Files
metasploit-gs/lib/rex/post/meterpreter/extensions/stdapi/sys/thread.rb
T

Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

198 lines
4.3 KiB
Ruby
Raw Normal View History

# -*- coding: binary -*-
2005-04-16 07:29:06 +00:00
2005-07-09 21:18:49 +00:00
require 'rex/post/thread'
require 'rex/post/meterpreter/client'
require 'rex/post/meterpreter/extensions/stdapi/constants'
2005-04-16 07:29:06 +00:00
module Rex
module Post
module Meterpreter
module Extensions
module Stdapi
module Sys
##
#
2011-11-20 11:39:27 +11:00
# This class implements the Rex::Post::Thread interface which
2005-04-16 07:29:06 +00:00
# wrappers a logical thread for a given process.
#
##
class Thread < Rex::Post::Thread
include Rex::Post::Meterpreter::ObjectAliasesContainer
##
#
# Constructor
#
##
2013-08-30 16:28:33 -05:00
2005-11-15 05:22:13 +00:00
#
# Initialize the thread instance.
#
2005-04-16 07:29:06 +00:00
def initialize(process, handle, tid)
self.process = process
self.handle = handle
self.tid = tid
# Ensure the remote object is closed when all references are removed
ObjectSpace.define_finalizer(self, self.class.finalize(process.client, handle))
end
def self.finalize(client,handle)
proc do
deferred_close_proc = proc do
begin
self.close(client, handle)
rescue => e
elog("finalize method for thread failed", error: e)
end
end
# Schedule the finalizing logic out-of-band; as this logic might be called in the context of a Signal.trap, which can't synchronize mutexes
client.framework.sessions.schedule(deferred_close_proc)
end
2005-04-16 07:29:06 +00:00
end
##
#
# Execution
#
##
2013-08-30 16:28:33 -05:00
2005-11-15 05:22:13 +00:00
#
# Suspends the thread's execution.
#
2005-04-16 07:29:06 +00:00
def suspend
request = Packet.create_request(COMMAND_ID_STDAPI_SYS_PROCESS_THREAD_SUSPEND)
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
request.add_tlv(TLV_TYPE_THREAD_HANDLE, handle)
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
process.client.send_request(request)
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
return true
end
2013-08-30 16:28:33 -05:00
2005-11-15 05:22:13 +00:00
#
# Resumes the thread's execution.
#
2005-04-16 07:29:06 +00:00
def resume
request = Packet.create_request(COMMAND_ID_STDAPI_SYS_PROCESS_THREAD_RESUME)
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
request.add_tlv(TLV_TYPE_THREAD_HANDLE, handle)
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
process.client.send_request(request)
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
return true
end
2013-08-30 16:28:33 -05:00
2005-11-15 05:22:13 +00:00
#
# Terminates the thread's execution.
#
2005-04-16 07:29:06 +00:00
def terminate(code)
request = Packet.create_request(COMMAND_ID_STDAPI_SYS_PROCESS_THREAD_TERMINATE)
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
request.add_tlv(TLV_TYPE_THREAD_HANDLE, handle)
request.add_tlv(TLV_TYPE_EXIT_CODE, code)
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
process.client.send_request(request)
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
return true
end
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
##
#
# Register manipulation
#
##
2013-08-30 16:28:33 -05:00
2005-11-15 05:22:13 +00:00
#
# Queries the register state of the thread.
#
2005-04-16 07:29:06 +00:00
def query_regs
request = Packet.create_request(COMMAND_ID_STDAPI_SYS_PROCESS_THREAD_QUERY_REGS)
2005-04-16 07:29:06 +00:00
regs = {}
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
request.add_tlv(TLV_TYPE_THREAD_HANDLE, handle)
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
response = process.client.send_request(request)
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
response.each(TLV_TYPE_REGISTER) { |reg|
regs[reg.get_tlv_value(TLV_TYPE_REGISTER_NAME)] = reg.get_tlv_value(TLV_TYPE_REGISTER_VALUE_32)
}
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
return regs
end
2013-08-30 16:28:33 -05:00
2005-11-15 05:22:13 +00:00
#
2005-04-16 07:29:06 +00:00
# Sets the register state of the thread. The registers are supplied
# in the form of a hash.
2005-11-15 05:22:13 +00:00
#
2005-04-16 07:29:06 +00:00
def set_regs(regs_hash)
request = Packet.create_request(COMMAND_ID_STDAPI_SYS_PROCESS_THREAD_SET_REGS)
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
request.add_tlv(TLV_TYPE_THREAD_HANDLE, handle)
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
# Add all of the register that we're setting
regs_hash.each_key { |name|
t = request.add_tlv(TLV_TYPE_REGISTER)
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
t.add_tlv(TLV_TYPE_REGISTER_NAME, name)
t.add_tlv(TLV_TYPE_REGISTER_VALUE_32, regs_hash[name])
}
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
process.client.send_request(request)
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
return true
end
2013-08-30 16:28:33 -05:00
2005-11-15 05:22:13 +00:00
#
# Formats the registers in a pretty way.
#
2005-04-16 07:29:06 +00:00
def pretty_regs
regs = query_regs
2013-08-30 16:28:33 -05:00
2011-11-20 11:39:27 +11:00
buf = sprintf("eax=%.8x ebx=%.8x ecx=%.8x edx=%.8x esi=%.8x edi=%.8x\n",
2005-04-16 07:29:06 +00:00
regs['eax'], regs['ebx'], regs['ecx'], regs['edx'], regs['esi'], regs['edi'])
buf += sprintf("eip=%.8x esp=%.8x ebp=%.8x\n",
regs['eip'], regs['esp'], regs['ebp'])
buf += sprintf("cs=%.4x ss=%.4x ds=%.4x es=%.4x fs=%.4x gs=%.4x\n",
regs['cs'], regs['ss'], regs['ds'], regs['es'], regs['fs'], regs['gs'])
2011-11-20 11:39:27 +11:00
2005-04-16 07:29:06 +00:00
return buf
end
2013-08-30 16:28:33 -05:00
2005-04-16 07:29:06 +00:00
##
#
# Closure
#
##
2005-11-15 05:22:13 +00:00
#
# Closes the thread handle.
#
def self.close(client, handle)
request = Packet.create_request(COMMAND_ID_STDAPI_SYS_PROCESS_THREAD_CLOSE)
2005-04-16 07:29:06 +00:00
request.add_tlv(TLV_TYPE_THREAD_HANDLE, handle)
client.send_request(request, nil)
2005-04-16 07:29:06 +00:00
handle = nil
return true
end
2011-11-20 11:39:27 +11:00
# Instance method
def close
unless self.handle.nil?
ObjectSpace.undefine_finalizer(self)
self.class.close(self.process.client, self.handle)
self.handle = nil
end
end
2013-08-30 16:28:33 -05:00
2005-11-15 05:22:13 +00:00
attr_reader :process, :handle, :tid # :nodoc:
2011-11-20 11:39:27 +11:00
protected
2005-11-15 05:22:13 +00:00
attr_writer :process, :handle, :tid # :nodoc:
2005-04-16 07:29:06 +00:00
end
end; end; end; end; end; end