tweak the suspicious bug when call SymGetSymFromName

This commit is contained in:
CORP\zengquan
2022-08-11 10:26:44 +08:00
parent e1659d5589
commit 56c93c85ea
7 changed files with 55 additions and 11 deletions
+18 -3
View File
@@ -48,6 +48,20 @@ SymbolInfo::~SymbolInfo() {
::free(m_Symbol);
}
ImagehlpSymbol::ImagehlpSymbol() {
auto size = sizeof(IMAGEHLP_SYMBOL) + MAX_SYM_NAME;
m_Symbol = static_cast<IMAGEHLP_SYMBOL*>(malloc(size));
if (m_Symbol) {
::memset(m_Symbol, 0, size);
m_Symbol->SizeOfStruct = sizeof(IMAGEHLP_SYMBOL);
m_Symbol->MaxNameLength = MAX_SYM_NAME;
}
}
ImagehlpSymbol::~ImagehlpSymbol() {
::free(m_Symbol);
}
SymbolHandler::SymbolHandler(HANDLE hProcess, PCSTR searchPath,DWORD symOptions){
m_hProcess = hProcess;
::SymSetOptions(symOptions);
@@ -199,7 +213,8 @@ IMAGEHLP_MODULE SymbolHandler::GetModuleInfo(DWORD64 address) {
ULONG_PTR SymbolHandler::GetSymbolAddressFromName(PCSTR name) {
IMAGEHLP_SYMBOL symbol = { sizeof(symbol) };
::SymGetSymFromName(m_hProcess, name, &symbol);
return symbol.Address;
auto symbol = std::make_unique<ImagehlpSymbol>();
auto info = symbol->GetSymbolInfo();
::SymGetSymFromName(m_hProcess, name, info);
return info->Address;
}
+13
View File
@@ -166,6 +166,19 @@ private:
SYMBOL_INFO* m_Symbol;
};
class ImagehlpSymbol {
public:
ImagehlpSymbol();
~ImagehlpSymbol();
IMAGEHLP_SYMBOL* GetSymbolInfo() const {
return m_Symbol;
}
private:
IMAGEHLP_SYMBOL* m_Symbol;
};
class SymbolHandler final{
public:
SymbolHandler(HANDLE hProcess = ::GetCurrentProcess(), PCSTR searchPath = nullptr,DWORD symOptions =
+1
View File
@@ -146,6 +146,7 @@
<PrecompiledHeaderFile>pch.h</PrecompiledHeaderFile>
<RuntimeLibrary>MultiThreaded</RuntimeLibrary>
<ExceptionHandling>false</ExceptionHandling>
<LanguageStandard>stdcpp20</LanguageStandard>
</ClCompile>
<Link>
<SubSystem>
+18 -2
View File
@@ -421,6 +421,16 @@ void CProcessInlineHookTable::CheckX64HookType4(cs_insn* insn, size_t j, size_t
return;
}
// 假设不在任何代码块
flag = true;
for (const auto& info : m_Items) {
if (targetAddress >= (ULONG_PTR)info->BaseAddress && targetAddress <= (ULONG_PTR)info->BaseAddress + info->RegionSize) {
flag = false;
}
}
if (flag)
return;
flag = false;
for (const auto& m : m_Sys64Modules) {
// 排除调用API
@@ -444,15 +454,21 @@ void CProcessInlineHookTable::CheckX64HookType4(cs_insn* insn, size_t j, size_t
if (0==count) {
return;
}
ULONG_PTR codeAddress;
cs_detail* d = jmpCode[0].detail;
if (d != nullptr) {
ULONG_PTR memAddress = targetAddress + jmpCode[0].size + d->x86.operands[0].mem.disp;
::ReadProcessMemory(m_hProcess, (LPVOID)memAddress, &targetAddress, sizeof(targetAddress), &dummy);
::ReadProcessMemory(m_hProcess, (LPVOID)memAddress, &codeAddress, sizeof(codeAddress), &dummy);
}
success = ::ReadProcessMemory(m_hProcess, (LPVOID)codeAddress, &dummy, sizeof(dummy), &dummy);
InlineHookInfo info;
if (success) {
info.TargetAddress = codeAddress;
}
else {
info.TargetAddress = targetAddress;
}
info.TargetModule = L"Unknown";
auto m = GetModuleByAddress(info.TargetAddress);
if (m != nullptr) {
+1 -1
View File
@@ -66,7 +66,7 @@ CString RegHelpers::GetErrorText(DWORD error) {
}
PCWSTR RegHelpers::GetSystemDir() {
static WCHAR dir[MAX_PATH];
static WCHAR dir[MAX_PATH] = { 0 };
if (dir[0] == 0)
::GetSystemDirectory(dir, _countof(dir));
+2 -2
View File
@@ -5,6 +5,7 @@
#include <vector>
#include <memory>
#include "SortHelper.h"
#include "Helpers.h"
constexpr int NBAR = 30;
@@ -532,8 +533,7 @@ void CTable<T>::PaintTable(HWND hw) {
int select = 0;
int symName = 0;
int len = ParseTableEntry(s, mask, select, info, col);
USES_CONVERSION;
std::string t = W2CA(s.GetString());
std::string t = Helpers::WstringToString(s.GetString());
HBRUSH hBkBrush;
if (!(m_Table.mode & TABLE_USERDEF) // ·Ç×Ô»æ
&& i==m_Table.data.selected
+1 -2
View File
@@ -202,9 +202,8 @@
<DebugInformationFormat />
<PreprocessorDefinitions>_WIN64;_WINDOWS;STRICT;NDEBUG;%(PreprocessorDefinitions)</PreprocessorDefinitions>
<AdditionalIncludeDirectories>..\capstone\include;..\PEParser;..\WinSysCore;..\PdbParser;..\Utils</AdditionalIncludeDirectories>
<LanguageStandard>stdcpplatest</LanguageStandard>
<LanguageStandard>stdcpp20</LanguageStandard>
<Optimization>MinSpace</Optimization>
<AdditionalOptions>/NODEFAULTLIB:"libcmt.lib" %(AdditionalOptions)</AdditionalOptions>
</ClCompile>
<Link>
<SubSystem>Windows</SubSystem>