extern "C" BYTE get_tss_selector(void);
int main()
{
#ifdef _WIN64
unsigned char idtr[10] = { 0 };
get_idtr(idtr);
unsigned long long idtrBase = (unsigned long long)idtr[0] << 56 |
(unsigned long long)idtr[1] << 48 |
(unsigned long long)idtr[2] << 40 |
(unsigned long long)idtr[3] << 32 |
(unsigned long long)idtr[4] << 24 |
(unsigned long long)idtr[5] << 16 |
(unsigned long long)idtr[6] << 8 |
(unsigned long long)idtr[7];
unsigned short idtrLimit = (unsigned int)idtr[8] << 8 |
(unsigned int)idtr[9];
printf("Interrupt Descriptor Table Register base: 0x%llx, limit: 0x%X\r\n", idtrBase, idtrLimit);
#else
unsigned char idtr[6] = { 0 };
__asm {
sidt idtr;
@@ -16,9 +35,28 @@ int main()
(unsigned int)idtr[1] << 16 |
(unsigned int)idtr[2] << 8 |
(unsigned int)idtr[3];
unsigned short idtrLimit = (unsigned int) idtr[4] << 8 |
unsigned short idtrLimit = (unsigned int)idtr[4] << 8 |
(unsigned int)idtr[5];
printf("Interrupt Descriptor Table Register base: 0x%X, limit: 0x%X\r\n", idtrBase, idtrLimit);
#endif
#ifdef _WIN64
unsigned char gdtr[10] = { 0 };
_sgdt(gdtr);
unsigned long long gdtrBase = (unsigned long long)gdtr[0] << 56 |
(unsigned long long)gdtr[1] << 48 |
(unsigned long long)gdtr[2] << 40 |
(unsigned long long)gdtr[3] << 32 |
(unsigned long long)gdtr[4] << 24 |
(unsigned long long)gdtr[5] << 16 |
(unsigned long long)gdtr[6] << 8 |
(unsigned long long)gdtr[7];
unsigned short gdtrLimit = (unsigned int)gdtr[8] << 8 |
(unsigned int)gdtr[9];
printf("Global Descriptor Table Register base: 0x%llx, limit: 0x%X\r\n", gdtrBase, gdtrLimit);
#else
unsigned char gdtr[6] = { 0 };
__asm {
sgdt gdtr;
@@ -30,14 +68,22 @@ int main()
unsigned short gdtrLimit = (unsigned int)gdtr[4] << 8 |
(unsigned int)gdtr[5];
printf("Global Descriptor Table Register base: 0x%X, limit: 0x%X\r\n", gdtrBase, gdtrLimit);
LDT_ENTRY tss;
#endif
WORD tr;
#ifdef _WIN64
tr = get_tss_selector();
#else
__asm str tr
#endif
#ifdef _WIN64
WOW64_LDT_ENTRY tss;
Wow64GetThreadSelectorEntry(GetCurrentThread(), tr, &tss);
#else
LDT_ENTRY tss;
GetThreadSelectorEntry(GetCurrentThread(), tr, &tss);
#endif
unsigned int tssBase = (tss.HighWord.Bits.BaseHi << 24) +
(tss.HighWord.Bits.BaseMid << 16) +
tss.BaseLow;
@@ -53,6 +53,7 @@
</PropertyGroup>
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.props" />
<ImportGroup Label="ExtensionSettings">
<Import Project="$(VCTargetsPath)\BuildCustomizations\masm.props" />
</ImportGroup>
<ImportGroup Label="Shared">
</ImportGroup>
@@ -157,7 +158,13 @@
<PrecompiledHeader Condition="'$(Configuration)|$(Platform)'=='Release|x64'">Create</PrecompiledHeader>
</ClCompile>
</ItemGroup>
<ItemGroup>
<MASM Include="asm_funcs.asm">
<FileType>Document</FileType>
</MASM>
</ItemGroup>
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
<ImportGroup Label="ExtensionTargets">
<Import Project="$(VCTargetsPath)\BuildCustomizations\masm.targets" />
</ImportGroup>
</Project>
@@ -33,4 +33,9 @@
<Filter>Source Files</Filter>
</ClCompile>
</ItemGroup>
<ItemGroup>
<MASM Include="asm_funcs.asm">
<Filter>Source Files</Filter>
</MASM>
</ItemGroup>
</Project>
@@ -0,0 +1,18 @@
_DATA SEGMENT
_DATA ENDS
_TEXT SEGMENT
PUBLIC get_idtr
get_idtr PROC
sidt [rcx]
ret
get_idtr ENDP
PUBLIC get_tss_selector
get_tss_selector PROC
str eax
ret
get_tss_selector ENDP
_TEXT ENDS
END
@@ -59,8 +59,12 @@ int main()
HANDLE handle = pHandleInfo->Handles[i].HandleValue;
HANDLE pid = pHandleInfo->Handles[i].UniqueProcessId;
printf("PID: %d\t", pid);
#ifdef _WIN64
printf("Object 0x%llx\t", object);
#else
printf("Object 0x%X\t", object);
printf("Handle 0x%X\r\n", handle);
#endif
printf("Handle 0x%x\r\n", handle);
}
return 0;
}
@@ -12,6 +12,9 @@ typedef struct _SYSTEM_LOCK {
ULONG ActiveCount;
ULONG ContentionCount;
ULONG Reserved2[2];
#ifdef _WIN64
ULONG Reserved3;
#endif
ULONG NumberOfSharedWaiters;
ULONG NumberOfExclusiveWaiters;
} SYSTEM_LOCK, *PSYSTEM_LOCK;
@@ -51,10 +54,14 @@ int main()
status = query(SystemLockInformation, pLockInfo, len, &len);
} while (status == (NTSTATUS)0xc0000004);
for (int i = 0; i < pLockInfo->LocksCount; i++) {
for (unsigned int i = 0; i < pLockInfo->LocksCount; i++) {
PVOID lockAddress = pLockInfo->Locks[i].Address;
USHORT lockType = (USHORT)pLockInfo->Locks[i].Type;
#ifdef _WIN64
printf("Lock Address 0x%llx\t", lockAddress);
#else
printf("Lock Address 0x%X\t", lockAddress);
#endif
printf("Lock Type 0x%X\r\n", lockType);
}
return 0;
@@ -9,6 +9,9 @@
typedef struct SYSTEM_MODULE {
ULONG Reserved1;
ULONG Reserved2;
#ifdef _WIN64
ULONG Reserved3;
#endif
PVOID ImageBaseAddress;
ULONG ImageSize;
ULONG Flags;
@@ -16,7 +19,7 @@ typedef struct SYSTEM_MODULE {
WORD Rank;
WORD w018;
WORD NameOffset;
BYTE Name[MAXIMUM_FILENAME_LENGTH];
CHAR Name[MAXIMUM_FILENAME_LENGTH];
}SYSTEM_MODULE, *PSYSTEM_MODULE;
typedef struct SYSTEM_MODULE_INFORMATION {
@@ -56,11 +59,15 @@ int main()
printf("Failed to retrieve system module information.\r\n");
return 1;
}
for (int i = 0; i < pModuleInfo->ModulesCount; i++) {
for (unsigned int i = 0; i < pModuleInfo->ModulesCount; i++) {
PVOID kernelImageBase = pModuleInfo->Modules[i].ImageBaseAddress;
PCHAR kernelImage = (PCHAR)pModuleInfo->Modules[i].Name;
printf("Module name %s\t", kernelImage);
printf("Base Address 0x%X\r\n", kernelImageBase);
printf("Mod name %s ", kernelImage);
#ifdef _WIN64
printf("Base Addr 0x%llx\r\n", kernelImageBase);
#else
printf("Base Addr 0x%X\r\n", kernelImageBase);
#endif
}
return 0;
}
@@ -0,0 +1,40 @@
========================================================================
CONSOLE APPLICATION : NtQuerySysInfo_SystemModuleInformation Project Overview
========================================================================
AppWizard has created this NtQuerySysInfo_SystemModuleInformation application for you.
This file contains a summary of what you will find in each of the files that
make up your NtQuerySysInfo_SystemModuleInformation application.
NtQuerySysInfo_SystemModuleInformation.vcxproj
This is the main project file for VC++ projects generated using an Application Wizard.
It contains information about the version of Visual C++ that generated the file, and
information about the platforms, configurations, and project features selected with the
Application Wizard.
NtQuerySysInfo_SystemModuleInformation.vcxproj.filters
This is the filters file for VC++ projects generated using an Application Wizard.
It contains information about the association between the files in your project
and the filters. This association is used in the IDE to show grouping of files with
similar extensions under a specific node (for e.g. ".cpp" files are associated with the
"Source Files" filter).
NtQuerySysInfo_SystemModuleInformation.cpp
This is the main application source file.
/////////////////////////////////////////////////////////////////////////////
Other standard files:
StdAfx.h, StdAfx.cpp
These files are used to build a precompiled header (PCH) file
named NtQuerySysInfo_SystemModuleInformation.pch and a precompiled types file named StdAfx.obj.
/////////////////////////////////////////////////////////////////////////////
Other notes:
AppWizard uses "TODO:" comments to indicate parts of the source code you
should add to or customize.
/////////////////////////////////////////////////////////////////////////////
@@ -86,8 +86,7 @@ typedef enum _KWAIT_REASON
MaximumWaitReason = 37
} KWAIT_REASON;
typedef struct _SYSTEM_THREAD_INFORMATION{
typedef struct _SYSTEM_THREAD_INFORMATION {
LARGE_INTEGER KernelTime;
LARGE_INTEGER UserTime;
LARGE_INTEGER CreateTime;
@@ -96,10 +95,13 @@ typedef struct _SYSTEM_THREAD_INFORMATION{
CLIENT_ID ClientId;
KPRIORITY Priority;
LONG BasePriority;
ULONG ContextSwitches;
ULONG ContextSwitchCount;
ULONG ThreadState;
KWAIT_REASON WaitReason;
} SYSTEM_THREAD_INFORMATION, *PSYSTEM_THREAD_INFORMATION;
#ifdef _WIN64
ULONG Reserved[4];
#endif
}SYSTEM_THREAD_INFORMATION, *PSYSTEM_THREAD_INFORMATION;
typedef struct _SYSTEM_EXTENDED_THREAD_INFORMATION
{
@@ -107,13 +109,11 @@ typedef struct _SYSTEM_EXTENDED_THREAD_INFORMATION
PVOID StackBase;
PVOID StackLimit;
PVOID Win32StartAddress;
PVOID TebAddress;
PVOID TebAddress; /* This is only filled in on Vista and above */
ULONG Reserved1;
ULONG Reserved2;
ULONG Reserved3;
} SYSTEM_EXTENDED_THREAD_INFORMATION, *
PSYSTEM_EXTENDED_THREAD_INFORMATION;
} SYSTEM_EXTENDED_THREAD_INFORMATION, *PSYSTEM_EXTENDED_THREAD_INFORMATION;
typedef struct _SYSTEM_EXTENDED_PROCESS_INFORMATION
{
ULONG NextEntryOffset;
@@ -126,7 +126,7 @@ typedef struct _SYSTEM_EXTENDED_PROCESS_INFORMATION
LARGE_INTEGER KernelTime;
UNICODE_STRING ImageName;
KPRIORITY BasePriority;
ULONG UniqueProcessId;
ULONG ProcessId;
ULONG InheritedFromUniqueProcessId;
ULONG HandleCount;
ULONG SessionId;
@@ -137,9 +137,8 @@ typedef struct _SYSTEM_EXTENDED_PROCESS_INFORMATION
SYSTEM_EXTENDED_THREAD_INFORMATION Threads[1];
} SYSTEM_EXTENDED_PROCESS_INFORMATION, *PSYSTEM_EXTENDED_PROCESS_INFORMATION;
typedef enum _SYSTEM_INFORMATION_CLASS {
SystemSessionProcessInformation = 57
SystemExtendedProcessInformation = 57
} SYSTEM_INFORMATION_CLASS;
typedef NTSTATUS(WINAPI *PNtQuerySystemInformation)(
@@ -157,20 +156,29 @@ int main()
printf("GetProcAddress() failed.\n");
return 1;
}
ULONG len = 20;
ULONG len = 2000;
NTSTATUS status = NULL;
PSYSTEM_EXTENDED_PROCESS_INFORMATION pProcessInfo = NULL;
do {
len *= 2;
len *= 2;
pProcessInfo = (PSYSTEM_EXTENDED_PROCESS_INFORMATION)GlobalAlloc(GMEM_ZEROINIT, len);
status = query(SystemSessionProcessInformation, pProcessInfo, len, &len);
status = query(SystemExtendedProcessInformation, pProcessInfo, len, &len);
} while (status == (NTSTATUS)0xc0000004);
for (unsigned int i = 0; i < pProcessInfo->NumberOfThreads; i++) {
PVOID stackBase = pProcessInfo->Threads[i].StackBase;
PVOID stackLimit = pProcessInfo->Threads[i].StackLimit;
printf("Stack base 0x%X\t", stackBase);
printf("Stack limit 0x%X\r\n", stackLimit);
while (pProcessInfo->NextEntryOffset != NULL) {
for (unsigned int i = 0; i < pProcessInfo->NumberOfThreads; i++) {
PVOID stackBase = pProcessInfo->Threads[i].StackBase;
PVOID stackLimit = pProcessInfo->Threads[i].StackLimit;
#ifdef _WIN64
printf("Stack base 0x%llx\t", stackBase);
printf("Stack limit 0x%llx\r\n", stackLimit);
#else
printf("Stack base 0x%X\t", stackBase);
printf("Stack limit 0x%X\r\n", stackLimit);
#endif
}
pProcessInfo = (PSYSTEM_EXTENDED_PROCESS_INFORMATION)((ULONG_PTR)pProcessInfo + pProcessInfo->NextEntryOffset);
}
return 0;
}
+6 -6
View File
@@ -4,13 +4,13 @@ This repository aims to provide functioning code that demonstrated usage of vari
| Technique | Windows 7 | Windows 8 | Windows 8.1 | Windows 10|
|---------------------------------------------------|-----------|-----------|-------------|-----------|
|[NtQuerySystemInformation (SystemHandleInformation)](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/NtQuerySysInfo_SystemHandleInformation/NtQuerySysInfo_SystemHandleInformation/NtQuerySysInfo_SystemHandleInformation.cpp) | ![](tick.png) | | | |
|[NtQuerySystemInformation (SystemLockInformation)](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/NtQuerySysInfo_SystemLockInformation/NtQuerySysInfo_SystemLockInformation/NtQuerySysInfo_SystemLockInformation.cpp) |![](tick.png) | | | |
|[NtQuerySystemInformation (SystemModuleInformation)](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/NtQuerySysInfo_SystemModuleInformation/NtQuerySysInfo_SystemModuleInformation/NtQuerySysInfo_SystemModuleInformation.cpp) |![](tick.png) | | | |
|[NtQuerySystemInformation (SystemProcessInformation)](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/NtQuerySysInfo_SystemProcessInformation/NtQuerySysInfo_SystemProcessInformation/NtQuerySysInfo_SystemProcessInformation.cpp)|![](tick.png) | | | |
|[NtQuerySystemInformation (SystemHandleInformation)](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/NtQuerySysInfo_SystemHandleInformation/NtQuerySysInfo_SystemHandleInformation/NtQuerySysInfo_SystemHandleInformation.cpp) | ![](tick.png) |![](tick.png) | | |
|[NtQuerySystemInformation (SystemLockInformation)](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/NtQuerySysInfo_SystemLockInformation/NtQuerySysInfo_SystemLockInformation/NtQuerySysInfo_SystemLockInformation.cpp) |![](tick.png) |![](tick.png) | | |
|[NtQuerySystemInformation (SystemModuleInformation)](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/NtQuerySysInfo_SystemModuleInformation/NtQuerySysInfo_SystemModuleInformation/NtQuerySysInfo_SystemModuleInformation.cpp) |![](tick.png) |![](tick.png) | | |
|[NtQuerySystemInformation (SystemProcessInformation)](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/NtQuerySysInfo_SystemProcessInformation/NtQuerySysInfo_SystemProcessInformation/NtQuerySysInfo_SystemProcessInformation.cpp)|![](tick.png) |![](tick.png) | | |
|[System Call Return Values](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/Syscalls/Syscalls/Syscalls.cpp) |![](tick.png) | | | |
|[Win32k Shared Info Handle Table](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/SharedInfoHandleTable/SharedInfoHandleTable/SharedInfoHandleTable.cpp) |![](tick.png) | | | |
|[Descriptor Tables](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/DescriptorTables/DescriptorTables/DescriptorTables.cpp) |![](tick.png) | | | |
|[Win32k Shared Info Handle Table](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/SharedInfoHandleTable/SharedInfoHandleTable/SharedInfoHandleTable.cpp) |![](tick.png) |![](tick.png) | | |
|[Descriptor Tables](https://github.com/sam-b/windows_kernel_address_leaks/blob/master/DescriptorTables/DescriptorTables/DescriptorTables.cpp) |![](tick.png) |![](tick.png) | | |
@@ -7,15 +7,20 @@
typedef struct _HANDLEENTRY {
PVOID phead;
ULONG pOwner;
PVOID pOwner;
BYTE bType;
BYTE bFlags;
WORD wUniq;
}HANDLEENTRY, *PHANDLEENTRY;
typedef struct _SERVERINFO {
DWORD dwSRVIFlags;
DWORD cHandleEntries;
#ifdef _WIN64
UINT64 dwSRVIFlags;
UINT64 cHandleEntries;
#else
DWORD dwSRVIFlags;
DWORD cHandleEntries;
#endif
WORD wSRVIFlags;
WORD wRIPPID;
WORD wRIPError;
@@ -39,7 +44,11 @@ int main()
for (unsigned int i = 0; i < gSharedInfo->psi->cHandleEntries; i++) {
HANDLEENTRY entry = gSharedInfo->aheList[i];
if (entry.bType != 0) { //ignore free entries
#ifdef _WIN64
printf("Head: 0x%llx, Owner: 0x%llx, Type: 0x%X\r\n", entry.phead, entry.pOwner, entry.bType);
#else
printf("Head: 0x%X, Owner: 0x%X, Type: 0x%X\r\n", entry.phead, entry.pOwner, entry.bType);
#endif
}
}
return 0;
+46 -13
View File
@@ -5,16 +5,28 @@
#include <Windows.h>
#include <Winddi.h>
//0x64D4B - NtUserModifyUserStartupInfoFlags
typedef DWORD(NTAPI * lNtUserModifyUserStartupInfoFlags)(DWORD Set, DWORD Flags);
//0xA2F4 - NtUserGetAsyncKeyState
typedef DWORD(NTAPI *lNtUserGetAsyncKeyState)(DWORD key);
#ifdef _WIN64
//win8, 64bit
#define NtUserModifyUserStartupInfoFlagsAddress 0x263F0
#define NtUserGetAsyncKeyStateAddress 0x3B30
#define NtGdiPATHOBJ_vEnumStartClipLinesAddress 0x67590
//0x47123 - NtGdiFONTOBJ_vGetInfo
#else
//win7, 32bit
#define NtUserModifyUserStartupInfoFlagsAddress 0x64D4B
#define NtUserGetAsyncKeyStateAddress 0xA2F4
#define NtGdiFONTOBJ_vGetInfoAddress 0x47123
#define NtGdiPATHOBJ_vEnumStartClipLinesAddress 0x47263
#endif
typedef DWORD(NTAPI * lNtUserModifyUserStartupInfoFlags)(DWORD Set, DWORD Flags);
typedef DWORD(NTAPI *lNtUserGetAsyncKeyState)(DWORD key);
typedef VOID(NTAPI * lNtGdiFONTOBJ_vGetInfo)(FONTOBJ *pfo,ULONG cjSize,FONTINFO *pfi);
//0x47263 - NtGdiPATHOBJ_vEnumStartClipLines
typedef VOID(NTAPI * lNtGdiPATHOBJ_vEnumStartClipLines)(PATHOBJ *ppo, CLIPOBJ *pco, SURFOBJ *pso, LINEATTRS *pla);
extern "C" unsigned long long get_rax();
int main()
{
HMODULE hUser32 = LoadLibraryA("user32.dll");
@@ -23,49 +35,70 @@ int main()
return 1;
}
lNtUserGetAsyncKeyState pNtUserGetAsyncKeyState = (lNtUserGetAsyncKeyState)((DWORD_PTR)hUser32 + 0xA2F4);
lNtUserGetAsyncKeyState pNtUserGetAsyncKeyState = (lNtUserGetAsyncKeyState)((DWORD_PTR)hUser32 + NtUserGetAsyncKeyStateAddress);
pNtUserGetAsyncKeyState(20);
#ifdef _WIN64
unsigned long long ethread = get_rax();
#else
unsigned int ethread = 0;
__asm {
mov ethread, eax;
}
#endif
printf("NtUserGetAsyncKeyState ETHREAD partial disclosure: 0x%X\r\n", ethread);
lNtUserModifyUserStartupInfoFlags pNtUserModifyUserStartupInfoFlags = (lNtUserModifyUserStartupInfoFlags)((DWORD_PTR)hUser32 + 0x64D4B);
lNtUserModifyUserStartupInfoFlags pNtUserModifyUserStartupInfoFlags = (lNtUserModifyUserStartupInfoFlags)((DWORD_PTR)hUser32 + NtUserModifyUserStartupInfoFlagsAddress);
pNtUserModifyUserStartupInfoFlags(20, 12);
#ifdef _WIN64
unsigned long long ethread_full = get_rax();
#else
unsigned ethread_full = 0;
__asm {
mov ethread_full, eax;
}
printf("NtUserModifyUserStartupInfoFlags ETHREAD full disclosure: 0x%X\r\n", ethread_full);
#endif
printf("NtUserModifyUserStartupInfoFlags ETHREAD full disclosure: 0x%X\r\n", ethread_full);
HMODULE hGDI32 = LoadLibraryA("gdi32.dll");
if (hGDI32 == NULL) {
printf("Failed to load gdi32");
return 1;
}
#ifdef _WIN64
//unsigned long long w32thread = get_rax();
#else
lNtGdiFONTOBJ_vGetInfo pNtGdiEngUnLockSurface = (lNtGdiFONTOBJ_vGetInfo)((DWORD_PTR)hGDI32 + 0x47123);
lNtGdiFONTOBJ_vGetInfo pNtGdiFONTOBJ_vGetInfo = (lNtGdiFONTOBJ_vGetInfo)((DWORD_PTR)hGDI32 + NtGdiFONTOBJ_vGetInfoAddress);
FONTOBJ surf = { 0 };
FONTINFO finfo = { 0 };
pNtGdiEngUnLockSurface(&surf,123, &finfo);
pNtGdiFONTOBJ_vGetInfo(&surf,123, &finfo);
long int w32thread = 0;
__asm {
mov w32thread, eax;
}
#endif
printf("NtGdiEngUnLockSurface W32THREAD full disclosure: 0x%X\r\n", ethread);
lNtGdiPATHOBJ_vEnumStartClipLines pNtGdiPATHOBJ_vEnumStartClipLines = (lNtGdiPATHOBJ_vEnumStartClipLines)((DWORD_PTR)hGDI32 + 0x47263);
lNtGdiPATHOBJ_vEnumStartClipLines pNtGdiPATHOBJ_vEnumStartClipLines = (lNtGdiPATHOBJ_vEnumStartClipLines)((DWORD_PTR)hGDI32 + NtGdiPATHOBJ_vEnumStartClipLinesAddress);
PATHOBJ pathobj = { 0 };
CLIPOBJ pco = { 0 };
SURFOBJ pso = { 0 };
LINEATTRS pla = { 0 };
pNtGdiPATHOBJ_vEnumStartClipLines(&pathobj, &pco, &pso, &pla);
#ifdef _WIN64
unsigned long long w32thread = get_rax();
#else
w32thread = 0;
__asm {
mov w32thread, eax;
}
#endif
printf("NtGdiPATHOBJ_vEnumStartClipLines W32THREAD full disclosure: 0x%X\r\n", ethread);
return 0;
+5
View File
@@ -53,6 +53,7 @@
</PropertyGroup>
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.props" />
<ImportGroup Label="ExtensionSettings">
<Import Project="$(VCTargetsPath)\BuildCustomizations\masm.props" />
</ImportGroup>
<ImportGroup Label="Shared">
</ImportGroup>
@@ -157,7 +158,11 @@
</ClCompile>
<ClCompile Include="Syscalls.cpp" />
</ItemGroup>
<ItemGroup>
<MASM Include="asm_funcs.asm" />
</ItemGroup>
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
<ImportGroup Label="ExtensionTargets">
<Import Project="$(VCTargetsPath)\BuildCustomizations\masm.targets" />
</ImportGroup>
</Project>
+6 -3
View File
@@ -26,11 +26,14 @@
</ClInclude>
</ItemGroup>
<ItemGroup>
<ClCompile Include="stdafx.cpp">
<Filter>Source Files</Filter>
</ClCompile>
<ClCompile Include="Syscalls.cpp">
<Filter>Source Files</Filter>
</ClCompile>
<ClCompile Include="stdafx.cpp" />
</ItemGroup>
<ItemGroup>
<MASM Include="asm_funcs.asm">
<Filter>Source Files</Filter>
</MASM>
</ItemGroup>
</Project>
+11
View File
@@ -0,0 +1,11 @@
_DATA SEGMENT
_DATA ENDS
_TEXT SEGMENT
PUBLIC get_rax
get_rax PROC
ret
get_rax ENDP
_TEXT ENDS
END
Binary file not shown.

After

Width:  |  Height:  |  Size: 19 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 19 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 27 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 20 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 23 KiB

Before

Width:  |  Height:  |  Size: 11 KiB

After

Width:  |  Height:  |  Size: 11 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 24 KiB

Before

Width:  |  Height:  |  Size: 14 KiB

After

Width:  |  Height:  |  Size: 14 KiB

Before

Width:  |  Height:  |  Size: 13 KiB

After

Width:  |  Height:  |  Size: 13 KiB

Before

Width:  |  Height:  |  Size: 15 KiB

After

Width:  |  Height:  |  Size: 15 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 6.0 KiB

Before

Width:  |  Height:  |  Size: 5.0 KiB

After

Width:  |  Height:  |  Size: 5.0 KiB

Before

Width:  |  Height:  |  Size: 18 KiB

After

Width:  |  Height:  |  Size: 18 KiB