Read-only archive. Login and posting are unavailable.
Reply
 
Thread Tools
  #1  
Old 12-06-2010, 15:12
foggyflute's Avatar
Thiếu Protein
Join Date: 10-2006
Posts: 5,796
Hỏi về assembly, lập trình dll trên nền window

Hiện tại em có 1 application sau khi run file .exe thì core.dll dump lên cpu tại ô nhớ 007711F6 có giá trị là 6A 17 giờ em muốn đổi nó thành 6A 18 thì nên viết 1 cái hook như nào ạ? hiện tại em cũng đang có 1 cái hook mẫu viết bằng .asm nhưng phức tạp hơn nhiều nên không có giá trị tham khảo với em lắm mà lừa thì cháy đến đít rồi nên em cũng không còn nhiều thời gian để research.

Bro nào biết về asm hoặc lập trình mấy cái dll có thể bỏ ít thời gian để giúp em được không ạ, em xin hậu tạ hết mình.
__________________
[I][COLOR="SlateGray"]Không cần clone nick để cãi nhau - [B]U MAD?[/B][/COLOR][/I]
Reply With Quote
  #2  
Old 12-06-2010, 15:27
foggyflute's Avatar
Thiếu Protein
Join Date: 10-2006
Posts: 5,796
Re: Hỏi về assembly, lập trình dll trên nền window

up





he message you have entered is too short. Please lengthen your message to at least 10 characters
__________________
[I][COLOR="SlateGray"]Không cần clone nick để cãi nhau - [B]U MAD?[/B][/COLOR][/I]
Reply With Quote
  #3  
Old 12-06-2010, 17:33
foggyflute's Avatar
Thiếu Protein
Join Date: 10-2006
Posts: 5,796
Re: Hỏi về assembly, lập trình dll trên nền window

up





he message you have entered is too short. Please lengthen your message to at least 10 characters
__________________
[I][COLOR="SlateGray"]Không cần clone nick để cãi nhau - [B]U MAD?[/B][/COLOR][/I]
Reply With Quote
  #4  
Old 12-06-2010, 17:58
Daviath.'s Avatar
Senior Member
Join Date: 02-2010
Posts: 1,426
Re: Hỏi về assembly, lập trình dll trên nền window

Up dùm thôi... :">
Reply With Quote
  #5  
Old 12-06-2010, 18:15
Thích Ăn Chuối's Avatar
Junior Member
Join Date: 02-2010
Posts: 6
Re: Hỏi về assembly, lập trình dll trên nền window

mov ax,6a18
mov @007711F6,ax
__________________
[QUOTE=Spirit_Love;23536633]Vừa quay tay xong tay còn dính , mà có bạn rủ dota , vào chơi 1 hồi quên rửa tay , lát ra bới cơm , múc canh vào . lúc bưng thọc cả ngón cái vô tô . Ăn đã mới sực nhớ ra . và sau đó tự an ủi rằng "của mình chứ của ai mà sợ " :sexy:[/QUOTE]
Reply With Quote
  #6  
Old 12-06-2010, 18:16
2love1989's Avatar
K.I.A
Join Date: 02-2008
Posts: 179
Re: Hỏi về assembly, lập trình dll trên nền window

bạn viết app đấy về mảng gì? Ứng dụng cụ thể vào việc gì
__________________
[SIZE="3"][B]Đời[/B] là [COLOR="Orange"]bể khổ[/COLOR]. [B]Người[/B] là cái [COLOR="Red"]khổ nhất[/COLOR]. [B]Khổ[/B] nhất là [COLOR="Blue"]sống trên đời[/COLOR].[/SIZE]
Reply With Quote
  #7  
Old 12-06-2010, 18:17
Senior Member
Join Date: 09-2007
Posts: 516
Re: Hỏi về assembly, lập trình dll trên nền window

Nếu làm ứng dụng hook thì bạn thử tham khảo bài viết của Iczelion xem sao,
trong Link là các lí thuyết về hook đơn giản , sử dụng SetWindowsHookEx. Ứng dụng demo đùng để hook chuột thông qua thư viện mousehook.dll
Bạn nên tham khảo cách viết dll này

http://win32assembly.online.fr/tut24.html

Về câu hỏi của bạn, phải có code hoặc cái dll và ứng dụng cụ thể để debug thì mới rõ là sai ở đâu và sửa thế nào , bạn mô tả như thế thì cũng chịu.
Reply With Quote
  #8  
Old 12-06-2010, 18:19
Senior Member
Join Date: 09-2007
Posts: 516
Re: Hỏi về assembly, lập trình dll trên nền window

Quote:
Originally Posted by Thích Ăn Chuối View Post
mov ax,6a18
mov @007711F6,ax
Địa chỉ cao tít thế kia em nghĩ là thuộc cái DLL thôi,
Tại địa chỉ này mà không có access protection là PAGE_READWRITE thì lệnh của bác gây exception ngay
Reply With Quote
  #9  
Old 12-06-2010, 21:43
foggyflute's Avatar
Thiếu Protein
Join Date: 10-2006
Posts: 5,796
Re: Hỏi về assembly, lập trình dll trên nền window

:x thx các bác đã vào chỉ giáo

đây là folder chứa cả exe và dll
http://revlineage2.com/revl2.v2.18.12.2009.rar

- đầu tiên em chạy l2.exe (sẽ hiện ra error vì thiếu file support về modeling nhưng ko ảnh hưởng đến việc debug lắm)
- sử dụng process Explorer để supend vì thằng này nó có cơ chế anti debug (link http://download.sysinternals.com/Fil...ssExplorer.zip)
- sử dụng ollydbg để attach và resume ở bên process Explorer

nhấn Alt + M, trong cột owner tìm những cái thuộc engine, sẽ thấy từ 6-7 cái, chọn cái thứ 2 (có cột "Contains" là rỗng) right click -> dump in CPU.

sau đó nhấn Alt + E chọn engine.dll

trong cửa sổ chính (CPU) nhấn Ctrl + G move về line 00770000 sau đó Ctrl+F để tìm "PUSH 17" (nằm ở vị trí khoảng 00770D0F).

tại đây em đã thử edit (right click -> edit -> binary edit) và trace ngược lại file gốc (right click -> edit -> copy to executable) nhưng có vẻ file gốc đã bị packed nên không có 1 địa chỉ tương ứng.

giờ em muốn chuyển cái PUSH 17 này thành PUSH 18 thì nên làm như thế nào ạ?

sẵn tiện đây em post 1 cái hook để change connect port xem các bác có thấy gì khả thi hoặc get idea từ trong đấy không

Code:
format PE GUI 4.0 DLL

include 'C:\FASM\INCLUDE\win32axp.inc'

section '.data' data readable writeable

settings	db	'settings', 0
authport	db	'authport', 0
engine		db	'engine.dll', 0
loaded		db	'authport, by Fyyre - loaded', 0
port		dd	0
iniValue	dd	0
tmp1		dd	?
tmp3		dd	?
port_number	dd	?
cmpb1		db	0
cmpb2		db	0
cmpb3		db	0
cmpb4		db	0
cmpb5		db	0

section '.text' code readable executable

DllEntryPoint:
entry $
  push	  ebp
  mov	  ebp, esp
  push	  ecx
  cmp	  dword [ebp+0Ch], 1
  jnz	  @F
  call	  ModifyAuthLogin
  call	  ThreadLibraryCalls
@@:
  mov	 eax, 1
  mov	 esp, ebp
  pop	 ebp
  ret

ModifyAuthLogin:
  pushad
  mov	  ebp, esp
  push	  ecx
  mov	  esi, 100h
  push	  4h
  push	  1000h
  push	  esi
  push	  0
  push	  -1
  call	  
  mov	  , eax
  push	  authport
  call	  
  lea	  ebx, 
  push	  100h
  push	  ebx
  push	  eax
  call	  
  add	  edi, 100h
  add	  ebx, 100h
@@:
  dec	  ebx
  cmp	  byte , '.'
  jnz	  @B
  mov	  dword , '.ini'
  lea	  ebx, 
@@:
  push	  ebx
  push	  4
  lea	  eax, 
  push	  eax
  push	  0
  push	  authport
  push	  settings
  call	  
  mov	  eax, [esp-0Ch]
  mov	  eax, 
  mov	  , eax
  ;ascii to hex routine... =)
  xor	  eax, eax
  xor	  bx, bx
  xor	  ax, ax
  lea	  esi, 
  mov	  bl, byte 
  mov	  ecx, 4
@makehex:
  cmp	  bl, 0
  jle	  hexdone
  sub	  bl, 30h
  cmp	  bl, 09h
  jle	  @next
  sub	  bl, 07h
  cmp	  bl, 0fh
  jle	  @next
  sub	  bl, 20h
@next:
  imul	  ax, 0010h
  add	  ax, bx
  inc	  esi
  mov	  bl, byte 
  dec	  ecx
  cmp	  ecx, 0
  jne	  @makehex
hexdone:
  mov	  , eax
  push	  8000h
  push	  0
  push	  
  push	  -1
  call	  
  push	  engine
  call	  
  xchg	  eax, esi
  mov	  al, 68h
  mov	  , al
  ;if you are thinking "wth using cmpsb and not cmpsd?! wuwu, the performance hit!"
  ;then try replacing this with cmpsd, if you can get it working on all chronicle clients,
  ;let me know.
@search:
  cld
  mov ecx, 1
  lea edi, byte 
  cmpsb
  jne @search
  cld
  mov ecx, 1
  mov al, 3Ah
  mov , al
  lea edi, byte 
  cmpsb
  jne @search
  cld
  mov ecx, 1
  mov al, 08h
  mov , al
  lea edi, byte 
  cmpsb
  jne @search
  cld
  mov ecx, 1
  mov al, 0
  mov , al
  lea edi, byte 
  cmpsb
  jne @search
  sub esi, 4
  cmp byte , 068h
  jne @search
  mov dword , 0
  mov , esi
  lea edx, dword [ebp-04h]
  push edx
  push 4h
  push 5h
  mov ebx, 
  push ebx
  push -1
  call 
  inc ebx
  mov eax, 
  mov , eax
  lea edx, dword [ebp-04h]
  push edx
  push 2h
  push 5h
  mov ebx, 
  push ebx
  push -1
  call 
  add  esp, 4
  popad
  ret

ThreadLibraryCalls:
  pushad
  push authport
  call 
  push eax
  call 
  push	  loaded
  call	  
  popad
  ret

section '.idata' import data readable writeable

  library kernel32, 'kernel32.dll'

  import kernel32,			       \
  GetModuleHandleA,	'GetModuleHandleA',	\
  GetModuleFileNameA,	'GetModuleFileNameA',	\
  GetPrivateProfileStringA, 'GetPrivateProfileStringA', \
  VirtualProtectEx,	    'VirtualProtectEx', 	\
  VirtualAllocEx,	    'VirtualAllocEx',		\
  VirtualFreeEx,	    'VirtualFreeEx',		\
  DisableThreadLibraryCalls, 'DisableThreadLibraryCalls', \
  OutputDebugStringA,		 'OutputDebugStringA'


section '.edata' export data readable writeable

  export 'authport',	\
	 DllEntryPoint, 'DllEntryPoint'

section '.reloc' fixups data discardable

section '.rsrc' data readable resource from 'authport.res'
__________________
[I][COLOR="SlateGray"]Không cần clone nick để cãi nhau - [B]U MAD?[/B][/COLOR][/I]
Reply With Quote
  #10  
Old 13-06-2010, 00:00
foggyflute's Avatar
Thiếu Protein
Join Date: 10-2006
Posts: 5,796
Re: Hỏi về assembly, lập trình dll trên nền window

up





he message you have entered is too short. Please lengthen your message to at least 10 characters
__________________
[I][COLOR="SlateGray"]Không cần clone nick để cãi nhau - [B]U MAD?[/B][/COLOR][/I]
Reply With Quote
Reply

« Previous Thread | Next Thread »

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


All times are GMT +7. The time now is 13:28.