MCPcopy Create free account
hub / github.com/ELMERIKH/PyinMemoryPE / stomp_PEB

Method stomp_PEB

pythonmemorymodule/__init__.py:501–516  ·  view source on GitHub ↗
(self)

Source from the content-addressed store, hash-verified

499 sys.exit()
500
501 def stomp_PEB(self):
502 self.cp=windows.current_process
503 peb = windows.current_process.peb
504 self.dbg("Current process PEB is <{0}>".format(peb))
505
506 self.commandline = peb.commandline
507 self.cmdlineaddr= self.commandline.Buffer
508 self.cmdlinetext=self.cp.read_memory(self.cmdlineaddr, self.commandline.Length).decode("utf-16")
509
510 self.dbg("Original commandline: {}".format(self.cmdlinetext))
511 newcmd=self.new_command + " \x00"
512 encnewcmd=newcmd.encode("utf-16")
513
514 self.cp.write_memory(self.cmdlineaddr,encnewcmd)
515
516 self.dbg("Stomped commandline: {}".format(self.cp.read_memory(self.cmdlineaddr, self.commandline.Length).decode("utf-16")))
517
518
519 def unstomp_PEB(self):

Callers 1

load_moduleMethod · 0.95

Calls 4

dbgMethod · 0.95
decodeMethod · 0.80
read_memoryMethod · 0.45
write_memoryMethod · 0.45

Tested by

no test coverage detected