mirror of
https://github.com/JKornev/hidden
synced 2026-08-09 12:09:17 +00:00
Added a usermode interface for hiding processes
This commit is contained in:
@@ -72,3 +72,4 @@
|
||||
- Поддержка case-sensetive путей на Windows 10
|
||||
- Реализовать сокрытие процессов
|
||||
- Реализовать сокрытие сервисов через scdb патч
|
||||
- Добавить тест для проверки сокрытия процессов
|
||||
@@ -94,6 +94,41 @@ const wstring& CommandMode::GetConfigRegistryKeyPath()
|
||||
|
||||
// =================
|
||||
|
||||
ProcessParametersParser::ProcessParametersParser() :
|
||||
m_procId(0),
|
||||
m_inheritType(HidPsInheritTypes::WithoutInherit),
|
||||
m_applyByDefault(false)
|
||||
{
|
||||
}
|
||||
|
||||
void ProcessParametersParser::LoadImageParameters(Arguments& args, CommandModeType mode)
|
||||
{
|
||||
m_inheritType = LoadInheritOption(args, HidPsInheritTypes::WithoutInherit);
|
||||
|
||||
m_applyByDefault = false;
|
||||
if (mode == CommandModeType::Execute)
|
||||
m_applyByDefault = LoadApplyOption(args, m_applyByDefault);
|
||||
|
||||
if (!args.GetNext(m_image))
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, mismatched process image argument");
|
||||
}
|
||||
|
||||
void ProcessParametersParser::LoadProcessIdParameters(Arguments& args)
|
||||
{
|
||||
wstring target;
|
||||
|
||||
m_inheritType = LoadInheritOption(args, HidPsInheritTypes::WithoutInherit);
|
||||
|
||||
if (!args.GetNext(target))
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, mismatched process id argument");
|
||||
|
||||
m_procId = _wtol(target.c_str());
|
||||
if (!m_procId)
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, invalid target pid for command");
|
||||
}
|
||||
|
||||
// =================
|
||||
|
||||
SingleCommand::SingleCommand(Arguments& args, CommandModeType mode)
|
||||
{
|
||||
wstring arg;
|
||||
|
||||
+17
-1
@@ -4,7 +4,7 @@
|
||||
#include "Connection.h"
|
||||
#include <memory>
|
||||
|
||||
enum CommandModeType {
|
||||
enum class CommandModeType {
|
||||
Execute,
|
||||
Install,
|
||||
Uninstall
|
||||
@@ -42,6 +42,22 @@ public:
|
||||
const std::wstring& GetConfigRegistryKeyPath();
|
||||
};
|
||||
|
||||
class ProcessParametersParser
|
||||
{
|
||||
protected:
|
||||
std::wstring m_image;
|
||||
HidProcId m_procId;
|
||||
HidPsInheritTypes m_inheritType;
|
||||
bool m_applyByDefault;
|
||||
|
||||
public:
|
||||
ProcessParametersParser();
|
||||
virtual ~ProcessParametersParser() {}
|
||||
|
||||
void LoadImageParameters(Arguments& args, CommandModeType mode);
|
||||
void LoadProcessIdParameters(Arguments& args);
|
||||
};
|
||||
|
||||
class ICommandTemplate
|
||||
{
|
||||
public:
|
||||
|
||||
+4
-2
@@ -84,14 +84,16 @@ public:
|
||||
static void DeleteKey(std::wstring regKey, HKEY root = HKEY_LOCAL_MACHINE);
|
||||
};
|
||||
|
||||
enum EObjTypes {
|
||||
enum class EObjTypes {
|
||||
TypeFile,
|
||||
TypeDir,
|
||||
TypeRegKey,
|
||||
TypeRegVal,
|
||||
TypePsId,
|
||||
TypePsImg,
|
||||
};
|
||||
|
||||
enum EProcTypes {
|
||||
enum class EProcTypes {
|
||||
TypeProcessId,
|
||||
TypeImage,
|
||||
};
|
||||
|
||||
+71
-20
@@ -37,30 +37,47 @@ void CommandHide::LoadArgs(Arguments& args, CommandModeType mode)
|
||||
if (!args.GetNext(object))
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, mismatched argument #1 for command 'hide'");
|
||||
|
||||
if (!args.GetNext(m_path))
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, mismatched argument #2 for command 'hide'");
|
||||
|
||||
if (object == L"file")
|
||||
if (object == L"image")
|
||||
{
|
||||
m_hideType = EObjTypes::TypeFile;
|
||||
m_hideType = EObjTypes::TypePsImg;
|
||||
ProcessParametersParser::LoadImageParameters(args, mode);
|
||||
}
|
||||
else if (object == L"dir")
|
||||
else if (object == L"pid")
|
||||
{
|
||||
m_hideType = EObjTypes::TypeDir;
|
||||
}
|
||||
else if (object == L"regkey")
|
||||
{
|
||||
m_hideType = EObjTypes::TypeRegKey;
|
||||
m_regRootType = GetTypeAndNormalizeRegPath(m_path);
|
||||
}
|
||||
else if (object == L"regval")
|
||||
{
|
||||
m_hideType = EObjTypes::TypeRegVal;
|
||||
m_regRootType = GetTypeAndNormalizeRegPath(m_path);
|
||||
if (mode != CommandModeType::Execute)
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, target 'pid' isn't allowed");
|
||||
|
||||
m_hideType = EObjTypes::TypePsId;
|
||||
ProcessParametersParser::LoadProcessIdParameters(args);
|
||||
}
|
||||
else
|
||||
{
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, invalid argument for command 'hide'");
|
||||
if (!args.GetNext(m_path))
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, mismatched argument #2 for command 'hide'");
|
||||
|
||||
if (object == L"file")
|
||||
{
|
||||
m_hideType = EObjTypes::TypeFile;
|
||||
}
|
||||
else if (object == L"dir")
|
||||
{
|
||||
m_hideType = EObjTypes::TypeDir;
|
||||
}
|
||||
else if (object == L"regkey")
|
||||
{
|
||||
m_hideType = EObjTypes::TypeRegKey;
|
||||
m_regRootType = GetTypeAndNormalizeRegPath(m_path);
|
||||
}
|
||||
else if (object == L"regval")
|
||||
{
|
||||
m_hideType = EObjTypes::TypeRegVal;
|
||||
m_regRootType = GetTypeAndNormalizeRegPath(m_path);
|
||||
}
|
||||
else
|
||||
{
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, invalid argument for command 'hide'");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -83,6 +100,12 @@ void CommandHide::PerformCommand(Connection& connection)
|
||||
case EObjTypes::TypeRegVal:
|
||||
status = Hid_AddHiddenRegValue(connection.GetContext(), m_regRootType, m_path.c_str(), &objId);
|
||||
break;
|
||||
case EObjTypes::TypePsImg:
|
||||
status = Hid_AddHiddenImage(connection.GetContext(), m_image.c_str(), m_inheritType, m_applyByDefault, &objId);
|
||||
break;
|
||||
case EObjTypes::TypePsId:
|
||||
status = Hid_AttachHiddenState(connection.GetContext(), m_procId, m_inheritType);
|
||||
break;
|
||||
default:
|
||||
throw WException(ERROR_UNKNOWN_COMPONENT, L"Internal error, invalid type for command 'hide'");
|
||||
}
|
||||
@@ -91,7 +114,8 @@ void CommandHide::PerformCommand(Connection& connection)
|
||||
throw WException(HID_STATUS_CODE(status), L"Error, command 'hide' rejected");
|
||||
|
||||
g_stderr << L"Command 'hide' successful" << endl;
|
||||
g_stdout << L"ruleid:" << objId << endl;
|
||||
if (m_hideType != EObjTypes::TypePsId)
|
||||
g_stdout << L"ruleid:" << objId << endl;
|
||||
}
|
||||
|
||||
void CommandHide::InstallCommand(RegistryKey& configKey)
|
||||
@@ -121,6 +145,10 @@ void CommandHide::InstallCommand(RegistryKey& configKey)
|
||||
valueName = L"Hid_HideRegValues";
|
||||
status = Hid_NormalizeRegistryPath(m_regRootType, m_path.c_str(), const_cast<wchar_t*>(entry.c_str()), entry.size());
|
||||
break;
|
||||
case EObjTypes::TypePsImg:
|
||||
valueName = L"Hid_HidePsImages";
|
||||
status = Hid_NormalizeFilePath(m_image.c_str(), const_cast<wchar_t*>(entry.c_str()), entry.size());
|
||||
break;
|
||||
default:
|
||||
throw WException(ERROR_UNKNOWN_COMPONENT, L"Internal error, invalid type for command 'hide'");
|
||||
}
|
||||
@@ -152,9 +180,12 @@ CommandPtr CommandHide::CreateInstance()
|
||||
|
||||
// =================
|
||||
|
||||
CommandUnhide::CommandUnhide() : m_command(L"/unhide")
|
||||
CommandUnhide::CommandUnhide() :
|
||||
m_command(L"/unhide"),
|
||||
m_hideType(EObjTypes::TypeFile),
|
||||
m_targetAll(false),
|
||||
m_targetId(0)
|
||||
{
|
||||
m_targetId = 0;
|
||||
}
|
||||
|
||||
CommandUnhide::~CommandUnhide()
|
||||
@@ -192,6 +223,14 @@ void CommandUnhide::LoadArgs(Arguments& args, CommandModeType mode)
|
||||
{
|
||||
m_hideType = EObjTypes::TypeRegVal;
|
||||
}
|
||||
else if (object == L"image")
|
||||
{
|
||||
m_hideType = EObjTypes::TypePsImg;
|
||||
}
|
||||
else if (object == L"pid")
|
||||
{
|
||||
m_hideType = EObjTypes::TypePsId;
|
||||
}
|
||||
else
|
||||
{
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, invalid argument for command 'unhide'");
|
||||
@@ -204,6 +243,9 @@ void CommandUnhide::LoadArgs(Arguments& args, CommandModeType mode)
|
||||
if (!m_targetId)
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, invalid target objid for command 'unhide'");
|
||||
}
|
||||
|
||||
if (m_targetAll && m_hideType == EObjTypes::TypePsId)
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, parameter 'pid' can't be applied for all");
|
||||
}
|
||||
|
||||
void CommandUnhide::PerformCommand(Connection& connection)
|
||||
@@ -226,6 +268,9 @@ void CommandUnhide::PerformCommand(Connection& connection)
|
||||
case EObjTypes::TypeRegVal:
|
||||
status = Hid_RemoveAllHiddenRegValues(connection.GetContext());
|
||||
break;
|
||||
case EObjTypes::TypePsImg:
|
||||
status = Hid_RemoveAllHiddenImages(connection.GetContext());
|
||||
break;
|
||||
default:
|
||||
throw WException(ERROR_UNKNOWN_COMPONENT, L"Internal error #1, invalid type for command 'unhide'");
|
||||
}
|
||||
@@ -246,6 +291,12 @@ void CommandUnhide::PerformCommand(Connection& connection)
|
||||
case EObjTypes::TypeRegVal:
|
||||
status = Hid_RemoveHiddenRegValue(connection.GetContext(), m_targetId);
|
||||
break;
|
||||
case EObjTypes::TypePsImg:
|
||||
status = Hid_RemoveHiddenImage(connection.GetContext(), m_targetId);
|
||||
break;
|
||||
case EObjTypes::TypePsId:
|
||||
status = Hid_RemoveHiddenState(connection.GetContext(), static_cast<HidProcId>(m_targetId));
|
||||
break;
|
||||
default:
|
||||
throw WException(ERROR_UNKNOWN_COMPONENT, L"Internal error #2, invalid type for command 'unhide'");
|
||||
}
|
||||
|
||||
+1
-1
@@ -2,7 +2,7 @@
|
||||
|
||||
#include "Commands.h"
|
||||
|
||||
class CommandHide : public ICommand
|
||||
class CommandHide : public ICommand, public ProcessParametersParser
|
||||
{
|
||||
const wchar_t* m_command = nullptr;
|
||||
|
||||
|
||||
+6
-24
@@ -28,6 +28,7 @@ void CommandIgnore::LoadArgs(Arguments& args, CommandModeType mode)
|
||||
if (object == L"image")
|
||||
{
|
||||
m_procType = EProcTypes::TypeImage;
|
||||
ProcessParametersParser::LoadImageParameters(args, mode);
|
||||
}
|
||||
else if (object == L"pid")
|
||||
{
|
||||
@@ -35,31 +36,12 @@ void CommandIgnore::LoadArgs(Arguments& args, CommandModeType mode)
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, target 'pid' isn't allowed");
|
||||
|
||||
m_procType = EProcTypes::TypeProcessId;
|
||||
ProcessParametersParser::LoadProcessIdParameters(args);
|
||||
}
|
||||
else
|
||||
{
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, invalid object type in command 'ignore'");
|
||||
}
|
||||
|
||||
m_inheritType = LoadInheritOption(args, HidPsInheritTypes::WithoutInherit);
|
||||
|
||||
m_applyByDefault = false;
|
||||
if (m_procType == EProcTypes::TypeImage && mode == CommandModeType::Execute)
|
||||
m_applyByDefault = LoadApplyOption(args, m_applyByDefault);
|
||||
|
||||
if (!args.GetNext(target))
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, mismatched argument #2 for command 'ignore'");
|
||||
|
||||
if (m_procType == EProcTypes::TypeImage)
|
||||
{
|
||||
m_targetImage = target;
|
||||
}
|
||||
else
|
||||
{
|
||||
m_targetProcId = _wtol(target.c_str());
|
||||
if (!m_targetProcId)
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, invalid target pid for command 'ignore'");
|
||||
}
|
||||
}
|
||||
|
||||
void CommandIgnore::PerformCommand(Connection& connection)
|
||||
@@ -70,10 +52,10 @@ void CommandIgnore::PerformCommand(Connection& connection)
|
||||
switch (m_procType)
|
||||
{
|
||||
case EProcTypes::TypeProcessId:
|
||||
status = Hid_AttachExcludedState(connection.GetContext(), m_targetProcId, m_inheritType);
|
||||
status = Hid_AttachExcludedState(connection.GetContext(), m_procId, m_inheritType);
|
||||
break;
|
||||
case EProcTypes::TypeImage:
|
||||
status = Hid_AddExcludedImage(connection.GetContext(), m_targetImage.c_str(), m_inheritType, m_applyByDefault, &objId);
|
||||
status = Hid_AddExcludedImage(connection.GetContext(), m_image.c_str(), m_inheritType, m_applyByDefault, &objId);
|
||||
break;
|
||||
default:
|
||||
throw WException(ERROR_UNKNOWN_COMPONENT, L"Internal error, invalid type for command 'ignore'");
|
||||
@@ -93,9 +75,9 @@ void CommandIgnore::InstallCommand(RegistryKey& configKey)
|
||||
wstring temp, entry;
|
||||
HidStatus status;
|
||||
|
||||
temp.insert(0, m_targetImage.size() + HID_NORMALIZATION_OVERHEAD, L'\0');
|
||||
temp.insert(0, m_image.size() + HID_NORMALIZATION_OVERHEAD, L'\0');
|
||||
|
||||
status = Hid_NormalizeFilePath(m_targetImage.c_str(), const_cast<wchar_t*>(temp.c_str()), temp.size());
|
||||
status = Hid_NormalizeFilePath(m_image.c_str(), const_cast<wchar_t*>(temp.c_str()), temp.size());
|
||||
if (!HID_STATUS_SUCCESSFUL(status))
|
||||
throw WException(HID_STATUS_CODE(status), L"Error, can't normalize path, 'ignore' rejected");
|
||||
|
||||
|
||||
+2
-6
@@ -2,15 +2,11 @@
|
||||
|
||||
#include "Commands.h"
|
||||
|
||||
class CommandIgnore : public ICommand
|
||||
class CommandIgnore : public ICommand, public ProcessParametersParser
|
||||
{
|
||||
const wchar_t* m_command = nullptr;
|
||||
|
||||
EProcTypes m_procType;
|
||||
std::wstring m_targetImage;
|
||||
HidProcId m_targetProcId;
|
||||
HidPsInheritTypes m_inheritType;
|
||||
bool m_applyByDefault;
|
||||
|
||||
public:
|
||||
|
||||
@@ -30,7 +26,7 @@ class CommandUnignore : public ICommand
|
||||
{
|
||||
const wchar_t* m_command = nullptr;
|
||||
|
||||
enum ETargetIdType {
|
||||
enum class ETargetIdType {
|
||||
RuleId,
|
||||
ProcId,
|
||||
All
|
||||
|
||||
+6
-24
@@ -28,6 +28,7 @@ void CommandProtect::LoadArgs(Arguments& args, CommandModeType mode)
|
||||
if (object == L"image")
|
||||
{
|
||||
m_procType = EProcTypes::TypeImage;
|
||||
ProcessParametersParser::LoadImageParameters(args, mode);
|
||||
}
|
||||
else if (object == L"pid")
|
||||
{
|
||||
@@ -35,31 +36,12 @@ void CommandProtect::LoadArgs(Arguments& args, CommandModeType mode)
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, target 'pid' isn't allowed");
|
||||
|
||||
m_procType = EProcTypes::TypeProcessId;
|
||||
ProcessParametersParser::LoadProcessIdParameters(args);
|
||||
}
|
||||
else
|
||||
{
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, invalid object type in command 'protect'");
|
||||
}
|
||||
|
||||
m_inheritType = LoadInheritOption(args, HidPsInheritTypes::WithoutInherit);
|
||||
|
||||
m_applyByDefault = false;
|
||||
if (m_procType == EProcTypes::TypeImage && mode == CommandModeType::Execute)
|
||||
m_applyByDefault = LoadApplyOption(args, m_applyByDefault);
|
||||
|
||||
if (!args.GetNext(target))
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, mismatched argument #2 for command 'protect'");
|
||||
|
||||
if (m_procType == EProcTypes::TypeImage)
|
||||
{
|
||||
m_targetImage = target;
|
||||
}
|
||||
else
|
||||
{
|
||||
m_targetProcId = _wtol(target.c_str());
|
||||
if (!m_targetProcId)
|
||||
throw WException(ERROR_INVALID_PARAMETER, L"Error, invalid target pid for command 'protect'");
|
||||
}
|
||||
}
|
||||
|
||||
void CommandProtect::PerformCommand(Connection& connection)
|
||||
@@ -70,10 +52,10 @@ void CommandProtect::PerformCommand(Connection& connection)
|
||||
switch (m_procType)
|
||||
{
|
||||
case EProcTypes::TypeProcessId:
|
||||
status = Hid_AttachProtectedState(connection.GetContext(), m_targetProcId, m_inheritType);
|
||||
status = Hid_AttachProtectedState(connection.GetContext(), m_procId, m_inheritType);
|
||||
break;
|
||||
case EProcTypes::TypeImage:
|
||||
status = Hid_AddProtectedImage(connection.GetContext(), m_targetImage.c_str(), m_inheritType, m_applyByDefault, &objId);
|
||||
status = Hid_AddProtectedImage(connection.GetContext(), m_image.c_str(), m_inheritType, m_applyByDefault, &objId);
|
||||
break;
|
||||
default:
|
||||
throw WException(ERROR_UNKNOWN_COMPONENT, L"Internal error, invalid type for command 'protect'");
|
||||
@@ -93,9 +75,9 @@ void CommandProtect::InstallCommand(RegistryKey& configKey)
|
||||
wstring temp, entry;
|
||||
HidStatus status;
|
||||
|
||||
temp.insert(0, m_targetImage.size() + HID_NORMALIZATION_OVERHEAD, L'\0');
|
||||
temp.insert(0, m_image.size() + HID_NORMALIZATION_OVERHEAD, L'\0');
|
||||
|
||||
status = Hid_NormalizeFilePath(m_targetImage.c_str(), const_cast<wchar_t*>(temp.c_str()), temp.size());
|
||||
status = Hid_NormalizeFilePath(m_image.c_str(), const_cast<wchar_t*>(temp.c_str()), temp.size());
|
||||
if (!HID_STATUS_SUCCESSFUL(status))
|
||||
throw WException(HID_STATUS_CODE(status), L"Error, can't normalize path, 'protect' rejected");
|
||||
|
||||
|
||||
+1
-5
@@ -2,15 +2,11 @@
|
||||
|
||||
#include "Commands.h"
|
||||
|
||||
class CommandProtect : public ICommand
|
||||
class CommandProtect : public ICommand, public ProcessParametersParser
|
||||
{
|
||||
const wchar_t* m_command = nullptr;
|
||||
|
||||
EProcTypes m_procType;
|
||||
std::wstring m_targetImage;
|
||||
HidProcId m_targetProcId;
|
||||
HidPsInheritTypes m_inheritType;
|
||||
bool m_applyByDefault;
|
||||
|
||||
public:
|
||||
|
||||
|
||||
+2
-2
@@ -78,8 +78,8 @@ void CommandQuery::PerformCommand(Connection& connection)
|
||||
g_stderr << L"Protected state:" << (protectedState == HidActiveState::StateEnabled ? L"true" : L"false")
|
||||
<< L", inherit:" << ConvertInheritTypeToUnicode(protectedInherit) << endl;
|
||||
|
||||
g_stdout << L"ignored:" << excludeState << L"," << excludedInherit
|
||||
<< L";protected:" << protectedState << L"," << protectedInherit << endl;
|
||||
g_stdout << L"ignored:" << static_cast<unsigned short>(excludeState) << L"," << static_cast<unsigned short>(excludedInherit)
|
||||
<< L";protected:" << static_cast<unsigned short>(protectedState) << L"," << static_cast<unsigned short>(protectedInherit) << endl;
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
+1
-1
@@ -4,7 +4,7 @@
|
||||
|
||||
class CommandQuery : public ICommand
|
||||
{
|
||||
enum EQueryType {
|
||||
enum class EQueryType {
|
||||
QueryProcess,
|
||||
QueryState,
|
||||
};
|
||||
|
||||
+45
-5
@@ -159,7 +159,7 @@ bool NormalizeRegistryPath(HidRegRootTypes root, const wchar_t* key, wchar_t* no
|
||||
|
||||
keyLen = wcslen(key);
|
||||
|
||||
if (root == RegHKCU)
|
||||
if (root == HidRegRootTypes::RegHKCU)
|
||||
{
|
||||
UNICODE_STRING currUser;
|
||||
|
||||
@@ -180,7 +180,7 @@ bool NormalizeRegistryPath(HidRegRootTypes root, const wchar_t* key, wchar_t* no
|
||||
|
||||
RtlFreeUnicodeString(&currUser);
|
||||
}
|
||||
else if (root == RegHKLM)
|
||||
else if (root == HidRegRootTypes::RegHKLM)
|
||||
{
|
||||
rootLen = wcslen(hklm);
|
||||
|
||||
@@ -191,7 +191,7 @@ bool NormalizeRegistryPath(HidRegRootTypes root, const wchar_t* key, wchar_t* no
|
||||
memcpy(normalized + rootLen, key, keyLen * sizeof(wchar_t));
|
||||
normalized[rootLen + keyLen] = L'\0';
|
||||
}
|
||||
else if (root == RegHKU)
|
||||
else if (root == HidRegRootTypes::RegHKU)
|
||||
{
|
||||
rootLen = wcslen(hku);
|
||||
|
||||
@@ -406,7 +406,7 @@ HidStatus SendIoctl_AddPsObjectPacket(PHidContextInternal context, const wchar_t
|
||||
hide = (PHid_AddPsObjectPacket)_alloca(size);
|
||||
hide->dataSize = (unsigned short)total;
|
||||
hide->objType = type;
|
||||
hide->inheritType = inheritType;
|
||||
hide->inheritType = static_cast<unsigned short>(inheritType);
|
||||
hide->applyForProcesses = applyForProcess;
|
||||
|
||||
memcpy((char*)hide + sizeof(Hid_AddPsObjectPacket), path, total);
|
||||
@@ -526,7 +526,7 @@ HidStatus SendIoctl_SetPsStatePacket(PHidContextInternal context, HidProcId proc
|
||||
info.objType = type;
|
||||
info.procId = procId;
|
||||
info.enable = (state == HidActiveState::StateEnabled);
|
||||
info.inheritType = inheritType;
|
||||
info.inheritType = static_cast<unsigned short>(inheritType);
|
||||
|
||||
// Send IOCTL to device
|
||||
|
||||
@@ -744,6 +744,46 @@ HidStatus _API Hid_RemoveProtectedState(HidContext context, HidProcId procId)
|
||||
return SendIoctl_SetPsStatePacket((PHidContextInternal)context, procId, PsProtectedObject, HidActiveState::StateDisabled, HidPsInheritTypes::WithoutInherit);
|
||||
}
|
||||
|
||||
HidStatus _API Hid_AddHiddenImage(HidContext context, const wchar_t* imagePath, HidPsInheritTypes inheritType, bool applyForProcess, HidObjId* objId)
|
||||
{
|
||||
HidStatus status;
|
||||
wchar_t* normalized;
|
||||
|
||||
status = AllocNormalizedPath(imagePath, &normalized);
|
||||
if (!HID_STATUS_SUCCESSFUL(status))
|
||||
return status;
|
||||
|
||||
status = SendIoctl_AddPsObjectPacket((PHidContextInternal)context, normalized, PsHiddenObject, inheritType, applyForProcess, objId);
|
||||
FreeNormalizedPath(normalized);
|
||||
|
||||
return status;
|
||||
}
|
||||
|
||||
HidStatus _API Hid_RemoveHiddenImage(HidContext context, HidObjId objId)
|
||||
{
|
||||
return SendIoctl_RemovePsObjectPacket((PHidContextInternal)context, PsHiddenObject, objId);
|
||||
}
|
||||
|
||||
HidStatus _API Hid_RemoveAllHiddenImages(HidContext context)
|
||||
{
|
||||
return SendIoctl_RemoveAllPsObjectsPacket((PHidContextInternal)context, PsHiddenObject);
|
||||
}
|
||||
|
||||
HidStatus _API Hid_GetHiddenState(HidContext context, HidProcId procId, HidActiveState* state, HidPsInheritTypes* inheritType)
|
||||
{
|
||||
return SendIoctl_GetPsStatePacket((PHidContextInternal)context, procId, PsHiddenObject, state, inheritType);
|
||||
}
|
||||
|
||||
HidStatus _API Hid_AttachHiddenState(HidContext context, HidProcId procId, HidPsInheritTypes inheritType)
|
||||
{
|
||||
return SendIoctl_SetPsStatePacket((PHidContextInternal)context, procId, PsHiddenObject, HidActiveState::StateEnabled, inheritType);
|
||||
}
|
||||
|
||||
HidStatus _API Hid_RemoveHiddenState(HidContext context, HidProcId procId)
|
||||
{
|
||||
return SendIoctl_SetPsStatePacket((PHidContextInternal)context, procId, PsHiddenObject, HidActiveState::StateDisabled, HidPsInheritTypes::WithoutInherit);
|
||||
}
|
||||
|
||||
HidStatus _API Hid_NormalizeFilePath(const wchar_t* filePath, wchar_t* normalized, size_t normalizedLen)
|
||||
{
|
||||
if (!ConvertToNtPath(filePath, normalized, normalizedLen))
|
||||
|
||||
+10
-3
@@ -18,7 +18,7 @@ typedef unsigned long long HidObjId;
|
||||
|
||||
typedef unsigned long HidProcId;
|
||||
|
||||
enum HidActiveState
|
||||
enum class HidActiveState
|
||||
{
|
||||
StateDisabled = 0,
|
||||
StateEnabled
|
||||
@@ -26,7 +26,7 @@ enum HidActiveState
|
||||
|
||||
// Important note:
|
||||
// This enum should be equal to PsRuleInheritTypes (PsRules.h)
|
||||
enum HidPsInheritTypes
|
||||
enum class HidPsInheritTypes
|
||||
{
|
||||
WithoutInherit = 0,
|
||||
InheritAlways,
|
||||
@@ -34,7 +34,7 @@ enum HidPsInheritTypes
|
||||
InheritMax
|
||||
};
|
||||
|
||||
enum HidRegRootTypes
|
||||
enum class HidRegRootTypes
|
||||
{
|
||||
RegHKCU,
|
||||
RegHKLM,
|
||||
@@ -82,6 +82,13 @@ HidStatus _API Hid_GetProtectedState(HidContext context, HidProcId procId, HidAc
|
||||
HidStatus _API Hid_AttachProtectedState(HidContext context, HidProcId procId, HidPsInheritTypes inheritType);
|
||||
HidStatus _API Hid_RemoveProtectedState(HidContext context, HidProcId procId);
|
||||
|
||||
HidStatus _API Hid_AddHiddenImage(HidContext context, const wchar_t* imagePath, HidPsInheritTypes inheritType, bool applyForProcess, HidObjId* objId);
|
||||
HidStatus _API Hid_RemoveHiddenImage(HidContext context, HidObjId objId);
|
||||
HidStatus _API Hid_RemoveAllHiddenImages(HidContext context);
|
||||
HidStatus _API Hid_GetHiddenState(HidContext context, HidProcId procId, HidActiveState* state, HidPsInheritTypes* inheritType);
|
||||
HidStatus _API Hid_AttachHiddenState(HidContext context, HidProcId procId, HidPsInheritTypes inheritType);
|
||||
HidStatus _API Hid_RemoveHiddenState(HidContext context, HidProcId procId);
|
||||
|
||||
// Misc
|
||||
|
||||
HidStatus _API Hid_NormalizeFilePath(const wchar_t* filePath, wchar_t* normalized, size_t normalizedLen);
|
||||
|
||||
@@ -476,7 +476,7 @@ void do_psmon_prot_tests(HidContext context)
|
||||
|
||||
if (state != HidActiveState::StateDisabled)
|
||||
{
|
||||
wcout << L"Error, state isn't StateDisabled, state: " << state << " " << inheritType << endl;
|
||||
wcout << L"Error, state isn't StateDisabled, state: " << (UINT)state << " " << (UINT)inheritType << endl;
|
||||
throw exception();
|
||||
}
|
||||
|
||||
@@ -496,7 +496,7 @@ void do_psmon_prot_tests(HidContext context)
|
||||
|
||||
if (state != HidActiveState::StateEnabled || inheritType != HidPsInheritTypes::WithoutInherit)
|
||||
{
|
||||
wcout << L"Error, state isn't StateEnabled, state: " << state << " " << inheritType << endl;
|
||||
wcout << L"Error, state isn't StateEnabled, state: " << (UINT)state << " " << (UINT)inheritType << endl;
|
||||
throw exception();
|
||||
}
|
||||
|
||||
@@ -516,7 +516,7 @@ void do_psmon_prot_tests(HidContext context)
|
||||
|
||||
if (state != HidActiveState::StateDisabled)
|
||||
{
|
||||
wcout << L"Error, state isn't StateDisabled, state: " << state << " " << inheritType << endl;
|
||||
wcout << L"Error, state isn't StateDisabled, state: " << (UINT)state << " " << (UINT)inheritType << endl;
|
||||
throw exception();
|
||||
}
|
||||
|
||||
@@ -708,7 +708,7 @@ void do_psmon_excl_tests(HidContext context)
|
||||
|
||||
if (state != HidActiveState::StateDisabled)
|
||||
{
|
||||
wcout << L"Error, state isn't StateDisabled, state: " << state << " " << inheritType << endl;
|
||||
wcout << L"Error, state isn't StateDisabled, state: " << (UINT)state << " " << (UINT)inheritType << endl;
|
||||
throw exception();
|
||||
}
|
||||
|
||||
@@ -728,7 +728,7 @@ void do_psmon_excl_tests(HidContext context)
|
||||
|
||||
if (state != HidActiveState::StateEnabled)
|
||||
{
|
||||
wcout << L"Error, state isn't StateEnabled, state: " << state << " " << inheritType << endl;
|
||||
wcout << L"Error, state isn't StateEnabled, state: " << (UINT)state << " " << (UINT)inheritType << endl;
|
||||
throw exception();
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user