v0.1 - initial commit
This commit is contained in:
@@ -0,0 +1,50 @@
|
||||
; messagebox_x64.asm — position-independent x64 shellcode: resolve
|
||||
; user32.dll!MessageBoxA via LoadLibraryA (user32.dll isn't guaranteed
|
||||
; loaded in a plain console process, unlike kernel32) and pop a real
|
||||
; message box. Returns normally (ret) once the user dismisses it, so the
|
||||
; host thread keeps running afterward.
|
||||
;
|
||||
; text_buf/caption_buf are fixed-size placeholders at the very end of the
|
||||
; assembled blob; winpwn patches them at runtime with the actual
|
||||
; NUL-terminated strings (see shellcraft.go).
|
||||
BITS 64
|
||||
default rel
|
||||
|
||||
start:
|
||||
push rbp
|
||||
push r12
|
||||
mov rbp, rsp
|
||||
and rsp, ~0xF ; force 16-byte stack alignment, unknown entry state
|
||||
|
||||
call get_kernel32_base
|
||||
mov rcx, rax
|
||||
lea rdx, [rel name_user32]
|
||||
lea r8, [rel name_messageboxa]
|
||||
call resolve_export
|
||||
mov r12, rax ; r12 = MessageBoxA address
|
||||
|
||||
xor rcx, rcx ; hWnd = NULL
|
||||
lea rdx, [rel text_buf] ; lpText
|
||||
lea r8, [rel caption_buf] ; lpCaption
|
||||
xor r9, r9 ; uType = MB_OK
|
||||
sub rsp, 0x20 ; shadow space required before any WinAPI call
|
||||
call r12
|
||||
add rsp, 0x20
|
||||
|
||||
mov rsp, rbp
|
||||
pop r12
|
||||
pop rbp
|
||||
ret
|
||||
|
||||
%include "resolver.inc"
|
||||
|
||||
name_user32: db "user32.dll", 0
|
||||
name_messageboxa: db "MessageBoxA", 0
|
||||
|
||||
align 8
|
||||
text_buf:
|
||||
times 256 db 0
|
||||
|
||||
align 8
|
||||
caption_buf:
|
||||
times 64 db 0
|
||||
Reference in New Issue
Block a user