分类 编程 下的文章

Delphi DLL注入x86/x64/Win2k~Win8.1全可用

之前测东西的时候要用就随手倒腾了一个

program Inject;

{$APPTYPE CONSOLE}


{$IF CompilerVersion >= 21.0}
{$WEAKLINKRTTI ON}
{$RTTI EXPLICIT METHODS([]) PROPERTIES([]) FIELDS([])}
{$IFEND}

uses
  Winapi.Windows;
  
Type
  NtCreateThreadExProc = Function(Var hThread:THandle; Access:DWORD; Attributes:Pointer; hProcess:THandle; pStart:Pointer; pParameter:Pointer; Suspended:BOOL; StackSize, u1, u2:DWORD; Unknown:Pointer):DWORD; stdcall;  


Function CheckOs():Boolean;
Var
  lpVersionInformation :TOSVersionInfoW;
begin
  Result := False;
  if GetVersionExW(lpVersionInformation) then
  begin
    if lpVersionInformation.dwPlatformId = VER_PLATFORM_WIN32_NT Then
    begin
      if (lpVersionInformation.dwMajorVersion < 6) then
      begin
        Result := True;
      end;  
    end;  
  end;
end;

Function EnableDebugPrivilege():Boolean;
Var
  hToKen   :THandle;
  TokenPri :TTokenPrivileges;
begin
  Result := False;
  if(OpenProcessToken(GetCurrentProcess(),TOKEN_ADJUST_PRIVILEGES, hToKen)) Then
  begin
    TokenPri.PrivilegeCount  := 1;
    If LookupPrivilegeValueW(Nil, 'SeDebugPrivilege', TokenPri.Privileges[0].Luid) Then
    begin
      TokenPri.Privileges[0].Attributes := SE_PRIVILEGE_ENABLED;
      Result := AdjustTokenPrivileges(hToken, False, TokenPri, SizeOf(TTokenPrivileges),  Nil, PDWORD(Nil)^);
    end Else Writeln('LookupPrivilege Error');
    CloseHandle(hToKen);
  end;
end;

Function RemoteThread(hProcess:THandle; pThreadProc:Pointer; pRemote:Pointer):THandle;
Label NtCreate, Create;
Var
  pFunc    :Pointer;
  hThread  :THandle;
begin
  hThread := 0;
  if Not CheckOs() then //根据系统版本来选择使用的API
  begin
    NtCreate:
    pFunc   := GetProcAddress(LoadLibraryW('ntdll.dll'), 'NtCreateThreadEx'); 
    if pFunc = Nil then Goto Create;  
    NtCreateThreadExProc(pFunc)(hThread, $1FFFFF, Nil, hProcess, pThreadProc, pRemote, False, 0, 0, 0, Nil);
    if hThread = 0 then Goto Create;
  end Else
  begin
    Create:
    hThread := CreateRemoteThread(hProcess, Nil, 0, pThreadProc, pRemote, 0, PDWORD(Nil)^);    		
  end; 
  Writeln('RemoteThread Ok!');
  Result := hThread;
end;  

Function InjectDll2Pid(szPath:PWideChar; uPID:DWORD):Boolean;
Var
  hProcess  :THandle;
  hThread   :THandle;
  szRemote  :PWideChar;
  uSize     :SIZE_T;
  uWrite    :SIZE_T;
  pStartAddr:Pointer;
begin
  Result := False;
  if EnableDebugPrivilege then
  begin //先提升下进程的权限
    hProcess := OpenProcess(PROCESS_ALL_ACCESS, false, uPID);
    if hProcess > 0 then
    begin
      uSize    := lstrlenW(szPath) * 2 + 4;
      szRemote := VirtualAllocEx(hProcess, Nil, uSize, MEM_COMMIT, PAGE_EXECUTE_READWRITE);
      if WriteProcessMemory(hProcess, szRemote, szPath, uSize, uWrite) And (uWrite = uSize) then
      begin
        pStartAddr := GetProcAddress(LoadLibrary('Kernel32.dll'), 'LoadLibraryW');
        hThread := RemoteThread(hProcess, pStartAddr, szRemote);
        Result  := hThread <> 0;
        CloseHandle(hThread);
      end Else
      begin
        Writeln('WriteMemory Error');
      end;  
    end;  
  end;  
end;  

Function StrToInt(S: String): Integer;
Var
  E: Integer;
Begin
  Val(S, Result, E);
End;

begin
  InjectDll2Pid(PWideChar(ParamStr(2)), StrToInt(ParamStr(1)));
end.


Ping包的DNS查询代码For Delphi

抓包抓的是Ping包的查询不是Nslookup所以内容有点少

Type
  PDNS_HDR = ^DNS_HDR;
  DNS_HDR = Record
    id    :Word; //ID编号有本地指定 服务器 返回时也带有此ID
    tag   :Word;
    numq  :Word;
    numa  :Word;
    numa1 :Word;
    numa2 :Word;
  End;

  PDNS_QER = ^DNS_QER;
  DNS_QER = Record
    utype   :Word;
    classes :Word;
  End;

  TIPAddr = Array [0..3] Of Byte;

Const
  BUF_SIZE = 1024;
  SRV_PORT = 53;
  
  
Function QueryDNS(szHost:PAnsiChar; Server:PAnsiChar):TIPAddr;
Label OnExit;
Var
  dnshdr :PDNS_HDR;
  dnsqer :PDNS_QER;
  Buffer :Array [0..BUF_SIZE-1] Of Byte;
  nSocket:TSocket;
  SerAddr:TSockAddrIn;
  I      :Integer;
  nRet   :Integer;
  dwLen  :Integer;
begin
  ZeroMemory(@Result, SizeOf(TIPAddr));
  nSocket := socket(AF_INET, SOCK_DGRAM, 0);
  If nSocket = INVALID_SOCKET then  Exit;
  SetSocketIoOutTime(nSocket, 8000);
  SerAddr.sin_family        := AF_INET;
  SerAddr.sin_port          := Htons(SRV_PORT);
  SerAddr.sin_addr.s_addr   := Inet_Addr(Server);
  if SerAddr.sin_addr.s_addr = SOCKET_ERROR then Goto OnExit;
  ZeroMemory(@Buffer, BUF_SIZE);
  Randomize;
  dnshdr       := @Buffer;
  dnshdr^.id   := Random(65534);  //随机个ID
  dnshdr^.tag  := htons($0100);
  dnshdr^.numq := htons(1);
  dnshdr^.numa := 0;
  lstrcpyA(@Buffer[SizeOf(DNS_HDR) + 1], szHost);
  I           := SizeOf(DNS_HDR) + 1;
  dwLen       := 0;
  While dwLen < lstrlenA(szHost)-2 Do
  begin
    if Buffer[I + dwLen] = 0 then Break;
    If AnsiChar(Buffer[I + dwLen]) = '.' Then
    begin
      Buffer[I - 1] := dwLen;
      Inc(I, dwLen + 1);
      dwLen := 0;
    end Else
    begin
      Inc(dwLen);
    end;
  end;
  Buffer[I - 1]   := dwLen;
  dnsqer          := PDNS_QER(@Buffer[SizeOf(DNS_HDR) + 3 + lstrlenA(szHost) - 1]);
  dnsqer^.utype   := htons(1);
  dnsqer^.classes := htons(1);
  sendto(nSocket, Buffer, SizeOf(DNS_HDR) + SizeOf(DNS_QER) + lstrlenA(szHost) + 2, 0, SerAddr, SizeOf(TSockAddrIn));
  I    := SizeOf(TSockAddrIn);
  ZeroMemory(@Buffer, BUF_SIZE);
  nRet := recvfrom(nSocket, Buffer, BUF_SIZE, 0, SerAddr, I);
  if dnshdr.numa = 0 then //这里=0是不存在的域名
  begin
    Result[0] := 0;
    Result[1] := 0;
    Result[2] := 0;
    Result[3] := 0;
    Goto OnExit;
  End Else
  begin
    dwLen     := nRet - 4;
    Result[0] := Buffer[dwLen];
    Result[1] := Buffer[dwLen+1];
    Result[2] := Buffer[dwLen+2];
    Result[3] := Buffer[dwLen+3];
  end;

  OnExit :
  closesocket(nSocket);
end;


WinlogonHack Upgrade

Inject Lsass.exe

Hook LsaApLogonUserEx2
  if(IsAdmin)
    (Save/Post) PassWord
  else
    Exit Or Msg(The password is incorrect)



<p>

<a href="http://bcs.duapp.com/flandre/Blog/20140731/fda97789-d8fe-4620-a8b2-6fdec5cb8cb8.jpg"><br />

fda97789-d8fe-4620-a8b2-6fdec5cb8cb8.jpg
</p>

PHP4Delphi 对PHP5.4.X支持的尝试修复

<p>

&nbsp; &nbsp;
PHP5.3.X的话 Delphi盒子论坛有人做了修改

</p>
<p>

&nbsp; &nbsp;
我是在他那个的基础上做修改的

</p>
<p>

&nbsp; &nbsp;
如果不是最近工程需求真不会去看这个代码..

</p>
<p>

&nbsp; &nbsp;
PHP5.4 把之前的php_body_write 修改成了&nbsp;php_output_write

</p>
<p>

&nbsp; &nbsp;
做向上升级兼容的话

</p>
<p>

<br />

</p>
<p>

&nbsp; &nbsp;
ZEND_BUILD_TS&nbsp;线程安全这里是一处要改的

</p>
<p>

&nbsp; &nbsp;
ZEND_MODULE_BUILD_ID 编译ID是一处

</p>
<p>

&nbsp; &nbsp;
ZEND_BUILD_SYSTEM 编译环境是一处{这个是指定是用VC6,9,11编译的}

</p>
<p>

&nbsp; &nbsp;
其他代码的话具体要看着改动了

</p>
<p>

&nbsp; &nbsp;
目前我测试PHP4Delphi的代码里至少需要有二十多个API需要做向上升级兼容

</p>
<p>

&nbsp; &nbsp;
比如 php_body_write&nbsp;需要修改成这样.. 貌似5.5.x 不支持xp跟2k3系统所以我暂时不会去看

</p>

{$IFDEF PHP540}
  php_output_write(Memory, Size, TSRMLS_DC);
{$ELSE}
  php_body_write(Memory, Size, TSRMLS_DC);
{$ENDIF}

<p>

<br />

</p>
<p>

&nbsp; &nbsp;
至于完整的Fix版等手上工程忙完了再改个完整的放出来

</p>
<p>

&nbsp; &nbsp;
下图是我DeBug时的输出....

</p>
<p>

&nbsp; &nbsp;
数了下二十多个...

</p>
<p>

<br />

</p>
<p>

<br />

</p>
<p>

<a href="http://bcs.duapp.com/flandre/Blog/20140511/无标题.jpg"><img src="http://bcs.duapp.com/flandre/Blog/20140511/无标题.jpg" alt="无标题.jpg" /></a>

</p>