Why does this injection not work?

Posts 1–5 of 5 · Page 1 of 1
Why does this injection not work?
Code:
#include <iostream>
#include <windows.h>
#include <TlHelp32.h>

char* dllPath = "C:\\Users\\Kalist\\Desktop\\Projects\\DLL\\bin\\Debug\\DLL.dll";
typedef DWORD WINAPI (*pThreadFunc)();

int main(){
    PROCESSENTRY32 pe32;
    pe32.dwSize = sizeof(PROCESSENTRY32);
    HANDLE procSnap = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
    DWORD procID;

    if(procSnap){
        if(Process32First(procSnap, &pe32)){
            do{
               if(!strcmp(pe32.szExeFile, "calc.exe")){
                    procID = pe32.th32ProcessID;
                    break;
               }
            }while(Process32Next(procSnap, &pe32));
        }
        CloseHandle(procSnap);
    }
    HANDLE procAccess = OpenProcess(PROCESS_ALL_ACCESS, false, procID);
    void* memSpace = VirtualAllocEx(procAccess, NULL, NULL, MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE);
    WriteProcessMemory(procAccess, memSpace, dllPath, sizeof(dllPath), NULL);
    HINSTANCE getLibadd = LoadLibrary(dllPath);
    pThreadFunc pThreadFuncVar = (pThreadFunc)GetProcAddress(getLibadd, "threadFunc");

    CreateRemoteThread(procAccess, NULL, 0, (LPTHREAD_START_ROUTINE)pThreadFuncVar, memSpace, 0, NULL);

    CloseHandle(procAccess);
}

DLL process:
Code:
include <iostream>
#include <windows.h>

extern "C" DWORD WINAPI threadFunc(){
    MessageBox(0, "Injection worked!", "Injection message", MB_OK);
    return 0;
}
Aww you didn't try out my suggestion from the last thread you made about this code? You aren't handling exceptions. How do you know that OpenProcess actually worked? Go back to your first thread and read my comment there.
Quote Originally Posted by Eddington View Post
Aww you didn't try out my suggestion from the last thread you made about this code? You aren't handling exceptions. How do you know that OpenProcess actually worked? Go back to your first thread and read my comment there.
Since when did OpenProcess throw an exception? You're not supposed to add an exception handler, you're supposed to check the return value (two different things). But if you want you can create a wrapper that throws runtime exceptions.

I know what you meant, I'm just bored
I posted this on Stack Overflow, here's the updated version. Still working consistently on getting it working.

Code:
#include <iostream>
#include <windows.h>
#include <TlHelp32.h>

char* dllPath = "C:\\Users\\Kalist\\Desktop\\Projects\\DLL\\bin\\Debug\\DLL.dll";
char* ProcToInject = "calc.exe";

int main(){
    PROCESSENTRY32 pe32;
    pe32.dwSize = sizeof(PROCESSENTRY32);
    HANDLE procSnap = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
    DWORD procID = 0;

    if(procSnap){
        if(Process32First(procSnap, &pe32)){
            do{
               if(!strcmp(pe32.szExeFile, ProcToInject)){
                    procID = pe32.th32ProcessID;
                    break;
               }
            }while(Process32Next(procSnap, &pe32));
        }
        CloseHandle(procSnap);
    }
    HANDLE procAccess = OpenProcess(PROCESS_ALL_ACCESS, false, procID);
    LPVOID memSpace = (LPVOID)VirtualAllocEx(procAccess, NULL, strlen(dllPath)+1, MEM_COMMIT | MEM_RESERVE, PAGE_READWRITE);
    WriteProcessMemory(procAccess, (LPVOID)memSpace, dllPath, strlen(dllPath)+1, NULL);
    LPVOID getLibadd = (LPVOID)GetProcAddress(GetModuleHandle("Kernel32.dll"), "LoadLibraryA");

    CreateRemoteThread(procAccess, NULL, 0, (LPTHREAD_START_ROUTINE)getLibadd, (LPVOID)memSpace, 0, NULL);

    CloseHandle(procAccess);
}
Code:
#include <windows.h>

BOOL WINAPI DllMain(HINSTANCE hInstDll, DWORD fdwReason, LPVOID lpvReserved)
{
    switch(fdwReason)
    {
        case DLL_PROCESS_ATTACH:
            MessageBox(NULL, "Process attached", "Message from Dll", MB_OK);
            break;
        case DLL_THREAD_ATTACH:
            MessageBox(NULL, "Thread attached", "Message from Dll", MB_OK);
            break;
        case DLL_PROCESS_DETACH:
            MessageBox(NULL, "Process detached", "Message from Dll", MB_OK);
            break;
        case DLL_THREAD_DETACH:
            MessageBox(NULL, "Thread detached", "Message from Dll", MB_OK);
            break;
    }
    return true;
}
I haven't done your suggestion because I haven't looked into exception handlers and GetError function. But I might be forced to if it continues to refuse working.
Are you sure your injector and the target process & the dll all use the same architecture (32bit/64bit) ?
Posts 1–5 of 5 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?