[RELEASE] Step 1!!! NbIDS(2)

Posts 1–7 of 7 · Page 1 of 1
[RELEASE] Step 1!!! NbIDS(2)
Hi everyone, remember that a long time ago I asked a question about how to read local port numbers? (Here)

I've done some research and I finaly have the first part of my IDS finished, so I thought it'd be nice if I'd released it here

But before I release the code let me explain some things

Overloading

Often you'll find that a function you wish to use uses other data types or uses the data you supplie in another way then you need

There's a way around this problem, and it's called Overloading

Say you have a function that looks like this:

Code:
int add(int a,  int b){
return  a + b;
}
But instead of using int's you want to use values of type double, you could just create another function, with another name. But what if this function is one of the standard libs?
So you're just going to overload the function!
Which is done like this:

Code:
int add(int a,  int b){
return  a + b;
}
double add(double a, double b){
return a + b;
}
Now if you call the function like this:
Code:
int i = ( int x  = 2, int z = 1 ) // the compiler choses to use the int version of add since it uses integer parameters (which are suplied here)
Now if you call it with type double the compiler will automaticly deside which of the functions to use based on it's parameter list, these list differ from each other in their types so the compiler can distinguish one from another

Summary:

You'd use overloading instead of using templates when overloading operators or Functions found in one of the Standard Library's or other important sources

You can have two functions with the same name, as long as their parameter lists have different data types

The compiler destinguishes two functions from one another when:

The number of parameters for each function is different

The number of parameters is the same, but at least one pair of corresponding parameters has different types

Headers used:

winsock2.h
iphlpapi.h

Library's used:

iphlpapi.lib

Standard library's used:

iostream

Namspaces used:

std

Source

Main.h

Code:
#pragma comment "Main.h"

#include <iostream>
#include <winsock2.h>
#include <iphlpapi.h>

#pragma comment(lib, "iphlpapi.lib")


using namespace std;
Main.cpp

Code:
#include "Main.h"


int GetTable() {
	    DWORD size = 0;
	  
		DWORD extdreturn = GetExtendedTcpTable(NULL, &size, TRUE, AF_INET, TCP_TABLE_OWNER_PID_ALL, NULL); //If a wrong buffer size is provided (DWORD size = 0) the value returned to this buffer equals the size of the current TCP structure
	   
		//we now know the table size so we can use that to create a new stucture containing all the information we need without hard-coding the structure size

	    PMIB_TCPTABLE_OWNER_PID NewTcpTable = (PMIB_TCPTABLE_OWNER_PID) new char[size];  // Dynamicly allocate a PMIB_TCPTABLE_OWNER_PID array with the obtained pTcpTable structere size

//We use a char for this because a char is exactly one byte big in memory so the array wil have exactly the right size (if we were using an integer for example the size of the array would be: size * 4 because an integer is 4 bytes long)

	    extdreturn = GetExtendedTcpTable(NewTcpTable, &size, TRUE, AF_INET, TCP_TABLE_OWNER_PID_ALL, NULL);  //copy pTcpTable to a pTcpTable called table 


	    if (extdreturn != NO_ERROR) {  // Check for errors 
			cerr << "Error in GetTable: "<<extdreturn<< endl;  // if errors spit them out
	        } 
	    return (int)NewTcpTable;  //return the table structure 
	}

	
      ostream& operator<<(ostream& out, const in_addr& RoLIP) { // overloading the << operator, if the compiler sees that '<<' tries to output in_addr (the parameter) it choses this overloaded function/operator as the one to be executed
		  
	    out << ( int)RoLIP.S_un.S_un_b.s_b1 << '.' // print the first 3 numbers of a ip addres and a '.'
	        << ( int)RoLIP.S_un.S_un_b.s_b2 << '.'  // the second 3 numbers and a '.'
	        << ( int)RoLIP.S_un.S_un_b.s_b3 << '.' // the third 3 numbers and a '.'
	        << ( int)RoLIP.S_un.S_un_b.s_b4;   // the last 3 numbers 
	    return out;   //return execution
	  }
	 
	ostream& operator<<(ostream& out, const MIB_TCPROW_OWNER_PID& table) {  //overloading the << operator again, if the compiler sees that '<<' tries to output MIB_TCPROW_OWNER_PID (the parameter) it choses this overloaded function/operator as the one to executed

	    out << "state: " << table.dwState << endl;  //cout the size of a connection (listening, bound, waiting, etc, etc for more info look up on: port states)
	    in_addr LocalIp, RemoteIp;   // Declare 2 in_addr types (used for IPv4 addresses in socket programming and stuff like that) 
	    LocalIp.S_un.S_addr = table.dwLocalAddr;   // initialize the local ip addres with our table addr
	    RemoteIp.S_un.S_addr = table.dwRemoteAddr;  // do the same with the remote ip address
	    out << "local: " <<  LocalIp  << ":" << table.dwLocalPort << endl;   //print the local ip and local port numbers, remember the printing of the local ip is done in the other overloaded function
	    out << "remote: " <<  RemoteIp  << ":" << table.dwRemotePort << endl;  // do the same for the remote ip and port numbers
	    out << "Owner: " << table.dwOwningPid << endl;  // print the Process id of the process owning the connection
	    return out;  //return exectution
	}



	
int main(){
DWORD NewTSize = 0;  // Using the same trick as before to get the table size
MIB_TCPTABLE_OWNER_PID *IP4Tables;  // declare our pTCPtable


IP4Tables = (MIB_TCPTABLE_OWNER_PID *)GetTable();  // initilize our Table->table

cout<<"There are: " << IP4Tables->dwNumEntries <<" Connections"<< endl << endl;  //Tell the user all connections

DWORD Stat = GetExtendedTcpTable(IP4Tables, &NewTSize, TRUE, AF_INET, TCP_TABLE_OWNER_PID_ALL, NULL);  //Shove all data to the TPCTABLE IP4Tables


         if (Stat == ERROR_INVALID_PARAMETER ) {  // Check for errors 
			cerr << "Error in Main: "<<Stat<< endl; // if there are errors spit them out
	        } 


for(int i = 0; i != IP4Tables->dwNumEntries; i++){  // loop through all entries
 cout << IP4Tables->table[i] << endl;  //spit them out using our overloaded operators (<< was overloaded remember?) 
}

ZeroMemory((void *)IP4Tables, sizeof(IP4Tables));   //When we're done change all data to '0' 
delete[] IP4Tables; // delte the buffer

cin.ignore();  // wait for imput and then close

}
On to step 2

Ok so now I've completed step 1, I'm going for step 2, I want to check on data flying in and out my system and prefroming scans on these chuncks of data, if you've any links to theory, source or tutorials on this topic please post them Thanks in advance

-SCHiM
Ideas are still welcome, c'mon someone must know about capturing data trafic no?
Quote Originally Posted by schim View Post
Ideas are still welcome, c'mon someone must know about capturing data trafic no?
I use WPE pro for capturing, if I need to edit I hook send/wsasend and use pattern scanning and replacing.

Code:
// Credits: Dominik, Patrick

unsigned long dwStartAddress = 0x00401000, dwLen = 0x00861FFF;

bool bDataCompare(const unsigned char* pData, const unsigned char* bMask, const char* szMask)
{
    for(;*szMask;++szMask,++pData,++bMask)
        if(*szMask=='x' && *pData!=*bMask )
            return false;
    return (*szMask) == 0;
}

unsigned long dwFindPattern( unsigned char *bMask,char * szMask, unsigned long dw_Address = dwStartAddress, unsigned long dw_Len = dwLen )
{
    for(unsigned long i=0; i < dw_Len; i++)
		if( bDataCompare( (unsigned char*)( dw_Address+i ),bMask,szMask) )
            return (unsigned long)(dw_Address+i);
    return 0;
}
just point it to your recieved buffer and set len to the string length of the buffer =
I already have a Bcompare function (remember I asked how to check memory in other programs)
But maybe'll use this
ReadProcessMemory, when the first char of the sig matches a char in the buffer read into a seperate buffer with length = sig length and start = buffer location, compare and repeat untill you have a match
Quote Originally Posted by Hell_Demon View Post
ReadProcessMemory, when the first char of the sig matches a char in the buffer read into a seperate buffer with length = sig length and start = buffer location, compare and repeat untill you have a match
True, but back in how to read from other proccesses I'd do it another way, I think I'm going to put that in the kernel part of my IDS because then you can just dereference all addresses (kernel is beast!! ) just like you'd do it inside a dll

But for now I still don't know how I can scan my packets (since I still haven't fixed it yet) Here...

Posts 1–7 of 7 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us