Sitelet https://web.archive.org/web/20220309142434im_/https://github.com/Idov31/FunctionStomping/issues/4
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[QUESTIONS] Some victim processes crash without execution #4

Open
Scaum opened this issue Feb 4, 2022 · 1 comment
Open

[QUESTIONS] Some victim processes crash without execution #4

Scaum opened this issue Feb 4, 2022 · 1 comment

Comments

@Scaum
Copy link

@Scaum Scaum commented Feb 4, 2022

First of all, thanks for your work and publishing it along with the very interesting blog post.

I've been playing a bit with your POC, especially the Rust version, and there is something I'm not fully getting. Depending on the victim process, I get the following results:

  • Majority of processes (e.g notepad): when the stomped function is called the shelllcode executes (calc pops open) and the victim process crashes with an access violation error.
  • Some processes (e.g explorer.exe): when the stomped function is called the process crashes with an access violation error, but the shellcode does not seem to execute (nothing happens, no calc).

I've tried with a custom shellcode and by changing the targeted function in kernel32.dll but I always get the same results. So my questions are:

  • Do you know why for some process the shellcode will not execute, the process will just crash ? (function used ? bad shellcode ?)
  • Do you have an idea to get reliable shellcode execution on all processes ?
@Idov31
Copy link
Owner

@Idov31 Idov31 commented Feb 4, 2022 •

Thank you for this issue, and I'm glad that you like my blog post.
Honestly I didn't tried that on explorer but it is very weird and I will try to dig into it.

About notepad and the majority of the processes: That is a behavior I saw as well but weirdly it doesn't happen all the time, most of the time when I tried that on notepad it just restarted itself and on a binary I created it just finished its run normally.

My speculation is that the remote process except a handle and gets nothing and therefore crashes, I think that if the shellcode will return value (even of INVALID_HANDLE_VALUE) the remote process won't crash (but again - that is my speculation and I need to check it out before I say it as a fact).

The shellcode I used is the simplest shellcode that generated with msfvenom. I recommend to check it will shellcode of Cobalt Strike beacon or metasploit's agent and see the result.

[UPDATE]
I tried to play around a bit with it and test several shellcodes (including metasploit agent & reverse shell) and tried to change the return value but for some reason it still crashed (I wasn't able to recreate the crash without execution).

Because it crashes (I still think that the return value is the issue) the host process after execution I would recommend to spawn your own process (e.g. notepad, svchost ) and inject your shellcode to it.

I didn't find any other processes that the injection crashes the process without the shellcode to be executed so if you find any - let me know!

Also, if you have a fix for it create a pull request and I'll happily review it :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
2 participants