mirror of
https://github.com/toneillcodes/windows-process-injection
synced 2026-06-21 14:11:25 +00:00
Adjusting function names to maintain obfuscation
This commit is contained in:
@@ -48,8 +48,8 @@ PVOID GetRemotePebAddress(HANDLE hProcess) {
|
||||
}
|
||||
|
||||
// find the address of an exported function within a given module
|
||||
// obviously depends on a name value being present in the array found at AddressOfNames
|
||||
PVOID GetProcAddressManualByName(HMODULE hMod, char* targetFunc) {
|
||||
// depends on a name value being present in the array found at AddressOfNames
|
||||
PVOID GPAManualByName(HMODULE hMod, char* targetFunc) {
|
||||
PBYTE base = (PBYTE)hMod;
|
||||
|
||||
PIMAGE_DOS_HEADER dos = (PIMAGE_DOS_HEADER)base;
|
||||
@@ -102,7 +102,7 @@ PVOID GetProcAddressManualByName(HMODULE hMod, char* targetFunc) {
|
||||
}
|
||||
|
||||
// find the address of an exported function within a given module
|
||||
PVOID GetProcAddressManualByOrdinal(HMODULE hMod, WORD ordinal) {
|
||||
PVOID GPAManualByOrdinal(HMODULE hMod, WORD ordinal) {
|
||||
PBYTE base = (PBYTE)hMod;
|
||||
|
||||
// 1. Navigate to the Export Directory (standard PE parsing)
|
||||
|
||||
@@ -22,10 +22,10 @@ PVOID GetRemotePebAddress(HANDLE hProcess);
|
||||
int my_strlen(const char* inputString);
|
||||
|
||||
// Manual implementation of GetProcAddress (by name)
|
||||
PVOID GetProcAddressManualByName(HMODULE hMod, char* targetFunc);
|
||||
PVOID GPAManualByName(HMODULE hMod, char* targetFunc);
|
||||
|
||||
// Manual implementation of GetProcAddress (by ordinal)
|
||||
PVOID GetProcAddressManualByOrdinal(HMODULE hMod, WORD ordinal);
|
||||
PVOID GPAManualByOrdinal(HMODULE hMod, WORD ordinal);
|
||||
|
||||
// Manually finds the base address of a module using the PEB's Ldr list
|
||||
PVOID GetModuleBaseManual(PPEB pebObject, const char* targetModuleName);
|
||||
|
||||
@@ -86,7 +86,7 @@ int main(int argc, char* argv[]) {
|
||||
}
|
||||
//ParseDll(moduleBaseAddress);
|
||||
PVOID moduleBase = moduleBaseAddress;
|
||||
// 1. Get DOS Header
|
||||
// Get DOS Header
|
||||
PIMAGE_DOS_HEADER dosHeader = (PIMAGE_DOS_HEADER)moduleBase;
|
||||
if (dosHeader->e_magic != IMAGE_DOS_SIGNATURE) {
|
||||
printf("Invalid DOS Signature\n");
|
||||
@@ -159,7 +159,7 @@ int main(int argc, char* argv[]) {
|
||||
// Iterate through every function exported by the DLL
|
||||
for (DWORD i = 0; i < NumberOfFunctions; i++) {
|
||||
|
||||
// 1. Get the Function RVA directly using the index 'i'
|
||||
// Get the Function RVA directly using the index 'i'
|
||||
DWORD functionRVA = functionsArray[i];
|
||||
if (functionRVA == 0) continue; // Skip entries with no address
|
||||
|
||||
|
||||
@@ -55,7 +55,7 @@ int main(int argc, char* argv[]) {
|
||||
PVOID dllBase = GetModuleBaseManual(peb_ptr, "USER32.dll"); // or maybe ntdll.dll
|
||||
if(dllBase) {
|
||||
printf("DLL found @ %llx\n",dllBase);
|
||||
PVOID rvaFound = GetProcAddressManualByName((HMODULE) dllBase, "MessageBoxA"); // and then NtAllocateVirtualMemory
|
||||
PVOID rvaFound = GPAManualByName((HMODULE) dllBase, "MessageBoxA"); // and then NtAllocateVirtualMemory
|
||||
if(rvaFound) {
|
||||
printf("found function within DLL @ %llx\n", rvaFound);
|
||||
// MessageBoxA example
|
||||
|
||||
Reference in New Issue
Block a user