PEB Stealing

Posts 1–14 of 14 · Page 1 of 1
PEB Stealing
Here is the source to an Aneurysm function I made just a bit ago for debugging foreign processes.

Code:
void* AneurysmForeignPEBPointer(char* pAddress)
{
	void* pPEB;
	*pAddress = 0x64;
	*(char*)(pAddress+1) = 0xA1;
	*(DWORD*)(pAddress+2) = 0x00000030;
	*(char*)(pAddress+6) = 0x64;
        *(char*)(pAddress+7) = 0x00;
        *(DWORD*)(pAddress+8) = &pPEB;
        while(!pPEB)Sleep(100);
	return pPEB;
}
Basically this is used for inserting
Code:
mov eax, fs:[0x30]
mov pPEB, eax
into memory, which when executed will move the pointer to the PEB to our variable.

Saltine did me the favor of watching, thanks for that.
Quote Originally Posted by poplm2 View Post
Here is the source to an Aneurysm function I made just a bit ago for debugging foreign processes.

Code:
void* AneurysmForeignPEBPointer(char* pAddress)
{
	void* pPEB;
	*pAddress = 0x64;
	*(char*)(pAddress+1) = 0xA1;
	*(DWORD*)(pAddress+2) = 0x00000030;
	__asm mov pPEB, eax
	return pPEB;
}
Saltine did me the favor of watching, thanks for that.
Or you could just do:

Code:
void *getPEB(void)
{
    void *pData;
    __asm
    {
        mov eax, fs:[18h]
        mov eax, [eax + 30h]
        mov pData, eax
    }
    return pData;
}
Quote Originally Posted by Jason View Post


Or you could just do:

Code:
void *getPEB(void)
{
    void *pData;
    __asm
    {
        mov eax, fs:[18h]
        mov eax, [eax + 30h]
        mov pData, eax
    }
    return pData;
}
No, actually you couldn't. Look up the terms before posting.
Quote Originally Posted by poplm2 View Post
No, actually you couldn't. Look up the terms before posting.
Do you even know what the PEB is? Rofl.
Quote Originally Posted by Jason View Post


Do you even know what the PEB is? Rofl.
Before you start insulting people, read the post.

Hereⓘ, for those of you who are as retarded as this guy.
Quote Originally Posted by poplm2 View Post
Before you start insulting people, read the post.

Here, for those of you who are as retarded as this guy.
Roflololol you didn't have any link NOR background informaton in your first post. You said you were getting the PEB (Process Environment Block for those who are wondering) of a process. I simply offered a more succint way of getting the PEB. No need to get all mad and shit LOL.

Now that I've seen the thread I can tell you that's a horrible way of doing things lol, AND I get to report you for external links too. Excellent.
It's for getting the PEB of a foreign process.... It's great that after all this time, you've yet missed that.
Quote Originally Posted by poplm2 View Post
It's for getting the PEB of a foreign process.... It's great that after all this time, you've yet missed that.
Lol and yours is? Dereferencing local addresses, yeah that DOES get the remote process's PEB, forgot about that.

Sigh, there's already existing Windows API functions to do this:

ZwQueryInformationProcess

is juse one of them.

Also, the inline asm you used in your first post makes zero sense.
Well, I've enjoyed our in depth conversation on this matter, although, I now declare thou troll.

Yes, there are many methods for getting this information, but for people that don't like relying on Microsoft API, this is another option.

Thanks for wasting my time, next time bring something interesting to the conversation.
Quote Originally Posted by poplm2 View Post
Well, I've enjoyed our in depth conversation on this matter, although, I now declare thou troll.

Yes, there are many methods for getting this information, but for people that don't like relying on Microsoft API, this is another option.

Thanks for wasting my time, next time bring something interesting to the conversation.
You declare me troll? You're just a script kiddie who has no idea what they're actually doing and when someone points this out they scream and fuss and insist that the other person is 'wrong' or a 'troll'. I've used the PEB a lot before, and I know how to get the pointer to it, either by using the Windows API for via other methods. Maybe instead of being stubborn and pigheaded you could actually read and synthesize what other people stay instead of raging at them with your inadequate knowledge.

As for 'not wanting to rely on the Microsoft API', yeah that makes total sense. How could Microsoft POSSIBLY know how to get information about a Windows-SPECIFIC section of process. This shit isn't cross-compatible with other operating systems and I daresay Microsoft knows their own operating system better than you do.

Food for thought. I know you probably won't end up doing this. But hey, gotta try at least help the leechers, my good deed for the day is done.
Updated, hopefully you can figure out what it does now.
If your not going to understand it, and act like you do, don't post. If your purposely trolling, take it elsewhere. Thanks.
Quote Originally Posted by poplm2 View Post
If your not going to understand it, and act like you do, don't post. If your purposely trolling, take it elsewhere. Thanks.
He is not trolling. You're the one who don't know anything.

/Closed.
Posts 1–14 of 14 · Page 1 of 1
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Talk with us