[Help] Different Injection

Posts 1–15 of 17 · Page 1 of 2
[Help] Different Injection
so i want to make an injector that does not use loadlibrary but calls an exported function from the DLL. I was thinking of ways to do it but i came up blank now will i be able to do that?
Quote Originally Posted by topblast View Post
so i want to make an injector that does not use loadlibrary but calls an exported function from the DLL. I was thinking of ways to do it but i came up blank now will i be able to do that?
My recommendation would be to ask people like @Hell_Demon and @Void (who I haven't seen around actually)
Although they code in C++, they can explain the various ways to inject. I'm pretty sure you either want to manually map the .dll, or so some other thing that HD always babbles on about.

Over to you Wezleh.
Ew. I had crash hell trying to manual map. So yeah, ask them, the PE headers were a royal PITA for me. But then again I'm just noob :)

EDIT: HOLY FUCK source code!! :D

Awesome. Except I'm not coding anything for the next 3 years til I finish high school.

Oh well, you have the source code. Now just transcode it. Very easy :)
All of that code just looks like a whole heap of gibberish to me. Good luck converting that to VB.NET topblast (if that's what you're intending to do anyway).
Quote Originally Posted by master131 View Post
All of that code just looks like a whole heap of gibberish to me. Good luck converting that to VB.NET topblast (if that's what you're intending to do anyway).
as to me also...

HMM i not sure i put it right.. because that looks like a whole heap of code of which lost me at the begining.

so all of that is to do what loadlibrary does but i want to call a function that the dll Exports...

like say i want to inject Kernel32.dll into a game and the Entry Point i want is not DLLMAIN but MessageBoxW.

I will like to inject Kernel32.dll into the game and my entry point is MessageBoxA.
how is that done?
Quote Originally Posted by user782106 View Post
WHATT?? Mind giving me the source to portal so I can improve? ;)
Unfortunately I don't have it anymore, which is why I haven't updated that piece of crap yet :/

If I want to update Portal I'd have to code the thing from scratch again :(

Quote Originally Posted by topblast View Post


as to me also...

HMM i not sure i put it right.. because that looks like a whole heap of code of which lost me at the begining.

so all of that is to do what loadlibrary does but i want to call a function that the dll Exports...

like say i want to inject Kernel32.dll into a game and the Entry Point i want is not DLLMAIN but MessageBoxW.

I will like to inject Kernel32.dll into the game and my entry point is MessageBoxA.
how is that done?
If it's your own kernal32.dll, you can set the entry point to any function under your link properties.
You should only be able to inject .net dlls into a .net process. But thats it. The .net pe file format is the same. Except for the fact that it calls the function to start the .net framework in the thread. and everything else is in the old com2 headers.
Quote Originally Posted by wtfiwantthatname View Post
You should only be able to inject .net dlls into a .net process. But thats it. The .net pe file format is the same. Except for the fact that it calls the function to start the .net framework in the thread. and everything else is in the old com2 headers.
Pretty sure he just wants to call a function from within the C++ .dll. The injection is the only thing he is doing from VB by the sound of it.
Quote Originally Posted by Jason View Post


Pretty sure he just wants to call a function from within the C++ .dll. The injection is the only thing he is doing from VB by the sound of it.
I was just saying what the limitations on it where. Because if i ported it and he was like it doesnt work why wont my .net dll run. I was going to slap him.
ill port it over later to vb.net for you. Notice however that it will only manually map non .net dll's to non .net process'.

Code:
http://en.wikipedia.org/wiki/DLL_injection
Some different ways to inject a dll. The appint method is a good way. But the only problem is you need your dll to check if its in the process and continue from there.
Quote Originally Posted by wtfiwantthatname View Post
ill port it over later to vb.net for you. Notice however that it will only manually map non .net dll's to non .net process'.

Code:
http://en.wikipedia.org/wiki/DLL_injection
Some different ways to inject a dll. The appint method is a good way. But the only problem is you need your dll to check if its in the process and continue from there.
I'm quite sure .NET processes can be targeted as well - as long as the DLL has a DLLMain function, you're fine. .NET DLs don't have this function, so nothing happens on injection.
Ew. I had crash hell trying to manual map. So yeah, ask them, the PE headers were a royal PITA for me. But then again I'm just noob

EDIT: HOLY FUCK source code!!

Awesome. Except I'm not coding anything for the next 3 years til I finish high school.

Oh well, you have the source code. Now just transcode it. Very easy
WHATT?? Mind giving me the source to portal so I can improve?
You'd need to write a wrapper function that calls MessageBox.
1. Write the strings to memory
2. Fix up the addresses to the strings in your wrapper function
3. Write wrapper function to memory
4. Create remote thread to execute it.

Going to be more work then is worth it.
example of mpgh SDK ... lets see
how does this look?


if this works you should see a message box showing Hello it works
the char* this really does nothing can be used for password or something to access your DLL but i only have it they because i am to lazy to change up all that stuff and stuffy stuff.
[highlight="C++"]
EXPORTED BOOL TopblastStartAddress (char* this_really_does_nothing)
{
MessageBoxA(0, this_really_does_nothing, "Topblast Start Address Test", MB_OK);
}
[/highlight]
[highlight="vbnet"]
Public Shared Function InjectDLL(ByVal hProcess As IntPtr, ByVal strDLLName As [String]) As Boolean
Dim bytesout As IntPtr
Dim themessage as String = "Hello It Works "
Dim LenWrite As Int32 = themessage.Length + 1
Dim AllocMem As IntPtr = VirtualAllocEx(hProcess, IntPtr.Zero, CUInt(LenWrite), &H1000, &H40)
WriteProcessMemory(hProcess, AllocMem, themessage, LenWrite, bytesout)
Dim Injector As String = GetProcAddress(GetModuleHandle(strDLLName), "TopblastStartAddress")

If Injector Is Nothing Then
MessageBox.Show(" Error ID 001 : " & vbLf & " Fail to find [ TopblastStartAddress] ", "Injector Error", MessageBoxButtons.OK, MessageBoxIcon.Error)
Return False
Exit Function
End If

Dim ThreadHd As String = CreateRemoteThread(hProcess, IntPtr.Zero, 0, Injector, AllocMem, 0, bytesout)

If ThreadHd Is Nothing Then
MessageBox.Show(" Error ID 101 : " & vbLf & " Fail Start DLL. ", "Thread Error", MessageBoxButtons.OK, MessageBoxIcon.Error)
Return False
Exit Function
End If

Dim Result As Integer = WaitForSingleObject(ThreadHd, Int32.MaxValue)

If Result = 128L OrElse Result = 258L OrElse Result = &HFFFFFFFF Then
If Result = 258L Then
MessageBox.Show(" Error ID 201 : " & vbLf & " FAIL Waiting To Long for Object. ", "Thread Error", MessageBoxButtons.OK, MessageBoxIcon.Error)
Else
MessageBox.Show(" Error ID 202 : " & vbLf & " FAIL Waiting To Long . ", "Thread Error", MessageBoxButtons.OK, MessageBoxIcon.Error)
End If

If ThreadHd IsNot Nothing Then
Return CloseHandle(ThreadHd)
End If
Return False
Exit Function
End If
Thread.Sleep(1000)
VirtualFreeEx(hProcess, AllocMem, 0, &H8000)
If ThreadHd IsNot Nothing Then
Return CloseHandle(ThreadHd)
End If
Return False
Exit Function


End Function
[/highlight]
Posts 1–15 of 17 · Page 1 of 2
This thread is closed for replies.

Tags for this Thread

None

Talk with us