small refactor

This commit is contained in:
S4ntiagoP
2024-06-15 11:47:56 -03:00
parent 894fffbcf4
commit f95ca6df4e
3 changed files with 29 additions and 20 deletions
+4
View File
@@ -1,5 +1,9 @@
#pragma once
BOOL string_is_included(
IN PCHAR list_of_strings,
IN PCHAR string_to_search);
BOOL find_pattern(
IN PVOID dwAddress,
IN ULONG32 dwLen,
+2 -20
View File
@@ -512,26 +512,8 @@ Cleanup:
BOOL IsExitAPI(
IN PCHAR name)
{
PCHAR str = NULL;
CHAR api[128] = { 0 };
INT i = 0;
str = "ExitProcess;exit;_exit;_cexit;_c_exit;quick_exit;_Exit;_o_exit;CorExitProcess\0";
for (;;)
{
// store string until null byte or semi-colon encountered
for (i = 0; str[i] != '\0' && str[i] != ';' && i < 128; i++) api[i] = str[i];
// nothing stored? end
if (i == 0) break;
// skip name plus one for separator
str += (i + 1);
// store null terminator
api[i] = '\0';
// if equal, return TRUE
if (!_stricmp(api, name)) return TRUE;
}
return FALSE;
PCHAR str = "ExitProcess;exit;_exit;_cexit;_c_exit;quick_exit;_Exit;_o_exit;CorExitProcess\0";
return string_is_included(str, name);
}
// returns TRUE if ptr is heap memory
+23
View File
@@ -1,5 +1,28 @@
#include "utils.h"
BOOL string_is_included(
IN PCHAR list_of_strings,
IN PCHAR string_to_search)
{
CHAR some_string[256] = { 0 };
INT i = 0;
for (;;)
{
// store string until null byte or semi-colon encountered
for (i = 0; list_of_strings[i] != '\0' && list_of_strings[i] != ';' && i < 256; i++) some_string[i] = list_of_strings[i];
// nothing stored? end
if (i == 0) break;
// skip name plus one for separator
list_of_strings += (i + 1);
// store null terminator
some_string[i] = '\0';
// if equal, return TRUE
if (!_stricmp(some_string, string_to_search)) return TRUE;
}
return FALSE;
}
BOOL compare_bytes(
IN PBYTE pData,
IN PBYTE bMask,