diff --git a/cxx-shared/cxx-shared.vcxitems b/cxx-shared/cxx-shared.vcxitems index 081badd..176a9e5 100644 --- a/cxx-shared/cxx-shared.vcxitems +++ b/cxx-shared/cxx-shared.vcxitems @@ -18,6 +18,7 @@ + \ No newline at end of file diff --git a/cxx-shared/shared/native.hpp b/cxx-shared/shared/native.hpp new file mode 100644 index 0000000..fe880a9 --- /dev/null +++ b/cxx-shared/shared/native.hpp @@ -0,0 +1,31 @@ +#pragma once +#include +#include + +#pragma pack(push, 1) +namespace native { + class PEB { + public: + std::uint8_t inherited_address_space; + std::uint8_t read_image_file_exec_options; + /// - we don't need other fields + }; + + static_assert(offsetof(PEB, read_image_file_exec_options) == 1); + + inline PEB* get_peb() { + static auto function = reinterpret_cast(GetProcAddress(GetModuleHandleA("ntdll.dll"), "RtlGetCurrentPeb")); + + if (function == nullptr) { + throw std::runtime_error("no RtlGetCurrentPeb"); + } + + static auto result = function(); + if (result == nullptr) [[unlikely]] { + throw std::runtime_error("no peb"); + } + + return result; + } +} // namespace native +#pragma pack(pop) diff --git a/defendnot-loader/core/inject.cpp b/defendnot-loader/core/inject.cpp index 6cf26fe..0f2c2db 100644 --- a/defendnot-loader/core/inject.cpp +++ b/defendnot-loader/core/inject.cpp @@ -1,6 +1,8 @@ #include "core/core.hpp" #include "shared/defer.hpp" +#include "shared/native.hpp" + #include #include @@ -19,6 +21,9 @@ namespace loader { .bInheritHandle = TRUE, }; + /// \xref: https://github.com/es3n1n/defendnot/issues/7#issuecomment-2874903650 + native::get_peb()->read_image_file_exec_options = 0; + std::println("** booting {}", proc_name); if (!CreateProcessA(nullptr, const_cast(proc_name.data()), &sa, &sa, FALSE, CREATE_SUSPENDED, nullptr, nullptr, &si, &pi)) { throw std::runtime_error(std::format("unable to create process: {}", GetLastError()));