(Question);

Posts 1–9 of 9 · Page 1 of 1
(Question);
what is Virtual protect and what is it used for ??
REGARDS.
What i know it is for:
1- It is For Convert Asm to C++ without WINAPI.
2- Its Used for most time,to protect a Pointer or Multiple Pointers with Bytes.
Example:
Nopping Way.
Quote Originally Posted by darlwis View Post
What i know it is for:
1- It is For Convert Asm to C++ without WINAPI.
2- Its Used for most time,to protect a Pointer or Multiple Pointers with Bytes.
Example:
Nopping Way.
wtf you kidding?

Quote Originally Posted by Zacherl View Post
OMFG hahaha made my day
same here

@Death-Dev
VirtualProtect changes the memory protection as some memories are read only or execute only
if you want to overwrite some piece of code (e.g hooking, patching stuff etc)
you must call VirtualProtect to allow writing

for example try this code to write two nops in MessageBoxA API in a windows application:
Code:
FARPROC MessageBoxA_Addr = GetProcAddress(GetModuleHandleA("user32.dll"), "MessageBoxA");
*(WORD*)(MessageBoxA_Addr = 0x9090; // error, memory protection is PAGE_EXECUTE only!
solution:

Code:
DWORD dwOld;
VirtualProtect(MessageBoxA_Addr, 2, PAGE_EXECUTE_READWRITE, &dwOld);//Allow read, write, execute access for first 2 bytes
*(WORD*)(MessageBoxA_Addr = 0x9090; //will not make error
VirtuallProtect(MessageBoxA_Addr, 2, dwOld, &dwOld); //restore old protection
sorry for my bad english
hope i helped
someone correct me if i said something wrong
Quote Originally Posted by giniyat101 View Post
wtf you kidding?



same here

@Death-Dev
VirtualProtect changes the memory protection as some memories are read only or execute only
if you want to overwrite some piece of code (e.g hooking, patching stuff etc)
you must call VirtualProtect to allow writing

for example try this code to write two nops in MessageBoxA API in a windows application:
Code:
FARPROC MessageBoxA_Addr = GetProcAddress(GetModuleHandleA("user32.dll"), "MessageBoxA");
*(WORD*)(MessageBoxA_Addr = 0x9090; // error, memory protection is PAGE_EXECUTE only!
solution:

Code:
DWORD dwOld;
VirtualProtect(MessageBoxA_Addr, 2, PAGE_EXECUTE_READWRITE, &dwOld);//Allow read, write, execute access for first 2 bytes
*(WORD*)(MessageBoxA_Addr = 0x9090; //will not make error
VirtuallProtect(MessageBoxA_Addr, 2, dwOld, &dwOld); //restore old protection
sorry for my bad english
hope i helped
someone correct me if i said something wrong
Thats is what my friend say me on msn.
Sorry if i am wrong
Quote Originally Posted by darlwis View Post
It is For Convert Asm to C++ without WINAPI.
OMFG hahaha made my day
Quote Originally Posted by Zacherl View Post
OMFG hahaha made my day
I read that and I was like... lolwut and I swear I had a slight black out from the stupidity of that statement.
I think this is a VirtualProtect code, I am not sure you gonna need to update the addys
(Note: This is leeched, so don`t ask me how to update because IDK how but I am not using it anymore)

Code:
BYTE nop = 0x90;
DWORD d, ds;

VirtualProtect((LPVOID)(CShell+0x85723), 17, PAGE_EXECUTE_READWRITE, &d);

for (int i=0; i<17;i++)
memcpy((LPVOID)(CShell+0x85723+i), &nop, 1);

VirtualProtect((LPVOID)(CShell+0x85723), 17, d, &ds);
It sets the protection of memory.
In xmen's example, 17 Bytes are getting protected, that these 17 Bytes are readable, writable and that they can get executed.
Then some NOPs are being copied into these 17 Bytes and then the protection is set to the protection before the first call of VirtualProtect.

@darlwis
What are you talking about?
Posts 1–9 of 9 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us