简体   繁体   English

使用 PPID 欺骗路由进程的标准输出

[英]Routing stdout of process with PPID Spoofing

I tried to write a code that uses CreateProcess() to execute CMD commands and will redirect the stdout to a named pipe.我试图编写一个使用CreateProcess()来执行CMD命令并将stdout重定向到命名管道的代码。 I wanted to add a functionality to spoof the Parent PID so that the cmd will spawn under explorer.exe.我想添加一个功能来欺骗父 PID,以便 cmd 将在 explorer.exe 下生成。 Each of the functionalities works on it's own but when I tried to merge them it will not work.每个功能都可以独立工作,但是当我尝试合并它们时,它不起作用。

The stdout routing:标准输出路由:

int main()
{
    HANDLE hStdout_Rd = NULL;
    HANDLE hStdout_Wr = NULL;
    SECURITY_ATTRIBUTES saAttr;
    saAttr.nLength = sizeof(SECURITY_ATTRIBUTES);
    saAttr.bInheritHandle = TRUE;
    saAttr.lpSecurityDescriptor = NULL;

    CreatePipe(&hStdout_Rd, &hStdout_Wr, &saAttr, NULL);
    SetHandleInformation(hStdout_Rd, HANDLE_FLAG_INHERIT, 0);

    //Set startup info
    STARTUPINFO si;
    ZeroMemory(&si, (sizeof(STARTUPINFO)));
    si.cb = sizeof(STARTUPINFO);
    si.dwFlags = STARTF_USESHOWWINDOW | STARTF_USESTDHANDLES;
    si.hStdError = hStdout_Wr;
    si.hStdOutput = hStdout_Wr;
    si.wShowWindow = SW_HIDE;

    PROCESS_INFORMATION pi;
    ZeroMemory(&pi, sizeof(PROCESS_INFORMATION));
    CString cmd;
    if (CreateProcess(NULL, cmd.GetBuffer(), NULL, NULL, TRUE, 0, NULL, NULL, &si, &pi))
    {
        //Great success read pipe contents
    }
    CloseHandle(hStdout_Rd);
    CloseHandle(hStdout_Wr);
}

The PPID Spoof: PPID 欺骗:

int main() {

    CString cmd;
    STARTUPINFOEXA sInfoEX;
    PROCESS_INFORMATION pInfo;
    SIZE_T sizeT;

    HANDLE expHandle = OpenProcess(PROCESS_ALL_ACCESS, false, getParentProcessID());

    ZeroMemory(&sInfoEX, sizeof(STARTUPINFOEXA));
    InitializeProcThreadAttributeList(NULL, 1, 0, &sizeT);
    sInfoEX.lpAttributeList = (LPPROC_THREAD_ATTRIBUTE_LIST)HeapAlloc(GetProcessHeap(), 0, sizeT);
    InitializeProcThreadAttributeList(sInfoEX.lpAttributeList, 1, 0, &sizeT);
    UpdateProcThreadAttribute(sInfoEX.lpAttributeList, 0, PROC_THREAD_ATTRIBUTE_PARENT_PROCESS, &expHandle, sizeof(HANDLE), NULL, NULL);
    sInfoEX.StartupInfo.cb = sizeof(STARTUPINFOEXA);

    CreateProcessA(NULL, cmd.GetBuffer(), NULL, NULL, TRUE, CREATE_SUSPENDED | CREATE_NO_WINDOW | EXTENDED_STARTUPINFO_PRESENT, NULL, NULL, reinterpret_cast<LPSTARTUPINFOA>(&sInfoEX), &pInfo);


    return 0;
}

All Together:全部一起:

int main() {

    HANDLE hStdout_Rd = NULL;
    HANDLE hStdout_Wr = NULL;
    SECURITY_ATTRIBUTES saAttr;
    saAttr.nLength = sizeof(SECURITY_ATTRIBUTES);
    saAttr.bInheritHandle = TRUE;
    saAttr.lpSecurityDescriptor = NULL;
    CString cmd;
    STARTUPINFOEXA sInfoEX;
    PROCESS_INFORMATION pInfo;
    ZeroMemory(&pInfo, sizeof(PROCESS_INFORMATION));
    SIZE_T sizeT;

    HANDLE expHandle = OpenProcess(PROCESS_ALL_ACCESS, false, getParentProcessID());

    ZeroMemory(&sInfoEX, sizeof(STARTUPINFOEXA));
    sInfoEX.StartupInfo = sizeof(STARTUPINFO);
    sInfoEX.StartupInfo = STARTF_USESHOWWINDOW | STARTF_USESTDHANDLES;
    sInfoEX.StartupInfo = hStdout_Wr;
    sInfoEX.StartupInfo = hStdout_Wr;
    sInfoEX.StartupInfo = SW_HIDE;
    InitializeProcThreadAttributeList(NULL, 1, 0, &sizeT);
    sInfoEX.lpAttributeList = (LPPROC_THREAD_ATTRIBUTE_LIST)HeapAlloc(GetProcessHeap(), 0, sizeT);
    InitializeProcThreadAttributeList(sInfoEX.lpAttributeList, 1, 0, &sizeT);
    UpdateProcThreadAttribute(sInfoEX.lpAttributeList, 0, PROC_THREAD_ATTRIBUTE_PARENT_PROCESS, &expHandle, sizeof(HANDLE), NULL, NULL);
    sInfoEX.StartupInfo.cb = sizeof(STARTUPINFOEXA);

    if (CreateProcessA(NULL, cmd.GetBuffer(), NULL, NULL, TRUE, CREATE_SUSPENDED | CREATE_NO_WINDOW | EXTENDED_STARTUPINFO_PRESENT, NULL, NULL, reinterpret_cast<LPSTARTUPINFOA>(&sInfoEX), &pInfo))
    {
        //Read pipe contents
    }
    return 0;
}

Is there anything I'm missing?有什么我想念的吗?

Each of the functionalities works on it's own but when I tried to merge them it will not work.每个功能都可以独立工作,但是当我尝试合并它们时,它不起作用。

An anonymous pipe is an unnamed, one-way pipe that typically transfers data between a parent process and a child process.匿名管道是一种未命名的单向管道,通常在父进程和子进程之间传输数据。 To communicate using the pipe, the pipe server must pass a pipe handle to another process.要使用管道进行通信,管道服务器必须将管道句柄传递给另一个进程。 Usually, this is done through inheritance ;通常,这是通过继承完成的; that is, the process allows the handle to be inherited by a child process.也就是说,进程允许子进程继承句柄。

Since you change the child process's parent to explorer.exe.由于您将子进程的父进程更改为 explorer.exe。 Initial parent-child relationship no longer exist.最初的父子关系不再存在。 So the new process can't access the handle ( hStdout_Wr ) created in the old parent process.因此,新进程无法访问在旧父进程中创建的handle ( hStdout_Wr )。 That's why it stops working.这就是它停止工作的原因。

To achieve your purpose:为了达到您的目的:

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM