No access reading memory

Posts 1–10 of 10 · Page 1 of 1
No access reading memory
Every time I try to read process memory it tells me I don't have access. I tried using GetLastError and it kept returning error 998, which tells me I don't have access. Am I using VirtualProtect wrong or what? Can someone help me out? Thanks.

Code:
#include <iostream>
#include <Windows.h>
#include <TlHelp32.h>

using namespace std;

int main()
{

	HANDLE openprocess;
	PROCESSENTRY32 pEntry;
	MODULEENTRY32 mEntry;
	
	HANDLE processes  = CreateToolhelp32Snapshot(TH32CS_SNAPALL, NULL);

	
	Process32First(processes, &pEntry);

	while(Process32Next(processes, &pEntry))
	{
		if(strcmp(pEntry.szExeFile, "test.exe")==0)
		{
			break;
		}
	}
	
	HANDLE process = CreateToolhelp32Snapshot(TH32CS_SNAPALL, pEntry.th32ProcessID);

	Module32First(process, &mEntry);

	int a = (int)mEntry.modBaseAddr;
	int s = (int)mEntry.modBaseSize;
	BYTE* b;
	b = new BYTE[s];

	cout<< mEntry.szModule << " " << hex << a << endl;

	while(true)
	{
		bool a = Module32Next(process, &mEntry);
		if(a == false)
		{
			break;
		}
		cout<< mEntry.szModule << " " << hex << (int)mEntry.modBaseAddr << endl;
		
	}
	
	
	openprocess = OpenProcess(PROCESS_VM_READ|PROCESS_VM_OPERATION, 0, pEntry.th32ProcessID);

	DWORD old = 0;
	
	VirtualProtectEx(openprocess,(LPVOID)a, s, PAGE_READWRITE, &old);
	
	
	

	if(!ReadProcessMemory(openprocess, (LPCVOID)a, &b, s, 0))
	{
		cout<< "fail";
	}

	cout<< b[0];
	
	cin.get();

}
Try checking the VirtualProtectEx return. Also, you may need PAGE_EXECUTE_READWRITE depending on if you're reading bytes from the .code section, and the PROCESS_QUERY_INFORMATION flag in the handle.
Your call to ReadProcessMemory is wrong (though it is probably not the problem). You supply the address of b as the buffer in which the data is to be written to instead of the allocated data (new BYTE[s]).

Make sure your process has the right privileges in order to perform reads and page access protection changes.
Quote Originally Posted by Fovea View Post
Your call to ReadProcessMemory is wrong (though it is probably not the problem). You supply the address of b as the buffer in which the data is to be written to instead of the allocated data (new BYTE[s]).

Make sure your process has the right privileges in order to perform reads and page access protection changes.
And perhaps the fact that he's calling OpenProcess with only OPERATION access? From MSDN, ReadProcessMemory requires a process handle that has PROCESS_VM_READ access attached to it.
Quote Originally Posted by Jason View Post


And perhaps the fact that he's calling OpenProcess with only OPERATION access? From MSDN, ReadProcessMemory requires a process handle that has PROCESS_VM_READ access attached to it.
Code:
openprocess = OpenProcess(PROCESS_VM_READ|PROCESS_VM_OPERATION, 0, pEntry.th32ProcessID);
Quote Originally Posted by master131 View Post
Code:
openprocess = OpenProcess(PROCESS_VM_READ|PROCESS_VM_OPERATION, 0, pEntry.th32ProcessID);
Fuck this hangover.
You're removing the execution rights from the entire module as well..
Quote Originally Posted by BlueSkittles View Post
Every time I try to read process memory it tells me I don't have access. I tried using GetLastError and it kept returning error 998, which tells me I don't have access. Am I using VirtualProtect wrong or what? Can someone help me out? Thanks.

Code:
#include <iostream>
#include <Windows.h>
#include <TlHelp32.h>

using namespace std;

int main()
{

	HANDLE openprocess;
	PROCESSENTRY32 pEntry;
	MODULEENTRY32 mEntry;
	
	HANDLE processes  = CreateToolhelp32Snapshot(TH32CS_SNAPALL, NULL);

	
	Process32First(processes, &pEntry);

	while(Process32Next(processes, &pEntry))
	{
		if(strcmp(pEntry.szExeFile, "test.exe")==0)
		{
			break;
		}
	}
	
	HANDLE process = CreateToolhelp32Snapshot(TH32CS_SNAPALL, pEntry.th32ProcessID);

	Module32First(process, &mEntry);

	int a = (int)mEntry.modBaseAddr;
	int s = (int)mEntry.modBaseSize;
	BYTE* b;
	b = new BYTE[s];

	cout<< mEntry.szModule << " " << hex << a << endl;

	while(true)
	{
		bool a = Module32Next(process, &mEntry);
		if(a == false)
		{
			break;
		}
		cout<< mEntry.szModule << " " << hex << (int)mEntry.modBaseAddr << endl;
		
	}
	
	
	openprocess = OpenProcess(PROCESS_VM_READ|PROCESS_VM_OPERATION, 0, pEntry.th32ProcessID);

	DWORD old = 0;
	
	VirtualProtectEx(openprocess,(LPVOID)a, s, PAGE_READWRITE, &old);
	
	
	

	if(!ReadProcessMemory(openprocess, (LPCVOID)a, &b, s, 0))
	{
		cout<< "fail";
	}

	cout<< b[0];
	
	cin.get();

}
you do relise it will be detected? and what game is this for btw?
Quote Originally Posted by R3Dx666 View Post
you do relise it will be detected? and what game is this for btw?
It doesnt matter, some people just want to learn first. Not everyone jumps into a dll hack and leech like a mad guy.
i know its old, but the problem is here:


if(!ReadProcessMemory(openprocess, (LPCVOID)a, &b, s, 0))
b is already a pointer, you're passing the pointer to the pointer, that will fail.


if(!ReadProcessMemory(openprocess, (LPCVOID)a, b, s, 0))
this should do the trick
Posts 1–10 of 10 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us