Hello every one,
This is a littel tutorial how to hook:
1: First make a test application. Make a loop:
2: Load it up in olly and find a place to hook:
Code:
01161030 |> 8B4424 04 /MOV EAX,DWORD PTR SS:[ESP+4]
01161034 |. 8B0D 64201601 |MOV ECX,DWORD PTR DS:[<&MSVCP100.?cout@
0116103A |. 40 |INC EAX
0116103B |. 68 18211601 |PUSH OFFSET 01162118 ; /_Val = " Feel free to hook in this part of code This is a very yes a very easy part to hook.
"
01161040 |. 50 |PUSH EAX ; |/Arg1
01161041 |. 68 70211601 |PUSH OFFSET 01162170 ; ||/_Val = "We are at number: "
01161046 |. 51 |PUSH ECX ; |||_Ostr
01161047 |. 894424 14 |MOV DWORD PTR SS:[ESP+14],EAX ; |||
0116104B |. E8 E0000000 |CALL std::operator<<<std::char_traits<c ; ||\std::operator<<<std::char_traits<char> >
01161050 |. 83C4 08 |ADD ESP,8 ; ||
01161053 |. 8BC8 |MOV ECX,EAX ; ||
01161055 |. FF15 5C201601 |CALL DWORD PTR DS:[<&MSVCP100.??6?$basi ; |\MSVCP100.??6?$basic_ostream@DU?$char_traits@D@<a href="http://www.mpgh.net/forum/member.php?u=567241" target="_blank">STD</a>@@@<a href="http://www.mpgh.net/forum/member.php?u=567241" target="_blank">STD</a>@@QAEAAV01@J@Z
0116105B |. 50 |PUSH EAX ; |_Ostr
0116105C |. E8 CF000000 |CALL std::operator<<<std::char_traits<c ; \std::operator<<<std::char_traits<char> >
01161061 |. A1 64201601 |MOV EAX,DWORD PTR DS:[<&MSVCP100.?cout@
01161066 |. 83C4 08 |ADD ESP,8
01161069 |. 68 84211601 |PUSH OFFSET 01162184 ; /_Val = " gl!!
"
0116106E |. 8D5424 08 |LEA EDX,[ESP+8] ; |
01161072 |. 52 |PUSH EDX ; |/Arg1
01161073 |. 68 8C211601 |PUSH OFFSET 0116218C ; ||/_Val = "THe address of counter is: "
01161078 |. 50 |PUSH EAX ; |||_Ostr
01161079 |. E8 B2000000 |CALL std::operator<<<std::char_traits<c ; ||\std::operator<<<std::char_traits<char> >
0116107E |. 83C4 08 |ADD ESP,8 ; ||
01161081 |. 8BC8 |MOV ECX,EAX ; ||
01161083 |. FF15 58201601 |CALL DWORD PTR DS:[<&MSVCP100.??6?$basi ; |\MSVCP100.??6?$basic_ostream@DU?$char_traits@D@<a href="http://www.mpgh.net/forum/member.php?u=567241" target="_blank">STD</a>@@@<a href="http://www.mpgh.net/forum/member.php?u=567241" target="_blank">STD</a>@@QAEAAV01@PBX@Z
01161089 |. 50 |PUSH EAX ; |_Ostr
0116108A |. E8 A1000000 |CALL std::operator<<<std::char_traits<c ; \std::operator<<<std::char_traits<char> >
0116108F |. 83C4 08 |ADD ESP,8
01161092 |. 68 E8030000 |PUSH 3E8
01161097 |. FFD6 |CALL ESI
01161099 \.- EB 95 \JMP SHORT 01161030
You will think, why how do I know a nice place to hook? And what do I need for that?
Nice place
You need to over ride a part of code. I chose a part with out any jumps or calls. Why? Becouse that is easy.
What do I need
You need 5 bytes. Becouse you are going to over ride 5 bytes with code. Why? A jump to a custom function needs 5 bytes
What are "5 bytes"
The 2nd "command" are the bytes:
0116108F |.
83C4 08 |ADD ESP,8
01161092 |.
68 E8030000 |PUSH 3E8
01161097 |.
FFD6 |CALL ESI
83C4 08 = 3 bytes
68 E8030000 = 5 bytes
FFD6 = 2 bytes
Why do you took more?
You need a place to jump back. You need to resume the code.
Can I take a part of a command?
no!
What do I need to do if I have left?
Nop it.
Oke, now we have a nice place. We are going to place a jump here.
Searth the bytes and over ride them with a jump to your location: (I pref a dll)
Code:
01181069 |. 68 84211801 |PUSH OFFSET 01182184 ; /_Val = " gl!!
"
0118106E |. 8D5424 08 |LEA EDX,[ESP+8] ; |
01181072 |. 52 |PUSH EDX ; |/Arg1
01181073 |. 68 8C211801 |PUSH OFFSET 0118218C ; ||/_Val = "THe address of counter is: "
01181078 |. 50 |PUSH EAX ; |||_Ostr
01181079 |. E8 B2000000 |CALL std::operator<<<std::char_traits<c ; ||\std::operator<<<std::char_traits<char> >
0118107E |. 83C4 08 |ADD ESP,8 ; ||
01181081 |. 8BC8 |MOV ECX,EAX ; ||
01181083 |. FF15 58201801 |CALL DWORD PTR DS:[<&MSVCP100.??6?$basi ; |\MSVCP100.??6?$basic_ostream@DU?$char_traits@D@<a href="http://www.mpgh.net/forum/member.php?u=567241" target="_blank">STD</a>@@@<a href="http://www.mpgh.net/forum/member.php?u=567241" target="_blank">STD</a>@@QAEAAV01@PBX@Z
01181089 |. 50 |PUSH EAX ; |_Ostr
0118108A |. E8 A1000000 |CALL std::operator<<<std::char_traits<c ; \std::operator<<<std::char_traits<char> >
0118108F |. E9 6CFFDF61 |JMP hookfunction
01181094 |? 90 |NOP
01181095 |? 90 |NOP
01181096 |? 90 |NOP
01181097 |. FFD6 |CALL ESI
01181099 \.- EB 95 \JMP SHORT 01181030
0118109B CC INT3
Now we have a jump to our location. But w8? We deleted some bytes...
What to do if you made a jump
Restore the old bytes. use inline assambly for that.
Can I do hacks now?
Yes, afther the restore do some hacks
Do I need to do more?
Yes, Return back under your jump
Code:
Dump - Crossfire:.text
Address Hex dump Command Comments
0118108F |. E9 6CFFDF61 |JMP hookfunction
01181094 |? 90 |NOP
01181095 |? 90 |NOP
01181096 |? 90 |NOP
01181097 |. FFD6 |CALL ESI
The result:
The loop in my test app:
Code:
0118108F |. E9 6CFFDF61 |JMP hookfunction
01181094 |? 90 |NOP
01181095 |? 90 |NOP
01181096 |? 90 |NOP
01181097 |. FFD6 |CALL ESI
01181099 \.- EB 95 \JMP SHORT 01181030
The function I called:
Code:
62F81009 |. 68 F4010000 PUSH 1F4 ; /Duration = 500.
62F8100E |. 68 F4010000 PUSH 1F4 ; |Frequency = 500.
62F81013 |. FF15 0020F862 CALL DWORD PTR DS:[<&KERNEL32.Beep>] ; \KERNEL32.Beep
More, and more, and more
62F8101A \. FF25 4433F862 JMP DWORD PTR DS:[jumplocation]
A video:
If you know the C++ basics, and know somting about memory edeting.. Then you can use this tutorial to make a hook. Good luck all
By Brimir
Edit:
Thanks @
258456 for correcting a part.
You don't need the "83C4 08" any more. You just can hook the 5 bytes bellow.