From 3d6b267579d5c06e8bcbc8b39b22de5cb98e98e3 Mon Sep 17 00:00:00 2001 From: xerox Date: Sun, 1 Nov 2020 15:44:15 -0800 Subject: [PATCH] cleaned some code --- VDM/main.cpp | 16 ++++++++++------ VDM/vdm/vdm.hpp | 3 ++- drivers/README.md | Bin 49084 -> 0 bytes 3 files changed, 12 insertions(+), 7 deletions(-) delete mode 100644 drivers/README.md diff --git a/VDM/main.cpp b/VDM/main.cpp index 0159eaf..aef75e2 100644 --- a/VDM/main.cpp +++ b/VDM/main.cpp @@ -10,21 +10,25 @@ int __cdecl main(int argc, char** argv) } vdm::vdm_ctx vdm; - std::printf("[+] drv_handle -> 0x%x, drv_key -> %s\n", drv_handle, drv_key.c_str()); - std::printf("[+] %s physical address -> 0x%p\n", vdm::syscall_hook.first, vdm::syscall_address.load()); - - const auto ntoskrnl_base = + const auto ntoskrnl_base = reinterpret_cast( util::get_module_base("ntoskrnl.exe")); - const auto ntoskrnl_memcpy = + const auto ntoskrnl_memcpy = util::get_kernel_export("ntoskrnl.exe", "memcpy"); + std::printf("[+] drv_handle -> 0x%x, drv_key -> %s\n", drv_handle, drv_key.c_str()); + std::printf("[+] %s physical address -> 0x%p\n", vdm::syscall_hook.first, vdm::syscall_address.load()); std::printf("[+] ntoskrnl base address -> 0x%p\n", ntoskrnl_base); std::printf("[+] ntoskrnl memcpy address -> 0x%p\n", ntoskrnl_memcpy); short mz_bytes = 0; - vdm.syscall(ntoskrnl_memcpy, &mz_bytes, ntoskrnl_base, sizeof mz_bytes); + vdm.syscall( + ntoskrnl_memcpy, + &mz_bytes, + ntoskrnl_base, + sizeof mz_bytes + ); std::printf("[+] kernel MZ -> 0x%x\n", mz_bytes); if (!vdm::unload_drv(drv_handle, drv_key)) diff --git a/VDM/vdm/vdm.hpp b/VDM/vdm/vdm.hpp index 913fa8f..d7d66b4 100644 --- a/VDM/vdm/vdm.hpp +++ b/VDM/vdm/vdm.hpp @@ -31,7 +31,8 @@ namespace vdm sizeof(vdm::raw_driver) ); - if (!result) return { {}, {} }; + if (!result) + return { {}, {} }; vdm::drv_handle = CreateFile( "\\\\.\\GIO", diff --git a/drivers/README.md b/drivers/README.md deleted file mode 100644 index 9e1cd6ad1f7d1e98e64d9584c290524080b2c17d..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 49084 zcmd_zZBtxVb_L-3IaT=&T})NtsTwPKvk<9NDu@@0j3v1cvf_NvV1#9jEukP}#rg3` z_H!1;t;Psw1RkJ^g1&uUPIs@f&f075bNcds|NDnwG<-e$F#IyS9bOIF^*b7#54*$5 z;pcj`TYLY0_`6}F&UjhdquR4Qycu?CE6+D;Ypb6BR6pCbwO9LhhS#-sXZXJU{yc29 z)^>(>?fReV@uxbj?akr4cGYP3tX_Agj_=j;U+Sti`|s#wwYXXPM*Ht=r>=5*d-(76 zF5cFwy&hf+f2@6z@A_Kpd01__(pB5-jO}`S(_VX2?Y?ep`{em7@9VkG_`I(04t)ln zWUt;0Wd2m!Z(E!GLQCr}>-B%Ab4GRUPJ4V`kGsQ# z$IXV;%etZ?qlL%qobT)JZasTjuVrhmwfM4O{7db5SI4~n*XvKard*2ohaPm!it&YWuI^LOtcbMSQj_NA->XUv?TMJcx`6fw0`??62i@w%WUJTz{=Qat!`ZGBs3JZa}F7K?L^Yrd|%_lB>AwZ@k`uGATi>-wW! z@!&i8rhPWN55sRZE-cqxpXODK%Y62m!}a>P-P%t3OLfJY;)dSny#K7;jS<+-#@Wqk zWmKPQr?nUr7!ChY2s`p`jm2IoN3OMg+#CM&gI8MF=OrFyG-k|X{2F(A^^^VzGwG1` z7RKwx=XDkyc(>nGuR5P5`E=jaJHZ<7Gh>TVxB|nqn@^lp?V$~0KIPp^G9cQqRj))H zj74M2`15YI>Qmc(QSFDTKEqf^aUHwznW9DZI5+Pl`#K}(S5zqPW!%0N#-s0G@Av2D z&BKji<@)fT*gyv#4$JkpRLr)uR;*rY+m5c**82X@uZ#U_bd{FeUxAu%wfJt-n!+(;^UT$0ObAMB~1yzWq>nCZm$` z##cT3wf}mL9QF9PT7FSn$jChE%;}C9^&jeM*M#X>`PkWyo66lBz8LNl^1uHN#6REv zIoYfCvpt^dij$r7VY}n)lU;lKS>qPZ_FW(U$~gnhi!~0vseZm)kL$H{t$4*<9p1)V zi+BHCqjsZ4xM(MyJ!sEYs)f-o_mL|PZ}0cnD;h2icZ<&}!>#(eP`}u{T%Y?+ZQZJ$ zyG@5y>hVr(-KaC2cdxdVhxxjCu{~R^=QnHbLW`TuzFz0g*SXiLjrrEr^8WSq+-U6w z=Qy9e+H?CDl%cp?_`a*i$hUKj*D4b6uVT|$DauyunI7xq7F82V7fYEE??&|*U)GW2 z0^0wl(&xA*Zpu6Uykc)6-_v>&8%4cIo?I^+RtpK}F14%R1*@gnf2Xzg?i3WP+dYyHaJKhe+k3l?-m0yI*52LL!cy(il0LcBdO-ioxBi))&zBQtjKwRz z*K7NW+JfzTZQrfGSPManrWzQF>3RchxVunC!eyg?mSl`L!}B|>S8(3-xNQ4&wX%2$ zKA%K4=1$1r51D?xe5Sqk8j4Hx+41Z~W8U4`UTM!@h>NSOC+^k$8?{X(u+x_KMVXhY z1*1cYl!#VeuU1ytD=gGA>O=2uwsWz4dOn{7=ZmM$iDnp?nCCAQ@qD@PxmS-j>Mz{! z+TI&=T-5YKNnCAQ(DV7WeY?)RQ5aK`)%tOT{-8*Da=ErVCL>)e$MCp0437Uejb3cA zPu+skkPmXwDi3Nrr~jFJ7pHIM@GIx*)57USQ;F4v&q^T!S4iEhJs2qFQ4_dR=DUS7 zF5_wfgjSvn6qM|H~u}$N}#pQiI&jQXO8AZKQkK6@BS8LB|Atv(q>yg61 zSNx(E_CeUud-Vv-`MMTkJ>INyxf0juN3S4C>KUzJdh}T~uln#)xr5!RQXI|bxw=aB zuePB|ip3A=`HR|C@!-dvm#g|Tmv=ZTPruhE|Dte#Ftm++D2j-yb?kcW7u}#re-~@p zURXL3mz^!wW4BSE9eyx=TWr)CrCF$7y~#~p-{oV&7HAnK#2axdz`sW4T?J8~bp&S;){;>I*X&BxS~E z*TD>ixNJY>^U!>pwi8oxES@|rQVa1LS086;nyf+Y0Z)vJUf?cA!CTO5s=-P4*Yrr?S-RsCS{#A@-&MGF{u|N_>6}8E#@1enJ@kl6~+9v;tc( zGgT%!!VyAozOJSe9Ee^~S;F?HP@EwTuAM|qOkb*JozJ`bnDUa7xE}mO=ZCZYGf(tm zi>0bXpMvb<`&JpEx{wk7sRzVUpAa3@dwAaDBXPpN9H6?%6PhwNEMyNx@3QFlpk}wvT4uYi{tQ)OXCXpHwcQFo+bM6 zdsJVJBCgVX*{3Kf$#nMK?@Mwr4B^%f!_AhB_6BhCrRR>si{K3iX)J>&2Ki#h~ZKSL-KK@DJnndEtD% ze1@@l1q>4fd1CP^9)s?tS{g4M%-{?&{1)vfyDSEV$+wgJiIbcPuSe-AbjAkl;ZDXl zKQ2B8T^Zi%`pF!|L98z)&hZ!V8mbcT;J3so3JQDf!x)#dBwwNF_)Sra15qtHBDNxXpC(8-p{G@&_SKckkQH|umnSV+=qpzviL6Z-$2e+Y* z{mIPj$j8b+8HYORPW08%BmVG39T4By`!eAQ2}ZjFJWZ!T#16%7ng^#++F5V zGmi~#3L@I!uwJ6v=DT?iPFiH8=tc`YR|(->=+3O*3|o%Ec#dzQ#@rbnK^>r+T12Wp zSg4N21M?>sPH($*Bs+vD)J4U(n5;CwX--{sSVu9q*P8F3PE zY}|-whoPCrwW0uy#se2_n|kwudQks4rmy($S;4vI$l?`GkbEWX4fDi7%1SFR6M7t+ zOr5?O`>Dxce&$}Yt|mF3F(Q|wOca@?6CI;fnNOJoK8t2BPIbdJ#!-m44da(CsL|1b zUjK;4z-G}gf7L~u;cw<)u%7>pE76XglDmkJDuc7aXF7njYLrx1Rl_5<%z?q1u5bt~kgnI6e(3|~$qV48U^o+dFtjx#$rn`JVpML?*_-Y5e1CSwu* zJo@F}Qa`2_9cNdIm1<1%-gEgQ#|QN|JH5oC=)cUKJ2opgCpW<~@d|4>TQMz}MBH9H zHjNhf%wb2t&AO)UVFZ}f=17bXelW9BeXSjJf-#h7lh>P_ILHsEGaKE>tyST;Vi=|- z2a&ASqP&zu#vCM5bD}AUkU>*U&6yh$SS#b96&y(B!P0v2lv#*_cN;fFKA#^`Ggrms zVI^M&Ev%#?v^+hN-jH>`5aT%$d5ONDJ{&k@w#SvZLaUA&K?^gZ8{BT3tutxoFNWZCjVy-5Eli*XYtP2p!npJmaBgg9xW z8{Pawu!R@QIS*PaDpHK7O!S<-WVMn$&`X)cf-tY4ACsH#fY8^Q$t!0C=gjs~+|=H( z@-V)Qa!_caUL6SH5YAj{{9L>WB}hhy#hf;sP9}))kcF`pWP$Wuzs`=|;304nI&h!_ zqMA%ObFblZ>ZUR}45c8MhcX^SNk}HQNv)3C$V^sR#Q7+YM^V9uNgZhx;$W&1_{+`V z94(-z{4NxYbiWu$eWL`h;t54J7^ZrcbxWxxMX{4y(OoVm56@EOsXEv(?ar?toxb;oMmpj z98Pjun4IyhqK1DkmowwGjFCQMotGntp6Z|!8RC3J<_pz5<6At+&gqRd!=Wn>j_w;(YldmckK!>KojPdS2?T*ldL8Q*+{}^ku#1 zK|Zh586T@YTitva>(8k`7}?@qRwTvI;U7)$42D!Ss}s$r#zoLt=mu{{awKYc`b(}T zPZv*RlEwv`U6H&d^MkX1b5_U6M|fZ(nr?7&atYZ8C*fFM_hmnQ>FZxy0 zx<((VMCm11bC2|g%Q0GJ2WO)`W8Qd9MbkcL+8>3LC(;4TP6bFEIrUIlY?MP<2E(sm zZj_uq;k|J^>uLBsEz_98^X{vt8>vd9_TaOt_!#>%ByKJl4F0C#Y%krwPmvJc^$evD zBWVMVLM>p++g?B=KS0%f2dsX)P6 zp2Hc+Z>Uddq+D{Ue9*>e#~}{;!+qUV#hDt=(kLyZz)8p(+0aw*QD?(NBOtyS)8S1m z_%}7^teUfplpX4nSnZh#XT^amkg8B>IVHAx#tY68&RKQDwQ zl{y(8PQsB^LsagU6}gmx*U)SB_ByuLQ&9=0X9wrZ=W%Qz7#3#DhUiC|qq^~TltDzJ zB^-#nPaLH=S=mp?(?`zA{43QrKD0=OTqOq3tXaW1YgZ^joP~K5ZWxX->BKD6G2j^1}}s4vxa-5$i(W;2mc4OfG88!< z-x2qWrSd+ASS8~ZXER?5bqbt{g?`dUY8|wi2MpR#_GFV<5L=x|vBkq#(T&t9Qq!lR zu%e+@o;;izQ^QQeqy^5(T(`$KI%i;T#)UCK7n~cV$&4+%F3h!R@xyjc`tA6WzjBbFpTQ(5EKi{$$va@ggV^J^yhO!R zyyQn56DL#cRBgsoy=cwQ{`Tz4}w~<+RJ(RN)O3Q_&mLk{!49@ zF2&c)0?x)Z_mv7Sm(22tym}Li(2S|aBhV1ct**S5o!VJwJZC{ zHF_g1#yH< zCe!22HOo!H0hxZlHqP|oZGdp)XU-8lrsLJ-}v3At`qRxq~&eI$8 zL;t7{%IR}|(OJM5jx?D1!kX9eBManxGrLU-Fg5kjs6}F%Y$nl@TJXs-7!^4!Q+}gB z=4Z@!9o{;1KN@u!KIi|Ctkwu{Kl3N;?w9VIoBzF%qbJvke&+e|IWw=K6iw!Wp%e$5 zIlj2LxQ$dXGPjadbdXFIL+2??#}KP&2~F2~yqw;O4w+M+=fOGu9qLuR@^N?H5C@k_ zF-E26E2STLe!X7z{{DSiyMAoc{ejR9uMnn%XxG4{IDOb`kyM3c;|oIhy&B8 z#BbYIE#ltzjYL6nO&nWXfqW3-=>z}9oxwRP339dmfqF6;c_K$`Ph2<+5@k6XJxOWQ z`uq3V{HGFkz`e>ii+{bY#tnN$O}PiS;d|7%uNGBd>T5mlp4vbali^Q+X*Krh9q~^j z%=`+rQxC1kbny9AMU~xh5j*wcznUHOUp@E>ncz4E{+2rzaSunwB|t_^nN~y#xVp?z zVPDu7H89YPw z?PGRu4nMJv#^NTGfF*v)lKEUd!8oS?$@uV`PSB6kn{k?3!FRQhzOI921X)?PUl~mN z_Uzzn1j8=b9_NeEuvY8W3;C8TJb4MM#&nU6(@tHoXF>rWNpa&4?1LYM zQVVEv!88QU$r5=sN)10A0*~R{wTI@=V%NxhV9WKAqa!IL-P=9kLPzbw6V^QE3a0JotG-#+3oUPdBnQVBCAsZux_)(};Bl7(;=@)U^b zK~9Eenn0)U4MK}1b7T(*#e^spu{#*55b)MBHIXSE8FP7pj)lH@bZ7M1+ zq}A%iyo5DglmIhb1=D2O;;2YULsI3#Tm7eY=T-C&$Kfxv@=B@mPlxk^#;)CB9rv6& z>!v!oH~eF(uVJLxUH)I&Nvn91@8UQenD#ifW}YO~Hb@xVnX{s#ncIe6I4}M|7l-3L z^Z|~-o+cO>)Hu~7O5tdfhq`Fn8G7&H=*D^D%mavCsV3tnwnb&>0G}J)!c%2aT|W+* zS&gH-2&ckP>p^4SH2Qow>l-|Q zksTM1^>JoLI0Ctw930ZT2j`ppR0FpuL-%;jSGUMs$HmgP7;!f13bbf80p6HBy>492 zI7oX{+psP!Sp6Y>19vGx(6SZwQ-NSgZ?TciDK9ncO3Q2N&&M}dWSl5ZkeCTN+xSdDKs6T%&t%7lQ~JT zHTCC}F)GJubM~HD^rJ6|UB}M=S!nMup%Oq$uj9g(9Dg9gmi_D>mf>HhL9@hPrBok_!{0r6?S@@ ze=lD*S+B#3^;3EcBZ9+#fEcB62L}#8{UNmtM@7SqmijX;_B>tgl9;Ez^b798nR7{Y zn4FxN;ILXs+}=g5i=K^M^j2icnL#qrts6>if!WxY8dJUpgy}e&IzPWb-Bps!)Q0zz zB+4!l>aAq)Sv5m5yqYSY*m@e>_`Uet5jva4;GC>FbtLH7!fbh>-*^KE`*DWeiTk4k z@Kb|xO`Hiu=^8|t98>wH>ztzqU>4`%>c-jN+gp*b8Tnx;jZkl+!w~6fz_@Da5$xju zRXwtnfPV9M&{V(BE16MDj@b2|))+C#G%4Oi_8VQF{XeGfY98f9%^MiE9l7Zq;Y?js z*HUW}%Xkej5GQ4NdLph4p3tTk;$(V8-c7I7GF;iWwVTSEDvImO&ghlQcjbFPv*4dG zR=(g7nj)Dzn)kIrDUQP@0MsexwAK-M!mCW}l3o7&4@^oyt$ ze{Lk`9p2Du7%%jFdYmsOpP`~Qp@NZF5*&@grO;U&1G&^adUT`*dPp>+?5RpSEBUxt z7Lk<>8yOrp-B1m6UFsY8e#&%l@N)85hApGUJ>Ega#xLh@vKH|XtD~t=3fTt6%CRvY zx}qK3i0g>E^Gv>&oJY&zpQuPpl+YoYBjZ=9Z$I4DboYSc92 znSN4UTy&(@;AkqH;D$Lq*okejK9x{epgCQ8=nTwp9p>tH6rOh$H8GkBO^@^CjDsqi zvWC<)aT^|f;~`RYqYBAN_`p;<=r7&n&frR&^_Xkzi-U`TIMWEAM_FNzm0%Zl9`1T#i9VVsYP5FM?$+(8{(Ovufiw$NVWof6;Pf} zpSV)Yg|R$EU&t&kF3t!2#@F=?=hJx&td2KJhMZYee1(LXl1P_&M`pX#fYdsnrV@gY zI3H({dXjA1Oe;riKE*SA;e7o@kyMyOgo}*xc+8*0792U>xH9^|t*Kt7rX*K}pL0Yr z`fBAeH%M3F1$z#|9p`%~xGF|wMUr#1D=RYFV#SPJot-#nUNG~iyh9XOr2?8_noLDc z1j#&8rNDWZm7S+gWahLt>+NVVHK#LCYI!8D0c90BSQ{1m9nA=rxehKH&X4MQOuqGz?;Ss` z?|!^J;#=MiD=%{wonLB>|LC$rNge`(zsudE)fyi z;uYe=?6vBSMr5Ucs7ayW$A?gKzM0#$%_Zs`eUue-dQ1eQ?y%PjuFHJ_5Br24Uu}Ll zamG=fTXvigtzyJKz`AG5(6Ltr(<^wH72z`Y2|7%><0WvLo*Nh3b!twY!Phf!l49Yr zZ;v^9^9UA?IkHmB->56L>JA6)Td-N2eqVoIpOVMD<;iy6)~NZuR*2gBqF&*3z2a#9 zu0o?4N8@|^d|uyz+o`*A9DR?D%phgli*h|mQD-?heeE8Yd+u6Im*WHVM>HAU7!6~Z zK)q> z2+>j&t|sDD#6>-ry687`$57w9TxoYQbDzEk_3U*qbFUtE4-FS)IK<=8E~ zac*CAKfPKX|1QFZQGGvDe&?=hxu@XdyEUF()ESfaQ%Y`4g;Sw`uZkvz$Ki4nv?Hsv z;+J`pxMS|Zs7>}R8&S!CIBn66K2sHyKhh)>R&G118Iun_tv#~Z_n7TIHwO23$B)^Uk)B!}-@$Rn#8p7z+hCdcGLCD*l_DS3IvQQp8&i>o{&|(oRGfpZI@Z#PeCWn@P^AH#q{8KmO{fq`Vo_cCx94(h|i-TfdwAp!P zXyqx%SX5N#hd4M3IO8#2oLO$Tz$-I=5Tgrfcd~14LT!TkrNXNIxC^h;lafv1Y}hRl zih#VI*GavD($jXHW>#=El4+;EyluAWGIdtv$oy>byR4Ptk{vbU7rlWsJ@+FD%4&=h zdV|M2NGeQ;t-+Y81ZS~hy*aWMb@p+(u~7>1xbFDpKk_b?4)A#^b-lZQc}|5^>zwu4 zKfd$VsIK|8emCk|bE|*aKhu3l=W6?Dd;RgdI9q*zRx**evqZF1I^c!hn5!NU2Vu=5 zK4;xgs;FFs%*C@fIeH9xNYLrr(I6^B&r^L)K6vmG9*y&P`MQJe;%sr2n}};%7H(r7 zR7E(kjf!Tig=4Bf&ZHWY7%x>lRFX2oVoXqDIgKq|8|R&?E$$`r>zsDhnIHUwN8`LQ zd^3DmuX?sPoHw6UEFj<~@e9iGi~f^%=y;Tz=ix@+OKI_(lh7x|t>YX;s(o_A