cobbr / cobbr/SharpSploit

InvalidArgument4 Error in NtFreeVirtualMemory Routine

Offen
#73 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
C#
Sterne
1.9k
Forks
317
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

When calling SharpSploit.Execution.DynamicInvoke.Generic.GetSyscallStub() the call to NtFreeVirtualMemory returns an NTSTATUS = STATUS_INVALID_PARAMETER_4 (0xC00000F2).

I was attempting to call "NtAllocateVirtualMemory" this way:

``
IntPtr pSyscall = SharpSploit.Execution.DynamicInvoke.Generic.GetSyscallStub("NtAllocateVirtualMemory");
``

This eventually causes this function to be called:

``
Native.NtFreeVirtualMemory((IntPtr)(-1), ref pImage, ref RegionSize, Execute.Win32.Kernel32.AllocationType.Reserve);
``

The error that was being returned was the catch-all error in Native.cs:

``
if (retValue != Execute.Native.NTSTATUS.Success)
{
// STATUS_OBJECT_TYPE_MISMATCH == 0xC0000024
throw new InvalidOperationException("There is a mismatch between the type of object that is required by the requested operation and the type of object that is specified in the request.");
}
``

Calling this code path, there is nothing that I can do to influence the variable type being used for the call to NtFreeVirtualMemory. I was able to add in an extra condition to get it to ignore the error as a work-around. It seems to not like the "Execute.Win32.Kernel32.AllocationType" being passed?

Beitragsleitfaden

Für dieses Repository ist kein Beitragsleitfaden indexiert

Rechercherichtung

Beginne bei SharpSploit.Execution.DynamicInvoke.Generic.GetSyscallStub() und folge dem Aufruf in Native.cs. Konzentriere dich dabei auf den Aufruf von NtFreeVirtualMemory und dessen Behandlung von NTSTATUS. Reproduziere den im Issue beschriebenen Pfad von NtAllocateVirtualMemory und überprüfe anschließend, dass der Aufruf nicht mehr STATUS_INVALID_PARAMETER_4 zurückgibt und dass echte Fehler weiterhin korrekt gemeldet werden.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
csharp
Bereich
security
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.