Maff1t / WindowsPermsPoC

A simple PoC to demonstrate that is possible to write Non writable memory and execute Non executable memory on Windows
52 stars 9 forks source link

WindowsPermsPoC

A simple PoC to demonstrate that is possible to write Non writable memory and execute Non executable memory on Windows You can build it using Visual Studio.

Writing non-writable memory

This simple program, allocate a non-writable piece of memory using VirtualAlloc and writes a shellcode inside of it, using WriteProcessMemory.

This is made possible by the fact that WriteProcessMemory is a function designed for debuggers so, under the hood, it changes permissions (calling syscall NtVirtualProtectMemory) and restores them at the end.

Executing non-executable memory

At the end of our program, the permissions of the allocated memory is changed to READ_ONLY, and the shellcode is executed. How is this possible?

The execution of code in a non-executable memory area in modern operating systems is prevented by a protection system called DEP (Data Execution Prevention). However, this mechanism is not enforced by the operating system, but it is up to the developer decide whether to enable it or not in his program, e.g. by setting the NXCOMPAT flag in VisualStudio. More details about this, here.