zoukankan      html  css  js  c++  java
  • Ring3层代码提权

    BOOL EnableDebugPri64()
    {
        typedef long (__fastcall *pfnRtlAdjustPrivilege64)(ULONG,ULONG,ULONG,PVOID);
        pfnRtlAdjustPrivilege64 RtlAdjustPrivilege;
    
        DWORD                  dwRetVal    = 0;
        LPTHREAD_START_ROUTINE FuncAddress = NULL;
    #ifdef _UNICODE
        FuncAddress = (PTHREAD_START_ROUTINE)::GetProcAddress(::GetModuleHandle(_T("Kernel32")), "LoadLibraryW");
    #else
        FuncAddress = (PTHREAD_START_ROUTINE)::GetProcAddress(::GetModuleHandle(_T("Kernel32")), "LoadLibraryA");
    #endif
    
        if (FuncAddress==NULL)
        {
            return FALSE;
        }
    
    
        RtlAdjustPrivilege=(pfnRtlAdjustPrivilege64)GetProcAddress((HMODULE)(FuncAddress(L"ntdll.dll")),"RtlAdjustPrivilege");
    
        if (RtlAdjustPrivilege==NULL)
        {
            return FALSE;
        }
        RtlAdjustPrivilege(20,1,0,&dwRetVal);
    }
    BOOL EnableDebugPri32()
    {
    
        HANDLE hToken;
        TOKEN_PRIVILEGES pTP;
        LUID uID;
    
        if (!OpenProcessToken(GetCurrentProcess(),TOKEN_ADJUST_PRIVILEGES|TOKEN_QUERY,&hToken))
        {
            printf("OpenProcessToken is Error
    ");
    
            return FALSE;
        }
    
        if (!LookupPrivilegeValue(NULL,SE_DEBUG_NAME,&uID))
        {
            printf("LookupPrivilegeValue is Error
    ");
    
            return FALSE;
        }
    
    
        pTP.PrivilegeCount = 1;
        pTP.Privileges[0].Attributes = SE_PRIVILEGE_ENABLED;
        pTP.Privileges[0].Luid = uID;
    
    
        //在这里我们进行调整权限
        if (!AdjustTokenPrivileges(hToken,false,&pTP,sizeof(TOKEN_PRIVILEGES),NULL,NULL))
        {
            printf("AdjuestTokenPrivileges is Error
    ");
            return  FALSE;
        }
    
    
        return TRUE;
    
    }
  • 相关阅读:
    sublime text 前端插件安装
    echarts常用的配置项
    2018年okr
    charlse配置
    运维笔记
    移动端开发兼容问题全记录
    centos6下python开发环境搭建
    centos安装python2.7
    centos6安装MariaDB
    pzea上centos6安装mysql57
  • 原文地址:https://www.cnblogs.com/yifi/p/6527700.html
Copyright © 2011-2022 走看看