第一次写这种内存补丁一样的东西.开始怎么写都出错.字节码没有对齐..跳转地址算错.等等...后来用ida分析+od调试搞定.(头一次认认真真用od和ida...值得纪念)
测试环境xp sp2+vc6.0
#include <stdio.h>
#include <windows.h>
data:image/s3,"s3://crabby-images/cfe7f/cfe7f64cd760bc76c30896355075d3653b3c3d83" alt=""
// 保存原始的5个字节代码,注意一定要保证完整
data:image/s3,"s3://crabby-images/ebd3c/ebd3c6f2179364643e7741beb0496c1cbf3d6db5" alt=""
BYTE orig_code[5] =
{0x90, 0x90, 0x90, 0x90, 0x90};
// JMP 0xXXXXXXXX
data:image/s3,"s3://crabby-images/ebd3c/ebd3c6f2179364643e7741beb0496c1cbf3d6db5" alt=""
BYTE hook_code[5] =
{ 0xe9, 0, 0, 0, 0 };
data:image/s3,"s3://crabby-images/ebd3c/ebd3c6f2179364643e7741beb0496c1cbf3d6db5" alt=""
BYTE jmp_orig_code[5] =
{ 0xe9, 0, 0, 0, 0};
data:image/s3,"s3://crabby-images/cfe7f/cfe7f64cd760bc76c30896355075d3653b3c3d83" alt=""
int func();
int fake_func();
void hook_func();
int jmp_back();
data:image/s3,"s3://crabby-images/cfe7f/cfe7f64cd760bc76c30896355075d3653b3c3d83" alt=""
data:image/s3,"s3://crabby-images/cfe7f/cfe7f64cd760bc76c30896355075d3653b3c3d83" alt=""
int main(int argc, char **argv)
data:image/s3,"s3://crabby-images/ebd3c/ebd3c6f2179364643e7741beb0496c1cbf3d6db5" alt=""
data:image/s3,"s3://crabby-images/22670/2267060d3e1971ff2dd292100ed1a4ab9e6d138d" alt=""
{
int ret;
hook_func();
ret = func();
return ret;
}
data:image/s3,"s3://crabby-images/cfe7f/cfe7f64cd760bc76c30896355075d3653b3c3d83" alt=""
int func()
data:image/s3,"s3://crabby-images/ebd3c/ebd3c6f2179364643e7741beb0496c1cbf3d6db5" alt=""
data:image/s3,"s3://crabby-images/22670/2267060d3e1971ff2dd292100ed1a4ab9e6d138d" alt=""
{
printf("I'm func(),I'm called!\r\n");
return 0;
}
data:image/s3,"s3://crabby-images/cfe7f/cfe7f64cd760bc76c30896355075d3653b3c3d83" alt=""
void hook_func()
data:image/s3,"s3://crabby-images/ebd3c/ebd3c6f2179364643e7741beb0496c1cbf3d6db5" alt=""
data:image/s3,"s3://crabby-images/22670/2267060d3e1971ff2dd292100ed1a4ab9e6d138d" alt=""
{
DWORD dwOldProtect;
if(!VirtualProtect(func, 5, PAGE_EXECUTE_READWRITE, &dwOldProtect))
data:image/s3,"s3://crabby-images/e1808/e180869b31d480c3c2f9cb2b1cea437f4285cc9e" alt=""
{
printf("VirtualProtect error!\r\n");
return;
}
if(!VirtualProtect(jmp_back, 12, PAGE_EXECUTE_READWRITE, &dwOldProtect))
data:image/s3,"s3://crabby-images/e1808/e180869b31d480c3c2f9cb2b1cea437f4285cc9e" alt=""
{
printf("VirtualProtect error!\r\n");
return;
}
data:image/s3,"s3://crabby-images/73c50/73c50d385852a0f8fe308c21ebb7d4e7f0df23db" alt=""
// 保存原始操作码
memcpy(orig_code, (BYTE )func, 5);
// 计算fack_func地址
((ULONG)(hook_code+1) ) = (ULONG)fake_func - (ULONG)func - 5;
// 修改原始入口
memcpy((BYTE )func, hook_code, 5);
// 计算跳回地址
( (ULONG)(jmp_orig_code+1) ) = (ULONG)func - (ULONG)jmp_back -5;
// 填充jmp_back
memcpy((BYTE )jmp_back, orig_code, 5);
memcpy((BYTE )jmp_back+5, jmp_orig_code, 5);
}
data:image/s3,"s3://crabby-images/cfe7f/cfe7f64cd760bc76c30896355075d3653b3c3d83" alt=""
__declspec(naked) int jmp_back()
data:image/s3,"s3://crabby-images/ebd3c/ebd3c6f2179364643e7741beb0496c1cbf3d6db5" alt=""
data:image/s3,"s3://crabby-images/22670/2267060d3e1971ff2dd292100ed1a4ab9e6d138d" alt=""
{
__asm
data:image/s3,"s3://crabby-images/e1808/e180869b31d480c3c2f9cb2b1cea437f4285cc9e" alt=""
{
_emit 0x90
_emit 0x90
_emit 0x90
_emit 0x90
_emit 0x90
_emit 0x90
_emit 0x90
_emit 0x90
_emit 0x90
_emit 0x90
}
}
data:image/s3,"s3://crabby-images/cfe7f/cfe7f64cd760bc76c30896355075d3653b3c3d83" alt=""
int fake_func()
data:image/s3,"s3://crabby-images/ebd3c/ebd3c6f2179364643e7741beb0496c1cbf3d6db5" alt=""
data:image/s3,"s3://crabby-images/22670/2267060d3e1971ff2dd292100ed1a4ab9e6d138d" alt=""
{
int ret;
printf("I'm fake_func(),I'm called!\r\n");
ret = jmp_back();
return ret;
}
data:image/s3,"s3://crabby-images/cfe7f/cfe7f64cd760bc76c30896355075d3653b3c3d83" alt=""
测试结果:
参考: http://www.whitecell.org/forums/viewthread.php?tid=360