-
Notifications
You must be signed in to change notification settings - Fork 12
/
CSkyDBK.h
83 lines (55 loc) · 1.92 KB
/
CSkyDBK.h
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
#pragma once
#include <Windows.h>
#include <TlHelp32.h>
#include <iostream>
#include <Shlwapi.h>
#pragma comment(lib, "Shlwapi.lib")
#define SKYDBK_DEBUGPRINT(...) ((void)0)
#ifndef _WIN64
#error "Only win x64 is supported"
#endif
typedef struct _LSA_UNICODE_STRING {
USHORT Length;
USHORT MaximumLength;
PWSTR Buffer;
} LSA_UNICODE_STRING, *PLSA_UNICODE_STRING, UNICODE_STRING, *PUNICODE_STRING;
typedef NTSTATUS (__stdcall *tZwLoadDriver)(
_In_ PUNICODE_STRING DriverServiceName
);
typedef NTSTATUS (__stdcall *tZwUnloadDriver)(
_In_ PUNICODE_STRING DriverServiceName
);
typedef NTSTATUS(__stdcall *tRtlInitUnicodeString)(
_Out_ PUNICODE_STRING DestinationString,
_In_opt_ PCWSTR SourceString
);
class CSkyDBK
{
private:
HANDLE m_hDBK;
HANDLE m_hCheatEngine;
HDESK m_hCheatEngineDesktop;
const wchar_t *m_szDBKPath;
const wchar_t *m_szCheatEnginePath;
std::wstring m_szServiceName;
std::wstring m_szProcessEventName;
std::wstring m_szThreadEventName;
tZwLoadDriver m_ZwLoadDriver;
tZwUnloadDriver m_ZwUnloadDriver;
tRtlInitUnicodeString m_RtlInitUnicodeString;
public:
HANDLE LoadDriver();
bool UnloadDriver();
CSkyDBK(const wchar_t *szDBK, const wchar_t *szCE);
~CSkyDBK();
static std::wstring GetRandomWString(size_t len);
private:
static HMODULE GetRemoteModule(const char *szModuleName, DWORD dwProcessId);
static bool GetRemoteModuleExportDirectory32(HMODULE hRemote, PIMAGE_EXPORT_DIRECTORY ExportDirectory, PIMAGE_DOS_HEADER DosHeader, PIMAGE_NT_HEADERS32 NtHeaders, HANDLE hProcess);
static PVOID GetRemoteFuncAddress32(const char *module, const char *func, HANDLE hProcess);
BYTE *GetCreateFileShellcode(HANDLE _In_ hProcess, const wchar_t _In_ *szDriverPipe, PVOID _Out_ *allocatedMemory);
bool LoadDBK();
bool UnloadDBK();
LSTATUS PrepareDriverRegEntry(const std::wstring& svcName, const std::wstring& path, bool cleanup = false);
static bool AttemptDebugPrivilege(HANDLE h);
};