mirror of
https://github.com/fortra/No-Consolation
synced 2026-06-06 15:44:28 +00:00
small refactor
This commit is contained in:
@@ -1,5 +1,9 @@
|
||||
#pragma once
|
||||
|
||||
BOOL string_is_included(
|
||||
IN PCHAR list_of_strings,
|
||||
IN PCHAR string_to_search);
|
||||
|
||||
BOOL find_pattern(
|
||||
IN PVOID dwAddress,
|
||||
IN ULONG32 dwLen,
|
||||
|
||||
+2
-20
@@ -512,26 +512,8 @@ Cleanup:
|
||||
BOOL IsExitAPI(
|
||||
IN PCHAR name)
|
||||
{
|
||||
PCHAR str = NULL;
|
||||
CHAR api[128] = { 0 };
|
||||
INT i = 0;
|
||||
|
||||
str = "ExitProcess;exit;_exit;_cexit;_c_exit;quick_exit;_Exit;_o_exit;CorExitProcess\0";
|
||||
|
||||
for (;;)
|
||||
{
|
||||
// store string until null byte or semi-colon encountered
|
||||
for (i = 0; str[i] != '\0' && str[i] != ';' && i < 128; i++) api[i] = str[i];
|
||||
// nothing stored? end
|
||||
if (i == 0) break;
|
||||
// skip name plus one for separator
|
||||
str += (i + 1);
|
||||
// store null terminator
|
||||
api[i] = '\0';
|
||||
// if equal, return TRUE
|
||||
if (!_stricmp(api, name)) return TRUE;
|
||||
}
|
||||
return FALSE;
|
||||
PCHAR str = "ExitProcess;exit;_exit;_cexit;_c_exit;quick_exit;_Exit;_o_exit;CorExitProcess\0";
|
||||
return string_is_included(str, name);
|
||||
}
|
||||
|
||||
// returns TRUE if ptr is heap memory
|
||||
|
||||
@@ -1,5 +1,28 @@
|
||||
#include "utils.h"
|
||||
|
||||
BOOL string_is_included(
|
||||
IN PCHAR list_of_strings,
|
||||
IN PCHAR string_to_search)
|
||||
{
|
||||
CHAR some_string[256] = { 0 };
|
||||
INT i = 0;
|
||||
|
||||
for (;;)
|
||||
{
|
||||
// store string until null byte or semi-colon encountered
|
||||
for (i = 0; list_of_strings[i] != '\0' && list_of_strings[i] != ';' && i < 256; i++) some_string[i] = list_of_strings[i];
|
||||
// nothing stored? end
|
||||
if (i == 0) break;
|
||||
// skip name plus one for separator
|
||||
list_of_strings += (i + 1);
|
||||
// store null terminator
|
||||
some_string[i] = '\0';
|
||||
// if equal, return TRUE
|
||||
if (!_stricmp(some_string, string_to_search)) return TRUE;
|
||||
}
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
BOOL compare_bytes(
|
||||
IN PBYTE pData,
|
||||
IN PBYTE bMask,
|
||||
|
||||
Reference in New Issue
Block a user