Permalink
Browse files

MS12-042

  • Loading branch information...
Gitmaninc committed Jul 19, 2017
1 parent 7356e38 commit ecc60d20daf70adf988fe413b1b2fe0309a1507b
Showing with 31,149 additions and 1 deletion.
  1. +3 −1 MS12-042/README.md
  2. BIN MS12-042/sysret-source/junk.suo
  3. +104 −0 MS12-042/sysret-source/junk/MinHook/MinHook.h
  4. BIN MS12-042/sysret-source/junk/MinHook/MinHook.x64.lib
  5. +40 −0 MS12-042/sysret-source/junk/ReadMe.txt
  6. +175 −0 MS12-042/sysret-source/junk/junk.vcxproj
  7. +77 −0 MS12-042/sysret-source/junk/junk.vcxproj.filters
  8. +3 −0 MS12-042/sysret-source/junk/junk.vcxproj.user
  9. +156 −0 MS12-042/sysret-source/junk/krnlutils.cpp
  10. +89 −0 MS12-042/sysret-source/junk/log.cpp
  11. +33 −0 MS12-042/sysret-source/junk/log.h
  12. +23 −0 MS12-042/sysret-source/junk/peutil.h
  13. +24 −0 MS12-042/sysret-source/junk/peutils.cpp
  14. +384 −0 MS12-042/sysret-source/junk/sources/CMakeLists.txt
  15. +56 −0 MS12-042/sysret-source/junk/sources/beaengineSources/BeaEngine.c
  16. BIN MS12-042/sysret-source/junk/sources/beaengineSources/BeaEngine.obj
  17. +9 −0 MS12-042/sysret-source/junk/sources/beaengineSources/CMakeLists.txt
  18. +165 −0 MS12-042/sysret-source/junk/sources/beaengineSources/COPYING.LESSER.txt
  19. +674 −0 MS12-042/sysret-source/junk/sources/beaengineSources/COPYING.txt
  20. +23 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/BeaEngineVersion.c
  21. +1,074 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/Routines_Disasm.c
  22. +3,556 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/Routines_ModRM.c
  23. +174 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/Data_opcode.h
  24. +168 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_AES.c
  25. +6,707 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_A_M.c
  26. +74 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_CLMUL.c
  27. +1,782 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_FPU.c
  28. +297 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_Grp1.c
  29. +195 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_Grp12.c
  30. +194 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_Grp13.c
  31. +203 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_Grp14.c
  32. +166 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_Grp15.c
  33. +85 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_Grp16.c
  34. +461 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_Grp2.c
  35. +257 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_Grp3.c
  36. +51 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_Grp4.c
  37. +153 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_Grp5.c
  38. +117 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_Grp6.c
  39. +278 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_Grp7.c
  40. +70 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_Grp8.c
  41. +84 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_Grp9.c
  42. +1,722 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_MMX.c
  43. +3,660 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_N_Z.c
  44. +4,570 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_SSE.c
  45. +239 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/instr_set/opcodes_prefixes.c
  46. +551 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/internal_datas.h
  47. +705 −0 MS12-042/sysret-source/junk/sources/beaengineSources/Includes/protos.h
  48. +30 −0 MS12-042/sysret-source/junk/sources/beaengineSources/README.txt
  49. +361 −0 MS12-042/sysret-source/junk/sources/include/beaengine/BeaEngine.h
  50. +272 −0 MS12-042/sysret-source/junk/sources/include/beaengine/basic_types.h
  51. +173 −0 MS12-042/sysret-source/junk/sources/include/beaengine/export.h
  52. +41 −0 MS12-042/sysret-source/junk/sources/include/beaengine/macros.h
  53. +8 −0 MS12-042/sysret-source/junk/stdafx.cpp
  54. +15 −0 MS12-042/sysret-source/junk/stdafx.h
  55. +491 −0 MS12-042/sysret-source/junk/sysret.cpp
  56. +83 −0 MS12-042/sysret-source/junk/sysret.h
  57. +8 −0 MS12-042/sysret-source/junk/targetver.h
  58. +10 −0 MS12-042/sysret-source/junk/trigger.asm
  59. +26 −0 MS12-042/sysret-source/sysret.sln
  60. BIN MS12-042/sysret-source/sysret.suo
  61. BIN MS12-042/sysret-source/x64/Release/MinHook.x64.dll
  62. BIN MS12-042/sysret-source/x64/Release/sysret.exe
View
@@ -13,6 +13,8 @@ Vulnerability reference:
## Usage
```
c:\> MS12-042.exe -pid xxx
```
```
* [YouTube](https://www.youtube.com/watch?v=whRRFOm-DLI&feature=youtu.be)
![win7](win7.png)
View
Binary file not shown.
@@ -0,0 +1,104 @@
/*
* MinHook - Minimalistic API Hook Library
* Copyright (C) 2009 Tsuda Kageyu. All rights reserved.
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted provided that the following conditions
* are met:
*
* 1. Redistributions of source code must retain the above copyright
* notice, this list of conditions and the following disclaimer.
* 2. Redistributions in binary form must reproduce the above copyright
* notice, this list of conditions and the following disclaimer in the
* documentation and/or other materials provided with the distribution.
* 3. The name of the author may not be used to endorse or promote products
* derived from this software without specific prior written permission.
*
* THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
* IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
* OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
* IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
* INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
* NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
* DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
* THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
* (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
* THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
*/
#pragma once
#include <Windows.h>
// MinHook Error Codes.
typedef enum MH_STATUS
{
// Unknown error. Should not be returned.
MH_UNKNOWN = -1,
// Successful.
MH_OK = 0,
// MinHook is already initialized.
MH_ERROR_ALREADY_INITIALIZED,
// MinHook is not initialized yet, or already uninitialized.
MH_ERROR_NOT_INITIALIZED,
// The hook for the specified target function is already created.
MH_ERROR_ALREADY_CREATED,
// The hook for the specified target function is not created yet.
MH_ERROR_NOT_CREATED,
// The hook for the specified target function is already enabled.
MH_ERROR_ENABLED,
// The hook for the specified target function is not enabled yet, or already disabled.
MH_ERROR_DISABLED,
// The specified pointer is invalid. It points the address of non-allocated and/or non-executable region.
MH_ERROR_NOT_EXECUTABLE,
// The specified target function cannot be hooked.
MH_ERROR_UNSUPPORTED_FUNCTION,
// Failed to allocate memory.
MH_ERROR_MEMORY_ALLOC,
// Failed to change the memory protection.
MH_ERROR_MEMORY_PROTECT
}
MH_STATUS;
#if defined __cplusplus
extern "C" {
#endif
// Initialize the MinHook library.
MH_STATUS WINAPI MH_Initialize();
// Uninitialize the MinHook library.
MH_STATUS WINAPI MH_Uninitialize();
// Creates the Hook for the specified target function, in disabled state.
// Parameters:
// pTarget [in] A pointer to the target function, which will be overridden by the detour function.
// pDetour [in] A pointer to the detour function, which will override the target function.
// ppOriginal [out] A pointer to the trampoline function, which will be used to call the original target function.
MH_STATUS WINAPI MH_CreateHook(void* pTarget, void* const pDetour, void** ppOriginal);
// Enables the already created hook.
// Parameters:
// pTarget [in] A pointer to the target function.
MH_STATUS WINAPI MH_EnableHook(void* pTarget);
// Disables the already created hook.
// Parameters:
// pTarget [in] A pointer to the target function.
MH_STATUS WINAPI MH_DisableHook(void* pTarget);
#if defined __cplusplus
}
#endif
Binary file not shown.
@@ -0,0 +1,40 @@
========================================================================
CONSOLE APPLICATION : junk Project Overview
========================================================================
AppWizard has created this junk application for you.
This file contains a summary of what you will find in each of the files that
make up your junk application.
junk.vcxproj
This is the main project file for VC++ projects generated using an Application Wizard.
It contains information about the version of Visual C++ that generated the file, and
information about the platforms, configurations, and project features selected with the
Application Wizard.
junk.vcxproj.filters
This is the filters file for VC++ projects generated using an Application Wizard.
It contains information about the association between the files in your project
and the filters. This association is used in the IDE to show grouping of files with
similar extensions under a specific node (for e.g. ".cpp" files are associated with the
"Source Files" filter).
junk.cpp
This is the main application source file.
/////////////////////////////////////////////////////////////////////////////
Other standard files:
StdAfx.h, StdAfx.cpp
These files are used to build a precompiled header (PCH) file
named junk.pch and a precompiled types file named StdAfx.obj.
/////////////////////////////////////////////////////////////////////////////
Other notes:
AppWizard uses "TODO:" comments to indicate parts of the source code you
should add to or customize.
/////////////////////////////////////////////////////////////////////////////
@@ -0,0 +1,175 @@
<?xml version="1.0" encoding="utf-8"?>
<Project DefaultTargets="Build" ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
<ItemGroup Label="ProjectConfigurations">
<ProjectConfiguration Include="Debug|Win32">
<Configuration>Debug</Configuration>
<Platform>Win32</Platform>
</ProjectConfiguration>
<ProjectConfiguration Include="Debug|x64">
<Configuration>Debug</Configuration>
<Platform>x64</Platform>
</ProjectConfiguration>
<ProjectConfiguration Include="Release|Win32">
<Configuration>Release</Configuration>
<Platform>Win32</Platform>
</ProjectConfiguration>
<ProjectConfiguration Include="Release|x64">
<Configuration>Release</Configuration>
<Platform>x64</Platform>
</ProjectConfiguration>
</ItemGroup>
<PropertyGroup Label="Globals">
<ProjectGuid>{33A91BC5-C798-4CA3-BDE2-ED317FCBCD7F}</ProjectGuid>
<Keyword>Win32Proj</Keyword>
<RootNamespace>junk</RootNamespace>
<ProjectName>sysret</ProjectName>
</PropertyGroup>
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.Default.props" />
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|Win32'" Label="Configuration">
<ConfigurationType>Application</ConfigurationType>
<UseDebugLibraries>true</UseDebugLibraries>
<CharacterSet>NotSet</CharacterSet>
</PropertyGroup>
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|x64'" Label="Configuration">
<ConfigurationType>Application</ConfigurationType>
<UseDebugLibraries>true</UseDebugLibraries>
<CharacterSet>NotSet</CharacterSet>
</PropertyGroup>
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|Win32'" Label="Configuration">
<ConfigurationType>Application</ConfigurationType>
<UseDebugLibraries>false</UseDebugLibraries>
<WholeProgramOptimization>true</WholeProgramOptimization>
<CharacterSet>Unicode</CharacterSet>
</PropertyGroup>
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'" Label="Configuration">
<ConfigurationType>Application</ConfigurationType>
<UseDebugLibraries>false</UseDebugLibraries>
<WholeProgramOptimization>true</WholeProgramOptimization>
<CharacterSet>NotSet</CharacterSet>
</PropertyGroup>
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.props" />
<ImportGroup Label="ExtensionSettings">
<Import Project="$(VCTargetsPath)\BuildCustomizations\masm.props" />
<Import Project="$(VCTargetsPath)\BuildCustomizations\vsyasm.props" />
</ImportGroup>
<ImportGroup Label="PropertySheets" Condition="'$(Configuration)|$(Platform)'=='Debug|Win32'">
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
</ImportGroup>
<ImportGroup Condition="'$(Configuration)|$(Platform)'=='Debug|x64'" Label="PropertySheets">
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
</ImportGroup>
<ImportGroup Label="PropertySheets" Condition="'$(Configuration)|$(Platform)'=='Release|Win32'">
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
</ImportGroup>
<ImportGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'" Label="PropertySheets">
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
</ImportGroup>
<PropertyGroup Label="UserMacros" />
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|Win32'">
<LinkIncremental>true</LinkIncremental>
</PropertyGroup>
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|x64'">
<LinkIncremental>true</LinkIncremental>
</PropertyGroup>
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|Win32'">
<LinkIncremental>false</LinkIncremental>
</PropertyGroup>
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'">
<LinkIncremental>false</LinkIncremental>
</PropertyGroup>
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Debug|Win32'">
<ClCompile>
<PrecompiledHeader>Use</PrecompiledHeader>
<WarningLevel>Level3</WarningLevel>
<Optimization>Disabled</Optimization>
<PreprocessorDefinitions>WIN32;_DEBUG;_CONSOLE;%(PreprocessorDefinitions)</PreprocessorDefinitions>
</ClCompile>
<Link>
<SubSystem>Console</SubSystem>
<GenerateDebugInformation>true</GenerateDebugInformation>
<TargetMachine>MachineX64</TargetMachine>
</Link>
</ItemDefinitionGroup>
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Debug|x64'">
<ClCompile>
<PrecompiledHeader>NotUsing</PrecompiledHeader>
<WarningLevel>Level3</WarningLevel>
<Optimization>Disabled</Optimization>
<PreprocessorDefinitions>WIN32;_DEBUG;_CONSOLE;%(PreprocessorDefinitions)</PreprocessorDefinitions>
</ClCompile>
<Link>
<SubSystem>Console</SubSystem>
<GenerateDebugInformation>true</GenerateDebugInformation>
</Link>
</ItemDefinitionGroup>
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Release|Win32'">
<ClCompile>
<WarningLevel>Level3</WarningLevel>
<PrecompiledHeader>Use</PrecompiledHeader>
<Optimization>MaxSpeed</Optimization>
<FunctionLevelLinking>true</FunctionLevelLinking>
<IntrinsicFunctions>true</IntrinsicFunctions>
<PreprocessorDefinitions>WIN32;NDEBUG;_CONSOLE;%(PreprocessorDefinitions)</PreprocessorDefinitions>
<RuntimeLibrary>MultiThreaded</RuntimeLibrary>
</ClCompile>
<Link>
<SubSystem>Console</SubSystem>
<GenerateDebugInformation>true</GenerateDebugInformation>
<EnableCOMDATFolding>true</EnableCOMDATFolding>
<OptimizeReferences>true</OptimizeReferences>
</Link>
</ItemDefinitionGroup>
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'">
<ClCompile>
<WarningLevel>Level3</WarningLevel>
<PrecompiledHeader>NotUsing</PrecompiledHeader>
<Optimization>MaxSpeed</Optimization>
<FunctionLevelLinking>true</FunctionLevelLinking>
<IntrinsicFunctions>true</IntrinsicFunctions>
<PreprocessorDefinitions>WIN32;NDEBUG;_CONSOLE;%(PreprocessorDefinitions)</PreprocessorDefinitions>
<RuntimeLibrary>MultiThreaded</RuntimeLibrary>
</ClCompile>
<Link>
<SubSystem>Console</SubSystem>
<GenerateDebugInformation>true</GenerateDebugInformation>
<EnableCOMDATFolding>true</EnableCOMDATFolding>
<OptimizeReferences>true</OptimizeReferences>
</Link>
</ItemDefinitionGroup>
<ItemGroup>
<None Include="ReadMe.txt" />
<MASM Include="trigger.asm">
<FileType>Document</FileType>
</MASM>
</ItemGroup>
<ItemGroup>
<ClInclude Include="log.h" />
<ClInclude Include="MinHook\MinHook.h" />
<ClInclude Include="peutil.h" />
<ClInclude Include="sources\include\beaengine\basic_types.h" />
<ClInclude Include="sources\include\beaengine\BeaEngine.h" />
<ClInclude Include="sources\include\beaengine\export.h" />
<ClInclude Include="sources\include\beaengine\macros.h" />
<ClInclude Include="stdafx.h" />
<ClInclude Include="sysret.h" />
<ClInclude Include="targetver.h" />
</ItemGroup>
<ItemGroup>
<ClCompile Include="KrnlUtils.cpp" />
<ClCompile Include="log.cpp" />
<ClCompile Include="peutils.cpp" />
<ClCompile Include="sources\beaengineSources\BeaEngine.c" />
<ClCompile Include="sysret.cpp" />
<ClCompile Include="stdafx.cpp">
<PrecompiledHeader Condition="'$(Configuration)|$(Platform)'=='Debug|Win32'">Create</PrecompiledHeader>
<PrecompiledHeader Condition="'$(Configuration)|$(Platform)'=='Debug|x64'">Create</PrecompiledHeader>
<PrecompiledHeader Condition="'$(Configuration)|$(Platform)'=='Release|Win32'">Create</PrecompiledHeader>
<PrecompiledHeader Condition="'$(Configuration)|$(Platform)'=='Release|x64'">Create</PrecompiledHeader>
</ClCompile>
</ItemGroup>
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
<ImportGroup Label="ExtensionTargets">
<Import Project="$(VCTargetsPath)\BuildCustomizations\masm.targets" />
<Import Project="$(VCTargetsPath)\BuildCustomizations\vsyasm.targets" />
</ImportGroup>
</Project>
Oops, something went wrong.

0 comments on commit ecc60d2

Please sign in to comment.