D3D9 Remote Hook VB.NET

Posts 1–12 of 12 · Page 1 of 1
D3D9 Remote Hook VB.NET
Hello! Today I made an EndScene d3d9 hook in vb.net. THIS HOOK WILL PROBABLY ONLY WORK IN WINDOWS VISTA/7... IT IS EASY TO TRANSFER TO OTHER OS. SKYPE ME FOR DETAILS : LUCASHEER715

What it does :
•Makes/allocates pointer objects to D3DRECT for rectangle drawing and endscene return address
•Creates allocated code cave which patches first 5 bytes of endscene function (that are being replaced)
•Writes asm stub function (including the patch) to the allocated space
•Writes JMP from endscene to code cave

Result :
 
Result in d3d9 test environment


Source (without memory module) :
 
Source
Code:
    Private PROCESS_ALL_ACCESS As UInt32 = &H1F0FFF

    Sub Main()
        Dim processID As Int32 = Process.GetProcessesByName("csgo")(0).Id
        Dim processHandle As IntPtr = OpenProcess(PROCESS_ALL_ACCESS, False, processID)


        Dim d3d9Module As IntPtr = GetModuleBaseAddress("csgo", "d3d9.dll")

        Dim sb_vTableBytes As Byte() = {&HC7, &H6, &H0, &H0, &H0, &H0, &H89, &H86, &H0, &H0, &H0, &H0, &H89, &H86}
        Dim pDeviceScan As IntPtr = Scan(processHandle, sb_vTableBytes, "xx????xx????xx", d3d9Module, &HFFFFFF)
        Dim vTableAddr As IntPtr = readDword(processHandle, pDeviceScan + &H2)
        Dim ESAddr As Int32 = readDword(processHandle, vTableAddr + &HA8)

        Dim rectBytes As Byte() = {&H5, &H0, &H0, &H0, &H5, &H0, &H0, &H0, &H64, &H0, &H0, &H0, &H64, &H0, &H0, &H0, &H0, &H0, &H0, &H0, &H75, &H98, &H0, &H0}

        Dim rectX As Int32 = 10
        Dim rectY As Int32 = 40
        Dim rectW As Int32 = 100
        Dim rectH As Int32 = 150

        Array.Copy(BitConverter.GetBytes(rectX), 0, rectBytes, 0, 4)
        Array.Copy(BitConverter.GetBytes(rectY), 0, rectBytes, 4, 4)
        Array.Copy(BitConverter.GetBytes(rectW), 0, rectBytes, 8, 4)
        Array.Copy(BitConverter.GetBytes(rectH), 0, rectBytes, 12, 4)

        Dim c_alpha As Byte = 255
        Dim c_red As Byte = 0
        Dim c_green As Byte = 255
        Dim c_blue As Byte = 255

        Dim colorBytes As Byte() = {c_alpha, c_red, c_green, c_blue}

        Dim rectAlloc As IntPtr = VirtualAllocEx(processHandle, 0, rectBytes.Length, &H1000, &H40)
        writeBytes(processHandle, rectAlloc, rectBytes, rectBytes.Length)

        Dim esRetAddr As IntPtr = VirtualAllocEx(processHandle, 0, 4, &H1000, &H40)
        writeDword(processHandle, esRetAddr, ESAddr + &H5)

        Dim ab_rectBytes As Byte() = BitConverter.GetBytes(rectAlloc.ToInt32)
        Dim ab_esRetBytes As Byte() = BitConverter.GetBytes(esRetAddr.ToInt32)

        Dim detourBytes As Byte() = {&H8B, &HFF, &H55, &H8B, &HEC, &H60, &H36, &H8B, &H75,
                                      &H8, &H89, &H75, &H8, &H8B, &HF4, &H6A, &H0, &H51, &HF,
                                      &H57, &HC0, &HF3, &HF, &H11, &H4, &H24, &H68, colorBytes(0), colorBytes(1),
                                      colorBytes(2), colorBytes(3), &H6A, &H1, &H68, ab_rectBytes(0), ab_rectBytes(1), ab_rectBytes(2), ab_rectBytes(3),
                                      &H6A, &H1, &H8B, &H45, &H8, &H8B, &H8, &H8B, &H55, &H8, &H52, &H8B, &H81, &HAC, &H0, &H0, &H0,
                                      &HFF, &HD0, &H3B, &HF4, &H61, &HFF, &H25, ab_esRetBytes(0), ab_esRetBytes(1), ab_esRetBytes(2), ab_esRetBytes(3)}
        Dim detourFuncAlloc As IntPtr = VirtualAllocEx(processHandle, 0, detourBytes.Length, &H1000, &H40)
        writeBytes(processHandle, detourFuncAlloc, detourBytes, detourBytes.Length)

        Dim jmpOffset As Int32 = detourFuncAlloc - ESAddr - 5
        Dim ab_jmpOffset As Byte() = BitConverter.GetBytes(jmpOffset)
        Dim jmpBytes As Byte() = {&HE9, ab_jmpOffset(0), ab_jmpOffset(1), ab_jmpOffset(2), ab_jmpOffset(3)}

        writeBytes(processHandle, ESAddr, jmpBytes, jmpBytes.Length)

        Console.ReadLine()

    End Sub


Memory Module :
 
Memory Module
Code:
Imports System.Runtime.InteropServices
Imports System.Diagnostics

Module Memory

#Region "Structures"
    Structure MODULEENTRY32
        Dim U32Size As UInteger
        Dim Th32ModuleId As UInteger
        Dim Th32ProcessId As UInteger
        Dim GlblcntUsage As UInteger
        Dim ProccntUsage As UInteger
        Dim ModBaseAddr As IntPtr
        Dim ModBaseSize As UInteger
        Dim HModule As IntPtr
        <Runtime.InteropServices.MarshalAs(Runtime.InteropServices.UnmanagedType.ByValTStr, SizeConst:=256)> Dim SzModule As String
        <Runtime.InteropServices.MarshalAs(Runtime.InteropServices.UnmanagedType.ByValTStr, SizeConst:=260)> Dim SzeExePath As String
    End Structure
#End Region

#Region "External Functions"
    Public Declare Function CloseHandle Lib "kernel32" (ByVal pHandle As IntPtr) As Boolean
    Public Declare Function OpenProcess Lib "kernel32" (ByVal dwDesiredAccess As Integer, ByVal bInheritHandle As Boolean, ByVal dwProcessId As UInteger) As IntPtr
    Public Declare Function ReadProcessMemory Lib "kernel32" (ByVal hProcess As IntPtr, ByVal lpBaseAddress As IntPtr, <Out()> ByVal lpBuffer As Byte(), ByVal nSize As UInteger, ByRef lpNumberOfBytesRead As UInteger) As Boolean
    Public Declare Function WriteProcessMemory Lib "kernel32" (ByVal hProcess As IntPtr, ByVal lpBaseAddress As IntPtr, ByVal lpBuffer As Byte(), ByVal nSize As UInteger, ByRef lpNumberOfBytesWritten As UInteger) As Boolean
    Public Declare Function VirtualProtectEx Lib "kernel32" (ByVal hProcess As IntPtr, ByVal lpAddress As UInt32, ByVal dwSize As UInteger, ByVal flNewProtect As UInteger, ByRef lpflOldProtect As UInteger) As Boolean

    Public Declare Function Module32Next Lib "kernel32" (ByVal hSnapshot As IntPtr, ByRef lpme As MODULEENTRY32) As Boolean
    Public Declare Function Module32First Lib "kernel32" (ByVal hSnapshot As IntPtr, ByRef lpme As MODULEENTRY32) As Boolean
    Public Declare Function CreateToolhelp32Snapshot Lib "kernel32" (ByVal dwFlags As UInteger, ByVal u32ProcessId As UInteger) As IntPtr

    Public Declare Function VirtualAllocEx Lib "kernel32" (ByVal hProcess As IntPtr, ByVal lpAddress As UInt32, ByVal dwSize As UInteger, ByVal flAllocationType As UInteger, ByVal flProtect As UInteger) As IntPtr

    Public Declare Function Toolhelp32ReadProcessMemory Lib "kernel32" (ByVal th32ProcessID As Integer, ByVal lpBaseAddress As IntPtr, <Out()> ByVal lpBuffer As Byte(), ByVal nSize As Integer, ByRef lpNumberOfBytesRead As Integer) As Boolean


    <DllImport("kernel32.dll", SetLastError:=True, CharSet:=CharSet.Ansi, ExactSpelling:=True)>
    Public Function GetProcAddress(ByVal hModule As IntPtr, ByVal procName As String) As UInt32
    End Function

    <DllImport("kernel32.dll", CharSet:=CharSet.Auto, SetLastError:=True)>
    Public Function GetModuleHandle(ByVal lpModuleName As String) As UInt32
    End Function
#End Region

#Region "Memory Reading"

    Private Const BUFFER_SIZE As Integer = 16384

    Public Function readBytes(ByVal hProcess As Integer, ByVal lpBaseAddress As UInt32, ByVal nSize As UInteger) As Byte()
        Dim Buffer(CInt(nSize - 1)) As Byte
        ReadProcessMemory(hProcess, lpBaseAddress, Buffer, nSize, Nothing)
        Return Buffer
    End Function

    Public Function readDword(ByVal hProcess As Integer, ByVal lpBaseAddress As UInt32) As Int32
        Return BitConverter.ToInt32(readBytes(hProcess, lpBaseAddress, 4), 0)
    End Function

    Public Function readFloat(ByVal hProcess As Integer, ByVal lpBaseAddress As UInt32) As Single
        Return BitConverter.ToSingle(readBytes(hProcess, lpBaseAddress, 4), 0)
    End Function

    Public Function readWord(ByVal hProcess As Integer, ByVal lpBaseAddress As UInt32) As Int16
        Return BitConverter.ToInt16(readBytes(hProcess, lpBaseAddress, 2), 0)
    End Function

    Public Function readByte(ByVal hProcess As Integer, ByVal lpBaseAddress As UInt32) As Byte
        Return readBytes(hProcess, lpBaseAddress, 1)(0)
    End Function

    Public Function Scan(ByVal processHandle As Int32, ByVal pattern As Byte(), ByVal mask As String, ByVal startAddress As IntPtr, ByVal length As Integer) As IntPtr
        If processHandle = IntPtr.Zero Then Throw New ArgumentNullException("processHandle")
        If pattern Is Nothing Then Throw New ArgumentNullException("pattern")
        If length <= 0 Then Throw New ArgumentOutOfRangeException("length")
        If pattern.Length <> mask.Length Then Throw New ArgumentException("Both 'pattern' and 'mask' must be of equal length.")

        Dim results = Scan_impl(processHandle, pattern, mask, startAddress, length, True)
        Return If(results.Count = 1, results(0), IntPtr.Zero)
    End Function

    Public Function ScanAll(ByVal processHandle As Int32, ByVal pattern As Byte(), ByVal mask As String, ByVal startAddress As IntPtr, ByVal length As Integer) As List(Of IntPtr)
        If processHandle = IntPtr.Zero Then Throw New ArgumentNullException("processHandle")
        If pattern Is Nothing Then Throw New ArgumentNullException("pattern")
        If length <= 0 Then Throw New ArgumentOutOfRangeException("length")
        If pattern.Length <> mask.Length Then Throw New ArgumentException("Both 'pattern' and 'mask' must be of equal length.")

        Dim results = Scan_impl(processHandle, pattern, mask, startAddress, length, False)
        Return results
    End Function

    Private Function Scan_impl(ByVal processHandle As Int32, ByVal pattern As Byte(), ByVal mask As String, ByVal startAddress As IntPtr, ByVal length As Integer, Optional ByVal shortCircuit As Boolean = True) As List(Of IntPtr)
        Dim blockSize As Integer = Math.Min(length, BUFFER_SIZE)
        Dim iterator As Integer = 0
        Dim read As UIntPtr = UIntPtr.Zero
        Dim buffer(blockSize - 1) As Byte
        Dim cmask = mask.ToCharArray()
        Dim results As New List(Of IntPtr)

        While iterator < length
            If Not ReadProcessMemory(processHandle, New IntPtr(startAddress.ToInt64() + iterator), buffer, CType(Math.Min(blockSize, length - iterator), UIntPtr), read) Then
                Throw New InvalidOperationException("Unable to read memory from the target process. Please ensure the process handle is valid and has correct read permissions.")
            End If

            Dim location = Scan_search(buffer, pattern, cmask, read.ToUInt32(), shortCircuit)
            If location.Count > 0 Then
                results.AddRange(location.Select(Function(i) New IntPtr(iterator + startAddress.ToInt32() + i)))
                If shortCircuit Then Return results
            End If

            iterator += read.ToUInt32()
        End While

        Return results
    End Function

    Private Function Scan_search(ByVal haystack As Byte(), ByVal pattern As Byte(), ByVal mask As Char(), ByVal length As Integer, Optional ByVal shortCircuit As Boolean = True) As List(Of Integer)
        Dim results As New List(Of Integer)

        For i As Integer = 0 To (length - pattern.Length - 1)
            For j As Integer = 0 To (pattern.Length - 1)
                If mask(j) = "?"c OrElse (haystack(i + j) = pattern(j)) Then
                    If j = (pattern.Length - 1) Then
                        results.Add(i)
                        If shortCircuit Then Return results
                    End If
                Else
                    Exit For ' no point iterating i * j times, can exit this loop as soon as a mismatch is identified
                End If
            Next j
        Next i

        Return results
    End Function

    Public Function ReadPointerFromMemory(ByVal hProcess As Integer, ByVal BaseAddress As Integer, ByVal PointerOffset As Integer, ByVal BytesToRead As Integer) As Integer
        Dim BytesAtAddress As Byte() = New Byte(BytesToRead - 1) {}
        Dim BytesRead As Integer
        Dim MemoryBase As Integer
        Dim ReturnVal As Integer
        ReadProcessMemory(hProcess, CType(BaseAddress, IntPtr), BytesAtAddress, BytesToRead, BytesRead)
        MemoryBase = BitConverter.ToInt32(BytesAtAddress, 0)
        MemoryBase += PointerOffset
        ReadProcessMemory(hProcess, CType(MemoryBase, IntPtr), BytesAtAddress, BytesToRead, BytesRead)
        ReturnVal = BitConverter.ToInt32(BytesAtAddress, 0)
        Return ReturnVal
    End Function

    Public Function RemoteGetProcAddressManual(ByVal hProcess As Integer, ByVal ModuleAddress As UInteger, ByVal Export As String) As UInteger

        Dim PEHeaderOffset As UInteger = BitConverter.ToUInt32(readBytes(hProcess, CType(ModuleAddress + &H3C, IntPtr), 4), 0)
        Dim ExportRVA As UInteger = BitConverter.ToUInt32(readBytes(hProcess, CType(ModuleAddress + PEHeaderOffset + &H78, IntPtr), 4), 0)
        Dim IExportDir() As Byte = readBytes(hProcess, CType(ModuleAddress + ExportRVA, IntPtr), 40)
        Dim NamesCnt As Integer = BitConverter.ToInt32(IExportDir, 24)
        Dim Names As UInteger = BitConverter.ToUInt32(IExportDir, 32) + ModuleAddress
        Dim FuncAddress As UInteger = BitConverter.ToUInt32(IExportDir, 28) + ModuleAddress
        Dim Ordinals As UInteger = BitConverter.ToUInt32(IExportDir, 36) + ModuleAddress

        Dim tpAddress, ApiAddress, Ord As UInteger
        Dim ApiString As String = Nothing
        Dim Ptr As IntPtr = Runtime.InteropServices.Marshal.AllocHGlobal(64)

        For i = 1 To NamesCnt
            tpAddress = BitConverter.ToUInt32(readBytes(hProcess, CType(Names + ((i - 1) * 4), IntPtr), 4), 0)
            Runtime.InteropServices.Marshal.Copy(readBytes(hProcess, CType(ModuleAddress + tpAddress, IntPtr), 64), 0, Ptr, 64)
            ApiString = Runtime.InteropServices.Marshal.PtrToStringAnsi(Ptr)
            Ord = BitConverter.ToInt16(readBytes(hProcess, CType(Ordinals + ((i - 1) * 2), IntPtr), 2), 0)
            ApiAddress = BitConverter.ToUInt32(readBytes(hProcess, CType(FuncAddress + (Ord * 4), IntPtr), 4), 0) + ModuleAddress

            If String.Compare(ApiString, Export, True) = 0 Then
                Runtime.InteropServices.Marshal.FreeHGlobal(Ptr)
                Return ApiAddress
            End If

        Next

        Runtime.InteropServices.Marshal.FreeHGlobal(Ptr)
        Return Nothing

    End Function

    Public Function GetModuleBaseAddress(ByVal strProcess As String, ByVal strModule As String) As IntPtr
        Dim hSnapshot As IntPtr = CreateToolhelp32Snapshot(&H18, CUInt(Diagnostics.Process.GetProcessesByName(strProcess)(0).Id))
        If hSnapshot = Nothing Then Return Nothing
        Dim me32Modules As New MODULEENTRY32
        me32Modules.U32Size = CUInt(Runtime.InteropServices.Marshal.SizeOf(me32Modules))
        If Module32First(hSnapshot, me32Modules) Then
            Do

                If Not me32Modules.ModBaseAddr.ToInt64 > &H7FFFFFFF Then
                    If String.Compare(strModule, me32Modules.SzModule, True) = 0 Then Return me32Modules.ModBaseAddr
                Else
                End If
            Loop While (Module32Next(hSnapshot, me32Modules))
        End If
        Return Nothing
    End Function

    Public Function GetModuleBaseAddress1(ByVal strProcess As String, ByVal strModule As String) As IntPtr
        Dim p As Process = Process.GetProcessesByName(strProcess)(0)
        For Each moz As System.Diagnostics.ProcessModule In p.Modules
            If (moz.ModuleName.ToLower = strModule.ToLower) Then

                Return moz.BaseAddress
            End If
        Next
        Return Nothing
    End Function
#End Region

#Region "Memory Writing"

    Public Sub writeBytes(ByVal hProcess As IntPtr, ByVal lpBaseAddress As IntPtr, ByVal writeBytes As Byte(), ByVal nSize As UInt32)
        WriteProcessMemory(hProcess, lpBaseAddress, writeBytes, nSize, vbNull)
    End Sub

    Public Sub writeDword(ByVal hProcess As IntPtr, ByVal lpBaseAddress As IntPtr, ByVal dwordToWrite As Int32)
        Dim bytesToWrite As Byte() = BitConverter.GetBytes(dwordToWrite)
        writeBytes(hProcess, lpBaseAddress, bytesToWrite, 4)
    End Sub

    Public Sub writeFloat(ByVal hProcess As IntPtr, ByVal lpBaseAddress As IntPtr, ByVal floatToWrite As Single)
        Dim bytesToWrite As Byte() = BitConverter.GetBytes(floatToWrite)
        writeBytes(hProcess, lpBaseAddress, bytesToWrite, 4)
    End Sub

    Public Sub writeWord(ByVal hProcess As IntPtr, ByVal lpBaseAddress As IntPtr, ByVal wordToWrite As Int16)
        Dim bytesToWrite As Byte() = BitConverter.GetBytes(wordToWrite)
        writeBytes(hProcess, lpBaseAddress, bytesToWrite, 2)
    End Sub

    Public Sub writeByte(ByVal hProcess As IntPtr, ByVal lpBaseAddress As IntPtr, ByVal byteToWrite As Byte)
        Dim bytesToWrite As Byte() = {byteToWrite}
        writeBytes(hProcess, lpBaseAddress, bytesToWrite, 1)
    End Sub

#End Region

End Module


TODO: Make a real hook. Be able to draw full frames instead of 1 single rectangle...

Credits : Mostly me; some parts in memory module are from others.. idk credits

What is the significance here? You can externally hook the process without the use of CreateThread.. AND you can draw on top because it is EndScene. You even get pDevice. Most people say you can only hook EndScene internally.. but this sort of counts right?
All you're doing is writing a hardcoded byte array that renders the rectangle. You might as well code a dll in C/++ and inject the dll, it's easier than copying out the bytecode of your hooked function and writing that from VB...
Quote Originally Posted by Hell_Demon View Post
All you're doing is writing a hardcoded byte array that renders the rectangle. You might as well code a dll in C/++ and inject the dll, it's easier than copying out the bytecode of your hooked function and writing that from VB...
Well this was older version. I didn't just want to render a rectangle lol I want to be able to render unlimited objects by allocating a large space (like 10000) bytes, depending on how much drawing functions i need to call. Then, like c++, have a drawing function in vb.net that clears the allocation then adds objects as you go? understand?

"You might as well code a dll in C/++"
But all of my hacks are in vb.net.
Quote Originally Posted by Nine11 View Post
"You might as well code a dll in C/++"
But all of my hacks are in vb.net.
Why would you want to code hacks in vb.net?
Quote Originally Posted by Hell_Demon View Post
Why would you want to code hacks in vb.net?
Its more fun to type than c# or c++ :P
Quote Originally Posted by Nine11 View Post
Its more fun to type than c# or c++ :P
There is a difference between fun and easier. lol
Quote Originally Posted by Mayion View Post


There is a difference between fun and easier. lol
I came up with other reasons too man

Remote hooking like this has less detection, maybe?

Why?

•Not Loading a full binary, nor writing a ton of bytes. (You are writing like 200 bytes at max)
•Depending on module injection method, you can use lower access memory like this.
•Its not very conventional, and works on every game that doesn't detect mid hook.
•Not much CPU required. (When I try to manual map inject my hacks on some games without stub, it detects because of slowness...)

Convenience?
•No need for redistributables, and if you use .net 2.0 then your program is completely supported by newest OSs.
•No injection required, so you can just run mid game and not worry about a single thing.
•Any language that supports function declaring can do this (ex. VB.Net)

Id say there are more cons than pros, but is it not interesting? :P
Doesnt matter which language you use, if it works it works.
Plus, its just a Preference since porting to another language is too tedious do to just to make you people happy that he is not using Vb.net.
I use VB.NET myself, but it is no way near C#:

> Performance wise
> Capabilities
> Available Libraries and Hooks
> Ease of use; especially with projects where multiple classes are required.
(..)
Quote Originally Posted by Mayion View Post
I use VB.NET myself, but it is no way near C#:

> Performance wise
> Capabilities
> Available Libraries and Hooks
> Ease of use; especially with projects where multiple classes are required.
(..)
VB.Net and C#.Net are very similar bro. I am not sure exactly what you are talking about because your whole list is false if you're talking about C#.NET
VB.Net and C#.Net are both interpreted the same (giving same performance) and both using .Net
VB.Net can do anything that C#.Net can do (might have to use external functions to do it, but you can)
VB.Net can use libraries created in C#.net....
And I really dont get what you mean by that last one.

but btw bro I POSTED THIS IN VB SECTION.... I dont get why you would even post on this just to say your language is better if its in vb section. Kind of defeats the purpose of having multi-language sections.
Quote Originally Posted by Nine11 View Post
VB.Net and C#.Net are very similar bro. I am not sure exactly what you are talking about because your whole list is false if you're talking about C#.NET
VB.Net and C#.Net are both interpreted the same (giving same performance) and both using .Net
VB.Net can do anything that C#.Net can do (might have to use external functions to do it, but you can)
VB.Net can use libraries created in C#.net....
And I really dont get what you mean by that last one.

but btw bro I POSTED THIS IN VB SECTION.... I dont get why you would even post on this just to say your language is better if its in vb section. Kind of defeats the purpose of having multi-language sections.
Alright, chill bro. lol
You are taking this way too serious, whatever floats your boat either way.
Quote Originally Posted by Mayion View Post


Alright, chill bro. lol
You are taking this way too serious, whatever floats your boat either way.
im gonna bomb yo towers

edit : pls dont ban me
Posts 1–12 of 12 · Page 1 of 1
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Need help?