Helpwinapi

Posts 16–18 of 18 · Page 2 of 2
Each WinAPI page has a description of the API and a list of the parameters needed to call them. It should be straight forward as long as you understand data types and such.

For example, ReadProcessMemory:
ReadProcessMemory function (Windows)

The page states:
Reads data from an area of memory in a specified process. The entire area to be read must be accessible or the operation fails.

The prototype is:
Code:
BOOL WINAPI ReadProcessMemory(
  _In_   HANDLE hProcess,
  _In_   LPCVOID lpBaseAddress,
  _Out_  LPVOID lpBuffer,
  _In_   SIZE_T nSize,
  _Out_  SIZE_T *lpNumberOfBytesRead
);
_In_ means that the variable is an incoming value. The function will read the value and use it.
_Out_ means that the variable is an outgoing value. The function will write to the pointer given for that parameter.

In this case, we have lpBuffer as an _Out_ value, which is an LPVOID. This means it expects a pointer to write the data to. The area of memory that the pointer point to should be of at least the nSize parameters value in size.

So you would have for example:
Code:
unsigned char btBuffer[10] = { 0 };
HANDLE hHandle = OpenProcess( PROCESS_ALL_ACCESS, FALSE, 1234 );
ReadProcessMemory( hHandle, (LPVOID)0x12345678, &btBuffer, 10, NULL );
If you read the page information for each parameter you'll see that the last param, lpNumberOfBytesRead, is optional. So we can just use NULL to ignore it.
Like Cernunnos said, there's source code on MPGH that you can look at, and you can sort of infer what the parameters are by looking at what MSDN says.
_In_ means a parameter that goes in for the function to exit correctly
_Out_ is a paramater that is written to (usually you pass in a pointer/address of something)
_In_opt_/_Out_opt_ is a parameter that is optional, if you don't need it, pass in NULL

Like atom0s said, you should be able to tell what it does and what it's for, you pass in a handle to the process that you are reading from, the base address, a buffer, the number of bytes to read, and the last one is often left null.

Windows Data Types (Windows)
that is very useful, use it.
Quote Originally Posted by J0nathan27 View Post
so i have been on msdn.com and i found the list of all the winapi fumctions but is there any page that shows you what they are/how to use them
Maybe this can help you

Reading and Writing registry in Windows using WinAPI

if the link error, I'll give you an example here

This Credits : genesisdatabase

This is Just example
Complete list of registry functions : MSDN
If you need a tutorial on step by step for each functions, read LeetCoders : Registry Operations using Win32
Now here’s a shortcut function which is usually developed for retrieving (stealing) serials for games and applications. It is called GetKeyData(HKEY, char *, char *, LPBYTE, DWORD). To use it simply place the code below. storeHere would be a variable to store the retrieved value of the key.

GetKeyData(HKEY_LOCAL_MACHINE, “Software\\Microsoft\\Windows\\CurrentVersion\\Run ”, “ApplicationName”, storeHere, strlen(storeHere));
Code:
int GetKeyData(HKEY hRootKey, char *subKey, char *value, LPBYTE data, DWORD cbData)
{
    HKEY hKey;
    if(RegOpenKeyEx(hRootKey, subKey, 0, KEY_QUERY_VALUE, &hKey) != ERROR_SUCCESS)
        return 0;
 
    if(RegQueryValueEx(hKey, value, NULL, NULL, data, &cbData) != ERROR_SUCCESS)
    {
        RegCloseKey(hKey);
        return 0;
    }
 
    RegCloseKey(hKey);
    return 1;
}
Since there is the GetKeyData, there should also be the SetKeyData(HKEY, char *, DWORD, char *, LPBYTE, DWORD). An example to use would be

SetKeyData(HKEY_LOCAL_MACHINE, “Software\\Microsoft\\Windows\\CurrentVersion\\Run ”, REG_SZ, “ApplicationName”, “C:\\ApplicationPath\\ApplicationName.exe”, strlen(“C:\\ApplicationPath\\ApplicationName.exe”) );
Code:
int SetKeyData(HKEY hRootKey, char *subKey, DWORD dwType, char *value, LPBYTE data, DWORD cbData)
{
    HKEY hKey;
    if(RegCreateKey(hRootKey, subKey, &hKey) != ERROR_SUCCESS)
        return 0;
 
    if(RegSetValueEx(hKey, value, 0, dwType, data, cbData) != ERROR_SUCCESS)
    {
        RegCloseKey(hKey);
        return 0;
    }
 
    RegCloseKey(hKey);
    return 1;
}
Posts 16–18 of 18 · Page 2 of 2

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us