注⼊技术--远程代码注⼊
1.简介:
代码注⼊和远程线程注⼊dll类似,但是隐蔽性更好,因为不产⽣⽂件.但是可靠性差,更加复杂
代码注⼊时注⼊的代码部分是从本进程空间复制过去的,所以不能出现依赖于本进程的数据存在.
所以注⼊的代码中数据,地址都是动态⽣成的, 因此可以考虑将这些数据作为参数传递给注⼊的代码.
将代码和数据都注⼊到⽬标进程中
(注意,该代码要以release模式编译才能运⾏成功,因为debug模式的编译的结构的函数调⽤是个jmp,⽽不是直接调⽤) //声明需要⽤到的函数
typedef HMODULE(WINAPI *lpLoadLibraryA)(char* filename);
typedef FARPROC(WINAPI *lpGetProcAddress)(HMODULE hModule, char* funcName);
typedef int(WINAPI *lpMessageBoxA)(HWND hWnd, LPCSTR lpText, LPCSTR lpCaption, UINT uType);
typedef struct _thread_param
{
lpLoadLibraryA loadFunc;
lpGetProcAddress GetPFunc;
char data[4][100]; //保存所有参数
}thread_param;
DWORD WINAPI threadProc(LPVOID param)
{
thread_param* tparam = (thread_param*)param;
HMODULE hd = tparam->loadFunc(tparam->data[0]); //data的第⼀个item是user32.dll
lpMessageBoxA msg = (lpMessageBoxA)tparam->GetPFunc(hd, tparam->data[1]);//data的第2个参数是MessageBoxA
msg(0, tparam->data[2], tparam->data[3], 0);//data后2个参数是messagebox的参数
}
thread技术
DWORD codeInject(DWORD pid)
{
HANDLE hProcess = OpenProcess(PROCESS_ALL_ACCESS, 0, pid);
if (hProcess==0||hProcess==INVALID_HANDLE_VALUE)
{
return0;
}
thread_param param = { 0 };
param.loadFunc = (lpLoadLibraryA)GetProcAddress(GetModuleHandleA("kernel32.dll"), "LoadLibraryA");
param.GetPFunc = (lpGetProcAddress)GetProcAddress(GetModuleHandleA("kernel32.dll"), "GetProcAddress");
memcpy(¶m.data[0], "user32.dll", 11);
memcpy(¶m.data[1], "MessageBoxA", 12);
memcpy(¶m.data[2], "freesec", 8);
memcpy(¶m.data[3], "inject", 7);
DWORD codesize = (DWORD)codeInject - (DWORD)threadProc; //计算线程函数的代码⼤⼩
LPVOID database = VirtualAllocEx(hProcess, 0, sizeof(thread_param), MEM_COMMIT, PAGE_READWRITE);
DWORD written;
HANDLE hThread;
if (database==0)
{
CloseHandle(hProcess);
return0;
}
WriteProcessMemory(hProcess, database, ¶m, sizeof(thread_param), &written);
LPVOID codebase = VirtualAllocEx(hProcess, 0, codesize, MEM_COMMIT, PAGE_EXECUTE_READWRITE);
if (codebase == 0)
{
VirtualFreeEx(hProcess, database, sizeof(thread_param), MEM_FREE);
CloseHandle(hProcess);
return0;
}
WriteProcessMemory(hProcess, codebase, threadProc, codesize, &written);
if ((hThread=CreateRemoteThread(hProcess, 0, 0, (LPTHREAD_START_ROUTINE)codebase, database, 0, 0))!=0)
{
VirtualFreeEx(hProcess, database, sizeof(thread_param), MEM_FREE);
VirtualFreeEx(hProcess, codebase, codesize, MEM_FREE);
CloseHandle(hThread);
CloseHandle(hProcess);
return1;
}
VirtualFreeEx(hProcess, database, sizeof(thread_param), MEM_FREE);
VirtualFreeEx(hProcess, codebase, codesize, MEM_FREE);
CloseHandle(hProcess);
return0;
}

版权声明:本站内容均来自互联网,仅供演示用,请勿用于商业和其他非法用途。如果侵犯了您的权益请与我们联系QQ:729038198,我们将在24小时内删除。