2022-02-01 21:19:37 +01:00
2022-02-01 21:03:38 +01:00
2022-02-01 21:03:38 +01:00
2022-02-01 21:03:38 +01:00
2022-02-01 21:19:37 +01:00

RecycledGate

This is just another implementation of Hellsgate + Halosgate/Tartarosgate.

However, this implementation makes sure that all system calls still go through ntdll.dll to avoid the usage of direct systemcalls. To do so, I parse the ntdll for nonhooked syscall-stubs and re-use existing syscall;ret instructions - thus the name of this project.

[*] Resolving Syscall: 916c6394
        Found syscall using Halos gate
        Found syscall; ret instruction
        Syscall nr: 74
        Gate: 00007FF9160100E2
[*] Resolving Syscall: 625d5a2e
        Found syscall using Halos gate
        Found syscall; ret instruction
        Syscall nr: 40
        Gate: 00007FF91600FCA2
[*] Resolving Syscall: 9523617c
        Found syscall using Halos gate
        Found syscall; ret instruction
        Syscall nr: 69
        Gate: 00007FF916010042

This probably bypasses some EDR trying to detect abnormal systemcalls.

A sample program using RecycledGate can be found in the sample folder

Usage

Here is a snippet, which should be self-explanatory.

Syscall sysNtCreateSection = { 0x00 };
NTSTATUS ntStatus;

dwSuccess = getSyscall(0x916c6394, &sysNtCreateSection);
if (dwSuccess == FAIL)
  goto exit;

PrepareSyscall(sysNtCreateSection.dwSyscallNr, sysNtCreateSection.pRecycledGate);
ntStatus = DoSyscall(&hSection, SECTION_MAP_READ | SECTION_MAP_WRITE | SECTION_MAP_EXECUTE, NULL, (PLARGE_INTEGER)&sizeBuffer, PAGE_EXECUTE_READWRITE, SEC_COMMIT, NULL);
if (!NT_SUCCESS(ntStatus)) {
  printf("[-] Failed to create section\n");
  goto exit;
}

Note:

  • No instructions must exist between the call to PrepareSyscall and DoSyscall
  • The hash algorithm used is djb2. All hashes must be encrypted with the key 0x41424344. You can use the Hashgenerator in this repository

Credits

S
Description
Automated archival mirror of github.com/thefLink/RecycledGate
Readme 47 KiB
Languages
C 98%
Assembly 2%