;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
;@ @
;@ EOFEXTRACT by krackwar @
;@ krackwar@hotmail.com @
;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
include 'win32ax.inc'
.code
start:
stdcall EOFEXTRACT,"C:\archivo.exe"
xor ebx,ebx
mov ebx,eax
invoke GlobalAlloc,GPTR,4
push eax
invoke wsprintf,eax,"0x%x",ebx
pop eax
push eax
invoke MessageBox,0,eax,"EOF data",0
pop eax
invoke GlobalFree,eax
invoke ExitProcess,0
proc EOFEXTRACT,ruta
locals
DireccionPE dd ?
bUsados dd ?
PE dd ?
NumeroSecciones dd ?
BeginLastSection dd ?
hFile dd ?
EOF dd ?
tamAr dd ?
PointerToRawData dd ?
IB dd ?
SizeOfRawData dd ?
endl
invoke CreateFile, [ruta], GENERIC_READ, 0, 0, OPEN_EXISTING, 0, 0
mov [hFile], eax
invoke GetFileSize, [hFile], 0
mov [tamAr], eax
invoke GlobalAlloc, GPTR, eax
mov [IB], eax
invoke ReadFile, [hFile], [IB], [tamAr], addr bUsados, 0
mov ebx ,[IB]
add ebx, 0x3c
mov eax,dword[ebx]
mov [DireccionPE] ,eax
xor ebx,ebx
mov ebx,[IB]
add ebx,eax
mov [PE],ebx
add ebx,0x6
xor edx,edx
mov dx,word[ebx]
mov [NumeroSecciones],edx
mov eax,$28
mov ebx,[NumeroSecciones]
dec ebx
mul ebx
xor edx,edx
mov edx,[DireccionPE]
add edx,$F8
add edx,eax
mov [BeginLastSection],edx
xor eax,eax
xor ebx,ebx
xor edx,edx
mov eax,[IB]
mov edx,[BeginLastSection]
add eax,edx
add eax,16
mov ebx,DWORD[eax]
mov [SizeOfRawData],ebx
add eax,4
xor ebx,ebx
mov ebx,DWORD[eax]
mov [PointerToRawData],ebx
xor ebx,ebx
xor eax,eax
mov edx, [PointerToRawData]
mov ebx,[SizeOfRawData]
add ebx,edx
mov [EOF],ebx
mov eax,[EOF]
ret
endp
.end start
Mostrando entradas con la etiqueta ASM. Mostrar todas las entradas
Mostrando entradas con la etiqueta ASM. Mostrar todas las entradas
martes, 24 de marzo de 2009
EOFEXTRACT - Funcion para extraer el EOF
Etiquetas:
ASM
viernes, 23 de enero de 2009
Server - Pequeño ejemplo de server conexion inversa "Messaageboxea" todos lo recivido [ASM]
;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
;!Autor: Krackwar !
;!Lenguaje: ASM !
;!Descripcion: Pequeño ejemplo de un server !
;! en este ejempplo todos los datos recividos!
;! son mostrados en un mensaje. !
;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
include 'win32ax.inc'
.data
Rev dd ?
Socket dd ?
.code
start:
invoke GlobalAlloc,GPTR,1024h
mov ebx,eax
invoke WSAStartup,200,eax
invoke socket,AF_INET,SOCK_STREAM,0 ;Creamos el socket
mov [Socket],eax ;Guardamos el handle en [Socket]
mov word[ebx],2
invoke htons,1234 ;El puerto
mov word[ebx],2
mov word[ebx+2], AX
invoke gethostbyname,'127.0.0.1' ;La ip
add eax,32
invoke inet_addr,eax
mov dword[ebx+4],eax
.BucleConectar: ;Bucle para conectarse
invoke connect,[Socket],ebx,16
cmp eax, 0xFFFFFFFF
JE .BucleConectar
.BucleRecivir: ;Bucle para recivir
invoke GlobalAlloc,GPTR,1024h
push eax
invoke recv,[Socket],eax,1023h,0
mov [Rev],eax
pop eax
cmp [Rev], 0
jng revisar
invoke MessageBox,0,eax,0,0
revisar:
cmp [Rev], 0
jne start.BucleRecivir
.reiniciar:
stdcall dword[closesocket],[Socket]
stdcall dword[WSACleanup]
jmp start
.end start
;!Autor: Krackwar !
;!Lenguaje: ASM !
;!Descripcion: Pequeño ejemplo de un server !
;! en este ejempplo todos los datos recividos!
;! son mostrados en un mensaje. !
;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
include 'win32ax.inc'
.data
Rev dd ?
Socket dd ?
.code
start:
invoke GlobalAlloc,GPTR,1024h
mov ebx,eax
invoke WSAStartup,200,eax
invoke socket,AF_INET,SOCK_STREAM,0 ;Creamos el socket
mov [Socket],eax ;Guardamos el handle en [Socket]
mov word[ebx],2
invoke htons,1234 ;El puerto
mov word[ebx],2
mov word[ebx+2], AX
invoke gethostbyname,'127.0.0.1' ;La ip
add eax,32
invoke inet_addr,eax
mov dword[ebx+4],eax
.BucleConectar: ;Bucle para conectarse
invoke connect,[Socket],ebx,16
cmp eax, 0xFFFFFFFF
JE .BucleConectar
.BucleRecivir: ;Bucle para recivir
invoke GlobalAlloc,GPTR,1024h
push eax
invoke recv,[Socket],eax,1023h,0
mov [Rev],eax
pop eax
cmp [Rev], 0
jng revisar
invoke MessageBox,0,eax,0,0
revisar:
cmp [Rev], 0
jne start.BucleRecivir
.reiniciar:
stdcall dword[closesocket],[Socket]
stdcall dword[WSACleanup]
jmp start
.end start
Etiquetas:
ASM
jueves, 22 de enero de 2009
[SRC] IsDbgCrss - Funcion para saber si estamos siendo 'debuggeados' [ASM]
; Funcion traducida por krackwar
; basada en la funcion de karcrack en Visual Basic
; Para detectar si estamos siendo ejecutados en el olly dbg 2.0 (Testeado en vista de 64 bits )
format pe gui
include 'win32a.inc'
call IsDbgCsrss
cmp eax,TRUE
je Verdad
push 0
call @f
db 'No lo estamos siendo :P',0
@@:
call @f
db 'No no estan debuggeando muahaha',0
@@:
invoke MessageBox,0
invoke ExitProcess,0
Verdad:
push 0
call @f
db 'Tamos siendo debuggeados',0
@@:
call @f
db 'O sierot lo tamos siendo :O',0
@@:
invoke MessageBox,0
invoke ExitProcess,0
IsDbgCsrss:
invoke CsrGetProcessId
invoke OpenProcess,PROCESS_ALL_ACCESS, 0,eax
cmp eax,0
je .Falso
mov eax,TRUE
jmp .Salir
.Falso:
mov eax,FALSE
jmp .Salir
.Salir:
ret
data import
library kernel32,'kernel32.dll',user32,'user32.dll',ntdll,'ntdll.dll'
include 'api/kernel32.inc'
include 'api/user32.inc'
import ntdll,CsrGetProcessId,'CsrGetProcessId'
end data
; basada en la funcion de karcrack en Visual Basic
; Para detectar si estamos siendo ejecutados en el olly dbg 2.0 (Testeado en vista de 64 bits )
format pe gui
include 'win32a.inc'
call IsDbgCsrss
cmp eax,TRUE
je Verdad
push 0
call @f
db 'No lo estamos siendo :P',0
@@:
call @f
db 'No no estan debuggeando muahaha',0
@@:
invoke MessageBox,0
invoke ExitProcess,0
Verdad:
push 0
call @f
db 'Tamos siendo debuggeados',0
@@:
call @f
db 'O sierot lo tamos siendo :O',0
@@:
invoke MessageBox,0
invoke ExitProcess,0
IsDbgCsrss:
invoke CsrGetProcessId
invoke OpenProcess,PROCESS_ALL_ACCESS, 0,eax
cmp eax,0
je .Falso
mov eax,TRUE
jmp .Salir
.Falso:
mov eax,FALSE
jmp .Salir
.Salir:
ret
data import
library kernel32,'kernel32.dll',user32,'user32.dll',ntdll,'ntdll.dll'
include 'api/kernel32.inc'
include 'api/user32.inc'
import ntdll,CsrGetProcessId,'CsrGetProcessId'
end data
Etiquetas:
ASM
Suscribirse a:
Entradas (Atom)