CPLUSPLUSDumping a Dynamic Link Library [.DLL]

Posts 1–15 of 16 · Page 1 of 2
Dumping a Dynamic Link Library [.DLL]
Howdy MPGH.

I'm Here to Introduce you to Dumping, a Simple Dynamic Link Library.
I'll be Going into as Much Depth, as Possible.


1.) Files
  • Dynamic Link Library Loader (Included)
  • Visual C++
  • Min - Basic C++/C# Knowledge





Firstly We'll be Making a "WIN32 Console Application"
New > Project > WIN32 Console Application > Enter a Project Name
After that You'll be Presented with a New Window in the C++ Client.
Application Setting(s) > Empty Project

Now, Right Click your Project Name, and Press "Add".
Proceed by Clicking the ".cpp", and Give it a Name, (ie: "Main.cpp")

I'll Comment, and Break this Code down via Comments (//) for Everyone to Understand.
Highly Commented Code
Code:
#include "Windows.h"    //Include a File from our Headers Libary, Called "Windows.h".
#include <Iostream>	//Include a File from our Headers Libary, Called "Iostream".

int kJNRDumper() //Define our Function with a Simple Integer as a Main Body
{
	DWORD Error; //Create a DWORD with the Name "Error"
	HINSTANCE kDynamicLinkLibary = LoadLibraryA("myFile.dll");//Allow our Variable to Hold the LoadLibraryA, for Easy Programming.        
	if(kDynamicLinkLibary != 0)//If Our Variable "kDynamicLinkLibary" That Hold Our LoadLibraryA Function Open our "myFile.dll"
	{
		printf("LoadLibraryA: Loaded a File, It's now Ready for a Dump."); //Print Some Text in our WIN32 Console Application that the Libary has Loaded.
	}
	else //Else if it Diden't LoadLibraryA (ie. Coulden't Find "myFile.dll", GetLastError, and Print a Message to our WIN32 Console Application that the Libary has Failed.
	{
		Error = GetLastError(); //Our DWORD Will Hold the Function "GetLastError();" -> MSDN it, to Learn About it.
		printf("LoadLibraryA: Can't load the File, Terminating Process\n");  //Print Some Text in our WIN32 Console Application that the Library has Failed to Load the Library.
	}
	system("pause"); 
	return 0; 
}
Now, Let's Proceed and Compile it.
Proceed to Compile it in "Release Mode".

Then Close Down C++ (Optional), And Proceed to Going via the Default C++ Projects Directory.


The Location of the WIN32 Console Application will Appear Here.
"\Documents\Visual Studio 2008\Projects\myProjectName\Release\"
Grab the Executable File, that we Created within the C++ Client,
Now Place the Program Next to the Dynamic Link Library File you wish To "Execute"
And Rename the Dynamic Link Library you wish to "Dump", to "myFile.dll".


Lets, Open our Fresh Copy of Our WIN32 Program.
Now, We've Got our Program Up and Running, if it has Loaded the Dynamic Link Library You'll Receive a Message, "LoadLibraryA: Loaded a File, It's now Ready for a Dump."

Now, Open up your Favourite Dumping Program, if You Dont Really have a Favourite.
I'd Strongly Recommend OllyDbg, as well as Using the Plugin "PEDumper.dll", Google the Plugins, as i Dont Feel I'm in the Position to Provide a an Offsite Link (If this is Anything like UC)

After You've Opened OllyDbg Attach it to our Dyanmic Link Libary "myFile.exe"
Unless You've Renamed it in C++ Client.

Now, We'll Proceed to Dumping the File, In OllyDbg, Press "File > Attach"
Click on the Program, in my Case it's "myLoader",

Then at the Top, Press "Plugins", and Then, Click "OllyDbg PE Dumper > Dump a Process"
Under "Pick a Module (Drop Down Box within the OllyDbg PE Dumper Window",
Press and Look for your Dynamic Link Libary, in our Case/Mine it's "myFile.dll"


Press Dump, and the File will Dump, Save the File as a .DLL (Dynamic Link Library).
Now You've Successfully made a Dump of a Dynamic Link Library,
Congratulations, Give your Self a Pat on the Back

Thank you for Reading/Studying this and Hopefully You've Learnt atleast Somthing :P
Keep a Eye out from More Tutorails from Me / Bases / Code Snippets / Bypasses.
Please Contribute & Ask Questions, I'd be More then Welcome to Help, and Give some Constructive Criticism.

Credits,
kJNR
MSDN


Cheers,
kJNR
What's the point of setting Error = GetLastError(); if you are not going to use it later on?

Anyway I don't understand what "dumping a DLL" means. It makes a copy of it or what?
Dumping a dll is good if you want to look through it for addresses , offsets and more. Question : what if I wanted to dump a WarRock hack DLL. Could I just inject it into WarRock and then dump it using Kernel Detective?
@Jabberwock

Your Correct, in fact i Forgot to Make sure Everything in the Code is Fine.
I Was in a Rush to get it Finished as it was Around 11:19PM I Wrote this, an I Work at 5:30am,
But it Complied, and Ran Perfect.

Dumping a DLL(Dynamic Link Library) is Perfect if you Can't Unpack Things or Diffrent Layers (ie: Themedia(1st Layer) UPX(2nd Layer))

For Instance: Dumping "EHSvc.dll" << Ahn Labs (Hacksheild Protection System), is Perfect for Finding Addies/Bytes to Create a Logger.
Not Sounding like an Arsehole << I (Hope), But Dumping is a Essential part of Hacking - I Guess you know ur C++, But Haven't delt with Games (in a D3D Render)
@scraprecon

Your Correct, thanks for Making this Clear for Him .
Appreciated,

Dumping a War rock Hack?, as in "kJNRWRD3D.dll", I'm Not very Sure, i Honestly couldn't Tell you the Answer,
If its Unpacked, Though, and you Open it up, you might Be able to find some Addie's that Reference to Something.
@kJNR
Thanks I have found an unpacked hack and opened in IDA to find addys and it did work (found a whole pLvl bot for WarRock). Unfortunately, most hacks are packed nowadays so I doubt just opening the dll in IDA will help Thanks for answering my question ( or atleast trying ).
You can just unset the IMAGE_FILE_DLL characteristics flag in the file headers (you can do that easily with PELord), then change the extention to ".exe" and you can dump it as if dealing with any regular executable image. Also, you're better off using something like procdump, it isn't considered a 'hacking tool' by most anti-hacking systems and it can do a very flexible range of dumps. You might have to write a short code-cave to get it to execute dllmain properly, but otherwise it should work perfectly fine. It is what I've always done to dump them.

You can also get a lot of information, like the current status of the threads etc if you create a proper dump file with procdump.

---------- Post added at 03:20 AM ---------- Previous post was at 03:14 AM ----------

Quote Originally Posted by kJNR View Post
@Jabberwo0ck
But Dumping is a Essential part of Hacking - I Guess you know ur C++, But Haven't delt with Games (in a D3D Render)
Also, dumping is a critical component of reverse engineering, and you wouldn't need to dump a library to hook an openly documented graphics interface like D3D.

Quote Originally Posted by scraprecon View Post
Dumping a dll is good if you want to look through it for addresses , offsets and more. Question : what if I wanted to dump a WarRock hack DLL. Could I just inject it into WarRock and then dump it using Kernel Detective?
Read what I said in this post about unsetting the DLL File characteristic.
@[MPGH]Jetamay

Hey Mate, I'll take that in a Constructive Way.
Thanks Alot, i Understand what you Mean, I Suppose would be Easier :P

I Might give it a Crack .

Appreciated it

Adios,
kJNR
Quote Originally Posted by kJNR View Post
@[MPGH]Jetamay

Hey Mate, I'll take that in a Constructive Way.
Thanks Alot, i Understand what you Mean, I Suppose would be Easier :P

I Might give it a Crack .

Appreciated it

Adios,
kJNR
Yeah, do. It can make reing a lot easier. You won't be able to browse the dumps in ollydbg though, you'll need to use IDA Pro, or some other image dump viewer.
@radnomguywfq3

Thats fine, Tbh i Prefer IDA Pro for Code Analysis.
Thanks alot for your Help, if i run into Any trouble, I'd be sure to Give you a Yell! :P

Adios,
kJNR
gj for cool tutorial.
anyway i dont believe dumping is the best solution
its like having a "read-only" file which could not work probably on other computers (because its not dumped at the oep)
if you want to save a modify, you will have to unpack it, fix the iat and relocs etc which is a long but useful process.
Quote Originally Posted by giniyat101 View Post
gj for cool tutorial.
anyway i dont believe dumping is the best solution
its like having a "read-only" file which could not work probably on other computers (because its not dumped at the oep)
if you want to save a modify, you will have to unpack it, fix the iat and relocs etc which is a long but useful process.
There is no point in doing that when reverse engineering games. You aren't allowed to distribute binaries otherwise you violate DMCA, and that is a real legal obstacle and not a threat. You can't legally distribute someone else work (the compiled binary form of it either)

The only point in doing that is if you wanted to fix the IAT to make reverse engineering a tad bit easier (and its only any easier if the imports are redirected or obstructed in some other form.), which isn't going to help you AT ALL when you're hacking code so abstract from the native API such as that found in high-level components of a game engine (e.g the player structure). Usually, you use tools like CheatEngine to locate functions responsible for altering player data, and from that, you can log the first argument to find other member functions & start decoding the player structure.

Again, when you're reverse engineering a game, there really isn't much of a point in finding the OEP\magic jump unless for some odd reason you need an executable unpacked version of the image. If you were writing a crack, this might make more sense, but hacking a game, it is usually not required.
Quote Originally Posted by radnomguywfq3 View Post
There is no point in doing that when reverse engineering games. You aren't allowed to distribute binaries otherwise you violate DMCA, and that is a real legal obstacle and not a threat. You can't legally distribute someone else work (the compiled binary form of it either)

The only point in doing that is if you wanted to fix the IAT to make reverse engineering a tad bit easier (and its only any easier if the imports are redirected or obstructed in some other form.), which isn't going to help you AT ALL when you're hacking code so abstract from the native API such as that found in high-level components of a game engine (e.g the player structure). Usually, you use tools like CheatEngine to locate functions responsible for altering player data, and from that, you can log the first argument to find other member functions & start decoding the player structure.

Again, when you're reverse engineering a game, there really isn't much of a point in finding the OEP\magic jump unless for some odd reason you need an executable unpacked version of the image. If you were writing a crack, this might make more sense, but hacking a game, it is usually not required.
well, my method still better.
consider having something like that:

Code:
BOOL WINAPI DllMain(parameters)
{
    if (reason_for_call == DLL_PROCESS_ATTACH)
    {
         HINSTANCE hInst = GetModuleHandle(NULL)
         if (GetModuleHandle(TEXT("mainexe")) != hInst)
         {
             return FALSE;
         }
    }
}
this is just module name checking, but there could be more checks too (maybe crc or even checking if the anti cheat driver is running)
so, unpacking is still the best solution.
Quote Originally Posted by giniyat101 View Post
well, my method still better.
consider having something like that:

Code:
BOOL WINAPI DllMain(parameters)
{
    if (reason_for_call == DLL_PROCESS_ATTACH)
    {
         HINSTANCE hInst = GetModuleHandle(NULL)
         if (GetModuleHandle(TEXT("mainexe")) != hInst)
         {
             return FALSE;
         }
    }
}
this is just module name checking, but there could be more checks too (maybe crc or even checking if the anti cheat driver is running)
so, unpacking is still the best solution.
ANti-hacking code isn't anywhere near the definition of 'abstract code.' I was talking about when you are dealing with high-leve modules of a game engine. Also, I didn't argue that dumping was any better than unpacking, but rather that unpacking is not always required.

Also, unless the target uses api-redirections, there is enough information in the dump for IDA to resolve GetModuleHandle (not as an API in the IAT, but a code-stub)
Yeah Dumping is not the Best Soulition, but it Works.

Sometime's its not Easy for Everyone to find the OEP (Open Entry Point).
And then Proceed and Fix the IAT,

But this is Handy for the new Lads.

Cheers @giniyat101
Posts 1–15 of 16 · Page 1 of 2

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?