1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79
| #include<stdio.h> #include<stdlib.h> #include<windows.h> char shellcode[] = {0x6a,0,0x6a,0,0x6a,0,0x6a,0,0xe8,0,0,0,0,0xc3};
__declspec(naked) void test() { __asm { push 0x30; pop fs; pushad; pushfd;
lea eax,shellcode; mov ebx,0xc0000000;
mov ecx,eax; shr ecx,30; and ecx,0x3; shl ecx,21; add ebx,ecx;
mov ecx,eax; shr ecx,21; and ecx,0x1ff; shl ecx,12; add ebx,ecx;
mov ecx,eax; shr ecx,12; and ecx,0x1ff; shl ecx,3; add ebx,ecx;
mov ebx,[ebx]; mov dword ptr ds:[0xc0000000],ebx;
popfd; popad; retf }
}
int main() {
int addr = (int)MessageBox; int offset1 = ((int) shellcode) & 0xfff; *((int*)(&shellcode[9])) = addr - (13 + offset1); char buf[6] = {0,0,0,0,0x48,0}; printf("MessageBox:%X test:%X shellcode:%X\n",MessageBox,test,shellcode); system("pause"); __asm { call fword ptr buf; push 0x3b; pop fs; mov eax,offset1; call eax; } return 0; }
|