Mid-Hook Function Help [Solved]

Posts 16–30 of 35 · Page 2 of 3
Quote Originally Posted by 258456 View Post
Thanks jetamay, I am glad ur back, we all benefit from your knowledge of assembly. It turned out that it works (i just had to change the dwJumpback address cuz it was wrong offset, LOL), and calling my functions in the hook as DWORD PTR:[function].

But i still don't understand why i have to call it as DWORD PTR? Why do i need to do that?

BTW Thanks for your help everyone Schim and Jason, and i appreciate it.
Weird, I had to treat MessageBoxA as a pointer to an entry in the jump thunk table in my compiler.

AFAIK, in VC++ by default & in debug mode, you get pointers to the entries in the jump thunk table (even those of which belong to your module.) This is so Visual Studios can easily move them around when you edit the code live. I had this problem when I was writing my polymorphism engine. I think I had to disable incremental linking - in the mean time though its probably easier for you just to accept that all referenced function pointers will point to an entry in the jump thunk table setup by VS. Keep this in mind though if you ever encounter the problem again.
Quote Originally Posted by radnomguywfq3 View Post
Weird, I had to treat MessageBoxA as a pointer to an entry in the jump thunk table in my compiler.

AFAIK, in VC++ by default & in debug mode, you get pointers to the entries in the jump thunk table (even those of which belong to your module.) This is so Visual Studios can easily move them around when you edit the code live. I had this problem when I was writing my polymorphism engine. I think I had to disable incremental linking - in the mean time though its probably easier for you just to accept that all referenced function pointers will point to an entry in the jump thunk table setup by VS. Keep this in mind though if you ever encounter the problem again.
Oh lol, ok i will remember to do so. Also, is this just for any windows function or do i have to do it for a function i made too. Like let's say i made a function in my dll called "void SomeFunction(void);", would i have to call it as a dword ptr also?
Quote Originally Posted by 258456 View Post
Oh lol, ok i will remember to do so. Also, is this just for any windows function or do i have to do it for a function i made too. Like let's say i made a function in my dll called "void SomeFunction(void);", would i have to call it as a dword ptr also?
I wish I had Visual C++ installed on this machine (My laptop's charger is faulty atm so I have to use my secondary PC.) so I could show why you're calling it as a dword-ptr.

I didn't know your project was a dll, had I known troubleshooting this would have been a lot easier xd, so it actually does make sense that you're calling functions in your own modules via the Jump Thunk Table (a dll can be loaded at numerous different base addresses) - So yes, you will have to call it as a dword ptr.
Quote Originally Posted by radnomguywfq3 View Post
I wish I had Visual C++ installed on this machine (My laptop's charger is faulty atm so I have to use my secondary PC.) so I could show why you're calling it as a dword-ptr.

I didn't know your project was a dll, had I known troubleshooting this would have been a lot easier xd, so it actually does make sense that you're calling functions in your own modules via the Jump Thunk Table (a dll can be loaded at numerous different base addresses) - So yes, you will have to call it as a dword ptr.
Oh, ok, so it's because since my dll won't always have the same base address so i must call it as a pointer in order for it to know where the function is this time. That makes sense. Thanks Jetamay.
you can´t hook with a while loop.. lol..
becouse you can´t run your thread or function all the time,.. you have to hook, then call your function (with CALL) then go outside, reset that things you hooked and hook it again, call your function... and so on..
and the bytes you ned have to be 6 long.. and not 5!!
Quote Originally Posted by Code[VB] View Post
you can´t hook with a while loop.. lol..
becouse you can´t run your thread or function all the time,.. you have to hook, then call your function (with CALL) then go outside, reset that things you hooked and hook it again, call your function... and so on..
and the bytes you ned have to be 6 long.. and not 5!!
Dude, why you always stalkin my threads and saying things that you don't even know what they mean. Obviously i don't have a while loop in my Dllmain in my real hack I just put it here and some other little errors so noobs like you can't copy and paste.

Secondly a midfunction hook needs 5 bytes. Don't just say stuff that you get from other threads and not actually research them on your own. You just gt the idea of 6 bytes from Brimir's thread, and i corrected him and told him it was 5 bytes and he said that he made a mistake. This just proves that you know nothing about asm. You need 1 byte for the JMP which is 0xE9 then 4 bytes for the jump to my function which is the size of a DWORD. So just in case you didn't already notice: 1 + 4 = 5.

Thirdly, i don't need to make a CALL because i can just make a jump to my function and restore the bytes in my function then jmp back at the end of my function.

So stop replying to my threads becaue your little scheme of making me look bad isn't working because yet again you have made your self look stupider than everybody already thought you were.
Quote Originally Posted by Code[VB] View Post
you can´t hook with a while loop.. lol..
becouse you can´t run your thread or function all the time,.. you have to hook, then call your function (with CALL) then go outside, reset that things you hooked and hook it again, call your function... and so on..
and the bytes you ned have to be 6 long.. and not 5!!
I'm not sure how I should interpret your first statement. You can hook from within a while loop, and you can insert a mid function hook inside of a while loop.

becouse you can´t run your thread or function all the time
Again, this statement is difficult to understand, however a hook is independent of the installing thread - the executing thread traveling the detour is that which is affected in regards to its path of execution. The installing thread will typically not travel the path of the detour (but it can without any problems...)

the bytes you ned have to be 6 long.
On a 32 bit machine, a short jump is two bytes, and a far jump is 5 bytes, there are near jumps as well, so its dependent on what sort you're talking about regarding its size. On a 64 bit machine it would be probably about two times the size(as the offsets are much larger...)

Use common sense; an offset, regardless to however far, will not be larger than four bytes (because 0xFFFFFFFF is the max address.) So you have four bytes for the operand and one byte for the instruction, so 5 bytes. Maybe 6 if you have applied sort of modifier to the jump(and if one even exists, but I haven't ever seen one.)

Edit
Ahh, you're talking about conditional jumps, they can be upto 6 bytes - there is a very distinct difference between the two. You usually don't use conditional jumps in a detour but I suppose you could(i don't know how you would execute the stolen bytes though...) The extra byte is found in the opcode in a conditional jump.

Quote Originally Posted by Jason View Post
Someone needs to make a generic midfunction hook that can applied to any base address and will intuitively find a point in *roughly* the middle of the function to place a hook which:
Code:
   a) isn't in a conditional location (i.e not after a conditional jmp, which may be skipped)
   b) isn't just whacked in at offset X from the beginning of the function (that is, intuitively detects part "a" and also that the location isn't in the middle of an instruction)
   c) is easily useable (class the hook, constructors consist of function address, detour address and optionally how far into the function you want the scan to start)
Since I have 3-4 months of holidays coming up I might give it a shot, but I'd have to probs learn ASM too haha. Hardest part would be recognizing the various instruction lengths and detecting conditional blocks of code, as well as when the end of the function is reached (so you don't continue scanning indefinitely, or put a hook in a random location in another function and crash the program.
That isn't possible. The point of a detour is to alter arguments or the return value, unless this isn't the point, then it isn't possible. The reason being is that a mid-function detour is established at a point where either the arguments haven't yet been processed or that they have but the effect of them being process can be reversed and then re performed with altered arguments. I suppose one could programatically find a convenient place for a mid-function detour but the logic behind locating it would be a complete hell to program(I had to build instruction dependency trees with my polymorhpism engine and it was quite a bit of work on its own.)

The reason universal detours can be made on the first executing instructions of any function using any calling convention is because the function hasn't yet been executed - all that needs to be done is to have the function redirected to a stub which alters the arguments passed to it and then allow it to continue execution.
Quote Originally Posted by radnomguywfq3 View Post
That isn't possible. The point of a detour is to alter arguments or the return value, unless this isn't the point, then it isn't possible. The reason being is that a mid-function detour is established at a point where either the arguments haven't yet been processed or that they have but the effect of them being process can be reversed and then re performed with altered arguments. I suppose one could programatically find a convenient place for a mid-function detour but the logic behind locating it would be a complete hell to program(I had to build instruction dependency trees with my polymorhpism engine and it was quite a bit of work on its own.)

The reason universal detours can be made on the first executing instructions of any function using any calling convention is because the function hasn't yet been executed - all that needs to be done is to have the function redirected to a stub which alters the arguments passed to it and then allow it to continue execution.
Hmm yeah that makes sense. Guess you have to handle midfunction hooks more manually because even if you set the hook at a safe location, if the stack had been altered the programmer wouldn't even know exactly where the midfunction was applied, nor the relevant ASM to reverse to get the stack back to its original state. Damn, seemed like such a good idea in theory haha.
Quote Originally Posted by Jason View Post


Hmm yeah that makes sense. Guess you have to handle midfunction hooks more manually because even if you set the hook at a safe location, if the stack had been altered the programmer wouldn't even know exactly where the midfunction was applied, nor the relevant ASM to reverse to get the stack back to its original state. Damn, seemed like such a good idea in theory haha.
I wish we could have universal mid-function detours as well
Quote Originally Posted by Code[VB] View Post
i´m sure that you will not become the hook working! (no more words.. here)
// if you are topblast then i would say that you are realy st****, in coding an easy hook..
Obviously you're an idiot cuz you can't read. I already said that i have got it working. Lol, i don't think you even fully grasp this concept of mid func hooking. I have used this method to create a base for cf, i don't think you can say the same for yourself, so go troll on someone else's thread.

@Hassan /req close, Only flaming is happening here, my issue is solved.
Someone needs to make a generic midfunction hook that can applied to any base address and will intuitively find a point in *roughly* the middle of the function to place a hook which:
Code:
   a) isn't in a conditional location (i.e not after a conditional jmp, which may be skipped)
   b) isn't just whacked in at offset X from the beginning of the function (that is, intuitively detects part "a" and also that the location isn't in the middle of an instruction)
   c) is easily useable (class the hook, constructors consist of function address, detour address and optionally how far into the function you want the scan to start)
Since I have 3-4 months of holidays coming up I might give it a shot, but I'd have to probs learn ASM too haha. Hardest part would be recognizing the various instruction lengths and detecting conditional blocks of code, as well as when the end of the function is reached (so you don't continue scanning indefinitely, or put a hook in a random location in another function and crash the program.
Quote Originally Posted by Jason View Post
Someone needs to make a generic midfunction hook that can applied to any base address and will intuitively find a point in *roughly* the middle of the function to place a hook which:
Code:
   a) isn't in a conditional location (i.e not after a conditional jmp, which may be skipped)
   b) isn't just whacked in at offset X from the beginning of the function (that is, intuitively detects part "a" and also that the location isn't in the middle of an instruction)
   c) is easily useable (class the hook, constructors consist of function address, detour address and optionally how far into the function you want the scan to start)
Since I have 3-4 months of holidays coming up I might give it a shot, but I'd have to probs learn ASM too haha. Hardest part would be recognizing the various instruction lengths and detecting conditional blocks of code, as well as when the end of the function is reached (so you don't continue scanning indefinitely, or put a hook in a random location in another function and crash the program.
Well, you can make a universal midfunc hook, cuz most programs and games, use the KERNELBASE.dll and then you can just hook the prologue or anywhere in the function of GetExitCodeThread cuz it runs many times within a game. Just make sure to restore the bytes cuz the app will get pissed at you then close, lol.
Quote Originally Posted by Code[VB] View Post
fail.

here is proof that i made my hook already.. and its working!


so thats my proof, where is yours? so stfu if you can´t proof that your hook is working
When the hell did this become a competition? Omg, i swear some people on this site drive me nuts.
Don't be jealous fool. Anyone can use topblasts base. So stop posting here cuz your replies aren't helpful to this topic, and there are other people who have wanted to learn this method of hooking and can't because of all the crap you're posting.
@258456: Deleted his posts. No need to close it now. Just marking it solved.
Quote Originally Posted by Hassan View Post
@258456: Deleted his posts. No need to close it now. Just marking it solved.
Thanks man. Now people can read and learn without having to filter through stupid flame posts. That's why ur the minion, haha.
Posts 16–30 of 35 · Page 2 of 3

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us