FazBrowse GitHub Viewer
|
Trending
|
URL:
|
Home
Tools:
[Download Repo ZIP]
[View Raw Code]
[Original HTTPS Page]
DllToShellCode/DllToShellCode/compress.c at master · Laster-dev/DllToShellCode · GitHub
Laster-dev
/
DllToShellCode
Public
forked from
killeven/DllToShellCode
Notifications
You must be signed in to change notification settings
Fork
0
Star
0
Code
Pull requests
0
Actions
Projects
Security and quality
0
Insights
Additional navigation options
Code
Pull requests
Actions
Projects
Security and quality
Insights
Expand file tree
Breadcrumbs
DllToShellCode
/
DllToShellCode
/
compress.c
Copy path
More file actions
More file actions
Latest commit
History
History
History
80 lines (74 loc) · 2.41 KB
Breadcrumbs
DllToShellCode
/
DllToShellCode
/
compress.c
Copy path
File metadata and controls
80 lines (74 loc) · 2.41 KB
Raw
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
#include
"compress.h"
#include
"aplib.h"
#include
<stdio.h>
#include
<windows.h>
#ifdef
_WIN64
# pragma
comment(lib, "aplib_x64.lib")
#else
# pragma
comment(lib, "aplib_x86.lib")
#endif
// _WIN64
#ifndef
NT_SUCCESS
# define
NT_SUCCESS
(
s
) ((NTSTATUS)(s)>=0)
#endif
// NT_SUCCESS
typedef
NTSTATUS
(__stdcall
*
_RtlCompressBuffer
)(
USHORT
CompressionFormatAndEngine
,
PUCHAR
UncompressedBuffer
,
ULONG
UncompressedBufferSize
,
PUCHAR
CompressedBuffer
,
ULONG
CompressedBufferSize
,
ULONG
UncompressedChunkSize
,
PULONG
FinalCompressedSize
,
PVOID
WorkSpace
);
typedef
NTSTATUS
(__stdcall
*
_RtlGetCompressionWorkSpaceSize
)(
USHORT
CompressionFormatAndEngine
,
PULONG
CompressBufferWorkSpaceSize
,
PULONG
CompressFragmentWorkSpaceSize
);
unsigned
int
nt_compress
(
void
*
src
,
unsigned
int
srclen
,
void
*
dest
,
unsigned
int
destlen
) {
HMODULE
ntdll
=
GetModuleHandle
(
"ntdll"
);
_RtlGetCompressionWorkSpaceSize
xRtlGetCompressionWorkSpaceSize
=
(
_RtlGetCompressionWorkSpaceSize
)
GetProcAddress
(
ntdll
,
"RtlGetCompressionWorkSpaceSize"
);
_RtlCompressBuffer
xRtlCompressBuffer
=
(
_RtlCompressBuffer
)
GetProcAddress
(
ntdll
,
"RtlCompressBuffer"
);
if
(
xRtlCompressBuffer
==
0
||
xRtlCompressBuffer
==
0
) {
printf
(
"get compress function error.\n"
);
return
COMPRESS_ERROR
;
}
ULONG
compressWorkSpaceSize
=
0
,
compressFragmentSpaceSize
;
NTSTATUS
ret
=
xRtlGetCompressionWorkSpaceSize
(
COMPRESSION_FORMAT_LZNT1
|
COMPRESSION_ENGINE_MAXIMUM
,
&
compressWorkSpaceSize
,
&
compressFragmentSpaceSize
);
if
(!
NT_SUCCESS
(
ret
)) {
printf
(
"get compression work space size error.\n"
);
return
COMPRESS_ERROR
;
}
void
*
compressWorkSpace
=
malloc
(
compressWorkSpaceSize
);
if
(
compressWorkSpace
==
0
) {
printf
(
"malloc work space error.\n"
);
return
COMPRESS_ERROR
;
}
ULONG
compressedSize
;
ret
=
xRtlCompressBuffer
(
COMPRESSION_FORMAT_LZNT1
|
COMPRESSION_ENGINE_MAXIMUM
,
(
PUCHAR
)
src
,
srclen
,
(
PUCHAR
)
dest
,
destlen
,
0
,
&
compressedSize
,
compressWorkSpace
);
free
(
compressWorkSpace
);
if
(!
NT_SUCCESS
(
ret
)) {
printf
(
"compress buffer error.\n"
);
return
COMPRESS_ERROR
;
}
return
(
unsigned
int
)
compressedSize
;
};
unsigned
int
aplib_compress
(
void
*
src
,
unsigned
int
srclen
,
void
*
dest
,
unsigned
int
destlen
) {
void
*
workMemory
=
malloc
(
aP_workmem_size
(
srclen
));
if
(
workMemory
==
0
) {
printf
(
"get compression work space size error.\n"
);
return
COMPRESS_ERROR
;
}
unsigned
int
ret
=
aP_pack
(
src
,
dest
,
srclen
,
workMemory
,
0
,
0
);
free
(
workMemory
);
return
ret
;
};
Back
|
FazBrowse Home
|
New Git URL