Extreme Security 01-30-2016, 05:23 AM
#1
So recently someone managed to break Ven0m's security by using OllyDbg to dump all the data we pass through WriteProcessMemory (Which we use to write the dll bytes into the target process).
So I kicked it into overdrive and in the matter of 3 days have completely educated myself about WinAPI, ManualMapping and a few select WinAPI functions that will prevent any possible leaks in the future.
I plan to make a visual gif of this later on but for now I'll make a step by step of what happens.
But until then ;_;7 you beautiful piece of art.
So I kicked it into overdrive and in the matter of 3 days have completely educated myself about WinAPI, ManualMapping and a few select WinAPI functions that will prevent any possible leaks in the future.
I plan to make a visual gif of this later on but for now I'll make a step by step of what happens.
- Client injects a Native Bootstrap into target process to allow Code Caving for Managed Libraries
- Client injects managed library
- Bootstrap invokes main method of Managed Library
- Managed Library uses System.IO.Pipes to open a memory stream between it and the client
- Client transfers the hack data and decryption key etc. to the managed library after it verifies it's identity.
- Managed Library Allocates, Code Caves, then uses memcpy to relocate the hack bytes into the target process
- Managed Library and Bootstrap are UNLOADED from the target process and all that remains is the hack
But until then ;_;7 you beautiful piece of art.




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)










![[Image: oAqtc2l.png]](https://i.imgur.com/oAqtc2l.png)




joking. Hopefully we can integrate the new system ASAP.