Python WriteProcessMemory Strings

Posts 1–6 of 6 · Page 1 of 1
Python WriteProcessMemory Strings
Hey, so my WriteProcessMemory thingy is working fine, but only for integers. I used ctypes documentation to make it write to strings aswell but it doesnt really work.

(First one is the actual WriteProcessMemory for integers)

def WriteProcessMemory(self, hProcess, lpBaseAddress, Value):
try:
lpBaseAddress = lpBaseAddress
Value = Value
WriteBuffer = ctypes.c_uint(Value)
lpBuffer = ctypes.byref(WriteBuffer)
nSize = ctypes.sizeof(WriteBuffer)
lpNumberOfBytesWritten = ctypes.c_ulong(0)

ctypes.windll.kernel32.WriteProcessMemory(
hProcess,
lpBaseAddress,
lpBuffer,
nSize,
lpNumberOfBytesWritten
)
except (BufferError, ValueError, TypeError):
self.CloseHandle(hProcess)
e = 'Handle Closed, Error', hProcess, self.GetLastError()
return e

def WriteProcessMemoryString(self, hProcess, lpBaseAddress, Value):
try:
lpBaseAddress = lpBaseAddress
Value = Value
WriteBuffer = ctypes.c_wchar_p(Value)
lpBuffer = ctypes.byref(WriteBuffer)
nSize = ctypes.sizeof(WriteBuffer)
lpNumberOfBytesWritten = ctypes.c_ulong(nSize)

ctypes.windll.kernel32.WriteProcessMemory(
hProcess,
lpBaseAddress,
lpBuffer,
nSize,
lpNumberOfBytesWritten
)
except (BufferError, ValueError, TypeError):
self.CloseHandle(hProcess)
e = 'Handle Closed, Error', hProcess, self.GetLastError()
return e
Code:
WriteBuffer = ctypes.c_wchar_p(Value)
i have honestly no clue about python, but for me it looks, like you are using wchar_t instead of char at this point.
c_char is for 1-character bytes object, wchat_t is for 1-character string. The one i used (wchar_p) is equivalent to wchar_t * which is for a string
I honestly dont know whats missing here, acording to the documentation
sorry, but thats not correct.
a "string" in C Context is a byte array of bytes which is '\0' terminated
a "wstring" in C Context is a wchar_t (= 4 Bytes / character) is an array of array of 4 bytes which is also '\0' terminated

a C String would look like this:
Code:
{ 
	0x68, // 'h'
	0x65, // 'e'
	0x6c, // 'l'
	0x6c, // 'l'
	0x6f, // 'o' 
	0x20,  // ' '
	0x77, // 'w'
	0x6f, // 'o'
	0x72, // 'r'
	0x6c, // 'l'
	0x64, // 'd' 
	0
}
and a wstring:
Code:
{ 
	0xfeff0068, // 'h'
	0xfeff0065, // 'e'
	0xfeff006c, // 'l'
	0xfeff006c, // 'l'
	0xfeff006f, // 'o' 
	0xfeff0020,  // ' '
	0xfeff0077, // 'w'
	0xfeff006f, // 'o'
	0xfeff0072, // 'r'
	0xfeff006c, // 'l'
	0xfeff0064, // 'd' 
	0	
}
Quote Originally Posted by MikeRohsoft View Post
sorry, but thats not correct.
a "string" in C Context is a byte array of bytes which is '\0' terminated
a "wstring" in C Context is a wchar_t (= 4 Bytes / character) is an array of array of 4 bytes which is also '\0' terminated

a C String would look like this:
Code:
{ 
	0x68, // 'h'
	0x65, // 'e'
	0x6c, // 'l'
	0x6c, // 'l'
	0x6f, // 'o' 
	0x20,  // ' '
	0x77, // 'w'
	0x6f, // 'o'
	0x72, // 'r'
	0x6c, // 'l'
	0x64, // 'd' 
	0
}
and a wstring:
Code:
{ 
	0xfeff0068, // 'h'
	0xfeff0065, // 'e'
	0xfeff006c, // 'l'
	0xfeff006c, // 'l'
	0xfeff006f, // 'o' 
	0xfeff0020,  // ' '
	0xfeff0077, // 'w'
	0xfeff006f, // 'o'
	0xfeff0072, // 'r'
	0xfeff006c, // 'l'
	0xfeff0064, // 'd' 
	0	
}
So, should i use char instead?
this is when i call the function:

rwm.WriteProcessMemory(self.hProcess, self.pdePlus, 0) doing this i disable the string text i want
rwm.WriteProcessMemoryString(self.hProcess, self.pdePlus, "+") but this is the new string i want to overwrite, i had to do the same in c#

with self.hProcess being the process itself, self.pdePlus being the address, and the last thing the Value

how should it look when using char?

rwm.WriteProcessMemoryString(self.hProcess, self.pdePlus, 0x77) ?
Moved as requested.
Posts 1–6 of 6 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?