青青草原综合久久大伊人导航_色综合久久天天综合_日日噜噜夜夜狠狠久久丁香五月_热久久这里只有精品

S.l.e!ep.¢%

像打了激速一樣,以四倍的速度運轉,開心的工作
簡單、開放、平等的公司文化;尊重個性、自由與個人價值;
posts - 1098, comments - 335, trackbacks - 0, articles - 1
  C++博客 :: 首頁 :: 新隨筆 :: 聯系 :: 聚合  :: 管理

SSDT原始地址,現在地址

Posted on 2009-10-26 13:45 S.l.e!ep.¢% 閱讀(1014) 評論(0)  編輯 收藏 引用 所屬分類: RootKit

#include <windows.h>

#include <winnt.h>

#include <WindowsX.h>

#include <commctrl.h>

#include <stdio.h>

#define ibaseDD *(PDWORD)&ibase

HINSTANCE g_hInst;

HWND hWinMain,hList;

#define ID_LISTVIEW 104

#pragma comment(lib,"comctl32")

typedef ULONG NTSTATUS;

#define RVATOVA(base,offset) ((PVOID)((DWORD)(base)+(DWORD)(offset)))

#define ibaseDD *(PDWORD)&ibase

#define STATUS_INFO_LENGTH_MISMATCH????? ((NTSTATUS)0xC0000004L)

#define NT_SUCCESS(Status) ((NTSTATUS)(Status) >= 0)

typedef struct {

??? WORD??? offset:12;

??? WORD??? type:4;

} IMAGE_FIXUP_ENTRY, *PIMAGE_FIXUP_ENTRY;

typedef ULONG (WINAPI *ZWQUERYSYSTEMINFORMATION)(

???????????? DWORD??? SystemInformationClass,

???????????? PVOID??? SystemInformation,

???????????? ULONG??? SystemInformationLength,

???????????? PULONG??? ReturnLength);

ZWQUERYSYSTEMINFORMATION ZwQuerySystemInformation = NULL;

typedef enum _SYSDBG_COMMAND {

// 以下是NT 5.1 新增的

??? //從內核空間拷貝到用戶空間,或者從用戶空間拷貝到用戶空間

??? //但是不能從用戶空間拷貝到內核空間???

SysDbgReadVirtualMemory = 8,

??

?? //從用戶空間拷貝到內核空間,或者從用戶空間拷貝到用戶空間

?? //但是不能從內核空間拷貝到用戶空間???

?? SysDbgWriteVirtualMemory = 9,

??

} SYSDBG_COMMAND, *PSYSDBG_COMMAND;

typedef struct _MEMORY_CHUNKS {

??? ULONG Address;

??? PVOID Data;

??? ULONG Length;

}MEMORY_CHUNKS, *PMEMORY_CHUNKS;

typedef NTSTATUS (NTAPI * ZWSYSTEMDEBUGCONTROL) (

???????????? SYSDBG_COMMAND ControlCode,

???????????? PVOID InputBuffer,

???????????? ULONG InputBufferLength,

???????????? PVOID OutputBuffer,

???????????? ULONG OutputBufferLength,

???????????? PULONG ReturnLength

???????????? );

ZWSYSTEMDEBUGCONTROL ZwSystemDebugControl = NULL;

typedef struct _SYSTEM_MODULE_INFORMATION { //Information Class 11

??? ULONG??? Reserved[2];

??? PVOID??? Base;

??? ULONG??? Size;

??? ULONG??? Flags;

??? USHORT??? Index;

??? USHORT??? Unknown;

??? USHORT??? LoadCount;

??? USHORT??? ModuleNameOffset;

??? CHAR??? ImageName[256];

}SYSTEM_MODULE_INFORMATION,*PSYSTEM_MODULE_INFORMATION;

#define??? SystemModuleInformation??? 11

typedef struct

{

CHAR fname[100];

ULONG address1;

ULONG address2;

} SSDT_LIST_ENTRY;

SSDT_LIST_ENTRY *ssdt_list;

/////////////////////////////////////////////////////////////////////////

BOOL LocateNtdllEntry()

{

HMODULE ntdll_dll?? = NULL;

if (!(ntdll_dll = GetModuleHandle("ntdll.dll"))) return FALSE;

if ( !( ZwQuerySystemInformation = (ZWQUERYSYSTEMINFORMATION)GetProcAddress(ntdll_dll, "ZwQuerySystemInformation" )))

?? return FALSE;

if ( !( ZwSystemDebugControl = (ZWSYSTEMDEBUGCONTROL)GetProcAddress(ntdll_dll, "ZwSystemDebugControl" )))

?? return FALSE;

return TRUE;

}

//////////////////////////////////////////////////////////////////////////

BOOL DebugPrivilege(TCHAR *PName,BOOL bEnable)

{

BOOL????????????? fOk = FALSE;

HANDLE??????????? hToken;

TOKEN_PRIVILEGES tp;

if(OpenProcessToken(GetCurrentProcess(),TOKEN_QUERY | TOKEN_ADJUST_PRIVILEGES,&hToken))

{

?? tp.PrivilegeCount?????????? = 1;

?? tp.Privileges[0].Attributes = bEnable ? SE_PRIVILEGE_ENABLED : 0;

?? LookupPrivilegeValue(NULL,PName,&tp.Privileges[0].Luid);

?? AdjustTokenPrivileges(hToken,FALSE,&tp,sizeof(TOKEN_PRIVILEGES),NULL,NULL);

?? fOk=(GetLastError() == ERROR_SUCCESS);

?? CloseHandle(hToken);

}

return fOk;

}

//////////////////////////////////////////////////////////////////////////

DWORD GetHeaders(PCHAR ibase,

???? PIMAGE_FILE_HEADER *pfh,

???? PIMAGE_OPTIONAL_HEADER *poh,

???? PIMAGE_SECTION_HEADER *psh)

????

{

PIMAGE_DOS_HEADER mzhead=(PIMAGE_DOS_HEADER)ibase;

if??? ((mzhead->e_magic!=IMAGE_DOS_SIGNATURE) ||

?? (ibaseDD[mzhead->e_lfanew]!=IMAGE_NT_SIGNATURE))

?? return FALSE;

*pfh=(PIMAGE_FILE_HEADER)&ibase[mzhead->e_lfanew];

if (((PIMAGE_NT_HEADERS)*pfh)->Signature!=IMAGE_NT_SIGNATURE)

?? return FALSE;

*pfh=(PIMAGE_FILE_HEADER)((PBYTE)*pfh+sizeof(IMAGE_NT_SIGNATURE));

*poh=(PIMAGE_OPTIONAL_HEADER)((PBYTE)*pfh+sizeof(IMAGE_FILE_HEADER));

if ((*poh)->Magic!=IMAGE_NT_OPTIONAL_HDR32_MAGIC)

?? return FALSE;

*psh=(PIMAGE_SECTION_HEADER)((PBYTE)*poh+sizeof(IMAGE_OPTIONAL_HEADER));

return TRUE;

}

//////////////////////////////////////////////////////////////////////////

// 搜索函數名稱

//////////////////////////////////////////////////////////////////////////

void FindExport()

{

PIMAGE_FILE_HEADER??? pfh;

PIMAGE_OPTIONAL_HEADER??? poh;

PIMAGE_SECTION_HEADER??? psh;

PIMAGE_EXPORT_DIRECTORY ped;

DWORD *arrayOfFunctionNames;

DWORD* arrayOfFunctionAddresses;

WORD* arrayOfFunctionOrdinals;

DWORD functionOrdinal,functionAddress;

HMODULE hNtdll=GetModuleHandle(TEXT("ntdll.dll"));

GetHeaders((PCHAR)hNtdll,&pfh,&poh,&psh);

if (poh->DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress)

{

?? ped=(PIMAGE_EXPORT_DIRECTORY)(poh->DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress+(BYTE*)hNtdll);

?? arrayOfFunctionNames=(DWORD*)(ped->AddressOfNames+(BYTE*)hNtdll);

?? arrayOfFunctionAddresses = (DWORD*)( (BYTE*)hNtdll + ped->AddressOfFunctions);

?? arrayOfFunctionNames = (DWORD*)( (BYTE*)hNtdll + ped->AddressOfNames);

?? arrayOfFunctionOrdinals = (WORD*)( (BYTE*)hNtdll + ped->AddressOfNameOrdinals);

??

?? for (int i=0;i<(int)(ped->NumberOfNames);i++)

?? {

??? char* fun_name= (char*)((BYTE*)hNtdll + arrayOfFunctionNames[i]);

??? functionOrdinal = arrayOfFunctionOrdinals[i] + ped->Base - 1;

??? functionAddress = (DWORD)( (BYTE*)hNtdll + arrayOfFunctionAddresses[functionOrdinal]);

??? if (fun_name[0]=='N'&&fun_name[1]=='t')

??? {

???? WORD number=*((WORD*)(functionAddress+1));

???? if (number>ped->NumberOfNames) continue;

???? lstrcpy(ssdt_list[number].fname,fun_name);

??? }

?? }

}

}

DWORD FindKiServiceTable(HMODULE hModule,DWORD dwKSDT)

{

??? PIMAGE_FILE_HEADER??? pfh;

??? PIMAGE_OPTIONAL_HEADER??? poh;

??? PIMAGE_SECTION_HEADER??? psh;

??? PIMAGE_BASE_RELOCATION??? pbr;

??? PIMAGE_FIXUP_ENTRY??? pfe;

???

??? DWORD??? dwFixups=0,i,dwPointerRva,dwPointsToRva,dwKiServiceTable;

??? BOOL??? bFirstChunk;

??? GetHeaders((PCHAR)hModule,&pfh,&poh,&psh);

??? // loop thru relocs to speed up the search

??? if ((poh->DataDirectory[IMAGE_DIRECTORY_ENTRY_BASERELOC].VirtualAddress) &&

??????? (!((pfh->Characteristics)&IMAGE_FILE_RELOCS_STRIPPED))) {

???????

??????? pbr=(PIMAGE_BASE_RELOCATION)RVATOVA(poh->DataDirectory[IMAGE_DIRECTORY_ENTRY_BASERELOC].VirtualAddress,hModule);

??

??????? bFirstChunk=TRUE;

??????? // 1st IMAGE_BASE_RELOCATION.VirtualAddress of ntoskrnl is 0

??????? while (bFirstChunk || pbr->VirtualAddress) {

??????????? bFirstChunk=FALSE;

???

??????????? pfe=(PIMAGE_FIXUP_ENTRY)((DWORD)pbr+sizeof(IMAGE_BASE_RELOCATION));

???

??????????? for (i=0;i<(pbr->SizeOfBlock-sizeof(IMAGE_BASE_RELOCATION))>>1;i++,pfe++) {

??????????????? if (pfe->type==IMAGE_REL_BASED_HIGHLOW) {

??????????????????? dwFixups++;

??????????????????? dwPointerRva=pbr->VirtualAddress+pfe->offset;

??????????????????? // DONT_RESOLVE_DLL_REFERENCES flag means relocs aren't fixed

??????????????????? dwPointsToRva=*(PDWORD)((DWORD)hModule+dwPointerRva)-(DWORD)poh->ImageBase;

?????

??????????????????? // does this reloc point to KeServiceDescriptorTable.Base?

??????????????????? if (dwPointsToRva==dwKSDT) {

??????????????????????? // check for mov [mem32],imm32. we are trying to find

??????????????????????? // "mov ds:_KeServiceDescriptorTable.Base, offset _KiServiceTable"

??????????????????????? // from the KiInitSystem.

??????????????????????? if (*(PWORD)((DWORD)hModule+dwPointerRva-2)==0x05c7) {

??????????????????????????? // should check for a reloc presence on KiServiceTable here

??????????????????????????? // but forget it

??????????????????????????? dwKiServiceTable=*(PDWORD)((DWORD)hModule+dwPointerRva+4)-poh->ImageBase;

??????????????????????????? return dwKiServiceTable;

??????????????????????? }

??????????????????? }

???????????????????

??????????????? }

???? // should never get here

??????????? }

??????????? *(PDWORD)&pbr+=pbr->SizeOfBlock;

??????? }

??? }???

???

??? return 0;

}

DWORD??? dwKSDT;??????????????? // rva of KeServiceDescriptorTable

DWORD??? dwKiServiceTable;??? // rva of KiServiceTable

DWORD??? dwKernelBase,dwServices=0;

//////////////////////////////////////////////////////////////////////////

void GetSSDT()

{????

??? HMODULE??? hKernel;

??? PCHAR??? pKernelName;

??? PDWORD??? pService;

??? PIMAGE_FILE_HEADER??? pfh;

??? PIMAGE_OPTIONAL_HEADER??? poh;

??? PIMAGE_SECTION_HEADER??? psh;

ULONG n;

??? // get system modules - ntoskrnl is always first there

??? ZwQuerySystemInformation(SystemModuleInformation,&n,0,&n);

PULONG p=new ULONG[n];

??? ZwQuerySystemInformation(SystemModuleInformation,p,n*sizeof(*p),0);

PSYSTEM_MODULE_INFORMATION module=PSYSTEM_MODULE_INFORMATION(p+1);

??? // imagebase

??? dwKernelBase=(DWORD)module->Base;

??? // filename - it may be renamed in the boot.ini

??? pKernelName=module->ModuleNameOffset+module->ImageName;

???

??? // map ntoskrnl - hopefully it has relocs

??? hKernel=LoadLibraryEx(pKernelName,0,DONT_RESOLVE_DLL_REFERENCES);

??? if (!hKernel) {

??????? return;

??? }

??? // our own export walker is useless here - we have GetProcAddress :)

??? if (!(dwKSDT=(DWORD)GetProcAddress(hKernel,"KeServiceDescriptorTable"))) {

??????? return;

??? }

??? // get KeServiceDescriptorTable rva

??? dwKSDT-=(DWORD)hKernel;

??? // find KiServiceTable

??? if (!(dwKiServiceTable=FindKiServiceTable(hKernel,dwKSDT))) {

??????? return;

??? }

??? // let's dump KiServiceTable contents

???

??? // MAY FAIL!!!

??? // should get right ServiceLimit here, but this is trivial in the kernel mode

??? GetHeaders((PCHAR)hKernel,&pfh,&poh,&psh);

??? dwServices=0;

??? for (pService=(PDWORD)((DWORD)hKernel+dwKiServiceTable);

*pService-poh->ImageBase<poh->SizeOfImage;

pService++,dwServices++)

{

?? ssdt_list[dwServices].address1=*pService-poh->ImageBase+dwKernelBase;

}

FreeLibrary(hKernel);

//讀取現在的

MEMORY_CHUNKS QueryBuff;

DWORD *address2=new DWORD[dwServices];

QueryBuff.Address = dwKernelBase+dwKiServiceTable;

QueryBuff.Data = address2;

QueryBuff.Length = sizeof(DWORD)*dwServices;

DWORD ReturnLength;

ZwSystemDebugControl

?? (

?? SysDbgReadVirtualMemory,

?? &QueryBuff,

?? sizeof(MEMORY_CHUNKS),

?? NULL,

?? 0,

?? &ReturnLength

?? );

LV_ITEM lvi;

lvi.mask = LVIF_TEXT;

char tmp[10];

ListView_DeleteAllItems(hList);

for (int j=0;j<(int)dwServices;j++)

{

?? lvi.iItem=j;

?? lvi.iSubItem=0;

?? lvi.pszText=tmp;

?? wsprintf(tmp,"0x%02X",j);

?? ListView_InsertItem(hList,&lvi);

?? ListView_SetItemText(hList,j,1,ssdt_list[j].fname);

?? wsprintf(tmp,"0x%08X",ssdt_list[j].address1);

?? ListView_SetItemText(hList,j,2,tmp);

?? wsprintf(tmp,"0x%08X",address2[j]);

?? ssdt_list[j].address2=address2[j];

?? ListView_SetItemText(hList,j,3,tmp);

??

?? //搜索模塊

?? for (int i=0;i<(int)*p;i++)

?? {

??? if (ssdt_list[j].address2 > ( DWORD)module[i].Base&&ssdt_list[j].address2 < (DWORD)module[i].Base + module[i].Size )

??? {

???? ListView_SetItemText(hList,j,4,module[i].ImageName);

???? break;

??? }

?? }

}

???

delete [] p;

delete [] address2;

}

int main()

{

ssdt_list=new SSDT_LIST_ENTRY[500];

LocateNtdllEntry();

FindExport();

DebugPrivilege (SE_DEBUG_NAME,TRUE);

GetSSDT();

//恢復SSDT

DWORD *address1=new DWORD[dwServices];

for (int i=0;i<(int)dwServices;i++)

{

?? //address1[i]=ssdt_list[i].address1;

?? printf("原始地址:0x%08X,現在地址:0x%08X,SSDTName=%s\n",ssdt_list[i].address1,ssdt_list[i].address2,ssdt_list[i].fname);

}

MEMORY_CHUNKS QueryBuff;

QueryBuff.Address=dwKiServiceTable+dwKernelBase;

QueryBuff.Data=address1;

QueryBuff.Length=dwServices*sizeof(DWORD);

DWORD ReturnLength;

ZwSystemDebugControl

?? (

?? SysDbgWriteVirtualMemory,

?? &QueryBuff,

?? sizeof(MEMORY_CHUNKS),

?? NULL,

?? 0,

?? &ReturnLength

?? );

printf("恢復SSDT成功!\n");

// system("pause");

return 0;

}

青青草原综合久久大伊人导航_色综合久久天天综合_日日噜噜夜夜狠狠久久丁香五月_热久久这里只有精品
  • <ins id="pjuwb"></ins>
    <blockquote id="pjuwb"><pre id="pjuwb"></pre></blockquote>
    <noscript id="pjuwb"></noscript>
          <sup id="pjuwb"><pre id="pjuwb"></pre></sup>
            <dd id="pjuwb"></dd>
            <abbr id="pjuwb"></abbr>
            99精品视频免费全部在线| 噜噜爱69成人精品| 免费在线欧美视频| 狼人天天伊人久久| 男人的天堂亚洲| 欧美国产日韩视频| 亚洲精品欧美日韩专区| 一区二区高清在线观看| 亚洲视频在线观看| 欧美一区二区播放| 美女精品在线观看| 欧美日韩在线播放| 国产一区高清视频| 亚洲黄页一区| 欧美一激情一区二区三区| 久久久久综合| 亚洲精品中文在线| 久久成人18免费观看| 欧美激情二区三区| 国产日本欧美一区二区| 亚洲国产裸拍裸体视频在线观看乱了| 亚洲精品1区2区| 久久成人人人人精品欧| 亚洲国产欧美日韩另类综合| 欧美高清视频免费观看| 亚洲手机在线| 欧美黄色免费| 国产亚洲在线| 亚洲永久免费av| 亚洲国产高清一区| 久久av资源网站| 国产精品久久久一区麻豆最新章节| 好看不卡的中文字幕| 亚洲综合视频网| 最新中文字幕一区二区三区| 欧美一区二区啪啪| 欧美午夜视频一区二区| 亚洲激情视频在线播放| 久久亚洲一区二区| 午夜精品www| 国产精品国产三级国产aⅴ入口| 最新日韩在线| 久久深夜福利免费观看| 亚洲综合色噜噜狠狠| 欧美日韩亚洲视频| 最新中文字幕亚洲| 欧美成人免费网站| 久久久国产91| 国产一区二区在线观看免费播放| 亚洲午夜免费视频| 亚洲卡通欧美制服中文| 免费国产一区二区| 亚洲电影毛片| 久热精品在线视频| 亚洲在线观看| 99精品欧美一区二区三区综合在线 | 亚洲欧美区自拍先锋| 亚洲精选中文字幕| 欧美精品激情| 99在线精品免费视频九九视| 亚洲国产老妈| 欧美高清视频在线| 99这里只有精品| 91久久在线播放| 欧美女主播在线| 一区二区欧美激情| 亚洲色在线视频| 国产精品一区二区在线| 欧美一区二区三区久久精品茉莉花| 亚洲一级一区| 国产一区二区三区自拍 | 亚洲欧美第一页| 国产精品99久久久久久人| 国产精品久久久久久久久久直播| 亚洲欧美综合国产精品一区| 亚洲一区二区久久| 国内精品久久久久久影视8| 免费久久精品视频| 欧美日韩大片| 久久国产加勒比精品无码| 麻豆freexxxx性91精品| 亚洲天堂av高清| 欧美一区影院| 亚洲免费成人av电影| 亚洲午夜黄色| 一区免费观看视频| 亚洲精品一区二区三区四区高清| 国产精品久久久久久久久果冻传媒| 香蕉久久夜色精品国产使用方法| 欧美一区二区视频在线观看2020| 伊人婷婷久久| 日韩一级精品视频在线观看| 国产区二精品视| 亚洲大胆视频| 国产精品综合不卡av| 欧美国产日韩精品免费观看| 欧美性猛交视频| 牛人盗摄一区二区三区视频| 国产精品成人一区二区艾草| 免费视频久久| 国产精品视频专区| 欧美国产欧美亚洲国产日韩mv天天看完整 | 亚洲第一精品影视| 一区二区国产日产| 在线看视频不卡| 久久精品国产免费| 欧美高清日韩| 国产亚洲精品成人av久久ww| 91久久精品日日躁夜夜躁国产| 国产精品一区视频| 亚洲精品久久视频| 一区二区三区在线观看视频| 亚洲视频精选| 夜夜嗨av一区二区三区网页| 久久成人在线| 午夜免费电影一区在线观看| 欧美黄免费看| 欧美国产成人在线| 国产一区二区久久久| 亚洲一二三区在线| 一本一道久久综合狠狠老精东影业 | 亚洲理论在线观看| 久久久久久一区二区三区| 欧美亚洲综合网| 国产精品护士白丝一区av| 亚洲日本va午夜在线电影| 亚洲第一精品电影| 久久久久久国产精品一区| 欧美亚洲免费| 国产精品久久久久久妇女6080 | 永久免费精品影视网站| 亚洲欧美色婷婷| 午夜精品视频在线| 国产精品久久久久久久久动漫| 亚洲日本激情| 一本久久a久久免费精品不卡| 另类专区欧美制服同性| 久久久久欧美| 精品99视频| 久久女同互慰一区二区三区| 久久综合网络一区二区| 韩国女主播一区| 久久久久国产一区二区三区四区 | 亚洲一区二区三区中文字幕在线| 欧美极品在线观看| 亚洲三级毛片| 亚洲图片欧洲图片av| 欧美午夜精品久久久久久久| 一区二区高清视频在线观看| 亚洲欧美视频在线观看| 国产精自产拍久久久久久蜜| 午夜精品久久久久久久99水蜜桃 | 亚洲欧美日韩精品久久亚洲区| 欧美亚洲自偷自偷| 亚洲在线一区| 黄色成人片子| 另类专区欧美制服同性| 亚洲激情成人网| 亚洲小说欧美另类社区| 国产精品视频在线观看| 久久久久久久成人| 亚洲精品日本| 久久精品免费观看| 亚洲国产精品久久精品怡红院| 欧美成人自拍| 亚洲在线视频一区| 欧美成人综合一区| 亚洲一区日韩在线| 在线观看日韩av先锋影音电影院| 欧美精品性视频| 欧美一区二区免费视频| 亚洲激情视频在线播放| 久久成人精品电影| 9国产精品视频| 国产综合色产在线精品| 欧美日韩亚洲成人| 久久亚洲综合| 亚洲欧美日韩中文播放| 亚洲另类自拍| 欧美 日韩 国产 一区| 亚洲综合日韩在线| 亚洲精品视频在线看| 国产亚洲精品成人av久久ww| 欧美另类人妖| 久久久综合香蕉尹人综合网| 一本大道久久a久久综合婷婷| 久久综合伊人| 欧美一区二区三区四区高清| 日韩一区二区精品视频| 在线观看日韩欧美| 国产亚洲一区二区在线观看| 欧美性感一类影片在线播放| 欧美二区在线观看| 久久午夜电影网| 欧美中文字幕在线视频| 亚洲欧美国产毛片在线| 在线视频精品一区| 日韩一区二区精品在线观看| 亚洲高清在线| 亚洲国产日韩美|