BanMe Master Cheater
Reputation: 0
Joined: 29 Nov 2005 Posts: 375 Location: Farmington NH, USA
|
Posted: Tue Dec 16, 2008 9:57 pm Post subject: |
|
|
a lil somethin somethin ive been working on... (hopefully future update will accomodate GDT Callgate using Share Mapped memory).. also this is only server end o0 so write client you must xD
| Code: |
static HANDLE CommEvent;
HANDLE CommEventPair[4];
#define PORTNAME L"\\LPC_SHARE_CONNECT"
#define EVENTNAME L"\\LPC_SHARE_EVENT"
bool ProspectThreads(DWORD TargetPid,DWORD ServerTid,int EventIndex)
{
THREADENTRY32 te32;
if(TargetPid)
{
HANDLE hProc = OpenProcess(PROCESS_ALL_ACCESS,0,TargetPid);
if(hProc != INVALID_HANDLE_VALUE)
{
HANDLE hSnap = CreateToolhelp32Snapshot(TH32CS_SNAPTHREAD,TargetPid);
if(hSnap != INVALID_HANDLE_VALUE)
{
memset(&te32,0,sizeof(THREADENTRY32));
te32.dwSize = sizeof(THREADENTRY32);
if(Thread32First(hSnap,&te32))
{
do
{
if(te32.th32OwnerProcessID == TargetPid)
{
HANDLE hThr = OpenThread(THREAD_ALL_ACCESS,0,te32.th32ThreadID);
if(hThr != INVALID_HANDLE_VALUE)
{
if(DuplicateHandle(GetCurrentProcess(),CommEvent,hProc,&CommEventPair[EventIndex],0,false,DUPLICATE_SAME_ACCESS))
{
if(NT_SUCCESS(NtSetInformationThread(hThr,8,&CommEvent,4)))
{
return true;
}
}
}
}
}while(Thread32Next(hSnap,&te32));
}
}
}
}
return false;
}
HANDLE LpcInitSection(HANDLE Thread,DWORD Size,bool Executable,wchar_t *Modifier,int *Initialized)
{
HANDLE SecObj = INVALID_HANDLE_VALUE;
LARGE_INTEGER SecSize;
OBJECT_ATTRIBUTES oa;
int Init = *Initialized;
wchar_t wstr[32];
UNICODE_STRING UString;
SecSize.LowPart = Size;
SecSize.HighPart = 0x0;
if(Executable)
{
Status = NtCreateSection(&SecObj,SECTION_ALL_ACCESS,NULL,&SecSize,PAGE_EXECUTE_READWRITE,SEC_COMMIT,NULL);
}
Status = NtCreateSection(&SecObj,SECTION_ALL_ACCESS,NULL,&SecSize,PAGE_READWRITE,SEC_COMMIT,NULL);
if(!NT_SUCCESS(Status))
{
return SecObj;
}
memset(&oa,0,sizeof(OBJECT_ATTRIBUTES));
oa.Length = sizeof(OBJECT_ATTRIBUTES);
wcscpy((wchar_t*)&wstr,L"\\LPC_SHARE_EVENT");
wcscat((wchar_t*)&wstr,Modifier);
RtlInitUnicodeString(&UString,(wchar_t*)&wstr);
oa.ObjectName = &UString;
Status = NtCreateEventPair(&CommEventPair[Init],STANDARD_RIGHTS_REQUIRED | SYNCHRONIZE ,&oa);
if(!NT_SUCCESS(Status))
{
return SecObj;
}
Status = NtSetInformationThread(Thread,8,&CommEventPair[Init],4);
if(!NT_SUCCESS(Status))
{
return SecObj;
}
Initialized++;
return SecObj;
}
ULONG LpcManageConnection(LPC_THREAD_INFORMATION Packed)
{
LPC_SECTION_OWNER_MEMORY ServerMemory;
LPC_SECTION_MAP_INFORMATION ClientMemory;
SECTION_BASIC_INFORMATION SectInfo;
HANDLE AcceptPort;
ULONG Result;
HANDLE ServerPort = Packed.Port;
HANDLE ServerBase = Packed.SectionBase;
LPC_MESSAGE LpcMessage;
while(1)
{
if(NT_SUCCESS(NtReplyWaitReceivePort(ServerPort,NULL,NULL,&LpcMessage)))
{
switch(LpcMessage.MsgHeader.MessageType)
{
case LPC_CONNECTION_REQUEST:
if(NT_SUCCESS(ZwQuerySection(ServerBase,SectionBasicInformation,&SectInfo,sizeof(SECTION_BASIC_INFORMATION),&Result)))
{
memset(&ServerMemory,0,sizeof(LPC_SECTION_OWNER_MEMORY));
memset(&ClientMemory,0,sizeof(LPC_SECTION_MAP_INFORMATION));
ClientMemory.Length = sizeof(LPC_SECTION_MAP_INFORMATION);
ClientMemory.ServerBaseAddress = *(DWORD*)SectInfo.BaseAddress;
ServerMemory.Length = sizeof(LPC_SECTION_OWNER_MEMORY);
ServerMemory.SectionHandle = ServerBase;
ServerMemory.SectionSize = SectInfo.Size.LowPart;
ServerMemory.ServerBaseAddress = *(DWORD*)SectInfo.BaseAddress;
Status = NtAcceptConnectPort(&AcceptPort,0,&LpcMessage,1,&ServerMemory,NULL);
if(!NT_SUCCESS(Status))
{
return Status;
}
Status = ZwCompleteConnectPort(AcceptPort);
if (!NT_SUCCESS(Status))
{
CloseHandle(AcceptPort);
return Status;
}
}
default:
break;
}
}
}
return Status;
}
ULONG ThreadProc(LPVOID Param)
{
return 0;
}
bool LpcInit()
{
LPC_MESSAGE LpcCode,LpcData,LpcContext,LpcStack;
LPC_THREAD_INFORMATION LpcInfo;
UNICODE_STRING UString;
OBJECT_ATTRIBUTES oa;
ULONG CodeId,DataId,ContextId,StackId;
ULONG MngCodeId,MngDataId,MngContextId,MngStackId;
HANDLE CodePort,DataPort,ContextPort,StackPort;
HANDLE Code,Data,Context,Stack;
HANDLE MngCode,MngData,MngContext,MngStack;
int Init = 0;
MngCode = CreateThread(NULL,NULL,ThreadProc,NULL,CREATE_SUSPENDED,&MngCodeId);
if(MngCode != 0)
{
HANDLE CodeSecObj = LpcInitSection(MngCode,4096,true,L"_CODE",&Init);
if(CodeSecObj != INVALID_HANDLE_VALUE)
{
memset(&oa,0,sizeof(OBJECT_ATTRIBUTES));
oa.Length = sizeof(OBJECT_ATTRIBUTES);
RtlInitUnicodeString(&UString, L"\\LPC_CODE_SHARE");
oa.ObjectName = &UString;
Status = NtCreatePort(&CodePort,&oa,sizeof(LPC_MESSAGE_HEADER),sizeof(LPC_MESSAGE),0x0);
if(NT_SUCCESS(Status))
{
LpcInfo.LpcMessage = &LpcCode;
LpcInfo.Port = CodePort;
LpcInfo.SectionBase = CodeSecObj;
Code = CreateThread(NULL,NULL,(LPTHREAD_START_ROUTINE)LpcManageConnection,(LPVOID)&LpcInfo,NULL,&CodeId);
if(Code == 0)
{
MessageBoxA(0,"Failed Creating Code Thread","",0);
return FALSE;
}
}
else
{
MessageBoxA(0,"Failed Creating Port","",0);
return FALSE;
}
}
else
{
MessageBoxA(0,"Failed Creating Section","",0);
return FALSE;
}
}
else
{
return FALSE;
}
MngData = CreateThread(NULL,NULL,ThreadProc,NULL,CREATE_SUSPENDED,&MngDataId);
if(MngData != 0)
{
HANDLE DataSecObj = LpcInitSection(MngData,2048,false,L"_DATA",&Init);
if(DataSecObj != INVALID_HANDLE_VALUE)
{
memset(&oa,0,sizeof(OBJECT_ATTRIBUTES));
oa.Length = sizeof(OBJECT_ATTRIBUTES);
RtlInitUnicodeString(&UString, L"\\LPC_DATA_SHARE");
oa.ObjectName = &UString;
Status = NtCreatePort(&DataPort,&oa,sizeof(LPC_MESSAGE_HEADER),sizeof(LPC_MESSAGE),0x0);
if(NT_SUCCESS(Status))
{
LpcInfo.LpcMessage = &LpcData;
LpcInfo.Port = DataPort;
LpcInfo.SectionBase = DataSecObj;
Data = CreateThread(NULL,NULL,(LPTHREAD_START_ROUTINE)LpcManageConnection,(LPVOID)&LpcInfo,NULL,&DataId);
if(Data == 0)
{
MessageBoxA(0,"Failed Creating Data Thread","",0);
return FALSE;
}
}
else
{
MessageBoxA(0,"Failed Creating Data Port","",0);
return FALSE;
}
}
else
{
MessageBoxA(0,"Failed Creating Data Section","",0);
return FALSE;
}
}
else
{
return FALSE;
}
MngContext = CreateThread(NULL,NULL,ThreadProc,NULL,CREATE_SUSPENDED,&MngContextId);
if(MngContext != 0)
{
HANDLE ContextSecObj = LpcInitSection(MngContext,sizeof(CONTEXT),false,L"_CONTEXT",&Init);
if(ContextSecObj != INVALID_HANDLE_VALUE)
{
memset(&oa,0,sizeof(OBJECT_ATTRIBUTES));
oa.Length = sizeof(OBJECT_ATTRIBUTES);
RtlInitUnicodeString(&UString, L"\\LPC_CONTEXT_SHARE");
oa.ObjectName = &UString;
Status = NtCreatePort(&ContextPort,&oa,sizeof(LPC_MESSAGE_HEADER),sizeof(LPC_MESSAGE),0x0);
if(NT_SUCCESS(Status))
{
LpcInfo.LpcMessage = &LpcContext;
LpcInfo.Port = ContextPort;
LpcInfo.SectionBase = ContextSecObj;
Context = CreateThread(NULL,NULL,(LPTHREAD_START_ROUTINE)LpcManageConnection,(LPVOID)&LpcInfo,NULL,&ContextId);
if(Context == 0)
{
MessageBoxA(0,"Failed Creating Context Thread","",0);
return FALSE;
}
}
else
{
MessageBoxA(0,"Failed Creating Context Port","",0);
return FALSE;
}
}
else
{
MessageBoxA(0,"Failed to Creating Context Section","",0);
return FALSE;
}
}
else
{
return FALSE;
}
MngStack = CreateThread(NULL,NULL,ThreadProc,NULL,CREATE_SUSPENDED,&StackId);
if(MngStack != 0)
{
HANDLE StackSecObj = LpcInitSection(MngStack,1024,true,L"_STACK",&Init);
if(StackSecObj != INVALID_HANDLE_VALUE)
{
memset(&oa,0,sizeof(OBJECT_ATTRIBUTES));
oa.Length = sizeof(OBJECT_ATTRIBUTES);
RtlInitUnicodeString(&UString, L"\\LPC_STACK_SHARE");
oa.ObjectName = &UString;
Status = NtCreatePort(&StackPort,&oa,sizeof(LPC_MESSAGE_HEADER),sizeof(LPC_MESSAGE),0x0);
if(NT_SUCCESS(Status))
{
LpcInfo.LpcMessage = &LpcStack;
LpcInfo.Port = StackPort;
LpcInfo.SectionBase = StackSecObj;
Stack = CreateThread(NULL,NULL,(LPTHREAD_START_ROUTINE)LpcManageConnection,(LPVOID)&LpcInfo,NULL,&StackId);
if(Stack == 0)
{
MessageBoxA(0,"Failed Creating Stack Thread","",0);
return FALSE;
}
}
else
{
MessageBoxA(0,"Failed Creating Stack Port","",0);
return FALSE;
}
}
else
{
MessageBoxA(0,"Failed Creating Stack section","",0);
return FALSE;
}
}
else
{
return FALSE;
}
return TRUE;
}
|
p.s. this also needs a Thread Manager to redirect Threads and resume them with proper CONTEXT.
|
|