Learn how to hook
Hello every one,
This is a littel tutorial how to hook:
1: First make a test application. Make a loop:

2: Load it up in olly and find a place to hook:
You will think, why how do I know a nice place to hook? And what do I need for that?
Nice place
You need to over ride a part of code. I chose a part with out any jumps or calls. Why? Becouse that is easy.
What do I need
You need 5 bytes. Becouse you are going to over ride 5 bytes with code. Why? A jump to a custom function needs 5 bytes
What are "5 bytes"
The 2nd "command" are the bytes:
0116108F |. 83C4 08 |ADD ESP,8
01161092 |. 68 E8030000 |PUSH 3E8
01161097 |. FFD6 |CALL ESI
83C4 08 = 3 bytes
68 E8030000 = 5 bytes
FFD6 = 2 bytes
Why do you took more?
You need a place to jump back. You need to resume the code.
Can I take a part of a command?
no!
What do I need to do if I have left?
Nop it.
Oke, now we have a nice place. We are going to place a jump here.
Searth the bytes and over ride them with a jump to your location: (I pref a dll)
Now we have a jump to our location. But w8? We deleted some bytes...
What to do if you made a jump
Restore the old bytes. use inline assambly for that.
Can I do hacks now?
Yes, afther the restore do some hacks
Do I need to do more?
Yes, Return back under your jump
The result:
The loop in my test app:
The function I called:
A video:
If you know the C++ basics, and know somting about memory edeting.. Then you can use this tutorial to make a hook. Good luck all
By Brimir
Edit:
Thanks @258456 for correcting a part.
You don't need the "83C4 08" any more. You just can hook the 5 bytes bellow.
This is a littel tutorial how to hook:
1: First make a test application. Make a loop:

2: Load it up in olly and find a place to hook:
Code:
01161030 |> 8B4424 04 /MOV EAX,DWORD PTR SS:[ESP+4] 01161034 |. 8B0D 64201601 |MOV ECX,DWORD PTR DS:[<&MSVCP100.?cout@ 0116103A |. 40 |INC EAX 0116103B |. 68 18211601 |PUSH OFFSET 01162118 ; /_Val = " Feel free to hook in this part of code This is a very yes a very easy part to hook. " 01161040 |. 50 |PUSH EAX ; |/Arg1 01161041 |. 68 70211601 |PUSH OFFSET 01162170 ; ||/_Val = "We are at number: " 01161046 |. 51 |PUSH ECX ; |||_Ostr 01161047 |. 894424 14 |MOV DWORD PTR SS:[ESP+14],EAX ; ||| 0116104B |. E8 E0000000 |CALL std::operator<<<std::char_traits<c ; ||\std::operator<<<std::char_traits<char> > 01161050 |. 83C4 08 |ADD ESP,8 ; || 01161053 |. 8BC8 |MOV ECX,EAX ; || 01161055 |. FF15 5C201601 |CALL DWORD PTR DS:[<&MSVCP100.??6?$basi ; |\MSVCP100.??6?$basic_ostream@DU?$char_traits@D@<a href="http://www.mpgh.net/forum/member.php?u=567241" target="_blank">STD</a>@@@<a href="http://www.mpgh.net/forum/member.php?u=567241" target="_blank">STD</a>@@QAEAAV01@J@Z 0116105B |. 50 |PUSH EAX ; |_Ostr 0116105C |. E8 CF000000 |CALL std::operator<<<std::char_traits<c ; \std::operator<<<std::char_traits<char> > 01161061 |. A1 64201601 |MOV EAX,DWORD PTR DS:[<&MSVCP100.?cout@ 01161066 |. 83C4 08 |ADD ESP,8 01161069 |. 68 84211601 |PUSH OFFSET 01162184 ; /_Val = " gl!! " 0116106E |. 8D5424 08 |LEA EDX,[ESP+8] ; | 01161072 |. 52 |PUSH EDX ; |/Arg1 01161073 |. 68 8C211601 |PUSH OFFSET 0116218C ; ||/_Val = "THe address of counter is: " 01161078 |. 50 |PUSH EAX ; |||_Ostr 01161079 |. E8 B2000000 |CALL std::operator<<<std::char_traits<c ; ||\std::operator<<<std::char_traits<char> > 0116107E |. 83C4 08 |ADD ESP,8 ; || 01161081 |. 8BC8 |MOV ECX,EAX ; || 01161083 |. FF15 58201601 |CALL DWORD PTR DS:[<&MSVCP100.??6?$basi ; |\MSVCP100.??6?$basic_ostream@DU?$char_traits@D@<a href="http://www.mpgh.net/forum/member.php?u=567241" target="_blank">STD</a>@@@<a href="http://www.mpgh.net/forum/member.php?u=567241" target="_blank">STD</a>@@QAEAAV01@PBX@Z 01161089 |. 50 |PUSH EAX ; |_Ostr 0116108A |. E8 A1000000 |CALL std::operator<<<std::char_traits<c ; \std::operator<<<std::char_traits<char> > 0116108F |. 83C4 08 |ADD ESP,8 01161092 |. 68 E8030000 |PUSH 3E8 01161097 |. FFD6 |CALL ESI 01161099 \.- EB 95 \JMP SHORT 01161030
Nice place
You need to over ride a part of code. I chose a part with out any jumps or calls. Why? Becouse that is easy.
What do I need
You need 5 bytes. Becouse you are going to over ride 5 bytes with code. Why? A jump to a custom function needs 5 bytes

What are "5 bytes"
The 2nd "command" are the bytes:
0116108F |. 83C4 08 |ADD ESP,8
01161092 |. 68 E8030000 |PUSH 3E8
01161097 |. FFD6 |CALL ESI
83C4 08 = 3 bytes
68 E8030000 = 5 bytes
FFD6 = 2 bytes
Why do you took more?
You need a place to jump back. You need to resume the code.
Can I take a part of a command?
no!
What do I need to do if I have left?
Nop it.
Oke, now we have a nice place. We are going to place a jump here.
Searth the bytes and over ride them with a jump to your location: (I pref a dll)
Code:
01181069 |. 68 84211801 |PUSH OFFSET 01182184 ; /_Val = " gl!! " 0118106E |. 8D5424 08 |LEA EDX,[ESP+8] ; | 01181072 |. 52 |PUSH EDX ; |/Arg1 01181073 |. 68 8C211801 |PUSH OFFSET 0118218C ; ||/_Val = "THe address of counter is: " 01181078 |. 50 |PUSH EAX ; |||_Ostr 01181079 |. E8 B2000000 |CALL std::operator<<<std::char_traits<c ; ||\std::operator<<<std::char_traits<char> > 0118107E |. 83C4 08 |ADD ESP,8 ; || 01181081 |. 8BC8 |MOV ECX,EAX ; || 01181083 |. FF15 58201801 |CALL DWORD PTR DS:[<&MSVCP100.??6?$basi ; |\MSVCP100.??6?$basic_ostream@DU?$char_traits@D@<a href="http://www.mpgh.net/forum/member.php?u=567241" target="_blank">STD</a>@@@<a href="http://www.mpgh.net/forum/member.php?u=567241" target="_blank">STD</a>@@QAEAAV01@PBX@Z 01181089 |. 50 |PUSH EAX ; |_Ostr 0118108A |. E8 A1000000 |CALL std::operator<<<std::char_traits<c ; \std::operator<<<std::char_traits<char> > 0118108F |. E9 6CFFDF61 |JMP hookfunction 01181094 |? 90 |NOP 01181095 |? 90 |NOP 01181096 |? 90 |NOP 01181097 |. FFD6 |CALL ESI 01181099 \.- EB 95 \JMP SHORT 01181030 0118109B CC INT3
What to do if you made a jump
Restore the old bytes. use inline assambly for that.
Can I do hacks now?
Yes, afther the restore do some hacks
Do I need to do more?
Yes, Return back under your jump
Code:
Dump - Crossfire:.text Address Hex dump Command Comments 0118108F |. E9 6CFFDF61 |JMP hookfunction 01181094 |? 90 |NOP 01181095 |? 90 |NOP 01181096 |? 90 |NOP 01181097 |. FFD6 |CALL ESI
The loop in my test app:
Code:
0118108F |. E9 6CFFDF61 |JMP hookfunction 01181094 |? 90 |NOP 01181095 |? 90 |NOP 01181096 |? 90 |NOP 01181097 |. FFD6 |CALL ESI 01181099 \.- EB 95 \JMP SHORT 01181030
Code:
62F81009 |. 68 F4010000 PUSH 1F4 ; /Duration = 500. 62F8100E |. 68 F4010000 PUSH 1F4 ; |Frequency = 500. 62F81013 |. FF15 0020F862 CALL DWORD PTR DS:[<&KERNEL32.Beep>] ; \KERNEL32.Beep More, and more, and more 62F8101A \. FF25 4433F862 JMP DWORD PTR DS:[jumplocation]
If you know the C++ basics, and know somting about memory edeting.. Then you can use this tutorial to make a hook. Good luck all

By Brimir
Edit:
Thanks @258456 for correcting a part.
You don't need the "83C4 08" any more. You just can hook the 5 bytes bellow.


