[Help]WriteProcessMemory - Write byte array?

Posts 16–30 of 30 · Page 2 of 2
Quote Originally Posted by Void View Post
I hope you know LoadLibrary does exactly this.

Edit: Agreed with whit.
Kernel32's LoadLibrary Function does not accept a Byte Array, it accepts a string.
Quote Originally Posted by Iamazn1 View Post
Kernel32's LoadLibrary Function does not accept a Byte Array, it accepts a string.
He's saying that the LoadLibrary function does write a byte array as part of it's process, sure it only accepts a string parameter for the path, but the process itself involves the writing of bytes. IMO they should have overloaded the function and allowed you to input raw bytes, but oh well.
Quote Originally Posted by topblast View Post
If this work.... maybe i can get injection method for my Blue file... i dont like outputing to temporary location... which takes time to create the file
How much time does it take to write 1GB onto disk? 5 seconds.

(I'm talking about 1 index, not 3000)

Quote Originally Posted by whit View Post


Dude STFU..
No one wants you here Trolling your wannabe pro ness
He kinda has a point.

Quote Originally Posted by Jason View Post


He's saying that the LoadLibrary function does write a byte array as part of it's process, sure it only accepts a string parameter for the path, but the process itself involves the writing of bytes. IMO they should have overloaded the function and allowed you to input raw bytes, but oh well.
Not possible, because Windows doesn't do it like that.

Quote Originally Posted by Void View Post
The problem with this is that modules are loaded into memory once, and they aren't loaded in a single programs allocated memory.

I'll do a bit of research on this for you, see what I can come up with.

Edit: Wow I'm dumb, I'm pretty sure this technique is called manual mapping.
Yes, you can manual map, but no, you're going to have a hell of a time coding it, especially in Visual Basic with all that interop. I found it hard enough doing it in C++.
Quote Originally Posted by Iamazn1 View Post
If you knew what the Injection code actually did, you'd know that writing the Byte Array to the Process's Memory instead of the DLL Path won't work.
You are wrong they. I understand every step in the injection function. It is mainly the only thing i really do in VB.


Quote Originally Posted by freedompeace View Post


How much time does it take to write 1GB onto disk? 5 seconds.

(I'm talking about 1 index, not 3000)

Everyone's computer is not the same.. and i had been bless with a slow computer for debugging.. It takes me some time to do those things.. Thanks to @Hassan i can use multi threading to do most my byte array and laggy work but it still lags.
Quote Originally Posted by master131 View Post
Hmm.. I don't like playing with System. Runtime.InteropServices. I'm already pissed off because of it since I've been wasting hours trying to make a working 64-bit injector in VB.Net. The problem seems to reside in CreateRemoteThread because it keps returning IntPtr.Zero (NULL).



PS - Why is . Run censored? O__o
Functions are the same in x86 and x64. The same code base in Portal (Combat Arms injector) is used for 32 and 64 bit operating systems. Just make sure you don't use Int32s because they are Int64s on x64.

Also, what is the value of the last error? (GetLastError())

Quote Originally Posted by topblast View Post


You are wrong they. I understand every step in the injection function. It is mainly the only thing i really do in VB.




Everyone's computer is not the same.. and i had been bless with a slow computer for debugging.. It takes me some time to do those things.. Thanks to @Hassan i can use multi threading to do most my byte array and laggy work but it still lags.
Obviously, we aren't dealing with Apple here. HDD speeds, however, have a lower bottom minimum to speed. I had used a very low speed to do my calculations.
Quote Originally Posted by master131 View Post
Hmm.. I don't like playing with System. Runtime.InteropServices. I'm already pissed off because of it since I've been wasting hours trying to make a working 64-bit injector in VB.Net. The problem seems to reside in CreateRemoteThread because it keps returning IntPtr.Zero (NULL).



PS - Why is . Run censored? O__o
Hmm i made Blue Mist injector in VB.net and from what i see it works for 64bit.


Quote Originally Posted by freedompeace View Post


Functions are the same in x86 and x64. The same code base in Portal (Combat Arms injector) is used for 32 and 64 bit operating systems. Just make sure you don't use Int32s because they are Int64s on x64.

Also, what is the value of the last error? (GetLastError())



Obviously, we aren't dealing with Apple here. HDD speeds, however, have a lower bottom minimum to speed. I had used a very low speed to do my calculations.
This computer cant play any game... and it lags when my injector is doing stuff and dont lag on other computers.
Quote Originally Posted by topblast View Post


Hmm i made Blue Mist injector in VB.net and from what i see it works for 64bit.




This computer cant play any game... and it lags when my injector is doing stuff and dont lag on other computers.
!(HDD space === lag.)

It's usually more to do with the available memory, graphics or processing unit than the hard drive. Hard drives from 10 years ago (the one I have on my home server) still run at perfect speeds.
Quote Originally Posted by freedompeace View Post


!(HDD space === lag.)

It's usually more to do with the available memory, graphics or processing unit than the hard drive. Hard drives from 10 years ago (the one I have on my home server) still run at perfect speeds.
You do know that i know that.

My problem is the whole computer. The Frequency is to low
Intel Pentium 4 Processor 2.4 gHz Clock speed 133mhz
512 MB DDR1 RAM @ 333 mHz (overclocked) 266 Default
OLD INTEL GRAPHIC CARD... DUDE I AM TALKING NO shader graphis, NO 3D Hardware... i dont even think it is over 32 mb. and the clock speed must be in the 10s
Quote Originally Posted by topblast View Post


You do know that i know that.

My problem is the whole computer. The Frequency is to low
Intel Pentium 4 Processor 2.4 gHz Clock speed 133mhz
512 MB DDR1 RAM @ 333 mHz (overclocked) 266 Default
OLD INTEL GRAPHIC CARD... DUDE I AM TALKING NO shader graphis, NO 3D Hardware... i dont even think it is over 32 mb. and the clock speed must be in the 10s
Why don't you upgrade ? :/
Quote Originally Posted by topblast View Post


Hmm i made Blue Mist injector in VB.net and from what i see it works for 64bit.
Yes, it may work in 64-bit but can it inject into 64-bit processes? I tried your Red Dragon 6 injector, didn't work.
Quote Originally Posted by master131 View Post
Yes, it may work in 64-bit but can it inject into 64-bit processes? I tried your Red Dragon 6 injector, didn't work.
Red Dragon does not work on 64bit.. But Blue Mist Injector does.

All my blue mist injector should work.... My Blue Mist injector haves to output the file into a random location (normally temp files) and inject from they ( and i can inject to more than one processes )In doing this it only makes a waste of the temp folder because i cant delete it because the Process us using it. And every injection outputs a Different file(allowing multiply processes to use a file for it self) This is why i wanted this so much. So i can just inject from the Blue class True File


Quote Originally Posted by Hassan View Post


Why don't you upgrade ? :/
I already have an upgrade.. this is a back up

UPGRADED HERE:

MSI P7N SLI (nForce 750i ) mother board
4gb DDR2 @ 666(kinda slow but over clocked)
AWAITING a Intel Core 2 Quad.. my Q9400 was not working well from the start and now it OUT!!!.
EVGA GeForce GTS 250 (planing on getting a 450 and SLI)
Sata drives and stuff but...
...../// I NEED A QUAD SO I AM STUCK WITH THIS THING
Hmm.. I don't like playing with System. Runtime.InteropServices. I'm already pissed off because of it since I've been wasting hours trying to make a working 64-bit injector in VB.Net. The problem seems to reside in CreateRemoteThread because it keps returning IntPtr.Zero (NULL).

Quote Originally Posted by http://msdn.microsoft.com/en-us/library/ms682437(v=vs.85)
If the function succeeds, the return value is a handle to the new thread.
If the function fails, the return value is NULL. To get extended error information, call GetLastError.
PS - Why is . Run censored? O__o
Quote Originally Posted by master131 View Post
Is it possible to inject an array of bytes? (lol, fail title)
I tried this, didn't work:

[highlight=vb.net] Public Declare Function VirtualAllocEx Lib "kernel32" ( _
ByVal hProcess As Integer, _
ByVal lpAddress As Integer, _
ByVal dwSize As Integer, _
ByVal flAllocationType As Integer, _
ByVal flProtect As Integer) As Integer

Public Declare Function WriteProcessMemory Lib "kernel32" ( _
ByVal hProcess As Integer, _
ByVal lpBaseAddress As Integer, _
ByVal lpBuffer As Byte(), _
ByVal nSize As Integer, _
ByRef lpNumberOfBytesWritten As Integer) As Integer

Private Declare Function CloseHandle Lib "kernel32" Alias "CloseHandle" ( _
ByVal hObject As Integer) As Integer

Public Declare Function CreateRemoteThread Lib "kernel32" ( _
ByVal hProcess As Integer, _
ByVal lpThreadAttributes As Integer, _
ByVal dwStackSize As Integer, _
ByVal lpStartAddress As Integer, _
ByVal lpParameter As Integer, _
ByVal dwCreationFlags As Integer, _
ByRef lpThreadId As Integer) As Integer

Public Declare Function OpenProcess Lib "kernel32" ( _
ByVal dwDesiredAccess As Integer, _
ByVal bInheritHandle As Integer, _
ByVal dwProcessId As Integer) As Integer

Public Declare Function GetProcAddress Lib "kernel32" ( _
ByVal hModule As Integer, ByVal lpProcName As String) As Integer

Private Declare Function GetModuleHandle Lib "Kernel32" Alias "GetModuleHandleA" ( _
ByVal lpModuleName As String) As Integer

Private TargetProcessHandle As Integer
Private pfnStartAddr As Integer
Public Const MEM_COMMIT = 4096
Public Const PAGE_READWRITE = 4
Public Const PROCESS_CREATE_THREAD = (&H2)
Public Const PROCESS_VM_OPERATION = (&H8)
Public Const PROCESS_VM_WRITE = (&H20)

Private Sub doCrap()
Dim TargetProcess As Process() = Process.GetProcessesByName("test")
TargetProcessHandle = OpenProcess(PROCESS_CREATE_THREAD Or PROCESS_VM_OPERATION Or PROCESS_VM_WRITE, False, TargetProcess(0).Id)
pfnStartAddr = GetProcAddress(GetModuleHandle("Kernel32"), "LoadLibraryA")
Dim LoadLibParamAdr As Integer
Dim fileBytes() As Byte = IO.File.ReadAllBytes("C:\test.dll")
Dim LoadLibParamAdr As Integer = VirtualAllocEx(TargetProcessHandle, 0, UBound(fileBytes), MEM_COMMIT, PAGE_READWRITE)
WriteProcessMemory(TargetProcessHandle, LoadLibParamAdr, fileBytes, UBound(fileBytes), 0)
CreateRemoteThread(TargetProcessHandle, 0, 0, pfnStartAddr, LoadLibParamAdr, 0, 0)
CloseHandle(TargetProcessHandle)
End Sub[/highlight]

I'm pretty sure it's something to do with LoadLibParamAdr or WriteProcessMemory. Btw, I'm just testing various injection methods.
Stop Spamming all of you.

It's possible...

But the ByVal fProtect is the problem. I saw this once... In my freaking vb bok is:
"A processusage program doesnt use to protect files that must be draged into the process, for example : if you are trying to hook a process just by adding: the protection by Integer it would fail without notice. But if you removed the files protection and bypassing the main hook from the process you will be able to make bytes to infiltrate a process."

I dont know what that is but it is in my vb book try that...

-SkinnLaw
Quote Originally Posted by topblast View Post


You do know that i know that.

My problem is the whole computer. The Frequency is to low
Intel Pentium 4 Processor 2.4 gHz Clock speed 133mhz
512 MB DDR1 RAM @ 333 mHz (overclocked) 266 Default
OLD INTEL GRAPHIC CARD... DUDE I AM TALKING NO shader graphis, NO 3D Hardware... i dont even think it is over 32 mb. and the clock speed must be in the 10s
And there you go boasting again. Again I will state that my computer is worse than that :L. If you want to compare something - no graphics card, 700Mhz CPU.

Now let's roll back and see why we started this in the first place.
Quote Originally Posted by Iamazn1 View Post
Quote Originally Posted by topblast View Post
If this work.... maybe i can get injection method for my Blue file... i dont like outputing to temporary location... which takes time to create the file
If you knew what the Injection code actually did, you'd know that writing the Byte Array to the Process's Memory instead of the DLL Path won't work.
Quote Originally Posted by freedompeace View Post
Quote Originally Posted by topblast View Post
If this work.... maybe i can get injection method for my Blue file... i dont like outputing to temporary location... which takes time to create the file
How much time does it take to write 1GB onto disk? 5 seconds.

(I'm talking about 1 index, not 3000)


Moving on.
Quote Originally Posted by Skinnlaw View Post
Stop Spamming all of you.

It's possible...

But the ByVal fProtect is the problem. I saw this once... In my freaking vb bok is:
"A processusage program doesnt use to protect files that must be draged into the process, for example : if you are trying to hook a process just by adding: the protection by Integer it would fail without notice. But if you removed the files protection and bypassing the main hook from the process you will be able to make bytes to infiltrate a process."

I dont know what that is but it is in my vb book try that...

-SkinnLaw
fProtect is not the problem.
Quote Originally Posted by freedompeace View Post


And there you go boasting again. Again I will state that my computer is worse than that :L. If you want to compare something - no graphics card, 700Mhz CPU.

Now let's roll back and see why we started this in the first place.




Moving on.


fProtect is not the problem.
Okay then what is the problem ?
Posts 16–30 of 30 · Page 2 of 2
This thread is closed for replies.

Tags for this Thread

None

Need help?