![]() |
|
|
Thread Tools |
|
#1
|
|||
|
|||
|
Hỏi về assembly, lập trình dll trên nền window
Hiện tại em có 1 application sau khi run file .exe thì core.dll dump lên cpu tại ô nhớ 007711F6 có giá trị là 6A 17 giờ em muốn đổi nó thành 6A 18 thì nên viết 1 cái hook như nào ạ? hiện tại em cũng đang có 1 cái hook mẫu viết bằng .asm nhưng phức tạp hơn nhiều nên không có giá trị tham khảo với em lắm mà lừa thì cháy đến đít rồi nên em cũng không còn nhiều thời gian để research.
Bro nào biết về asm hoặc lập trình mấy cái dll có thể bỏ ít thời gian để giúp em được không ạ, em xin hậu tạ hết mình.
__________________
[I][COLOR="SlateGray"]Không cần clone nick để cãi nhau - [B]U MAD?[/B][/COLOR][/I] |
| foggyflute |
| View Public Profile |
| Find all posts by foggyflute |
|
#2
|
|||
|
|||
|
Re: Hỏi về assembly, lập trình dll trên nền window
up
he message you have entered is too short. Please lengthen your message to at least 10 characters
__________________
[I][COLOR="SlateGray"]Không cần clone nick để cãi nhau - [B]U MAD?[/B][/COLOR][/I] |
| foggyflute |
| View Public Profile |
| Find all posts by foggyflute |
|
#3
|
|||
|
|||
|
Re: Hỏi về assembly, lập trình dll trên nền window
up
he message you have entered is too short. Please lengthen your message to at least 10 characters
__________________
[I][COLOR="SlateGray"]Không cần clone nick để cãi nhau - [B]U MAD?[/B][/COLOR][/I] |
| foggyflute |
| View Public Profile |
| Find all posts by foggyflute |
|
#4
|
|||
|
|||
|
Re: Hỏi về assembly, lập trình dll trên nền window
Up dùm thôi... :">
|
|
#5
|
|||
|
|||
|
Re: Hỏi về assembly, lập trình dll trên nền window
mov ax,6a18
mov @007711F6,ax
__________________
[QUOTE=Spirit_Love;23536633]Vừa quay tay xong tay còn dính , mà có bạn rủ dota , vào chơi 1 hồi quên rửa tay , lát ra bới cơm , múc canh vào . lúc bưng thọc cả ngón cái vô tô . Ăn đã mới sực nhớ ra . và sau đó tự an ủi rằng "của mình chứ của ai mà sợ " :sexy:[/QUOTE] |
| Thích Ăn Chuối |
| View Public Profile |
| Find all posts by Thích Ăn Chuối |
|
#6
|
|||
|
|||
|
Re: Hỏi về assembly, lập trình dll trên nền window
bạn viết app đấy về mảng gì? Ứng dụng cụ thể vào việc gì
__________________
[SIZE="3"][B]Đời[/B] là [COLOR="Orange"]bể khổ[/COLOR]. [B]Người[/B] là cái [COLOR="Red"]khổ nhất[/COLOR]. [B]Khổ[/B] nhất là [COLOR="Blue"]sống trên đời[/COLOR].[/SIZE] |
|
#7
|
||
|
||
|
Re: Hỏi về assembly, lập trình dll trên nền window
Nếu làm ứng dụng hook thì bạn thử tham khảo bài viết của Iczelion xem sao,
trong Link là các lí thuyết về hook đơn giản , sử dụng SetWindowsHookEx. Ứng dụng demo đùng để hook chuột thông qua thư viện mousehook.dll Bạn nên tham khảo cách viết dll này http://win32assembly.online.fr/tut24.html Về câu hỏi của bạn, phải có code hoặc cái dll và ứng dụng cụ thể để debug thì mới rõ là sai ở đâu và sửa thế nào , bạn mô tả như thế thì cũng chịu. |
| quangredlight |
| View Public Profile |
| Find all posts by quangredlight |
|
#8
|
||
|
||
|
Re: Hỏi về assembly, lập trình dll trên nền window
Địa chỉ cao tít thế kia em nghĩ là thuộc cái DLL thôi,
Tại địa chỉ này mà không có access protection là PAGE_READWRITE thì lệnh của bác gây exception ngay |
| quangredlight |
| View Public Profile |
| Find all posts by quangredlight |
|
#9
|
|||
|
|||
|
Re: Hỏi về assembly, lập trình dll trên nền window
:x thx các bác đã vào chỉ giáo
đây là folder chứa cả exe và dll http://revlineage2.com/revl2.v2.18.12.2009.rar - đầu tiên em chạy l2.exe (sẽ hiện ra error vì thiếu file support về modeling nhưng ko ảnh hưởng đến việc debug lắm) - sử dụng process Explorer để supend vì thằng này nó có cơ chế anti debug (link http://download.sysinternals.com/Fil...ssExplorer.zip) - sử dụng ollydbg để attach và resume ở bên process Explorer nhấn Alt + M, trong cột owner tìm những cái thuộc engine, sẽ thấy từ 6-7 cái, chọn cái thứ 2 (có cột "Contains" là rỗng) right click -> dump in CPU. sau đó nhấn Alt + E chọn engine.dll trong cửa sổ chính (CPU) nhấn Ctrl + G move về line 00770000 sau đó Ctrl+F để tìm "PUSH 17" (nằm ở vị trí khoảng 00770D0F). tại đây em đã thử edit (right click -> edit -> binary edit) và trace ngược lại file gốc (right click -> edit -> copy to executable) nhưng có vẻ file gốc đã bị packed nên không có 1 địa chỉ tương ứng. ![]() giờ em muốn chuyển cái PUSH 17 này thành PUSH 18 thì nên làm như thế nào ạ? sẵn tiện đây em post 1 cái hook để change connect port xem các bác có thấy gì khả thi hoặc get idea từ trong đấy không Code:
format PE GUI 4.0 DLL include 'C:\FASM\INCLUDE\win32axp.inc' section '.data' data readable writeable settings db 'settings', 0 authport db 'authport', 0 engine db 'engine.dll', 0 loaded db 'authport, by Fyyre - loaded', 0 port dd 0 iniValue dd 0 tmp1 dd ? tmp3 dd ? port_number dd ? cmpb1 db 0 cmpb2 db 0 cmpb3 db 0 cmpb4 db 0 cmpb5 db 0 section '.text' code readable executable DllEntryPoint: entry $ push ebp mov ebp, esp push ecx cmp dword [ebp+0Ch], 1 jnz @F call ModifyAuthLogin call ThreadLibraryCalls @@: mov eax, 1 mov esp, ebp pop ebp ret ModifyAuthLogin: pushad mov ebp, esp push ecx mov esi, 100h push 4h push 1000h push esi push 0 push -1 call mov , eax push authport call lea ebx, push 100h push ebx push eax call add edi, 100h add ebx, 100h @@: dec ebx cmp byte , '.' jnz @B mov dword , '.ini' lea ebx, @@: push ebx push 4 lea eax, push eax push 0 push authport push settings call mov eax, [esp-0Ch] mov eax, mov , eax ;ascii to hex routine... =) xor eax, eax xor bx, bx xor ax, ax lea esi, mov bl, byte mov ecx, 4 @makehex: cmp bl, 0 jle hexdone sub bl, 30h cmp bl, 09h jle @next sub bl, 07h cmp bl, 0fh jle @next sub bl, 20h @next: imul ax, 0010h add ax, bx inc esi mov bl, byte dec ecx cmp ecx, 0 jne @makehex hexdone: mov , eax push 8000h push 0 push push -1 call push engine call xchg eax, esi mov al, 68h mov , al ;if you are thinking "wth using cmpsb and not cmpsd?! wuwu, the performance hit!" ;then try replacing this with cmpsd, if you can get it working on all chronicle clients, ;let me know. @search: cld mov ecx, 1 lea edi, byte cmpsb jne @search cld mov ecx, 1 mov al, 3Ah mov , al lea edi, byte cmpsb jne @search cld mov ecx, 1 mov al, 08h mov , al lea edi, byte cmpsb jne @search cld mov ecx, 1 mov al, 0 mov , al lea edi, byte cmpsb jne @search sub esi, 4 cmp byte , 068h jne @search mov dword , 0 mov , esi lea edx, dword [ebp-04h] push edx push 4h push 5h mov ebx, push ebx push -1 call inc ebx mov eax, mov , eax lea edx, dword [ebp-04h] push edx push 2h push 5h mov ebx, push ebx push -1 call add esp, 4 popad ret ThreadLibraryCalls: pushad push authport call push eax call push loaded call popad ret section '.idata' import data readable writeable library kernel32, 'kernel32.dll' import kernel32, \ GetModuleHandleA, 'GetModuleHandleA', \ GetModuleFileNameA, 'GetModuleFileNameA', \ GetPrivateProfileStringA, 'GetPrivateProfileStringA', \ VirtualProtectEx, 'VirtualProtectEx', \ VirtualAllocEx, 'VirtualAllocEx', \ VirtualFreeEx, 'VirtualFreeEx', \ DisableThreadLibraryCalls, 'DisableThreadLibraryCalls', \ OutputDebugStringA, 'OutputDebugStringA' section '.edata' export data readable writeable export 'authport', \ DllEntryPoint, 'DllEntryPoint' section '.reloc' fixups data discardable section '.rsrc' data readable resource from 'authport.res'
__________________
[I][COLOR="SlateGray"]Không cần clone nick để cãi nhau - [B]U MAD?[/B][/COLOR][/I] |
| foggyflute |
| View Public Profile |
| Find all posts by foggyflute |
|
#10
|
|||
|
|||
|
Re: Hỏi về assembly, lập trình dll trên nền window
up
he message you have entered is too short. Please lengthen your message to at least 10 characters
__________________
[I][COLOR="SlateGray"]Không cần clone nick để cãi nhau - [B]U MAD?[/B][/COLOR][/I] |
| foggyflute |
| View Public Profile |
| Find all posts by foggyflute |
![]() |
|
|