Solvedsome help please :(

Posts 1–6 of 6 · Page 1 of 1
some help please :(
I've seen some tuts on mid function hooking if that's what it's called. Any ways i am trying it out and my target process is cheat engine's first tutorial.
but when i inject the dll and hit "hit me" the program crashes, i know it is something wrong with my hook length, and the assembly code. i would really appreciate it if some one can help me out here. all i want it to do is instead of sub let it add that's all

#include <iostream>
#include <Windows.h>
using namespace std;


void Hook(BYTE*original,DWORD dwMyFunc,DWORD dwLen) {

DWORD oldProtection;
DWORD newProtection;
DWORD relAddress;

VirtualProtect(original, dwLen, PAGE_EXECUTE_READWRITE, &oldProtection);

relAddress = (DWORD)(dwMyFunc - (DWORD)original) - 5;

*original = 0xE9;

*((DWORD*)(original + 0x1)) = relAddress;

for (DWORD x = 0x5; x < dwLen; x++) {
*(original + x) = 0x90;
}

VirtualProtect(original, dwLen, oldProtection, &newProtection);
}

DWORD jmpBackAddress;
void _declspec(naked) myfunc() {
__asm {
add eax, edx
mov dword ptr ds:[ebx+480], eax
jmp [jmpBackAddress]
}
}

DWORD WINAPI myThread(LPVOID lpParam) {
DWORD hookLength = 0x8;
DWORD original = 0x00423AFE;
jmpBackAddress = original + hookLength;
Hook((BYTE*)original, (DWORD)myfunc, hookLength);
FreeLibraryAndExitThread((HMODULE)lpParam, 0);
return 0;
}


BOOL WINAPI DllMain(HINSTANCE hModule, DWORD dwReason, LPVOID lpReserve) {
switch (dwReason) {
case DLL_PROCESS_ATTACH:
CreateThread(NULL, 0, &myThread, hModule, 0, NULL);
break;
case DLL_PROCESS_DETACH:
break;
case DLL_THREAD_ATTACH:
break;
case DLL_THREAD_DETACH:
break;
}
return 1;
}
ex1.png19 KB · 9 downloads
Code:
#include <iostream>
#include <Windows.h>
using namespace std;


void Hook(BYTE*original,DWORD dwMyFunc,DWORD dwLen) {

	DWORD oldProtection;
	DWORD newProtection;
	DWORD relAddress;

	VirtualProtect(original, dwLen, PAGE_EXECUTE_READWRITE, &oldProtection);

	relAddress = (DWORD)(dwMyFunc - (DWORD)original) - 5;

	*original = 0xE9;

	*((DWORD*)(original + 0x1)) = relAddress;

	for (DWORD x = 0x5; x < dwLen; x++) {
		*(original + x) = 0x90;
	}

	VirtualProtect(original, dwLen, oldProtection, &newProtection);
}

DWORD jmpBackAddress;
void _declspec(naked) myfunc() {
	__asm {
		add eax, edx
		mov dword ptr ds:[ebx+480], eax
		jmp [jmpBackAddress]
	}
}

DWORD WINAPI myThread(LPVOID lpParam) {
	DWORD hookLength = 0x8;
	DWORD original = 0x00423AFE;
	jmpBackAddress = original + hookLength;
	Hook((BYTE*)original, (DWORD)myfunc, hookLength);
	FreeLibraryAndExitThread((HMODULE)lpParam, 0);
	return 0;
}


BOOL WINAPI DllMain(HINSTANCE hModule, DWORD dwReason, LPVOID lpReserve) {
	switch (dwReason) {
	case DLL_PROCESS_ATTACH:
		CreateThread(NULL, 0, &myThread, hModule, 0, NULL);
		break;
	case DLL_PROCESS_DETACH:
		break;
	case DLL_THREAD_ATTACH:
		break;
	case DLL_THREAD_DETACH:
		break;
	}
	return 1;
}
Commenting with proper indentation of the OP. Next time include it in [code] tags to make it more readable.

Which part of the tutorial are you trying to hook? I'll take a look when I have a few spare minutes.
here is what cheat engine memory viewer looks like before and after i inject

BEFORE injection
address bytes Opcode
00423AFE E9 51D6E00E sub
00423B00 89 83 80040000 nop
00423B06 8D 55 D4 lea

AFTER injection
address bytes Opcode
00423AFE E9 51D6E00E jmp
00423B03 90 nop
00423B04 90 nop
00423B05 90 nop
00423B06 8D 55 D4 lea

keep in mind that my hook address is 00423AFE and length is 8, these changed of values in the memory viewer tells me that the hook function is working as intended. do a jmp at the hook address, the jmp takes up 5 bytes, then fill the remaining bytes(in this case 3) with nop

so i think the problem is with the code that we jump to(which i suppose is the little inline assembly that i wrote)
here's that code
add eax, edx
mov dword ptr ds:[ebx+480], eax
jmp [jmpBackAddress]

as you can see there's only one change in my code than the original code that we overwrite, and that is changing the opcode sub to add.

the full code is at the top of the thread, i honestly dont know what else to do.

Nimboso thanks for your reply man, appreciate it alot. and its tutorial 1(step 2) i'm working on
Set a breakpoint and step through your code, see where it stops working.
Ok guys is found the problem
i attach the process to ollydbg, and i notice when i inject it said at the buttom thread exited code(0)
then when i hit the button ("hit me ") in the cheat engine tutorial, it have an access violation and not readable for my function address(obviously because the thread is killed)
so here's where i screwed up
Hook((BYTE*)original, (DWORD)myfunc, hookLength);
FreeLibraryAndExitThread((HMODULE)lpParam, 0);

after calling hook, i called the function to exit the thread, so if i hit the hit me button "hit me" it jmps to a function address that is not threre (because the thread is killed)
so i just put a loop there before calling FreeLibraryAndExitThread

thanks everyone
Seems like you got things solved, closed.
Posts 1–6 of 6 · Page 1 of 1
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Talk with us