|
| 1 | +import sys |
| 2 | +import os.path |
| 3 | +import pprint |
| 4 | +import argparse |
| 5 | +sys.path.append(os.path.abspath(__file__ + "\..\..")) |
| 6 | + |
| 7 | +import windows |
| 8 | +import windows.debug |
| 9 | +import windows.generated_def as gdef |
| 10 | + |
| 11 | +class FollowNtCreateFile(windows.debug.FunctionBP): |
| 12 | + TARGET = windows.winproxy.NtCreateFile |
| 13 | + |
| 14 | + def trigger(self, dbg, exc): |
| 15 | + params = self.extract_arguments(dbg.current_process, dbg.current_thread) |
| 16 | + filename = params["ObjectAttributes"].contents.ObjectName.contents.str |
| 17 | + handle_addr = params["FileHandle"].value |
| 18 | + self.data = (filename, handle_addr) |
| 19 | + self.break_on_ret(dbg, exc) |
| 20 | + |
| 21 | + def ret_trigger(self, dbg, exc): |
| 22 | + filename, handle_addr = self.data |
| 23 | + ret_value = dbg.current_thread.context.func_result # EAX / RAX depending of bitness |
| 24 | + if ret_value: |
| 25 | + return # Creation failed |
| 26 | + handle_value = dbg.current_process.read_ptr(handle_addr) |
| 27 | + return dbg.on_file_create(filename, handle_value) |
| 28 | + |
| 29 | +class FollowReadFile(windows.debug.FunctionBP): |
| 30 | + TARGET = windows.winproxy.ReadFile |
| 31 | + |
| 32 | + def trigger(self, dbg, exc): |
| 33 | + params = self.extract_arguments(dbg.current_process, dbg.current_thread) |
| 34 | + self.data = params |
| 35 | + if params["hFile"] in dbg.followed_handles: |
| 36 | + self.break_on_ret(dbg, exc) |
| 37 | + |
| 38 | + def ret_trigger(self, dbg, exc): |
| 39 | + params = self.data |
| 40 | + ret_value = dbg.current_thread.context.func_result |
| 41 | + if not ret_value: # Read failed |
| 42 | + return |
| 43 | + buffer_size = dbg.current_process.read_dword(params["lpNumberOfBytesRead"]) |
| 44 | + read_data = dbg.current_process.read_memory(params["lpBuffer"], buffer_size) |
| 45 | + return dbg.on_file_read(params["hFile"], read_data) |
| 46 | + |
| 47 | +class FollowWriteFile(windows.debug.FunctionBP): |
| 48 | + TARGET = windows.winproxy.WriteFile |
| 49 | + |
| 50 | + def trigger(self, dbg, exc): |
| 51 | + params = self.extract_arguments(dbg.current_process, dbg.current_thread) |
| 52 | + write_data = dbg.current_process.read_memory(params["lpBuffer"], params["nNumberOfBytesToWrite"]) |
| 53 | + return dbg.on_file_write(params["hFile"], write_data) |
| 54 | + |
| 55 | +class FollowCloseFile(windows.debug.FunctionBP): |
| 56 | + TARGET = windows.winproxy.CloseHandle |
| 57 | + |
| 58 | + def trigger(self, dbg, exc): |
| 59 | + params = self.extract_arguments(dbg.current_process, dbg.current_thread) |
| 60 | + return dbg.on_file_close(params["hObject"]) |
| 61 | + |
| 62 | + |
| 63 | +class FileFollowDebugger(windows.debug.Debugger): |
| 64 | + def __init__(self, target, filenames): |
| 65 | + super(FileFollowDebugger, self).__init__(target) |
| 66 | + self.filenames = filenames |
| 67 | + self.followed_handles = {} |
| 68 | + self.add_bp(FollowNtCreateFile()) |
| 69 | + self.add_bp(FollowReadFile()) |
| 70 | + self.add_bp(FollowWriteFile()) |
| 71 | + self.add_bp(FollowCloseFile()) |
| 72 | + |
| 73 | + def on_exception(self, exc): |
| 74 | + if exc.ExceptionRecord.ExceptionCode == gdef.EXCEPTION_BREAKPOINT: |
| 75 | + return gdef.DBG_CONTINUE |
| 76 | + return gdef.DBG_EXCEPTION_NOT_HANDLED |
| 77 | + |
| 78 | + def on_file_create(self, filename, handle): |
| 79 | + if any(filename.lower().endswith(fname) for fname in self.filenames): |
| 80 | + self.followed_handles[handle] = filename |
| 81 | + print("Opened <{0}> as handle <{1:#x}>".format(filename, handle)) |
| 82 | + |
| 83 | + |
| 84 | + def on_file_read(self, handle, data): |
| 85 | + filename = self.followed_handles[handle] |
| 86 | + print("Read from <{0}> ({1:#x})".format(filename, handle)) |
| 87 | + print(repr(data)) |
| 88 | + |
| 89 | + def on_file_write(self, handle, data): |
| 90 | + filename = self.followed_handles[handle] |
| 91 | + print("Write to <{0}> ({1:#x})".format(filename, handle)) |
| 92 | + print(repr(data)) |
| 93 | + |
| 94 | + def on_file_close(self, handle): |
| 95 | + try: |
| 96 | + filename = self.followed_handles[handle] |
| 97 | + except KeyError as e: |
| 98 | + return |
| 99 | + print("Closing handle <{0:#x}> to <{1}>".format(handle, filename)) |
| 100 | + del self.followed_handles[handle] |
| 101 | + |
| 102 | + |
| 103 | + |
| 104 | +if __name__ == "__main__": |
| 105 | + parser = argparse.ArgumentParser(prog=__file__) |
| 106 | + parser.add_argument('exe') |
| 107 | + parser.add_argument('--cmdline', default="") |
| 108 | + parser.add_argument('files', nargs="+") |
| 109 | + args = parser.parse_args() |
| 110 | + print(args) |
| 111 | + |
| 112 | + target = windows.utils.create_process(args.exe, args.cmdline.split(), dwCreationFlags=gdef.DEBUG_PROCESS, show_windows=True) |
| 113 | + |
| 114 | + dbg = FileFollowDebugger(target, args.files) |
| 115 | + dbg.loop() |
| 116 | + print("BYE") |
| 117 | + |
| 118 | + |
0 commit comments