diff --git a/PEB_Walk/Cargo.lock b/PEB_Walk/Cargo.lock new file mode 100644 index 0000000..30d5a2c --- /dev/null +++ b/PEB_Walk/Cargo.lock @@ -0,0 +1,53 @@ +# This file is automatically @generated by Cargo. +# It is not intended for manual editing. +version = 3 + +[[package]] +name = "PEB_Walk" +version = "0.1.0" +dependencies = [ + "windows-sys", +] + +[[package]] +name = "windows-sys" +version = "0.36.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "ea04155a16a59f9eab786fe12a4a450e75cdb175f9e0d80da1e17db09f55b8d2" +dependencies = [ + "windows_aarch64_msvc", + "windows_i686_gnu", + "windows_i686_msvc", + "windows_x86_64_gnu", + "windows_x86_64_msvc", +] + +[[package]] +name = "windows_aarch64_msvc" +version = "0.36.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9bb8c3fd39ade2d67e9874ac4f3db21f0d710bee00fe7cab16949ec184eeaa47" + +[[package]] +name = "windows_i686_gnu" +version = "0.36.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "180e6ccf01daf4c426b846dfc66db1fc518f074baa793aa7d9b9aaeffad6a3b6" + +[[package]] +name = "windows_i686_msvc" +version = "0.36.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "e2e7917148b2812d1eeafaeb22a97e4813dfa60a3f8f78ebe204bcc88f12f024" + +[[package]] +name = "windows_x86_64_gnu" +version = "0.36.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "4dcd171b8776c41b97521e5da127a2d86ad280114807d0b2ab1e462bc764d9e1" + +[[package]] +name = "windows_x86_64_msvc" +version = "0.36.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "c811ca4a8c853ef420abd8592ba53ddbbac90410fab6903b3e79972a631f7680" diff --git a/PEB_Walk/src/main.rs b/PEB_Walk/src/main.rs index 5914a6e..21d28cb 100644 --- a/PEB_Walk/src/main.rs +++ b/PEB_Walk/src/main.rs @@ -5,7 +5,7 @@ use windows_sys::Win32::System::Threading::PEB; use windows_sys::Win32::System::WindowsProgramming::LDR_DATA_TABLE_ENTRY; use windows_sys::Win32::System::SystemServices::{IMAGE_DOS_HEADER, IMAGE_EXPORT_DIRECTORY}; use windows_sys::Win32::System::Diagnostics::Debug::{IMAGE_NT_HEADERS64, IMAGE_DATA_DIRECTORY}; - +use windows_sys::Win32::System::Kernel::LIST_ENTRY; mod types; #[inline] @@ -28,7 +28,7 @@ fn get_module_base_addr(module_name: &str) -> HINSTANCE { let peb = *rf_peb; let mut p_ldr_data_table_entry: *const LDR_DATA_TABLE_ENTRY = (*peb.Ldr).InMemoryOrderModuleList.Flink as *const LDR_DATA_TABLE_ENTRY; - let mut p_list_entry = (*peb.Ldr).InMemoryOrderModuleList.Flink; + let mut p_list_entry = &(*peb.Ldr).InMemoryOrderModuleList as *const LIST_ENTRY; loop { let buffer = std::slice::from_raw_parts( @@ -39,6 +39,10 @@ fn get_module_base_addr(module_name: &str) -> HINSTANCE { let module_base: HINSTANCE = (*p_ldr_data_table_entry).Reserved2[0] as HINSTANCE; return module_base; } + if p_list_entry == (*peb.Ldr).InMemoryOrderModuleList.Blink { + println!("Module not found!"); + return 0; + } p_list_entry = (*p_list_entry).Flink; p_ldr_data_table_entry = (*p_list_entry).Flink as *const LDR_DATA_TABLE_ENTRY; } @@ -78,6 +82,7 @@ fn get_proc_addr(module_handle: HINSTANCE, function_name: &str) -> FARPROC { } } + fn main() { unsafe{ println!("[+] Getting base address of kernel32.dll");