Mostrando entradas con la etiqueta ASM. Mostrar todas las entradas
Mostrando entradas con la etiqueta ASM. Mostrar todas las entradas

martes, 24 de marzo de 2009

EOFEXTRACT - Funcion para extraer el EOF

;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
;@ @
;@ EOFEXTRACT by krackwar @
;@ krackwar@hotmail.com @
;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
include 'win32ax.inc'
.code
start:
stdcall EOFEXTRACT,"C:\archivo.exe"
xor ebx,ebx
mov ebx,eax
invoke GlobalAlloc,GPTR,4
push eax
invoke wsprintf,eax,"0x%x",ebx
pop eax
push eax
invoke MessageBox,0,eax,"EOF data",0
pop eax

invoke GlobalFree,eax
invoke ExitProcess,0
proc EOFEXTRACT,ruta
locals
DireccionPE dd ?
bUsados dd ?
PE dd ?
NumeroSecciones dd ?
BeginLastSection dd ?
hFile dd ?
EOF dd ?
tamAr dd ?
PointerToRawData dd ?
IB dd ?
SizeOfRawData dd ?
endl
invoke CreateFile, [ruta], GENERIC_READ, 0, 0, OPEN_EXISTING, 0, 0
mov [hFile], eax
invoke GetFileSize, [hFile], 0
mov [tamAr], eax
invoke GlobalAlloc, GPTR, eax
mov [IB], eax
invoke ReadFile, [hFile], [IB], [tamAr], addr bUsados, 0
mov ebx ,[IB]
add ebx, 0x3c
mov eax,dword[ebx]
mov [DireccionPE] ,eax
xor ebx,ebx
mov ebx,[IB]
add ebx,eax
mov [PE],ebx
add ebx,0x6
xor edx,edx
mov dx,word[ebx]
mov [NumeroSecciones],edx
mov eax,$28
mov ebx,[NumeroSecciones]
dec ebx
mul ebx
xor edx,edx
mov edx,[DireccionPE]
add edx,$F8
add edx,eax
mov [BeginLastSection],edx
xor eax,eax
xor ebx,ebx
xor edx,edx
mov eax,[IB]
mov edx,[BeginLastSection]
add eax,edx
add eax,16
mov ebx,DWORD[eax]
mov [SizeOfRawData],ebx
add eax,4
xor ebx,ebx
mov ebx,DWORD[eax]
mov [PointerToRawData],ebx
xor ebx,ebx
xor eax,eax
mov edx, [PointerToRawData]
mov ebx,[SizeOfRawData]
add ebx,edx
mov [EOF],ebx
mov eax,[EOF]
ret
endp

.end start

viernes, 23 de enero de 2009

Server - Pequeño ejemplo de server conexion inversa "Messaageboxea" todos lo recivido [ASM]

;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
;!Autor: Krackwar !
;!Lenguaje: ASM !
;!Descripcion: Pequeño ejemplo de un server !
;! en este ejempplo todos los datos recividos!
;! son mostrados en un mensaje. !
;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
include 'win32ax.inc'
.data
Rev dd ?
Socket dd ?
.code
start:
invoke GlobalAlloc,GPTR,1024h
mov ebx,eax
invoke WSAStartup,200,eax
invoke socket,AF_INET,SOCK_STREAM,0 ;Creamos el socket
mov [Socket],eax ;Guardamos el handle en [Socket]
mov word[ebx],2
invoke htons,1234 ;El puerto
mov word[ebx],2
mov word[ebx+2], AX
invoke gethostbyname,'127.0.0.1' ;La ip
add eax,32
invoke inet_addr,eax
mov dword[ebx+4],eax

.BucleConectar: ;Bucle para conectarse
invoke connect,[Socket],ebx,16
cmp eax, 0xFFFFFFFF
JE .BucleConectar

.BucleRecivir: ;Bucle para recivir
invoke GlobalAlloc,GPTR,1024h
push eax
invoke recv,[Socket],eax,1023h,0
mov [Rev],eax
pop eax
cmp [Rev], 0
jng revisar

invoke MessageBox,0,eax,0,0
revisar:
cmp [Rev], 0
jne start.BucleRecivir

.reiniciar:
stdcall dword[closesocket],[Socket]
stdcall dword[WSACleanup]
jmp start
.end start

jueves, 22 de enero de 2009

[SRC] IsDbgCrss - Funcion para saber si estamos siendo 'debuggeados' [ASM]

; Funcion traducida por krackwar
; basada en la funcion de karcrack en Visual Basic
; Para detectar si estamos siendo ejecutados en el olly dbg 2.0 (Testeado en vista de 64 bits )
format pe gui
include 'win32a.inc'
call IsDbgCsrss
cmp eax,TRUE
je Verdad
push 0
call @f
db 'No lo estamos siendo :P',0
@@:
call @f
db 'No no estan debuggeando muahaha',0
@@:
invoke MessageBox,0
invoke ExitProcess,0
Verdad:
push 0
call @f
db 'Tamos siendo debuggeados',0
@@:
call @f
db 'O sierot lo tamos siendo :O',0
@@:
invoke MessageBox,0
invoke ExitProcess,0
IsDbgCsrss:
invoke CsrGetProcessId
invoke OpenProcess,PROCESS_ALL_ACCESS, 0,eax
cmp eax,0
je .Falso
mov eax,TRUE
jmp .Salir
.Falso:
mov eax,FALSE
jmp .Salir
.Salir:
ret
 
data import
library kernel32,'kernel32.dll',user32,'user32.dll',ntdll,'ntdll.dll'
 
include 'api/kernel32.inc'
include 'api/user32.inc'
import ntdll,CsrGetProcessId,'CsrGetProcessId'
end data