Dll injector

Posts 1–15 of 15 · Page 1 of 1
Dll injector
Could someone take a look at this and point out if there are any errors? I have spent so much time looking for a good example of an injector to study that actually works, I get all of them to compile (have been using both dev-c++ and codeblocks) but they never inject my dll to any process.

Code:
#include <windows.h>
#include <tlhelp32.h>

BOOL EnablePriv(LPCSTR lpszPriv)
	{
	    HANDLE hToken;
	    LUID luid;
	    TOKEN_PRIVILEGES tkprivs;
	    ZeroMemory(&tkprivs, sizeof(tkprivs));
	    if(!OpenProcessToken(GetCurrentProcess(), (TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY), &hToken)) return FALSE;
	    if(!LookupPrivilegeValue(NULL, lpszPriv, &luid)){ CloseHandle(hToken); return FALSE; }
	    tkprivs.PrivilegeCount = 1;
	    tkprivs.Privileges[0].Luid = luid;
	    tkprivs.Privileges[0].Attributes = SE_PRIVILEGE_ENABLED;
	    BOOL bRet = AdjustTokenPrivileges(hToken, FALSE, &tkprivs, sizeof(tkprivs), NULL, NULL);
	    CloseHandle(hToken);
	    return bRet;
	}


DWORD RemoteLoadLibrary(LPSTR lpszProcess, DWORD dwPID, HANDLE hProcess, LPSTR lpszModuleName)
	{
	    DWORD dwModuleBase;
	    if(lpszProcess != NULL){
	        HANDLE hProcesses = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
	        if(hProcesses != NULL){
	            PROCESSENTRY32 pe32 = { sizeof(PROCESSENTRY32) };
	            if(Process32First(hProcesses, &pe32)){
	                do{
	                    if(!strcmp(lpszProcess, pe32.szExeFile)){
	                        dwPID = pe32.th32ProcessID; break;
	                    }                      
	                }
					while(Process32Next(hProcesses, &pe32));
	            }	            CloseHandle(hProcesses);
	        }
	    }
	    if(dwPID != 0) hProcess = OpenProcess(PROCESS_ALL_ACCESS, FALSE, dwPID);
	    if(hProcess != NULL){
	        DWORD dwSize = lstrlen(lpszModuleName) + 1;
	        LPBYTE lpszModuleRemoteName = (LPBYTE)VirtualAllocEx(hProcess, NULL, dwSize, MEM_COMMIT, PAGE_EXECUTE_READWRITE);
	        if(lpszModuleRemoteName != NULL)
	        {
	            WriteProcessMemory(hProcess, lpszModuleRemoteName, lpszModuleName, dwSize, NULL);
	            HANDLE hThread = CreateRemoteThread(hProcess, NULL, 0,
	                (LPTHREAD_START_ROUTINE)GetProcAddress(GetModuleHandle("kernel32.dll"), "LoadLibraryA"), lpszModuleRemoteName, 0, NULL);
	            if(hThread != NULL)
	            {	                WaitForSingleObject(hThread, 10000); // 10 seconds
	                GetExitCodeThread(hThread, &dwModuleBase);
	                CloseHandle(hThread);
	            }
	            VirtualFreeEx(hProcess, lpszModuleRemoteName, dwSize, MEM_RELEASE);
	        }
	        if(dwPID != 0) CloseHandle(hProcess);
	    }
	    return dwModuleBase;
	}
	
int main(){
	EnablePriv(SE_DEBUG_NAME);
	DWORD dwBase = RemoteLoadLibrary("notepad.exe", 0, NULL, "lol.dll");
	return 0;
}
Here is my example dll I'm trying to inject (it injects correctly with xsyr1ngex, perx etc).

[CODE]

#include <windows.h>
#include <stdio.h>

DWORD ThreadID;

DWORD WINAPI Action(LPVOID lParam) {

//Do stuff

ExitThread(0);
}

BOOL WINAPI DllMain(HINSTANCE hinstDLL, DWORD fdwReason, LPVOID lpvReserved)
{
if(fdwReason == DLL_PROCESS_ATTACH) {
MessageBox(0, "Dll Injection Successful! ", "Dll calling", MB_ICONEXCLAMATION | MB_OK);
CreateThread(NULL, 0, (LPTHREAD_START_ROUTINE)&Action, 0, 0, &ThreadID);
}

return 1;
}
I'm sorry, I looked through it and tried it and it doesn't work for me either. It does look a little over complicated though. If you don't know how it works you should simplify it as much as possible, then work your way from there.

Here, me and Jetamay already explained this in another thread.

Go here

And here

I hope that helps.
Thank you for your answer. Yea, I suppose I just have to keep on trying...
But it seems more and more likely to me that there are some problems with my priviligies or something else because most of the sources I've used seem to work for other people. Another source I tried did allow me to spawn a process and inject directly, but injecting while running failed as usual (and also as usual, no errorhandling whatsoever kicked in which makes it a lot harder to locate the problem).

I run Win XP with admin acc so priviliges shouldn't be a problem though.
I don't think it's a problem with your priviliges, I removed that function from your program and tried it again, it still doesn't inject. Like I said, simplify it as much as possible, only use the necessary functions.

I can give you an example if you'd like.
Would love that. I understand the most parts of the code (except for the set priviligies stuff), it just seems hard to get it to work by myself since I already tried so many different sources (both easier and more complicated one's like this) and yet fail.
I just made this now and tested it, it works fine with your DLL.

[php]#include <iostream>
#include <windows.h>

using namespace std;

DWORD Pid;
string DllPath = "C:\\lol.dll"; // Path to DLL
DWORD Load = (DWORD)GetProcAddress(GetModuleHandle("kernel32"), "LoadLibraryA");

int main()
{
HWND hwnd = FindWindow(0,"Notepad - Untitled");

GetWindowThreadProcessId(hwnd,&Pid);

HANDLE handle = OpenProcess(PROCESS_ALL_ACCESS,0,Pid);

LPVOID Address = VirtualAllocEx(handle,0,DllPath.size(),MEM_COMMIT, PAGE_READWRITE);

WriteProcessMemory(handle,Address,DllPath.c_str(), DllPath.size(),0);

CreateRemoteThread(handle,0,0,(LPTHREAD_START_ROUT INE)Load,Address,0,0);
}

[/php]

I tried to make it as simple as possible.
Mate, awsome! Haha I cannot find words to thank you really, this has been pissing me off a lot. Now it shouldn't be any problem for me to grab process to inject to with the process snapshot thingie if I want to or add other stuff, I just wanted a working base to look at. Ty again!
Hehe, glad I helped.

I guess this is what this section was made for.
I'm learning form this too. Thanks David.

I need to read up on WriteProcessMem and CreateRemoteThread. Or for that matter windows in general.


Actually I was just thinking. Injectors are a fairly popular topic around here. Maybe you could write just write a brief summary of how it works and I would love to add it to the tutorial list if its not too much trouble.
I'll write one soon that works by exe name instead of window name
Quote Originally Posted by TehKiller View Post
I'll write one soon that works by exe name instead of window name
Yeh injecting by process name seems a little easier.
haha, i cant help u but im just sayng, i've got the same problem but i try to make a dll injector in vb
David is tha man hehe
That code would be an excellent tutorial/intro to dll injections I think, because it's so simple. If it's added to a tutorial, just remove iostream though and use char instead to hold the dll path/name and the injector will shrink a lot in size =) (for me it went from 400 kb+ to about 19 kb).

Quote Originally Posted by martijno0o0 View Post
haha, i cant help u but im just sayng, i've got the same problem but i try to make a dll injector in vb
Good luck, I've seen a couple of tuts on them too.
'char' doesn't end with a null terminated character. Not sure if that will work.

Take a look at this. Null terminated string

You could always manually add the null character at the end of the path.

[php]
char DllPath[] = "C:\\lol.dll\0";
[/php]

If you use a 'char*' I suggest using strlen instead of sizeof.

strlen
Quote Originally Posted by Void View Post
'char' doesn't end with a null terminated character. Not sure if that will work.

Take a look at this. Null terminated string

You could always manually add the null character at the end of the path.

[php]
char DllPath[] = "C:\\lol.dll\0";
[/php]

If you use a 'char*' I suggest using strlen instead of sizeof.

strlen
Yep I know.
char DllPath[] = "C:\\lol.dll"; worked fine for me though when I tried it.
Posts 1–15 of 15 · Page 1 of 1
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Talk with us