TalkingProblem with the injected inline assembly code

Posts 1–15 of 15 · Page 1 of 1
Problem with the injected inline assembly code
Hello guys , I never used inline assembly before and im having a problem


Code:
DWORD return= 0x00927826;
DWORD returnhere= return+5;

__declspec (naked) void script(){

	_asm

	{ 
	   start:
	  push eax
          lea eax,[ecx+edx+98]
          call decrypt
	   jmp dword ptr [returnhere]

	}
}
All the code is injected just fine using WriteProcessMemory to the allocated memory and no problems at all , The only problem im having is that

&returnhere == jmp dword ptr[returnhere]

How to make it jump to return+5 instead of the pointer of returnhere? Am i doing something wrong ? , Well i know im doing something wrong just not sure what it is .
Remove the ptr
without ptr im getting the following error
/*inline assembler syntax error in 'first operand'; found '[' */
i removed dword
jmp [returnhere]
it jumped to the pointer of returnhere same as before .
are you trying to get the path of execution to jump back to 0x00927826 + 5

OR

or is there a memory address stored at 0x00927826, which you read, then add 5 to, and jump there?

If the second, you can't add +5 BEFORE you read the pointer : P ..you'd be reading for it in the wrong location.
If the first, don't use [ ] on the line w/ the jump.

edit: ^^ was in a hurry and misread your code..for some reason I was thinking 'returnhere' was a label, not a variable. Since it's a variable, you do want to read it's contents.
Quote Originally Posted by abuckau907 View Post
are you trying to get the path of execution to jump back to 0x00927826 + 5

OR

or is there a memory address stored at 0x00927826, which you read, then add 5 to, and jump there?

If the second, you can't add +5 BEFORE you read the pointer : P ..you'd be reading for it in the wrong location.
I just want to make a jump from the code to the address at 0x0092782B , tried writing jmp 0x0092782B but im getting compiler error .

error C2415: improper operand type
well, [ ] means read a value from the addr inside it , so that's not what you want. You're getting closer.

edit: sry mpgh is timing out for me, I edited my post a minute ago. See the comment about []'s.
i tried
jmp returnhere
but when i check the memory which was written to the process its
FF25 3CA00601 - jmp dword ptr [0106A03C]
The bytes should be
EB 26789206
or
e9 26789206

Im using VS Express 2012 , Could it be a compiler error ?.
If you simply want to jump to a static address, do something like this:

Code:
#define ADDR 0x0092782B
#define ADDR2 ADDR+5

int main()
{
    __asm
    {
        mov eax, ADDR
        jmp eax
        mov ebx, ADDR2
        jmp ebx
    }
}
As you can see it works:



If you need to use a pointer, here is how its done:

Code:
DWORD Addr = 0x0092782B+5;
DWORD AddrOfAddr = (DWORD)&Addr;

int main()
{
    __asm
    {
        mov eax, AddrOfAddr
        jmp [eax]
    }
}
Since "jmp [eax]" is jumping to the address stored in the address pointed by eax, we need a pointer to the address of the value you want to jump to.
Quote Originally Posted by Harava View Post
If you simply want to jump to a static address, do something like this:

Code:
#define ADDR 0x0092782B
#define ADDR2 ADDR+5

int main()
{
    __asm
    {
        mov eax, ADDR
        jmp eax
        mov ebx, ADDR2
        jmp ebx
    }
}
As you can see it works:

If you need to use a pointer, here is how its done:

Code:
DWORD Addr = 0x0092782B+5;
DWORD AddrOfAddr = (DWORD)&Addr;

int main()
{
    __asm
    {
        mov eax, AddrOfAddr
        jmp [eax]
    }
}
Since "jmp [eax]" is jumping to the address stored in the address pointed by eax, we need a pointer to the address of the value you want to jump to.
First i wanna thank you for your response , As for your advise
#1 it works fine but it can't be adjusted once the program is compiled
#2 would never work with WriteProcessMemory , Because when it copy the bytes &script in my case it would copy the pointer of my own process instead of copying its value
e.g. if &AddrOfAddr = 0x80000000
in my own process it would find the AddrOfAddr or [0x80000000] pointing to 0x0092782B but in another process it would give a garbage value or even cause a crash , I think i need some kind of runtime assembly compiler , Or read the bytes at &script into a buffer then edit some of it before using WriteProcessMemory .

If anyone know a simpler way please let me know .

#abuckau907 I know you may know this but anyway if anyone wanna do it your way , After you push the address then return use ret 04 to adjust the stack so it doesn't crash .
@Harava Can I ask for some advice?

Code:
_asm

	{ 
	   start:
	  push eax
          lea eax,[ecx+edx+98]
          call decrypt
	   jmp dword ptr [returnhere]

	}
The last line of the codecave is a jump out..so if we change a register (to set it == our jmp.addr), how do we decide which is scratch (because after we leave our codecave, we won't have a chance to fix up the register(s)) ?



@OP I think another way to achieve the goal is to push the return addr onto the stack and then a return instruction.
Quote Originally Posted by abuckau907 View Post
@Harava Can I ask for some advice?

Code:
_asm

	{ 
	   start:
	  push eax
          lea eax,[ecx+edx+98]
          call decrypt
	   jmp dword ptr [returnhere]

	}
The last line of the codecave is a jump out..so if we change a register (to set it == our jmp.addr), how do we decide which is scratch (because after we leave our codecave, we won't have a chance to fix up the register(s)) ?



@OP I think another way to achieve the goal is to push the return addr onto the stack and then a return instruction.
Either RE a bit to find a register you can use, or just use pushad & popad to keep the registers in tact. If you do the hook in a way where the first instruction after the original ones is pushad and the return from the cave lands on a popad, all registers should be as they should. The hook will obvously eat up a few more bytes though...

Using push & ret should keep the registers in tact as well.

@Esp++, why don't you make a dll? Then you would have no need for the nasty WriteProcessMemory.
If you absolutely must use it, you could allocate some memory for yourself with VirtualAllocEx and use that memory for all your variables.

Just store the address you want to jump to to the 4 first bytes of your memory region, and use the pointer to the memory region for the jump:
Code:
[...]
DWORD PointerToMemory = (DWORD)VirtualAllocEx();
*(DWORD*)PointerToMemory = 0x12345678;
__asm
{
    mov eax, PointerToMemory
    jmp [eax]
}
[...]
Quote Originally Posted by Harava View Post
@Esp++, why don't you make a dll? Then you would have no need for the nasty WriteProcessMemory.
If you absolutely must use it, you could allocate some memory for yourself with VirtualAllocEx and use that memory for all your variables.

Just store the address you want to jump to to the 4 first bytes of your memory region, and use the pointer to the memory region for the jump:
Code:
[...]
DWORD PointerToMemory = (DWORD)VirtualAllocEx();
*(DWORD*)PointerToMemory = 0x12345678;
__asm
{
    mov eax, PointerToMemory
    jmp [eax]
}
[...]
with *(DWORD*)PointerToMemory , You are trying to directly access a memory in another process which would cause access violation , Right?.
Nope, assuming you injected that into the target process.

VirtualAlloc will be called via the target process, and the mem location returned by it will be in the target process.

Any *(ptr*) is always local to the process running it. Readprocessmemory is required to read another process space.
(#2 made me realise why you're original code wasn't working --> the jmp instruction E9 is 'relative'; you say go forward/backward some amount, not an absolute address. The problem is same as you described..the code is being compiled/loaded in your program's memory space -- at some random location, so the calculation for the jump will be " jmp (this_code_current_location - targetAddress) "

but when you create the codecave, the jmp instruction won't be correctly relative to it.



not too many options.. use a literal, or a register, or a pointer (both).
http://stackoverflow.com/questions/1..****-direct-jump
Just make a freaking dll. It's a million times easier for stuff like this.

But yeah you are completely right, you can't access the memory like that, but hey, just use WriteProcessMemory for that if you absolutely have to.
Posts 1–15 of 15 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?