refactor: remove MAX_BUF_SIZE and other constants

This commit is contained in:
2024-12-23 22:43:02 +01:00
parent 078c53dce0
commit bc95713f0b
8 changed files with 38 additions and 34 deletions
+1 -1
View File
@@ -139,7 +139,7 @@ BOOL InstallPplService()
return FALSE;
}
WCHAR serviceCMD[MAX_BUF_SIZE] = L"c:\\RedEdr\\RedEdrPplService.exe";
WCHAR serviceCMD[PATH_LEN] = L"c:\\RedEdr\\RedEdrPplService.exe";
// Add PPL option
hService = CreateService(
+15 -13
View File
@@ -419,7 +419,7 @@ NTSTATUS NTAPI Catch_NtSetContextThread(
*/
/******************* LdrLoadDll ************************/
#define DLL_NAME_LEN 128
typedef NTSTATUS(NTAPI* pLdrLoadDll)(
IN PWSTR SearchPath OPTIONAL,
IN PULONG DllCharacteristics OPTIONAL,
@@ -435,12 +435,12 @@ NTSTATUS NTAPI Catch_LdrLoadDll(
) {
LARGE_INTEGER time = get_time();
wchar_t buf[DATA_BUFFER_SIZE] = L"";
wchar_t wDllName[1024] = L""; // Buffer for the decoded DllName
wchar_t wDllName[DLL_NAME_LEN] = L""; // Buffer for the decoded DllName
wchar_t empty[32] = L"<broken>"; // Empty string in case SearchPath is NULL
if (HooksInitialized) { // dont log our own hooking
wchar_t* searchPath = empty; // SearchPath seems to be 8 (the number 8, not a string) BROKEN
UnicodeStringToWChar(DllName, wDllName, 1024);
UnicodeStringToWChar(DllName, wDllName, DLL_NAME_LEN);
ULONG dllCharacteristics = (DllCharacteristics != NULL) ? *DllCharacteristics : 0;
int offset = 0;
@@ -463,7 +463,7 @@ NTSTATUS NTAPI Catch_LdrLoadDll(
/******************* LdrGetProcedureAddress ************************/
#define WIDE_FUNCTION_NAME_LEN 128
typedef NTSTATUS(NTAPI* pLdrGetProcedureAddress)(
IN HMODULE ModuleHandle,
IN PANSI_STRING FunctionName,
@@ -479,14 +479,14 @@ NTSTATUS NTAPI Catch_LdrGetProcedureAddress(
) {
LARGE_INTEGER time = get_time();
wchar_t buf[DATA_BUFFER_SIZE] = L"";
wchar_t wideFunctionName[1024] = L"";
wchar_t wideFunctionName[WIDE_FUNCTION_NAME_LEN] = L"";
if (HooksInitialized) { // dont log our own hooking
//UnicodeStringToWChar(FunctionName, wideFunctionName, 1024);
//UnicodeStringToWChar(FunctionName, wideFunctionName, WIDE_FUNCTION_NAME_LEN);
if (FunctionName && FunctionName->Buffer) {
// Convert ANSI string to wide string
MultiByteToWideChar(CP_ACP, 0, FunctionName->Buffer, -1, wideFunctionName, 1024);
MultiByteToWideChar(CP_ACP, 0, FunctionName->Buffer, -1, wideFunctionName, WIDE_FUNCTION_NAME_LEN);
}
int offset = 0;
@@ -786,6 +786,7 @@ NTSTATUS NTAPI Catch_NtOpenProcess(
/******************* NtLoadDriver ************************/
#define WIDE_SERVICE_NAME_LEN 128
typedef NTSTATUS(NTAPI* pNtLoadDriver)(
IN PUNICODE_STRING DriverServiceName
);
@@ -795,11 +796,11 @@ NTSTATUS NTAPI Catch_NtLoadDriver(
) {
LARGE_INTEGER time = get_time();
wchar_t buf[DATA_BUFFER_SIZE] = L"";
wchar_t wDriverServiceName[1024];
wchar_t wDriverServiceName[WIDE_SERVICE_NAME_LEN];
if (HooksInitialized) { // dont log our own hooking
OutputDebugString(L"A12");
UnicodeStringToWChar(DriverServiceName, wDriverServiceName, 1024);
UnicodeStringToWChar(DriverServiceName, wDriverServiceName, WIDE_SERVICE_NAME_LEN);
int offset = 0;
offset += swprintf_s(buf + offset, DATA_BUFFER_SIZE - offset, L"{");
@@ -1292,6 +1293,7 @@ NTSTATUS NTAPI Catch_NtResumeThread(
}
//----------------------------------------------------
#define STARTSTOP_LEN 1024
// This function initializes the hooks via the MinHook library
DWORD WINAPI InitHooksThread(LPVOID param) {
@@ -1300,12 +1302,12 @@ DWORD WINAPI InitHooksThread(LPVOID param) {
if (DetourIsHelperProcess()) {
return TRUE;
}
wchar_t start_str[1024] = { 0 };
wchar_t stop_str[1024] = { 0 };
wchar_t start_str[STARTSTOP_LEN] = { 0 };
wchar_t stop_str[STARTSTOP_LEN] = { 0 };
swprintf(start_str, 1024, L"{\"type\":\"dll\",\"func\":\"hooking_start\",\"pid\":%lu,\"tid\":%lu}",
swprintf(start_str, STARTSTOP_LEN, L"{\"type\":\"dll\",\"func\":\"hooking_start\",\"pid\":%lu,\"tid\":%lu}",
(DWORD)GetCurrentProcessId(), (DWORD)GetCurrentThreadId());
swprintf(stop_str, 1024, L"{\"type\":\"dll\",\"func\":\"hooking_finished\",\"pid\":%lu,\"tid\":%lu}",
swprintf(stop_str, STARTSTOP_LEN, L"{\"type\":\"dll\",\"func\":\"hooking_finished\",\"pid\":%lu,\"tid\":%lu}",
(DWORD)GetCurrentProcessId(), (DWORD)GetCurrentThreadId());
LOG_A(LOG_INFO, "Injected DLL Detours Main thread started on pid %lu threadid %lu",
+5 -2
View File
@@ -4,12 +4,15 @@
#include <string.h>
#include <stdio.h>
#define PROC_NAME_LEN 128
typedef struct _PROCESS_INFO {
HANDLE ProcessId;
wchar_t name[128];
wchar_t name[PROC_NAME_LEN];
HANDLE ppid;
wchar_t parent_name[128];
wchar_t parent_name[PROC_NAME_LEN];
int observe;
int injected;
+4 -4
View File
@@ -59,9 +59,9 @@ void CreateProcessNotifyRoutine(PEPROCESS parent_process, HANDLE pid, PPS_CREATE
}
processInfo->ProcessId = pid;
UnicodeStringToWChar(processName, processInfo->name, 128);
UnicodeStringToWChar(processName, processInfo->name, PROC_NAME_LEN);
processInfo->ppid = createInfo->ParentProcessId;
UnicodeStringToWChar(parent_processName, processInfo->parent_name, 128);
UnicodeStringToWChar(parent_processName, processInfo->parent_name, PROC_NAME_LEN);
processInfo->observe = 0;
// Search in the unicode atm
@@ -89,9 +89,9 @@ void CreateProcessNotifyRoutine(PEPROCESS parent_process, HANDLE pid, PPS_CREATE
systemTime,
(unsigned __int64)PsGetCurrentProcessId(),
(unsigned __int64)pid,
JsonEscape(processInfo->name, 128),
JsonEscape(processInfo->name, PROC_NAME_LEN),
(unsigned __int64)createInfo->ParentProcessId,
JsonEscape(processInfo->parent_name, 128),
JsonEscape(processInfo->parent_name, PROC_NAME_LEN),
processInfo->observe);
LogEvent(line);
}
+2 -2
View File
@@ -8,14 +8,14 @@
void LOG_A(int severity, const char* format, ...)
{
UNREFERENCED_PARAMETER(severity);
char message[MAX_BUF_SIZE] = "[RedEdr KRN] ";
char message[KRN_LOG_LEN] = "[RedEdr KRN] ";
size_t offset = strlen(message);
va_list arg_ptr;
va_start(arg_ptr, format);
// Use RtlStringCbVPrintfA for kernel-safe string formatting
RtlStringCbVPrintfA(&message[offset], MAX_BUF_SIZE - offset, format, arg_ptr);
RtlStringCbVPrintfA(&message[offset], KRN_LOG_LEN - offset, format, arg_ptr);
va_end(arg_ptr);
+4 -5
View File
@@ -102,10 +102,10 @@ void StopControl() {
// broken atm
void rededr_remove_service() {
//wchar_t* cmd = L"C:\\RedEdr\\RedEdr.exe --pplstop";
WCHAR childCMD[MAX_BUF_SIZE] = { 0 };
//wcscpy_s(childCMD, MAX_BUF_SIZE, L"C:\\windows\\system32\\cmd.exe /c \"echo AAA > c:\\rededr\\aa\"");
//wcscpy_s(childCMD, MAX_BUF_SIZE, L"C:\\RedEdr\\RedEdrPplRemover.exe");
wcscpy_s(childCMD, MAX_BUF_SIZE, L"C:\\RedEdr\\RedEdr.exe --pplstop");
WCHAR childCMD[PATH_LEN] = { 0 };
//wcscpy_s(childCMD, PATH_LEN, L"C:\\windows\\system32\\cmd.exe /c \"echo AAA > c:\\rededr\\aa\"");
//wcscpy_s(childCMD, PATH_LEN, L"C:\\RedEdr\\RedEdrPplRemover.exe");
wcscpy_s(childCMD, PATH_LEN, L"C:\\RedEdr\\RedEdr.exe --pplstop");
start_child_process(childCMD);
}
@@ -113,7 +113,6 @@ void rededr_remove_service() {
DWORD start_child_process(wchar_t* childCMD)
{
DWORD retval = 0;
DWORD dataSize = MAX_BUF_SIZE;
LOG_W(LOG_INFO, L"start_child_process: Starting");
// Create Attribute List
+4 -4
View File
@@ -97,7 +97,7 @@ void LOG_A(int verbosity, const char* format, ...)
va_list arg_ptr;
va_start(arg_ptr, format);
int ret = vsnprintf_s(&message[offset], DATA_BUFFER_SIZE - offset, MAX_BUF_SIZE - offset, format, arg_ptr);
int ret = vsnprintf_s(&message[offset], DATA_BUFFER_SIZE - offset, DATA_BUFFER_SIZE - offset, format, arg_ptr);
va_end(arg_ptr);
OutputDebugStringA(message);
@@ -133,7 +133,7 @@ void LOG_A(int verbosity, const char* format, ...)
va_list arg_ptr;
va_start(arg_ptr, format);
int ret = vsnprintf_s(&message[offset], DATA_BUFFER_SIZE - offset, MAX_BUF_SIZE - offset, format, arg_ptr);
int ret = vsnprintf_s(&message[offset], DATA_BUFFER_SIZE - offset, DATA_BUFFER_SIZE - offset, format, arg_ptr);
va_end(arg_ptr);
OutputDebugStringA(message);
@@ -174,7 +174,7 @@ void LOG_A(int verbosity, const char* format, ...)
va_list arg_ptr;
va_start(arg_ptr, format);
int ret = vsnprintf_s(&message[offset], DATA_BUFFER_SIZE - offset, MAX_BUF_SIZE - offset, format, arg_ptr);
int ret = vsnprintf_s(&message[offset], DATA_BUFFER_SIZE - offset, DATA_BUFFER_SIZE - offset, format, arg_ptr);
va_end(arg_ptr);
Microsoft::VisualStudio::CppUnitTestFramework::Logger::WriteMessage(message);
@@ -217,7 +217,7 @@ void LOG_A(int verbosity, const char* format, ...)
va_list arg_ptr;
va_start(arg_ptr, format);
int ret = vsnprintf_s(&message[offset], DATA_BUFFER_SIZE - offset, MAX_BUF_SIZE - offset, format, arg_ptr);
int ret = vsnprintf_s(&message[offset], DATA_BUFFER_SIZE - offset, DATA_BUFFER_SIZE - offset, format, arg_ptr);
va_end(arg_ptr);
printf("%s", message);
+3 -3
View File
@@ -4,7 +4,7 @@
#define COMMON_H
#define PIPE_BUFFER_SIZE 8192 // thats the pipe buffer (default 4096)
#define DATA_BUFFER_SIZE 4096 // events, most important
#define DATA_BUFFER_SIZE 8192 // events, most important
#define IOCTL_MY_IOCTL_CODE CTL_CODE(FILE_DEVICE_UNKNOWN, 0x800, METHOD_BUFFERED, FILE_ANY_ACCESS)
@@ -13,6 +13,7 @@
#define DLL_CONFIG_LEN 128 // for DLL pipe
#define PPL_CONFIG_LEN 128 // for PPL pipe
#define KRN_CONFIG_LEN 128 // for Kernel pipe
#define KRN_LOG_LEN 1024
typedef struct _MY_DRIVER_DATA {
wchar_t filename[TARGET_WSTR_LEN];
@@ -29,8 +30,7 @@ typedef struct _MY_DRIVER_DATA {
#define SERVICE_NAME L"RedEdrPplService"
#define DRIVER_NAME L"c:\\RedEdr\\elam_driver.sys"
#define MAX_BUF_SIZE 2048
#define MAX_CALLSTACK_ENTRIES 5
#define MAX_CALLSTACK_ENTRIES 8
#endif