mirror of
https://github.com/BeneficialCode/WinArk
synced 2026-08-09 12:00:31 +00:00
tweak the suspicious bug when call SymGetSymFromName
This commit is contained in:
@@ -48,6 +48,20 @@ SymbolInfo::~SymbolInfo() {
|
||||
::free(m_Symbol);
|
||||
}
|
||||
|
||||
ImagehlpSymbol::ImagehlpSymbol() {
|
||||
auto size = sizeof(IMAGEHLP_SYMBOL) + MAX_SYM_NAME;
|
||||
m_Symbol = static_cast<IMAGEHLP_SYMBOL*>(malloc(size));
|
||||
if (m_Symbol) {
|
||||
::memset(m_Symbol, 0, size);
|
||||
m_Symbol->SizeOfStruct = sizeof(IMAGEHLP_SYMBOL);
|
||||
m_Symbol->MaxNameLength = MAX_SYM_NAME;
|
||||
}
|
||||
}
|
||||
|
||||
ImagehlpSymbol::~ImagehlpSymbol() {
|
||||
::free(m_Symbol);
|
||||
}
|
||||
|
||||
SymbolHandler::SymbolHandler(HANDLE hProcess, PCSTR searchPath,DWORD symOptions){
|
||||
m_hProcess = hProcess;
|
||||
::SymSetOptions(symOptions);
|
||||
@@ -199,7 +213,8 @@ IMAGEHLP_MODULE SymbolHandler::GetModuleInfo(DWORD64 address) {
|
||||
|
||||
|
||||
ULONG_PTR SymbolHandler::GetSymbolAddressFromName(PCSTR name) {
|
||||
IMAGEHLP_SYMBOL symbol = { sizeof(symbol) };
|
||||
::SymGetSymFromName(m_hProcess, name, &symbol);
|
||||
return symbol.Address;
|
||||
auto symbol = std::make_unique<ImagehlpSymbol>();
|
||||
auto info = symbol->GetSymbolInfo();
|
||||
::SymGetSymFromName(m_hProcess, name, info);
|
||||
return info->Address;
|
||||
}
|
||||
@@ -166,6 +166,19 @@ private:
|
||||
SYMBOL_INFO* m_Symbol;
|
||||
};
|
||||
|
||||
|
||||
class ImagehlpSymbol {
|
||||
public:
|
||||
ImagehlpSymbol();
|
||||
~ImagehlpSymbol();
|
||||
|
||||
IMAGEHLP_SYMBOL* GetSymbolInfo() const {
|
||||
return m_Symbol;
|
||||
}
|
||||
private:
|
||||
IMAGEHLP_SYMBOL* m_Symbol;
|
||||
};
|
||||
|
||||
class SymbolHandler final{
|
||||
public:
|
||||
SymbolHandler(HANDLE hProcess = ::GetCurrentProcess(), PCSTR searchPath = nullptr,DWORD symOptions =
|
||||
|
||||
@@ -146,6 +146,7 @@
|
||||
<PrecompiledHeaderFile>pch.h</PrecompiledHeaderFile>
|
||||
<RuntimeLibrary>MultiThreaded</RuntimeLibrary>
|
||||
<ExceptionHandling>false</ExceptionHandling>
|
||||
<LanguageStandard>stdcpp20</LanguageStandard>
|
||||
</ClCompile>
|
||||
<Link>
|
||||
<SubSystem>
|
||||
|
||||
@@ -420,6 +420,16 @@ void CProcessInlineHookTable::CheckX64HookType4(cs_insn* insn, size_t j, size_t
|
||||
// 排除循环跳转
|
||||
return;
|
||||
}
|
||||
|
||||
// 假设不在任何代码块
|
||||
flag = true;
|
||||
for (const auto& info : m_Items) {
|
||||
if (targetAddress >= (ULONG_PTR)info->BaseAddress && targetAddress <= (ULONG_PTR)info->BaseAddress + info->RegionSize) {
|
||||
flag = false;
|
||||
}
|
||||
}
|
||||
if (flag)
|
||||
return;
|
||||
|
||||
flag = false;
|
||||
for (const auto& m : m_Sys64Modules) {
|
||||
@@ -444,15 +454,21 @@ void CProcessInlineHookTable::CheckX64HookType4(cs_insn* insn, size_t j, size_t
|
||||
if (0==count) {
|
||||
return;
|
||||
}
|
||||
|
||||
ULONG_PTR codeAddress;
|
||||
cs_detail* d = jmpCode[0].detail;
|
||||
if (d != nullptr) {
|
||||
ULONG_PTR memAddress = targetAddress + jmpCode[0].size + d->x86.operands[0].mem.disp;
|
||||
::ReadProcessMemory(m_hProcess, (LPVOID)memAddress, &targetAddress, sizeof(targetAddress), &dummy);
|
||||
::ReadProcessMemory(m_hProcess, (LPVOID)memAddress, &codeAddress, sizeof(codeAddress), &dummy);
|
||||
}
|
||||
|
||||
success = ::ReadProcessMemory(m_hProcess, (LPVOID)codeAddress, &dummy, sizeof(dummy), &dummy);
|
||||
InlineHookInfo info;
|
||||
info.TargetAddress = targetAddress;
|
||||
if (success) {
|
||||
info.TargetAddress = codeAddress;
|
||||
}
|
||||
else {
|
||||
info.TargetAddress = targetAddress;
|
||||
}
|
||||
info.TargetModule = L"Unknown";
|
||||
auto m = GetModuleByAddress(info.TargetAddress);
|
||||
if (m != nullptr) {
|
||||
|
||||
@@ -66,7 +66,7 @@ CString RegHelpers::GetErrorText(DWORD error) {
|
||||
}
|
||||
|
||||
PCWSTR RegHelpers::GetSystemDir() {
|
||||
static WCHAR dir[MAX_PATH];
|
||||
static WCHAR dir[MAX_PATH] = { 0 };
|
||||
if (dir[0] == 0)
|
||||
::GetSystemDirectory(dir, _countof(dir));
|
||||
|
||||
|
||||
+2
-2
@@ -5,6 +5,7 @@
|
||||
#include <vector>
|
||||
#include <memory>
|
||||
#include "SortHelper.h"
|
||||
#include "Helpers.h"
|
||||
|
||||
constexpr int NBAR = 30;
|
||||
|
||||
@@ -532,8 +533,7 @@ void CTable<T>::PaintTable(HWND hw) {
|
||||
int select = 0;
|
||||
int symName = 0;
|
||||
int len = ParseTableEntry(s, mask, select, info, col);
|
||||
USES_CONVERSION;
|
||||
std::string t = W2CA(s.GetString());
|
||||
std::string t = Helpers::WstringToString(s.GetString());
|
||||
HBRUSH hBkBrush;
|
||||
if (!(m_Table.mode & TABLE_USERDEF) // ·Ç×Ô»æ
|
||||
&& i==m_Table.data.selected
|
||||
|
||||
@@ -202,9 +202,8 @@
|
||||
<DebugInformationFormat />
|
||||
<PreprocessorDefinitions>_WIN64;_WINDOWS;STRICT;NDEBUG;%(PreprocessorDefinitions)</PreprocessorDefinitions>
|
||||
<AdditionalIncludeDirectories>..\capstone\include;..\PEParser;..\WinSysCore;..\PdbParser;..\Utils</AdditionalIncludeDirectories>
|
||||
<LanguageStandard>stdcpplatest</LanguageStandard>
|
||||
<LanguageStandard>stdcpp20</LanguageStandard>
|
||||
<Optimization>MinSpace</Optimization>
|
||||
<AdditionalOptions>/NODEFAULTLIB:"libcmt.lib" %(AdditionalOptions)</AdditionalOptions>
|
||||
</ClCompile>
|
||||
<Link>
|
||||
<SubSystem>Windows</SubSystem>
|
||||
|
||||
Reference in New Issue
Block a user