hasherezade / pe_to_shellcode

Converts PE into a shellcode
https://www.youtube.com/watch?v=WQCiM0X11TA
BSD 2-Clause "Simplified" License
2.27k stars 423 forks source link

Your project can't inject to "OneDrive"! #28

Open Hames0024 opened 1 year ago

Hames0024 commented 1 year ago

hi there. why doesn't inject you project to OneDrive? Is it bug?

hasherezade commented 1 year ago

hi @Hames0024 ! some questions:

On the sidenote I just tried to make and injection to OneDrive on my test machine, and everything worked fine.

Hames0024 commented 1 year ago

Thank you for your reply I think the reason is in SetProcessMitigationPolicy function. But I don't know what the parameter has to be in that function. I thank you if you send the parameter value of SetProcessMitigationPolicy, with example.

Regards.

Sent with Proton Mail secure email.

------- Original Message ------- On Sunday, July 24th, 2022 at 9:55 AM, hasherezade @.***> wrote:

hi @.***(https://github.com/Hames0024) ! some questions:

  • did the shellcode that you generated was tested, and runs properly with runshc32/64 (appropriate to its bitness)?
  • are you sure that the shellcode has the same bitness as the target, and the injector that you used has the same bitness? (Mismatch in the biness will always cause the injection failure, and it is not a bug)
  • what are the process mitigation policies set on the target?

On the sidenote I just tried to make and injection to OneDrive on my test machine, and everything worked fine.

— Reply to this email directly, view it on GitHub, or unsubscribe. You are receiving this because you were mentioned.Message ID: @.***>

hasherezade commented 1 year ago

why do you think the problem lies in this function? can you please answer my other questions? I need more information to be able to help you.

Hames0024 commented 1 year ago

my telegram id is @blackkal.

Let's discuss more about injection on telegram. I will wait

Regards

Sent with Proton Mail secure email.

------- Original Message ------- On Wednesday, July 27th, 2022 at 4:30 AM, hasherezade @.***> wrote:

why do you think the problem lies in this function? can you please answer my other questions? I need more information to be able to help you.

— Reply to this email directly, view it on GitHub, or unsubscribe. You are receiving this because you were mentioned.Message ID: @.***>