mirror of
https://github.com/dobin/RedEdr
synced 2026-08-09 12:30:51 +00:00
refactor: remove MAX_BUF_SIZE and other constants
This commit is contained in:
@@ -139,7 +139,7 @@ BOOL InstallPplService()
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
WCHAR serviceCMD[MAX_BUF_SIZE] = L"c:\\RedEdr\\RedEdrPplService.exe";
|
||||
WCHAR serviceCMD[PATH_LEN] = L"c:\\RedEdr\\RedEdrPplService.exe";
|
||||
|
||||
// Add PPL option
|
||||
hService = CreateService(
|
||||
|
||||
+15
-13
@@ -419,7 +419,7 @@ NTSTATUS NTAPI Catch_NtSetContextThread(
|
||||
*/
|
||||
|
||||
/******************* LdrLoadDll ************************/
|
||||
|
||||
#define DLL_NAME_LEN 128
|
||||
typedef NTSTATUS(NTAPI* pLdrLoadDll)(
|
||||
IN PWSTR SearchPath OPTIONAL,
|
||||
IN PULONG DllCharacteristics OPTIONAL,
|
||||
@@ -435,12 +435,12 @@ NTSTATUS NTAPI Catch_LdrLoadDll(
|
||||
) {
|
||||
LARGE_INTEGER time = get_time();
|
||||
wchar_t buf[DATA_BUFFER_SIZE] = L"";
|
||||
wchar_t wDllName[1024] = L""; // Buffer for the decoded DllName
|
||||
wchar_t wDllName[DLL_NAME_LEN] = L""; // Buffer for the decoded DllName
|
||||
wchar_t empty[32] = L"<broken>"; // Empty string in case SearchPath is NULL
|
||||
|
||||
if (HooksInitialized) { // dont log our own hooking
|
||||
wchar_t* searchPath = empty; // SearchPath seems to be 8 (the number 8, not a string) BROKEN
|
||||
UnicodeStringToWChar(DllName, wDllName, 1024);
|
||||
UnicodeStringToWChar(DllName, wDllName, DLL_NAME_LEN);
|
||||
ULONG dllCharacteristics = (DllCharacteristics != NULL) ? *DllCharacteristics : 0;
|
||||
|
||||
int offset = 0;
|
||||
@@ -463,7 +463,7 @@ NTSTATUS NTAPI Catch_LdrLoadDll(
|
||||
|
||||
|
||||
/******************* LdrGetProcedureAddress ************************/
|
||||
|
||||
#define WIDE_FUNCTION_NAME_LEN 128
|
||||
typedef NTSTATUS(NTAPI* pLdrGetProcedureAddress)(
|
||||
IN HMODULE ModuleHandle,
|
||||
IN PANSI_STRING FunctionName,
|
||||
@@ -479,14 +479,14 @@ NTSTATUS NTAPI Catch_LdrGetProcedureAddress(
|
||||
) {
|
||||
LARGE_INTEGER time = get_time();
|
||||
wchar_t buf[DATA_BUFFER_SIZE] = L"";
|
||||
wchar_t wideFunctionName[1024] = L"";
|
||||
wchar_t wideFunctionName[WIDE_FUNCTION_NAME_LEN] = L"";
|
||||
|
||||
if (HooksInitialized) { // dont log our own hooking
|
||||
//UnicodeStringToWChar(FunctionName, wideFunctionName, 1024);
|
||||
//UnicodeStringToWChar(FunctionName, wideFunctionName, WIDE_FUNCTION_NAME_LEN);
|
||||
|
||||
if (FunctionName && FunctionName->Buffer) {
|
||||
// Convert ANSI string to wide string
|
||||
MultiByteToWideChar(CP_ACP, 0, FunctionName->Buffer, -1, wideFunctionName, 1024);
|
||||
MultiByteToWideChar(CP_ACP, 0, FunctionName->Buffer, -1, wideFunctionName, WIDE_FUNCTION_NAME_LEN);
|
||||
}
|
||||
|
||||
int offset = 0;
|
||||
@@ -786,6 +786,7 @@ NTSTATUS NTAPI Catch_NtOpenProcess(
|
||||
|
||||
/******************* NtLoadDriver ************************/
|
||||
|
||||
#define WIDE_SERVICE_NAME_LEN 128
|
||||
typedef NTSTATUS(NTAPI* pNtLoadDriver)(
|
||||
IN PUNICODE_STRING DriverServiceName
|
||||
);
|
||||
@@ -795,11 +796,11 @@ NTSTATUS NTAPI Catch_NtLoadDriver(
|
||||
) {
|
||||
LARGE_INTEGER time = get_time();
|
||||
wchar_t buf[DATA_BUFFER_SIZE] = L"";
|
||||
wchar_t wDriverServiceName[1024];
|
||||
wchar_t wDriverServiceName[WIDE_SERVICE_NAME_LEN];
|
||||
|
||||
if (HooksInitialized) { // dont log our own hooking
|
||||
OutputDebugString(L"A12");
|
||||
UnicodeStringToWChar(DriverServiceName, wDriverServiceName, 1024);
|
||||
UnicodeStringToWChar(DriverServiceName, wDriverServiceName, WIDE_SERVICE_NAME_LEN);
|
||||
|
||||
int offset = 0;
|
||||
offset += swprintf_s(buf + offset, DATA_BUFFER_SIZE - offset, L"{");
|
||||
@@ -1292,6 +1293,7 @@ NTSTATUS NTAPI Catch_NtResumeThread(
|
||||
}
|
||||
|
||||
//----------------------------------------------------
|
||||
#define STARTSTOP_LEN 1024
|
||||
|
||||
// This function initializes the hooks via the MinHook library
|
||||
DWORD WINAPI InitHooksThread(LPVOID param) {
|
||||
@@ -1300,12 +1302,12 @@ DWORD WINAPI InitHooksThread(LPVOID param) {
|
||||
if (DetourIsHelperProcess()) {
|
||||
return TRUE;
|
||||
}
|
||||
wchar_t start_str[1024] = { 0 };
|
||||
wchar_t stop_str[1024] = { 0 };
|
||||
wchar_t start_str[STARTSTOP_LEN] = { 0 };
|
||||
wchar_t stop_str[STARTSTOP_LEN] = { 0 };
|
||||
|
||||
swprintf(start_str, 1024, L"{\"type\":\"dll\",\"func\":\"hooking_start\",\"pid\":%lu,\"tid\":%lu}",
|
||||
swprintf(start_str, STARTSTOP_LEN, L"{\"type\":\"dll\",\"func\":\"hooking_start\",\"pid\":%lu,\"tid\":%lu}",
|
||||
(DWORD)GetCurrentProcessId(), (DWORD)GetCurrentThreadId());
|
||||
swprintf(stop_str, 1024, L"{\"type\":\"dll\",\"func\":\"hooking_finished\",\"pid\":%lu,\"tid\":%lu}",
|
||||
swprintf(stop_str, STARTSTOP_LEN, L"{\"type\":\"dll\",\"func\":\"hooking_finished\",\"pid\":%lu,\"tid\":%lu}",
|
||||
(DWORD)GetCurrentProcessId(), (DWORD)GetCurrentThreadId());
|
||||
|
||||
LOG_A(LOG_INFO, "Injected DLL Detours Main thread started on pid %lu threadid %lu",
|
||||
|
||||
@@ -4,12 +4,15 @@
|
||||
#include <string.h>
|
||||
#include <stdio.h>
|
||||
|
||||
|
||||
#define PROC_NAME_LEN 128
|
||||
|
||||
typedef struct _PROCESS_INFO {
|
||||
HANDLE ProcessId;
|
||||
wchar_t name[128];
|
||||
wchar_t name[PROC_NAME_LEN];
|
||||
|
||||
HANDLE ppid;
|
||||
wchar_t parent_name[128];
|
||||
wchar_t parent_name[PROC_NAME_LEN];
|
||||
|
||||
int observe;
|
||||
int injected;
|
||||
|
||||
@@ -59,9 +59,9 @@ void CreateProcessNotifyRoutine(PEPROCESS parent_process, HANDLE pid, PPS_CREATE
|
||||
}
|
||||
|
||||
processInfo->ProcessId = pid;
|
||||
UnicodeStringToWChar(processName, processInfo->name, 128);
|
||||
UnicodeStringToWChar(processName, processInfo->name, PROC_NAME_LEN);
|
||||
processInfo->ppid = createInfo->ParentProcessId;
|
||||
UnicodeStringToWChar(parent_processName, processInfo->parent_name, 128);
|
||||
UnicodeStringToWChar(parent_processName, processInfo->parent_name, PROC_NAME_LEN);
|
||||
processInfo->observe = 0;
|
||||
|
||||
// Search in the unicode atm
|
||||
@@ -89,9 +89,9 @@ void CreateProcessNotifyRoutine(PEPROCESS parent_process, HANDLE pid, PPS_CREATE
|
||||
systemTime,
|
||||
(unsigned __int64)PsGetCurrentProcessId(),
|
||||
(unsigned __int64)pid,
|
||||
JsonEscape(processInfo->name, 128),
|
||||
JsonEscape(processInfo->name, PROC_NAME_LEN),
|
||||
(unsigned __int64)createInfo->ParentProcessId,
|
||||
JsonEscape(processInfo->parent_name, 128),
|
||||
JsonEscape(processInfo->parent_name, PROC_NAME_LEN),
|
||||
processInfo->observe);
|
||||
LogEvent(line);
|
||||
}
|
||||
|
||||
@@ -8,14 +8,14 @@
|
||||
void LOG_A(int severity, const char* format, ...)
|
||||
{
|
||||
UNREFERENCED_PARAMETER(severity);
|
||||
char message[MAX_BUF_SIZE] = "[RedEdr KRN] ";
|
||||
char message[KRN_LOG_LEN] = "[RedEdr KRN] ";
|
||||
size_t offset = strlen(message);
|
||||
|
||||
va_list arg_ptr;
|
||||
va_start(arg_ptr, format);
|
||||
|
||||
// Use RtlStringCbVPrintfA for kernel-safe string formatting
|
||||
RtlStringCbVPrintfA(&message[offset], MAX_BUF_SIZE - offset, format, arg_ptr);
|
||||
RtlStringCbVPrintfA(&message[offset], KRN_LOG_LEN - offset, format, arg_ptr);
|
||||
|
||||
va_end(arg_ptr);
|
||||
|
||||
|
||||
@@ -102,10 +102,10 @@ void StopControl() {
|
||||
// broken atm
|
||||
void rededr_remove_service() {
|
||||
//wchar_t* cmd = L"C:\\RedEdr\\RedEdr.exe --pplstop";
|
||||
WCHAR childCMD[MAX_BUF_SIZE] = { 0 };
|
||||
//wcscpy_s(childCMD, MAX_BUF_SIZE, L"C:\\windows\\system32\\cmd.exe /c \"echo AAA > c:\\rededr\\aa\"");
|
||||
//wcscpy_s(childCMD, MAX_BUF_SIZE, L"C:\\RedEdr\\RedEdrPplRemover.exe");
|
||||
wcscpy_s(childCMD, MAX_BUF_SIZE, L"C:\\RedEdr\\RedEdr.exe --pplstop");
|
||||
WCHAR childCMD[PATH_LEN] = { 0 };
|
||||
//wcscpy_s(childCMD, PATH_LEN, L"C:\\windows\\system32\\cmd.exe /c \"echo AAA > c:\\rededr\\aa\"");
|
||||
//wcscpy_s(childCMD, PATH_LEN, L"C:\\RedEdr\\RedEdrPplRemover.exe");
|
||||
wcscpy_s(childCMD, PATH_LEN, L"C:\\RedEdr\\RedEdr.exe --pplstop");
|
||||
start_child_process(childCMD);
|
||||
}
|
||||
|
||||
@@ -113,7 +113,6 @@ void rededr_remove_service() {
|
||||
DWORD start_child_process(wchar_t* childCMD)
|
||||
{
|
||||
DWORD retval = 0;
|
||||
DWORD dataSize = MAX_BUF_SIZE;
|
||||
LOG_W(LOG_INFO, L"start_child_process: Starting");
|
||||
|
||||
// Create Attribute List
|
||||
|
||||
@@ -97,7 +97,7 @@ void LOG_A(int verbosity, const char* format, ...)
|
||||
|
||||
va_list arg_ptr;
|
||||
va_start(arg_ptr, format);
|
||||
int ret = vsnprintf_s(&message[offset], DATA_BUFFER_SIZE - offset, MAX_BUF_SIZE - offset, format, arg_ptr);
|
||||
int ret = vsnprintf_s(&message[offset], DATA_BUFFER_SIZE - offset, DATA_BUFFER_SIZE - offset, format, arg_ptr);
|
||||
va_end(arg_ptr);
|
||||
|
||||
OutputDebugStringA(message);
|
||||
@@ -133,7 +133,7 @@ void LOG_A(int verbosity, const char* format, ...)
|
||||
|
||||
va_list arg_ptr;
|
||||
va_start(arg_ptr, format);
|
||||
int ret = vsnprintf_s(&message[offset], DATA_BUFFER_SIZE - offset, MAX_BUF_SIZE - offset, format, arg_ptr);
|
||||
int ret = vsnprintf_s(&message[offset], DATA_BUFFER_SIZE - offset, DATA_BUFFER_SIZE - offset, format, arg_ptr);
|
||||
va_end(arg_ptr);
|
||||
|
||||
OutputDebugStringA(message);
|
||||
@@ -174,7 +174,7 @@ void LOG_A(int verbosity, const char* format, ...)
|
||||
|
||||
va_list arg_ptr;
|
||||
va_start(arg_ptr, format);
|
||||
int ret = vsnprintf_s(&message[offset], DATA_BUFFER_SIZE - offset, MAX_BUF_SIZE - offset, format, arg_ptr);
|
||||
int ret = vsnprintf_s(&message[offset], DATA_BUFFER_SIZE - offset, DATA_BUFFER_SIZE - offset, format, arg_ptr);
|
||||
va_end(arg_ptr);
|
||||
|
||||
Microsoft::VisualStudio::CppUnitTestFramework::Logger::WriteMessage(message);
|
||||
@@ -217,7 +217,7 @@ void LOG_A(int verbosity, const char* format, ...)
|
||||
|
||||
va_list arg_ptr;
|
||||
va_start(arg_ptr, format);
|
||||
int ret = vsnprintf_s(&message[offset], DATA_BUFFER_SIZE - offset, MAX_BUF_SIZE - offset, format, arg_ptr);
|
||||
int ret = vsnprintf_s(&message[offset], DATA_BUFFER_SIZE - offset, DATA_BUFFER_SIZE - offset, format, arg_ptr);
|
||||
va_end(arg_ptr);
|
||||
|
||||
printf("%s", message);
|
||||
|
||||
+3
-3
@@ -4,7 +4,7 @@
|
||||
#define COMMON_H
|
||||
|
||||
#define PIPE_BUFFER_SIZE 8192 // thats the pipe buffer (default 4096)
|
||||
#define DATA_BUFFER_SIZE 4096 // events, most important
|
||||
#define DATA_BUFFER_SIZE 8192 // events, most important
|
||||
|
||||
#define IOCTL_MY_IOCTL_CODE CTL_CODE(FILE_DEVICE_UNKNOWN, 0x800, METHOD_BUFFERED, FILE_ANY_ACCESS)
|
||||
|
||||
@@ -13,6 +13,7 @@
|
||||
#define DLL_CONFIG_LEN 128 // for DLL pipe
|
||||
#define PPL_CONFIG_LEN 128 // for PPL pipe
|
||||
#define KRN_CONFIG_LEN 128 // for Kernel pipe
|
||||
#define KRN_LOG_LEN 1024
|
||||
|
||||
typedef struct _MY_DRIVER_DATA {
|
||||
wchar_t filename[TARGET_WSTR_LEN];
|
||||
@@ -29,8 +30,7 @@ typedef struct _MY_DRIVER_DATA {
|
||||
#define SERVICE_NAME L"RedEdrPplService"
|
||||
|
||||
#define DRIVER_NAME L"c:\\RedEdr\\elam_driver.sys"
|
||||
#define MAX_BUF_SIZE 2048
|
||||
|
||||
#define MAX_CALLSTACK_ENTRIES 5
|
||||
#define MAX_CALLSTACK_ENTRIES 8
|
||||
|
||||
#endif
|
||||
Reference in New Issue
Block a user