
Carregador PE reflexivo escrito em Zig. Carrega e executa arquivos PE nativos e .NET diretamente da memória.
Carregador de PE reflexivo escrito em Zig. Carrega e executa arquivos PE nativos e .NET diretamente da memória.
__security_cookie para segurança de buffer /GS)SetProcessValidCallTargetsFunções utilitárias para resolver exportações de uma imagem PE carregada:
getExportByName(base, ntheaders, name) — resolver por nomegetExportByOrdinal(base, ntheaders, ordinal) — resolver por ordinalLida automaticamente com exportações encaminhadas carregando a DLL alvo (ex.: "NTDLL.RtlAllocateHeap" resolve para a função real em ntdll.dll).
Resolve automaticamente conjuntos de API do Windows (api-ms-win-*, ext-ms-win-*) para suas DLLs host reais usando o PEB ApiSetMap. Isso permite carregar PEs que importam de DLLs virtuais de conjuntos de API.
utils.detect_platform(buffer) — Detectar se PE é 32 ou 64 bitsutils.is_dotnet_assembly(ntheaders) — Verificar se PE é um assembly .NETutils.getDotNetVersion(buffer) — Extrair string de versão do runtime .NET dos metadadosutils.rvaToFileOffset(buffer, rva) — Converter RVA para offset de arquivo bruto| Arquitetura | Código da Máquina | Bits |
|---|---|---|
| i386 | 0x014c | 32-bit |
| AMD64 | 0x8664 | 64-bit |
| IA64 | 0x0200 | 64-bit |
| ARM (ARMNT) | 0x01C4 | 32-bit |
| ARM64 | 0xAA64 | 64-bit |
Clone o repositório:
git clone https://github.com/Thoxy67/zig-pe.git
cd zig-pe
Compile o projeto:
zig build
zig build -Ddotnet=false # Disable .NET support (enabled by default)
zig build # Build all targets
zig build run-putty64 # Run 64-bit native PE example
zig build run-putty32 # Run 32-bit native PE example
zig build run-dotnet # Run .NET assembly example
zig build test # Run unit tests
const pe = @import("pe");
pub fn main() !void {
// Load and execute an embedded PE file
try pe.RunPE.init(@embedFile("bin/app.exe")).run();
}
const pe = @import("pe");
pub fn main() !void {
var loader = pe.RunPE.init(@embedFile("bin/app.exe"));
try loader.runWithArgs(&.{ "arg1", "arg2", "arg3" });
}
const std = @import("std");
const pe = @import("pe");
pub fn main() !void {
var gpa = std.heap.GeneralPurposeAllocator(.{}){};
defer _ = gpa.deinit();
const allocator = gpa.allocator();
const file_content = try std.fs.cwd().readFileAlloc(
allocator,
"path/to/executable.exe",
std.math.maxInt(usize),
);
defer allocator.free(file_content);
try pe.RunPE.init(file_content).run();
}
const pe = @import("pe");
// After loading a DLL into memory...
const base: [*]const u8 = @ptrCast(loaded_base);
const ntheaders = // ... get NT headers
// Resolve by name
if (pe.getExportByName(base, ntheaders, "ExportedFunction")) |func_ptr| {
const func: *const fn () void = @ptrCast(@alignCast(func_ptr));
func();
}
// Resolve by ordinal
if (pe.getExportByOrdinal(base, ntheaders, 42)) |func_ptr| {
// Use the function pointer
}
GetCommandLineW() retorne os argumentos fornecidosMain(string[] args) via invocação do CLREste projeto envolve carregar e executar código arbitrário, o que pode ser potencialmente perigoso. Use este carregador apenas com arquivos PE confiáveis e em ambientes controlados. Os autores não são responsáveis por qualquer uso indevido ou dano causado por este software.
Contribuições para zig-pe são bem-vindas! Sinta-se à vontade para enviar pull requests, criar issues ou divulgar.
git checkout -b feature/AmazingFeature)git commit -m 'Add some AmazingFeature')git push origin feature/AmazingFeature)Este projeto está licenciado sob a Licença MIT - consulte o arquivo LICENSE para detalhes.
Este projeto é apenas para fins educacionais. Certifique-se de ter os direitos e permissões necessários antes de carregar e executar qualquer arquivo PE.