{"id":4352,"date":"2024-07-28T10:25:30","date_gmt":"2024-07-28T02:25:30","guid":{"rendered":"https:\/\/www.aqwu.net\/wp\/?p=4352"},"modified":"2024-07-28T10:25:30","modified_gmt":"2024-07-28T02:25:30","slug":"gpu%e4%b8%ad%e6%af%92%e5%9c%a8-gpu-%e5%86%85%e5%ad%98%e4%b8%ad%e9%9a%90%e8%97%8f%e6%9c%89%e6%95%88%e8%b4%9f%e8%bd%bd","status":"publish","type":"post","link":"https:\/\/www.aqwu.net\/wp\/?p=4352","title":{"rendered":"GPU\u4e2d\u6bd2,\u5728 GPU \u5185\u5b58\u4e2d\u9690\u85cf\u6709\u6548\u8d1f\u8f7d"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\">\u5728\u6211\u7684\u65e7&nbsp;<a href=\"https:\/\/gitlab.com\/ORCA000\/t.d.p\">repo<\/a>&nbsp;\u4e4b\u540e\uff0c\u6211\u4f7f\u7528\u7ebf\u7a0b\u63cf\u8ff0\u6765\u9690\u85cf\u6709\u6548\u8f7d\u8377\uff0c\u6211\u60f3\u627e\u5230\u65b0\u65b9\u6cd5\uff0c\u6240\u4ee5\u73b0\u5728\u6211\u4f7f\u7528&nbsp;<strong>Nividia<\/strong>&nbsp;GPU \u5185\u5b58\uff0c\u4f7f\u7528 CUDA API \u6765\u5206\u914d\u3001\u5199\u5165\u548c\u91ca\u653e\uff0c\u5f53\u4e0d\u9700\u8981\u5728\u5185\u5b58\u4e2d\u627e\u5230\u6709\u6548\u8f7d\u8377\u65f6\u3002<\/h5>\n\n\n\n<p><a href=\"https:\/\/github.com\/H1d3r\/GPU_ShellCode#after-my-older-repo-in-which-i-used-the-thread-description-to-hide-the-payload-i-wanted-to-find-new-way-so-now-im-using-nividia-gpu-memory-using-cuda-apis-to-allocate-write-and-free-when-there-is-no-need-for-the-payload-to-be-found-in-memory\"><\/a><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u6b65\u9aa4\uff1a<\/h4>\n\n\n\n<p><a href=\"https:\/\/github.com\/H1d3r\/GPU_ShellCode#steps\"><\/a><\/p>\n\n\n\n<p>1- \u9996\u5148\uff0c\u6211\u4eec\u9700\u8981\u8bbe\u7f6e\u548c\u521d\u59cb\u5316\u4e00\u4e9b\u7ed3\u6784\u4f53 \/ \u5e76\u8fd0\u884c\u6211\u4eec\u7684 ve \u5904\u7406\u7a0b\u5e8f\u3002<\/p>\n\n\n\n<p>2-\u7b2c\u4e8c\uff0c\u6211\u4eec\u8fd0\u884c<strong>\u65e0\u7ea7<\/strong>\u6709\u6548\u8f7d\u8377\uff0c<strong>\u6211\u4eec\u5fc5\u987b<\/strong>\u4f7f\u7528\u65e0\u7ea7\uff0c\u8981\u77e5\u9053\u5728\u54ea\u91cc \u53cd\u5c04\u5c06\u843d\u5730\uff08\u6211\u4f7f\u7528 Cobalt Strike \u5e76\u4f7f\u7528 DLL \u53cd\u5c04\u52a0\u8f7d\u5668\uff09\uff0c\u6211\u4eec\u53ea\u5173\u5fc3\u5b9e\u9645\u7684 CZ \u6709\u6548\u8f7d\u8377\u3002\u6211\u6ca1\u6709\u5728\u6b64\u6b65\u9aa4\u4e2d\u6dfb\u52a0\u4efb\u4f55\u6280\u5de7\uff0c\u53ea\u662f\u4e00\u4e2a VirtualAlloc \u548c\u4e00\u4e2a RWX \u90e8\u5206<code>2nd stage<\/code><\/p>\n\n\n\n<p>3- \u73b0\u5728\uff0c\u5f53\u6709\u6548\u8f7d\u8377\u8fdb\u5165\u7761\u7720\u72b6\u6001\u65f6\uff0c\u6211\u4eec\u5c06\u6709\u6548\u8f7d\u8377\u590d\u5236\u5230 GPU \u5185\u5b58\u4e2d\uff0c\u5e76\u5728\u771f\u5b9e\u5185\u5b58\u4e2d\u6e05\u7406\u6709\u6548\u8f7d\u8377\u3002<\/p>\n\n\n\n<p>4- \u4f11\u7720\u5b8c\u6210\u540e\uff0cVEH \u5c06\u901a\u8fc7\u5c06\u5185\u5b58\u6743\u9650\u91cd\u65b0\u8bbe\u7f6e\u4e3a \u5e76\u5c06\u6709\u6548\u8f7d\u8377\u4ece GPU \u653e\u56de\u539f\u4f4d\u6765\u5904\u7406\u5f02\u5e38 \uff08EXCEPTION_ACCESS_VIOLATION\uff09\u3002<code>PAGE_EXECUTE_READWRITE<\/code><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u6f14\u793a\uff1a<\/h4>\n\n\n\n<p><a href=\"https:\/\/github.com\/H1d3r\/GPU_ShellCode#demo\"><\/a><\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/camo.githubusercontent.com\/1116e2c1ce3d8387a4fea80a4b5e1f311c09fe7fef4f228dcae7cb8d7d7e3744\/68747470733a2f2f6769746c61622e636f6d2f4f5243413030302f67702f2d2f7261772f6d61696e2f696d616765732f64656d6f312e706e67\" target=\"_blank\" rel=\"noreferrer noopener\"><img decoding=\"async\" src=\"https:\/\/camo.githubusercontent.com\/1116e2c1ce3d8387a4fea80a4b5e1f311c09fe7fef4f228dcae7cb8d7d7e3744\/68747470733a2f2f6769746c61622e636f6d2f4f5243413030302f67702f2d2f7261772f6d61696e2f696d616765732f64656d6f312e706e67\" alt=\"\u56fe\u7247\"\/><\/a><\/figure>\n\n\n\n<p>\u539f\u6587\u94fe\u63a5\uff1a<a href=\"https:\/\/github.com\/H1d3r\/GPU_ShellCode\">H1D3R\/GPU_ShellCode (github.com)<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u5728\u6211\u7684\u65e7&nbsp;repo&nbsp;\u4e4b\u540e\uff0c\u6211\u4f7f\u7528\u7ebf\u7a0b\u63cf\u8ff0\u6765\u9690\u85cf\u6709\u6548\u8f7d\u8377\uff0c\u6211\u60f3\u627e\u5230\u65b0\u65b9\u6cd5\uff0c\u6240\u4ee5\u73b0\u5728\u6211\u4f7f\u7528&#038;n [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[37,43],"tags":[461,74],"class_list":["post-4352","post","type-post","status-publish","format-standard","hentry","category-samples","category-infoarticle","tag-gpu","tag-shellcode"],"views":2368,"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts\/4352","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4352"}],"version-history":[{"count":1,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts\/4352\/revisions"}],"predecessor-version":[{"id":4353,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts\/4352\/revisions\/4353"}],"wp:attachment":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4352"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4352"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4352"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}