青青草原综合久久大伊人导航_色综合久久天天综合_日日噜噜夜夜狠狠久久丁香五月_热久久这里只有精品

S.l.e!ep.¢%

像打了激速一樣,以四倍的速度運轉,開心的工作
簡單、開放、平等的公司文化;尊重個性、自由與個人價值;
posts - 1098, comments - 335, trackbacks - 0, articles - 1
  C++博客 :: 首頁 :: 新隨筆 :: 聯系 :: 聚合  :: 管理

SSDT原始地址,現在地址

Posted on 2009-10-26 13:45 S.l.e!ep.¢% 閱讀(1014) 評論(0)  編輯 收藏 引用 所屬分類: RootKit

#include <windows.h>

#include <winnt.h>

#include <WindowsX.h>

#include <commctrl.h>

#include <stdio.h>

#define ibaseDD *(PDWORD)&ibase

HINSTANCE g_hInst;

HWND hWinMain,hList;

#define ID_LISTVIEW 104

#pragma comment(lib,"comctl32")

typedef ULONG NTSTATUS;

#define RVATOVA(base,offset) ((PVOID)((DWORD)(base)+(DWORD)(offset)))

#define ibaseDD *(PDWORD)&ibase

#define STATUS_INFO_LENGTH_MISMATCH????? ((NTSTATUS)0xC0000004L)

#define NT_SUCCESS(Status) ((NTSTATUS)(Status) >= 0)

typedef struct {

??? WORD??? offset:12;

??? WORD??? type:4;

} IMAGE_FIXUP_ENTRY, *PIMAGE_FIXUP_ENTRY;

typedef ULONG (WINAPI *ZWQUERYSYSTEMINFORMATION)(

???????????? DWORD??? SystemInformationClass,

???????????? PVOID??? SystemInformation,

???????????? ULONG??? SystemInformationLength,

???????????? PULONG??? ReturnLength);

ZWQUERYSYSTEMINFORMATION ZwQuerySystemInformation = NULL;

typedef enum _SYSDBG_COMMAND {

// 以下是NT 5.1 新增的

??? //從內核空間拷貝到用戶空間,或者從用戶空間拷貝到用戶空間

??? //但是不能從用戶空間拷貝到內核空間???

SysDbgReadVirtualMemory = 8,

??

?? //從用戶空間拷貝到內核空間,或者從用戶空間拷貝到用戶空間

?? //但是不能從內核空間拷貝到用戶空間???

?? SysDbgWriteVirtualMemory = 9,

??

} SYSDBG_COMMAND, *PSYSDBG_COMMAND;

typedef struct _MEMORY_CHUNKS {

??? ULONG Address;

??? PVOID Data;

??? ULONG Length;

}MEMORY_CHUNKS, *PMEMORY_CHUNKS;

typedef NTSTATUS (NTAPI * ZWSYSTEMDEBUGCONTROL) (

???????????? SYSDBG_COMMAND ControlCode,

???????????? PVOID InputBuffer,

???????????? ULONG InputBufferLength,

???????????? PVOID OutputBuffer,

???????????? ULONG OutputBufferLength,

???????????? PULONG ReturnLength

???????????? );

ZWSYSTEMDEBUGCONTROL ZwSystemDebugControl = NULL;

typedef struct _SYSTEM_MODULE_INFORMATION { //Information Class 11

??? ULONG??? Reserved[2];

??? PVOID??? Base;

??? ULONG??? Size;

??? ULONG??? Flags;

??? USHORT??? Index;

??? USHORT??? Unknown;

??? USHORT??? LoadCount;

??? USHORT??? ModuleNameOffset;

??? CHAR??? ImageName[256];

}SYSTEM_MODULE_INFORMATION,*PSYSTEM_MODULE_INFORMATION;

#define??? SystemModuleInformation??? 11

typedef struct

{

CHAR fname[100];

ULONG address1;

ULONG address2;

} SSDT_LIST_ENTRY;

SSDT_LIST_ENTRY *ssdt_list;

/////////////////////////////////////////////////////////////////////////

BOOL LocateNtdllEntry()

{

HMODULE ntdll_dll?? = NULL;

if (!(ntdll_dll = GetModuleHandle("ntdll.dll"))) return FALSE;

if ( !( ZwQuerySystemInformation = (ZWQUERYSYSTEMINFORMATION)GetProcAddress(ntdll_dll, "ZwQuerySystemInformation" )))

?? return FALSE;

if ( !( ZwSystemDebugControl = (ZWSYSTEMDEBUGCONTROL)GetProcAddress(ntdll_dll, "ZwSystemDebugControl" )))

?? return FALSE;

return TRUE;

}

//////////////////////////////////////////////////////////////////////////

BOOL DebugPrivilege(TCHAR *PName,BOOL bEnable)

{

BOOL????????????? fOk = FALSE;

HANDLE??????????? hToken;

TOKEN_PRIVILEGES tp;

if(OpenProcessToken(GetCurrentProcess(),TOKEN_QUERY | TOKEN_ADJUST_PRIVILEGES,&hToken))

{

?? tp.PrivilegeCount?????????? = 1;

?? tp.Privileges[0].Attributes = bEnable ? SE_PRIVILEGE_ENABLED : 0;

?? LookupPrivilegeValue(NULL,PName,&tp.Privileges[0].Luid);

?? AdjustTokenPrivileges(hToken,FALSE,&tp,sizeof(TOKEN_PRIVILEGES),NULL,NULL);

?? fOk=(GetLastError() == ERROR_SUCCESS);

?? CloseHandle(hToken);

}

return fOk;

}

//////////////////////////////////////////////////////////////////////////

DWORD GetHeaders(PCHAR ibase,

???? PIMAGE_FILE_HEADER *pfh,

???? PIMAGE_OPTIONAL_HEADER *poh,

???? PIMAGE_SECTION_HEADER *psh)

????

{

PIMAGE_DOS_HEADER mzhead=(PIMAGE_DOS_HEADER)ibase;

if??? ((mzhead->e_magic!=IMAGE_DOS_SIGNATURE) ||

?? (ibaseDD[mzhead->e_lfanew]!=IMAGE_NT_SIGNATURE))

?? return FALSE;

*pfh=(PIMAGE_FILE_HEADER)&ibase[mzhead->e_lfanew];

if (((PIMAGE_NT_HEADERS)*pfh)->Signature!=IMAGE_NT_SIGNATURE)

?? return FALSE;

*pfh=(PIMAGE_FILE_HEADER)((PBYTE)*pfh+sizeof(IMAGE_NT_SIGNATURE));

*poh=(PIMAGE_OPTIONAL_HEADER)((PBYTE)*pfh+sizeof(IMAGE_FILE_HEADER));

if ((*poh)->Magic!=IMAGE_NT_OPTIONAL_HDR32_MAGIC)

?? return FALSE;

*psh=(PIMAGE_SECTION_HEADER)((PBYTE)*poh+sizeof(IMAGE_OPTIONAL_HEADER));

return TRUE;

}

//////////////////////////////////////////////////////////////////////////

// 搜索函數名稱

//////////////////////////////////////////////////////////////////////////

void FindExport()

{

PIMAGE_FILE_HEADER??? pfh;

PIMAGE_OPTIONAL_HEADER??? poh;

PIMAGE_SECTION_HEADER??? psh;

PIMAGE_EXPORT_DIRECTORY ped;

DWORD *arrayOfFunctionNames;

DWORD* arrayOfFunctionAddresses;

WORD* arrayOfFunctionOrdinals;

DWORD functionOrdinal,functionAddress;

HMODULE hNtdll=GetModuleHandle(TEXT("ntdll.dll"));

GetHeaders((PCHAR)hNtdll,&pfh,&poh,&psh);

if (poh->DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress)

{

?? ped=(PIMAGE_EXPORT_DIRECTORY)(poh->DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress+(BYTE*)hNtdll);

?? arrayOfFunctionNames=(DWORD*)(ped->AddressOfNames+(BYTE*)hNtdll);

?? arrayOfFunctionAddresses = (DWORD*)( (BYTE*)hNtdll + ped->AddressOfFunctions);

?? arrayOfFunctionNames = (DWORD*)( (BYTE*)hNtdll + ped->AddressOfNames);

?? arrayOfFunctionOrdinals = (WORD*)( (BYTE*)hNtdll + ped->AddressOfNameOrdinals);

??

?? for (int i=0;i<(int)(ped->NumberOfNames);i++)

?? {

??? char* fun_name= (char*)((BYTE*)hNtdll + arrayOfFunctionNames[i]);

??? functionOrdinal = arrayOfFunctionOrdinals[i] + ped->Base - 1;

??? functionAddress = (DWORD)( (BYTE*)hNtdll + arrayOfFunctionAddresses[functionOrdinal]);

??? if (fun_name[0]=='N'&&fun_name[1]=='t')

??? {

???? WORD number=*((WORD*)(functionAddress+1));

???? if (number>ped->NumberOfNames) continue;

???? lstrcpy(ssdt_list[number].fname,fun_name);

??? }

?? }

}

}

DWORD FindKiServiceTable(HMODULE hModule,DWORD dwKSDT)

{

??? PIMAGE_FILE_HEADER??? pfh;

??? PIMAGE_OPTIONAL_HEADER??? poh;

??? PIMAGE_SECTION_HEADER??? psh;

??? PIMAGE_BASE_RELOCATION??? pbr;

??? PIMAGE_FIXUP_ENTRY??? pfe;

???

??? DWORD??? dwFixups=0,i,dwPointerRva,dwPointsToRva,dwKiServiceTable;

??? BOOL??? bFirstChunk;

??? GetHeaders((PCHAR)hModule,&pfh,&poh,&psh);

??? // loop thru relocs to speed up the search

??? if ((poh->DataDirectory[IMAGE_DIRECTORY_ENTRY_BASERELOC].VirtualAddress) &&

??????? (!((pfh->Characteristics)&IMAGE_FILE_RELOCS_STRIPPED))) {

???????

??????? pbr=(PIMAGE_BASE_RELOCATION)RVATOVA(poh->DataDirectory[IMAGE_DIRECTORY_ENTRY_BASERELOC].VirtualAddress,hModule);

??

??????? bFirstChunk=TRUE;

??????? // 1st IMAGE_BASE_RELOCATION.VirtualAddress of ntoskrnl is 0

??????? while (bFirstChunk || pbr->VirtualAddress) {

??????????? bFirstChunk=FALSE;

???

??????????? pfe=(PIMAGE_FIXUP_ENTRY)((DWORD)pbr+sizeof(IMAGE_BASE_RELOCATION));

???

??????????? for (i=0;i<(pbr->SizeOfBlock-sizeof(IMAGE_BASE_RELOCATION))>>1;i++,pfe++) {

??????????????? if (pfe->type==IMAGE_REL_BASED_HIGHLOW) {

??????????????????? dwFixups++;

??????????????????? dwPointerRva=pbr->VirtualAddress+pfe->offset;

??????????????????? // DONT_RESOLVE_DLL_REFERENCES flag means relocs aren't fixed

??????????????????? dwPointsToRva=*(PDWORD)((DWORD)hModule+dwPointerRva)-(DWORD)poh->ImageBase;

?????

??????????????????? // does this reloc point to KeServiceDescriptorTable.Base?

??????????????????? if (dwPointsToRva==dwKSDT) {

??????????????????????? // check for mov [mem32],imm32. we are trying to find

??????????????????????? // "mov ds:_KeServiceDescriptorTable.Base, offset _KiServiceTable"

??????????????????????? // from the KiInitSystem.

??????????????????????? if (*(PWORD)((DWORD)hModule+dwPointerRva-2)==0x05c7) {

??????????????????????????? // should check for a reloc presence on KiServiceTable here

??????????????????????????? // but forget it

??????????????????????????? dwKiServiceTable=*(PDWORD)((DWORD)hModule+dwPointerRva+4)-poh->ImageBase;

??????????????????????????? return dwKiServiceTable;

??????????????????????? }

??????????????????? }

???????????????????

??????????????? }

???? // should never get here

??????????? }

??????????? *(PDWORD)&pbr+=pbr->SizeOfBlock;

??????? }

??? }???

???

??? return 0;

}

DWORD??? dwKSDT;??????????????? // rva of KeServiceDescriptorTable

DWORD??? dwKiServiceTable;??? // rva of KiServiceTable

DWORD??? dwKernelBase,dwServices=0;

//////////////////////////////////////////////////////////////////////////

void GetSSDT()

{????

??? HMODULE??? hKernel;

??? PCHAR??? pKernelName;

??? PDWORD??? pService;

??? PIMAGE_FILE_HEADER??? pfh;

??? PIMAGE_OPTIONAL_HEADER??? poh;

??? PIMAGE_SECTION_HEADER??? psh;

ULONG n;

??? // get system modules - ntoskrnl is always first there

??? ZwQuerySystemInformation(SystemModuleInformation,&n,0,&n);

PULONG p=new ULONG[n];

??? ZwQuerySystemInformation(SystemModuleInformation,p,n*sizeof(*p),0);

PSYSTEM_MODULE_INFORMATION module=PSYSTEM_MODULE_INFORMATION(p+1);

??? // imagebase

??? dwKernelBase=(DWORD)module->Base;

??? // filename - it may be renamed in the boot.ini

??? pKernelName=module->ModuleNameOffset+module->ImageName;

???

??? // map ntoskrnl - hopefully it has relocs

??? hKernel=LoadLibraryEx(pKernelName,0,DONT_RESOLVE_DLL_REFERENCES);

??? if (!hKernel) {

??????? return;

??? }

??? // our own export walker is useless here - we have GetProcAddress :)

??? if (!(dwKSDT=(DWORD)GetProcAddress(hKernel,"KeServiceDescriptorTable"))) {

??????? return;

??? }

??? // get KeServiceDescriptorTable rva

??? dwKSDT-=(DWORD)hKernel;

??? // find KiServiceTable

??? if (!(dwKiServiceTable=FindKiServiceTable(hKernel,dwKSDT))) {

??????? return;

??? }

??? // let's dump KiServiceTable contents

???

??? // MAY FAIL!!!

??? // should get right ServiceLimit here, but this is trivial in the kernel mode

??? GetHeaders((PCHAR)hKernel,&pfh,&poh,&psh);

??? dwServices=0;

??? for (pService=(PDWORD)((DWORD)hKernel+dwKiServiceTable);

*pService-poh->ImageBase<poh->SizeOfImage;

pService++,dwServices++)

{

?? ssdt_list[dwServices].address1=*pService-poh->ImageBase+dwKernelBase;

}

FreeLibrary(hKernel);

//讀取現在的

MEMORY_CHUNKS QueryBuff;

DWORD *address2=new DWORD[dwServices];

QueryBuff.Address = dwKernelBase+dwKiServiceTable;

QueryBuff.Data = address2;

QueryBuff.Length = sizeof(DWORD)*dwServices;

DWORD ReturnLength;

ZwSystemDebugControl

?? (

?? SysDbgReadVirtualMemory,

?? &QueryBuff,

?? sizeof(MEMORY_CHUNKS),

?? NULL,

?? 0,

?? &ReturnLength

?? );

LV_ITEM lvi;

lvi.mask = LVIF_TEXT;

char tmp[10];

ListView_DeleteAllItems(hList);

for (int j=0;j<(int)dwServices;j++)

{

?? lvi.iItem=j;

?? lvi.iSubItem=0;

?? lvi.pszText=tmp;

?? wsprintf(tmp,"0x%02X",j);

?? ListView_InsertItem(hList,&lvi);

?? ListView_SetItemText(hList,j,1,ssdt_list[j].fname);

?? wsprintf(tmp,"0x%08X",ssdt_list[j].address1);

?? ListView_SetItemText(hList,j,2,tmp);

?? wsprintf(tmp,"0x%08X",address2[j]);

?? ssdt_list[j].address2=address2[j];

?? ListView_SetItemText(hList,j,3,tmp);

??

?? //搜索模塊

?? for (int i=0;i<(int)*p;i++)

?? {

??? if (ssdt_list[j].address2 > ( DWORD)module[i].Base&&ssdt_list[j].address2 < (DWORD)module[i].Base + module[i].Size )

??? {

???? ListView_SetItemText(hList,j,4,module[i].ImageName);

???? break;

??? }

?? }

}

???

delete [] p;

delete [] address2;

}

int main()

{

ssdt_list=new SSDT_LIST_ENTRY[500];

LocateNtdllEntry();

FindExport();

DebugPrivilege (SE_DEBUG_NAME,TRUE);

GetSSDT();

//恢復SSDT

DWORD *address1=new DWORD[dwServices];

for (int i=0;i<(int)dwServices;i++)

{

?? //address1[i]=ssdt_list[i].address1;

?? printf("原始地址:0x%08X,現在地址:0x%08X,SSDTName=%s\n",ssdt_list[i].address1,ssdt_list[i].address2,ssdt_list[i].fname);

}

MEMORY_CHUNKS QueryBuff;

QueryBuff.Address=dwKiServiceTable+dwKernelBase;

QueryBuff.Data=address1;

QueryBuff.Length=dwServices*sizeof(DWORD);

DWORD ReturnLength;

ZwSystemDebugControl

?? (

?? SysDbgWriteVirtualMemory,

?? &QueryBuff,

?? sizeof(MEMORY_CHUNKS),

?? NULL,

?? 0,

?? &ReturnLength

?? );

printf("恢復SSDT成功!\n");

// system("pause");

return 0;

}

青青草原综合久久大伊人导航_色综合久久天天综合_日日噜噜夜夜狠狠久久丁香五月_热久久这里只有精品
  • <ins id="pjuwb"></ins>
    <blockquote id="pjuwb"><pre id="pjuwb"></pre></blockquote>
    <noscript id="pjuwb"></noscript>
          <sup id="pjuwb"><pre id="pjuwb"></pre></sup>
            <dd id="pjuwb"></dd>
            <abbr id="pjuwb"></abbr>
            中国亚洲黄色| 欧美成人三级在线| 免费欧美电影| 亚洲视频网站在线观看| 亚洲乱码久久| 亚洲精选国产| 亚洲一品av免费观看| 一区二区欧美精品| 亚洲一区二区欧美| 亚洲主播在线| 一区二区日韩欧美| 一区二区av在线| 一区二区三区产品免费精品久久75 | 欧美激情第五页| 免费看亚洲片| 欧美电影免费观看大全| 亚洲一区在线免费观看| 亚洲一区日本| 久久久国产91| 欧美激情在线狂野欧美精品| 欧美成人综合| 99re亚洲国产精品| 亚洲精品一区在线| 亚洲欧洲一区二区三区在线观看| 欧美国产综合| 久久不射网站| 欧美日韩亚洲系列| 亚洲第一精品电影| 欧美在线播放一区二区| 亚洲高清中文字幕| 午夜精品久久久久久久久久久| 老司机午夜精品视频| 卡一卡二国产精品| 蜜臀va亚洲va欧美va天堂| 一本在线高清不卡dvd | 日韩视频免费| 久久久亚洲综合| 欧美一区二区大片| 国产精品一区二区久久久久| 一区二区精品在线观看| 欧美成人影音| 久久在精品线影院精品国产| 国产精品美女久久久浪潮软件| 国产婷婷色一区二区三区| 亚洲视频一区在线| 免费影视亚洲| 久久人人看视频| 伊人色综合久久天天五月婷| 久久色中文字幕| 久久夜色精品国产噜噜av| 在线观看欧美黄色| 亚洲精品日韩激情在线电影| 欧美日韩不卡在线| 久久精品国产欧美亚洲人人爽| 亚洲精品一区二区三区不| 久久久999精品视频| 久久久欧美精品| 亚洲精品久久久久中文字幕欢迎你| 欧美好骚综合网| 国产精品99一区二区| 欧美亚洲一区| 欧美精品一卡| 欧美专区18| 欧美日韩国产成人高清视频| 欧美中文字幕不卡| 欧美日韩免费高清一区色橹橹| 久久精品亚洲精品| 国产精品美女一区二区| 欧美91精品| 国产精品最新自拍| 国产精品视频大全| av成人动漫| 亚洲无亚洲人成网站77777| 久久久99爱| 久久久蜜桃一区二区人| 国产美女精品| 亚洲欧美国产不卡| 欧美一级淫片aaaaaaa视频| 欧美成人精品在线播放| 久久夜色精品国产噜噜av| 国产区在线观看成人精品| 中国亚洲黄色| 欧美亚洲色图校园春色| 国产日产欧美一区| 性欧美xxxx视频在线观看| 久久国产综合精品| 影音先锋久久久| 欧美成人在线网站| 一区二区精品国产| 欧美自拍偷拍| 亚洲国产另类 国产精品国产免费| 亚洲欧美国内爽妇网| 国产欧美亚洲视频| 久久久久一区二区三区| 欧美激情精品久久久久久免费印度| 国内精品一区二区三区| 欧美精品一区二区视频| 亚洲曰本av电影| 欧美激情视频在线免费观看 欧美视频免费一 | 亚洲精品久久久蜜桃| 欧美日韩一区在线视频| 欧美一区二区三区免费在线看| 女同性一区二区三区人了人一| 亚洲免费观看高清在线观看| 欧美激情亚洲综合一区| 欧美一区二区三区播放老司机 | 亚洲视频第一页| 精品91久久久久| 亚洲午夜一区| 91久久香蕉国产日韩欧美9色| 中国成人亚色综合网站| 亚洲人成毛片在线播放女女| 亚洲免费网址| 夜夜爽www精品| 欧美国产免费| 久久九九有精品国产23| 亚洲欧美国产高清| 亚洲精品视频免费在线观看| 99国产精品视频免费观看| 国产一区二区三区四区hd| 亚洲免费精品| 亚洲国产成人tv| 性一交一乱一区二区洋洋av| 一区二区av在线| 久久免费视频在线观看| 亚洲影院色在线观看免费| 欧美高清视频在线播放| 日韩系列在线| 黄色资源网久久资源365| 亚洲尤物在线| 亚洲欧美激情精品一区二区| 欧美激情精品久久久久久大尺度 | 久久精品99国产精品| 亚洲一区二区三区高清| 美女诱惑一区| 欧美成人免费全部| 极品av少妇一区二区| 欧美尤物一区| 久久精品欧美| 狠狠狠色丁香婷婷综合久久五月| 欧美一级视频一区二区| 久久成人免费视频| 国产日韩欧美在线视频观看| 午夜一区在线| 久久综合图片| 1024成人网色www| 麻豆av一区二区三区久久| 欧美不卡视频一区| 亚洲国产另类 国产精品国产免费| 美女在线一区二区| 亚洲精品综合在线| 亚洲免费综合| 国产视频在线一区二区| 久久久亚洲一区| 亚洲激情影院| 99一区二区| 国产精品一区二区久久| 欧美在线亚洲一区| 欧美日韩大陆在线| 久久深夜福利免费观看| 亚洲国产精品美女| 欧美精品 国产精品| 在线亚洲自拍| 久久视频在线免费观看| 亚洲欧洲在线一区| 欧美丝袜第一区| 久久精品国产亚洲一区二区| 欧美激情在线观看| 欧美日韩视频在线| 亚洲一区自拍| 美女精品在线观看| 在线中文字幕不卡| 韩日精品视频| 欧美色道久久88综合亚洲精品| 久久激情五月激情| 亚洲国产精选| 性欧美暴力猛交69hd| 狠狠网亚洲精品| 欧美亚州韩日在线看免费版国语版| 欧美中文在线观看国产| 亚洲精选视频免费看| 久久久久久久久伊人| 亚洲免费黄色| 伊人婷婷久久| 国产欧美日韩另类一区| 欧美韩国日本综合| 久久都是精品| 亚洲视频一区在线| 亚洲国产精品第一区二区三区| 欧美一级片在线播放| 99伊人成综合| 91久久国产综合久久蜜月精品 | 亚洲电影在线看| 国产乱子伦一区二区三区国色天香| 欧美精品www| 久久一区亚洲| 欧美一区二区视频在线观看2020| 99热这里只有成人精品国产| 亚洲大胆美女视频| 欧美成在线观看|