FazBrowse GitHub Viewer
|
Trending
|
URL:
|
Home
Tools:
[Download Repo ZIP]
[View Raw Code]
[Original HTTPS Page]
ReflectiveDLLInjection/inject/src/GetProcAddressR.c at master · ScriptIdiot/ReflectiveDLLInjection · GitHub
ScriptIdiot
ReflectiveDLLInjection
Repository navigation
Code
Pull requests
Actions
Projects
Security and quality
Insights
Expand file tree
Breadcrumbs
ReflectiveDLLInjection
/
inject
/
src
/
GetProcAddressR.c
Copy path
More file actions
More file actions
Latest commit
History
History
History
122 lines (102 loc) · 4.95 KB
Breadcrumbs
ReflectiveDLLInjection
/
inject
/
src
/
GetProcAddressR.c
Copy path
File metadata and controls
122 lines (102 loc) · 4.95 KB
Raw
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
//===============================================================================================//
// Copyright (c) 2013, Stephen Fewer of Harmony Security (www.harmonysecurity.com)
// All rights reserved.
//
// Redistribution and use in source and binary forms, with or without modification, are permitted
// provided that the following conditions are met:
//
// * Redistributions of source code must retain the above copyright notice, this list of
// conditions and the following disclaimer.
//
// * Redistributions in binary form must reproduce the above copyright notice, this list of
// conditions and the following disclaimer in the documentation and/or other materials provided
// with the distribution.
//
// * Neither the name of Harmony Security nor the names of its contributors may be used to
// endorse or promote products derived from this software without specific prior written permission.
//
// THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR
// IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND
// FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR
// CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
// CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
// SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
// THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR
// OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
// POSSIBILITY OF SUCH DAMAGE.
//===============================================================================================//
#include
"GetProcAddressR.h"
#ifdef
__MINGW32__
#define
__try
#define
__except
(
x
) if(0)
#endif
//===============================================================================================//
// We implement a minimal GetProcAddress to avoid using the native kernel32!GetProcAddress which
// wont be able to resolve exported addresses in reflectivly loaded librarys.
FARPROC
WINAPI
GetProcAddressR
(
HANDLE
hModule
,
LPCSTR
lpProcName
)
{
UINT_PTR
uiLibraryAddress
=
0
;
FARPROC
fpResult
=
NULL
;
if
(
hModule
==
NULL
)
return
NULL
;
// a module handle is really its base address
uiLibraryAddress
=
(
UINT_PTR
)
hModule
;
__try
{
UINT_PTR
uiAddressArray
=
0
;
UINT_PTR
uiNameArray
=
0
;
UINT_PTR
uiNameOrdinals
=
0
;
PIMAGE_NT_HEADERS
pNtHeaders
=
NULL
;
PIMAGE_DATA_DIRECTORY
pDataDirectory
=
NULL
;
PIMAGE_EXPORT_DIRECTORY
pExportDirectory
=
NULL
;
// get the VA of the modules NT Header
pNtHeaders
=
(
PIMAGE_NT_HEADERS
)(
uiLibraryAddress
+
((
PIMAGE_DOS_HEADER
)
uiLibraryAddress
)
->
e_lfanew
);
pDataDirectory
=
(
PIMAGE_DATA_DIRECTORY
)
&
pNtHeaders
->
OptionalHeader
.
DataDirectory
[
IMAGE_DIRECTORY_ENTRY_EXPORT
];
// get the VA of the export directory
pExportDirectory
=
(
PIMAGE_EXPORT_DIRECTORY
)(
uiLibraryAddress
+
pDataDirectory
->
VirtualAddress
);
// get the VA for the array of addresses
uiAddressArray
=
(
uiLibraryAddress
+
pExportDirectory
->
AddressOfFunctions
);
// get the VA for the array of name pointers
uiNameArray
=
(
uiLibraryAddress
+
pExportDirectory
->
AddressOfNames
);
// get the VA for the array of name ordinals
uiNameOrdinals
=
(
uiLibraryAddress
+
pExportDirectory
->
AddressOfNameOrdinals
);
// test if we are importing by name or by ordinal...
if
( (((
DWORD_PTR
)
lpProcName
) >>
16
)
==
0
)
{
// import by ordinal...
// use the import ordinal (- export ordinal base) as an index into the array of addresses
uiAddressArray
+=
( (
IMAGE_ORDINAL
( (
DWORD
)(
DWORD_PTR
)
lpProcName
)
-
pExportDirectory
->
Base
)
*
sizeof
(
DWORD
) );
// resolve the address for this imported function
fpResult
=
(
FARPROC
)(
uiLibraryAddress
+
DEREF_32
(
uiAddressArray
) );
}
else
{
// import by name...
DWORD
dwCounter
=
pExportDirectory
->
NumberOfNames
;
while
(
dwCounter
--
)
{
char
*
cpExportedFunctionName
=
(
char
*
)(
uiLibraryAddress
+
DEREF_32
(
uiNameArray
));
// test if we have a match...
if
(
strcmp
(
cpExportedFunctionName
,
lpProcName
)
==
0
)
{
// use the functions name ordinal as an index into the array of name pointers
uiAddressArray
+=
(
DEREF_16
(
uiNameOrdinals
)
*
sizeof
(
DWORD
) );
// calculate the virtual address for the function
fpResult
=
(
FARPROC
)(
uiLibraryAddress
+
DEREF_32
(
uiAddressArray
));
// finish...
break
;
}
// get the next exported function name
uiNameArray
+=
sizeof
(
DWORD
);
// get the next exported function name ordinal
uiNameOrdinals
+=
sizeof
(
WORD
);
}
}
}
__except(
EXCEPTION_EXECUTE_HANDLER
)
{
fpResult
=
NULL
;
}
return
fpResult
;
}
//===============================================================================================//
Back
|
FazBrowse Home
|
New Git URL