ripped from ContentDeliveryManager.Utilities.dll
Показаны сообщения с ярлыком wnf. Показать все сообщения
Показаны сообщения с ярлыком wnf. Показать все сообщения
понедельник, 14 января 2019 г.
вторник, 3 июля 2018 г.
пятница, 18 августа 2017 г.
среда, 24 мая 2017 г.
wnf kernelmode callbacks
I already described how to enum usermode wnf callbacks
Now it`s time to enum WNF callbacks in kernel
It is not surprising that they stored in EPROCESS.WnfContext, this struct is undocumented but can be partially recovered from function ExpWnfCreateProcessContext:
offset 0 - WORD signature 0x906
offset 4 - WORD - size 0x88 (0x44 for x86)
offset 8 - eprocess
offset 0x10 - linked list for WNF contexts
offset 0x28 - push lock
offset 0x40 - linked list
offset 0x58 - linked list
offset 0x70 - linked list
Lets see at this struct in windbg
Now it`s time to enum WNF callbacks in kernel
It is not surprising that they stored in EPROCESS.WnfContext, this struct is undocumented but can be partially recovered from function ExpWnfCreateProcessContext:
offset 0 - WORD signature 0x906
offset 4 - WORD - size 0x88 (0x44 for x86)
offset 8 - eprocess
offset 0x10 - linked list for WNF contexts
offset 0x28 - push lock
offset 0x40 - linked list
offset 0x58 - linked list
offset 0x70 - linked list
Lets see at this struct in windbg
понедельник, 10 октября 2016 г.
another cross-process scan
you can use EPROCESS.WnfContext to find list of processes. Lets see how this can be done:
kd> ? nt!ExpWnfProcessesListHead
Evaluate expression: -8781752063864 = fffff803`56c9a888
kd> dp fffff803`56c9a888
fffff803`56c9a888 fffff8a0`00125750 fffff8a0`021fb760
fffff803`56c9a898 00000000`00840082 fffff803`56a43460
fffff803`56c9a8a8 00000000`00120010 fffff803`56a43448
fffff803`56c9a8b8 00000000`00000060 00000000`00000058
fffff803`56c9a8c8 fffff803`56693df0 fffff803`56693dd8
fffff803`56c9a8d8 00000000`00760074 fffff803`56a41cd0
fffff803`56c9a8e8 00000000`00240022 fffff803`56a416c0
fffff803`56c9a8f8 00000000`00140012 fffff803`56a416a8
kd> !pool fffff8a0`00125750 2
Pool page fffff8a000125750 region is Paged pool
*fffff8a000125730 size: f0 previous size: 90 (Allocated) *Wnf
Pooltag Wnf : Windows Notification Facility, Binary : nt!wnf
kd> dp fffff8a0`00125740
fffff8a0`00125740 00000000`00d80906 fffffa80`018a46c0
fffff8a0`00125750 fffff8a0`0010b9e0 fffff803`56c9a888
fffff8a0`00125760 00000000`00000000 00000000`00000000
fffff8a0`00125770 00000000`00000000 00000000`00000000
fffff8a0`00125780 fffff8a0`020c5a50 fffff8a0`00f03690
fffff8a0`00125790 00000000`00000000 fffff8a0`00129028
fffff8a0`001257a0 fffff8a0`015ee5c8 00000000`00000000
fffff8a0`001257b0 fffff8a0`001257b0 fffff8a0`001257b0
kd> !process fffffa80`018a46c0 0
PROCESS fffffa80018a46c0
SessionId: none Cid: 0004 Peb: 00000000 ParentCid: 0000
DirBase: 00187000 ObjectTable: fffff8a000003000 HandleCount:
Image: System
kd> dp fffff8a0`0010b9d0
fffff8a0`0010b9d0 00000000`00d80906 fffffa80`038b4940
fffff8a0`0010b9e0 fffff8a0`058ed020 fffff8a0`00125750
fffff8a0`0010b9f0 fffff8a0`00117f40 00000000`00000000
fffff8a0`0010ba00 00000000`00000000 00000000`00000000
fffff8a0`0010ba10 fffff8a0`0010ba10 fffff8a0`0010ba10
fffff8a0`0010ba20 00000000`00000000 fffff8a0`0010b938
fffff8a0`0010ba30 fffff8a0`0587f968 00000000`00000000
fffff8a0`0010ba40 fffff8a0`0010ba40 fffff8a0`0010ba40
kd> !process fffffa80`038b4940 0
PROCESS fffffa80038b4940
SessionId: 0 Cid: 0148 Peb: 7f630624000 ParentCid: 0140
DirBase: 10feb000 ObjectTable: fffff8a000555cc0 HandleCount:
Image: csrss.exeвторник, 4 октября 2016 г.
simple wnf id decoder
extern "C" int __stdcall check_id(PDWORD); extern "C" int __stdcall get_wnf_value(PDWORD); int _tmain(int argc, _TCHAR* argv[]) { if ( argc == 3 ) { wchar_t *end; DWORD ids[2]; ids[0] = wcstoul(argv[1], &end, 16); ids[1] = wcstoul(argv[2], &end, 16); int whut = check_id(ids); if ( whut ) printf("invalid pair\n"); else printf("id1 %X id2 %X index %d\n", ids[0] ^ 0xA3BC0074, ids[1] ^ 0x41C64E6D, get_wnf_value(ids) ); }
return 0;
}
the main part of code is functions check_id & get_wnf_value. I am too lazy so just ripped piece of code from ntoskrnl.exe!ExpCaptureWnfStateName function:
суббота, 5 декабря 2015 г.
WNF identifiers
I have made a mistake in my previous article about WNF. It seems that WNF idenificators are not standard IID but pair of DWORDs, so struct my_wnf_item actually looks like:
Sample from windows 10 build 10586:
List of some WNF identifiers (sure is not completed):
// struct can be ripped from ntdll!RtlpCreateWnfNameSubscription
struct wnf_name
{
/* 0x0 */ DWORD tag; // 0x980912 under x64, 0x700912 under x86
/* 0x4 */ DWORD unk4;
/* 0x8 */ DWORD unk8;
/* 0xC */ DWORD unkC;
/* 0x10 */ DWORD id1;
/* 0x14 */ DWORD id2;
};
struct my_wnf_item
{
LIST_ENTRY List; // linked list of my_wnf_item
wnf_name *wnfId;
PBYTE notify;
};Sample from windows 10 build 10586:
CheckProcess PID 420 (csrss.exe):
PEB.NtGlobalFlag: 0
PEB.Ldr: 00007FF946ED5200
PEB.GdiSharedHandleTable: 000001EFD8BC0000
WnfRoot: 000001EFD8A05BF0
Wnf[0] at 000001EFD8A08238: id1 A3BC4035 id2 96003D (WNF_PNPA_PORTS_CHANGED_SESSION) - 00007FF943335410 (C:\Windows\system32\winsrv.DLL)
Wnf[1] at 000001EFD8A080C8: id1 A3BC3875 id2 96003D (WNF_PNPA_PORTS_CHANGED) - 00007FF943335410 (C:\Windows\system32\winsrv.DLL)
Wnf[2] at 000001EFD8A07F58: id1 A3BC3035 id2 96003D (WNF_PNPA_HARDWAREPROFILES_CHANGED_SESSION) - 00007FF943335410 (C:\Windows\system32\winsrv.DLL)
Wnf[3] at 000001EFD8A07DE8: id1 A3BC2875 id2 96003D (WNF_PNPA_HARDWAREPROFILES_CHANGED) - 00007FF943335410 (C:\Windows\system32\winsrv.DLL)
Wnf[4] at 000001EFD8A07C78: id1 A3BC2035 id2 96003D (WNF_PNPA_VOLUMES_CHANGED_SESSION) - 00007FF943335410 (C:\Windows\system32\winsrv.DLL)
Wnf[5] at 000001EFD8A07B08: id1 A3BC1875 id2 96003D (WNF_PNPA_VOLUMES_CHANGED) - 00007FF943335410 (C:\Windows\system32\winsrv.DLL)
Wnf[6] at 000001EFD8A04EF8: id1 A3BC1035 id2 96003D (WNF_PNPA_DEVNODES_CHANGED_SESSION) - 00007FF943335410 (C:\Windows\system32\winsrv.DLL)
Wnf[7] at 000001EFD8A05058: id1 A3BC0875 id2 96003D (WNF_PNPA_DEVNODES_CHANGED) - 00007FF943335410 (C:\Windows\system32\winsrv.DLL)List of some WNF identifiers (sure is not completed):
пятница, 14 сентября 2012 г.
WNF notifiers
It seems that windows 8 has some new (undocumented as usually) mechanism to call user-mode code from kernel - WNF
There are several new exported functions in ntdll.dll related to it:
There are several new exported functions in ntdll.dll related to it:
- RtlAllocateWnfSerializationGroup
- RtlEqualWnfChangeStamps
- RtlPublishWnfStateData
- RtlQueryWnfMetaNotification
- RtlQueryWnfStateData
- RtlQueryWnfStateDataWithExplicitScope
- RtlRegisterForWnfMetaNotification
- RtlSubscribeWnfStateChangeNotification
- RtlTestAndPublishWnfStateData
- RtlUnsubscribeWnfNotificationWaitForCompletion
- RtlUnsubscribeWnfNotificationWithCompletionCallback
- RtlUnsubscribeWnfStateChangeNotification
- RtlWaitForWnfMetaNotification
- RtlWnfCompareChangeStamp
- RtlWnfDllUnloadCallback
- RtlpWnfNotificationThread - this one really called from kernel mode
- NtWaitForWnfNotifications
- NtUnsubscribeWnfStateChange
- NtUpdateWnfStateData
- NtSubscribeWnfStateChange
- NtQueryWnfStateData
- NtQueryWnfStateNameInformation
- NtDeleteWnfStateName
- NtDeleteWnfStateData
- NtCreateWnfStateName
Подписаться на:
Сообщения (Atom)