From 0e3492559c6fb2d1d3186ea13d54740376e30bb8 Mon Sep 17 00:00:00 2001 From: segfault Date: Sun, 15 Mar 2020 11:32:23 -0700 Subject: added TODOs for HUNTED Signed-off-by: Toni Uhlig --- Hunted/Hunted.cpp | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'Hunted') diff --git a/Hunted/Hunted.cpp b/Hunted/Hunted.cpp index 848d0f9..0eca6d0 100644 --- a/Hunted/Hunted.cpp +++ b/Hunted/Hunted.cpp @@ -292,7 +292,7 @@ int wmain(int argc, wchar_t **argv) *(UINT64 *)((BYTE *)cc + 31) = targetAddr + 91; *(UINT64 *)((BYTE *)cc + 41) = dll.GetEntryPoint(); /* PATTERN: 48 89 4C 24 08 48 83 EC 48 +0x275 */ - UINT64 jumpBackAddr = (UINT64)md.DllBase + 0x70875; + UINT64 jumpBackAddr = (UINT64)md.DllBase + 0x70875; /* TODO: SigScan Me! */ *(UINT64 *)((BYTE *)cc + 81) = jumpBackAddr; *(UINT64 *)((BYTE *)cc + 91) = g_pEntSys; *(UINT64 *)((BYTE *)cc + 99) = g_pEnvSysSigged; @@ -307,7 +307,7 @@ int wmain(int argc, wchar_t **argv) printBuf(dd, sizeof dd, 32); /* PATTERN: 48 89 4C 24 08 48 83 EC 48 +0x9 */ - KMemoryBuf::Wpm(targetPID, (PVOID)((UINT64)md.DllBase + 0x70609), &dd[0]); + KMemoryBuf::Wpm(targetPID, (PVOID)((UINT64)md.DllBase + 0x70609 /* TODO: SigScan Me! */), &dd[0]); } } } -- cgit v1.2.3