- Joined
- Apr 4, 2009
- Messages
- 898
- Reaction score
- 157
Another idea I had for executable protection: an application relying on threads to modify registers to change the control and flow of an application.
For example, Thread 1 launches Thread 2; Thread 2 suspends Thread 1, then changes the EIP/RIP to point to a different function, and resumes; in this new function, Thread 1 executes some permutated/obfuscated code, then alters Thread 2 to execute in a similar manner.
CC?
EDIT:
Quick example:
For example, Thread 1 launches Thread 2; Thread 2 suspends Thread 1, then changes the EIP/RIP to point to a different function, and resumes; in this new function, Thread 1 executes some permutated/obfuscated code, then alters Thread 2 to execute in a similar manner.
CC?
EDIT:
Quick example:
Code:
#pragma once
#define WIN32_LEAN_AND_MEAN
#include <windows.h>
#pragma comment( linker, "/SUBSYSTEM:WINDOWS" )
#pragma comment( linker, "/ENTRY:main" )
DWORD CurrentThread = 1;
HANDLE MainThreadHandle, SecondaryThreadHandle;
DWORD MainThreadId;
void Test( )
{
MessageBox( 0, "Redirected", "", MB_OK );
}
void SecondaryThread( )
{
CONTEXT ctx;
ctx.ContextFlags = CONTEXT_FULL;
MainThreadHandle = OpenThread( THREAD_SET_CONTEXT | THREAD_GET_CONTEXT | THREAD_SUSPEND_RESUME, FALSE, MainThreadId );
GetThreadContext( MainThreadHandle, &ctx );
ctx.Eip = ( DWORD_PTR ) Test;
SuspendThread( MainThreadHandle );
SetThreadContext( MainThreadHandle, &ctx );
ResumeThread( MainThreadHandle );
CloseHandle( MainThreadHandle );
CurrentThread = 0;
}
void main( )
{
MainThreadId = GetCurrentThreadId( );
CreateThread( 0, 0, ( LPTHREAD_START_ROUTINE ) SecondaryThread, 0, 0, 0 );
while( CurrentThread )
Sleep( 10 );
}
Last edited:

