From 5eccb8689500d4cd4bed7b7a03f417faeca70dcd Mon Sep 17 00:00:00 2001 From: wj32 Date: Fri, 17 Apr 2009 02:29:25 +0000 Subject: [PATCH] * reorganized KProcessHacker * added KphDuplicateObject git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1078 21ef857c-d57f-4fe0-8362-d861dc6d29cd --- trunk/KProcessHacker/{ => include}/debug.h | 0 trunk/KProcessHacker/include/ex.h | 68 ++++ .../{kph_nt.h => include/kph.h} | 102 ++--- .../{ => include}/kprocesshacker.h | 1 + trunk/KProcessHacker/include/mm.h | 122 ++++++ trunk/KProcessHacker/include/ob.h | 189 ++++++++++ .../{kernel_types.h => include/ps.h} | 352 ++++-------------- trunk/KProcessHacker/include/se.h | 51 +++ trunk/KProcessHacker/include/types.h | 6 + trunk/KProcessHacker/kph.c | 71 ++++ trunk/KProcessHacker/kprocesshacker.c | 47 ++- trunk/KProcessHacker/mm.c | 166 +++++++++ trunk/KProcessHacker/ob.c | 186 +++++++++ trunk/KProcessHacker/{kph_nt.c => ps.c} | 265 +------------ trunk/KProcessHacker/se.c | 87 +++++ trunk/KProcessHacker/sources | 6 +- 16 files changed, 1104 insertions(+), 615 deletions(-) rename trunk/KProcessHacker/{ => include}/debug.h (100%) create mode 100644 trunk/KProcessHacker/include/ex.h rename trunk/KProcessHacker/{kph_nt.h => include/kph.h} (63%) rename trunk/KProcessHacker/{ => include}/kprocesshacker.h (96%) create mode 100644 trunk/KProcessHacker/include/mm.h create mode 100644 trunk/KProcessHacker/include/ob.h rename trunk/KProcessHacker/{kernel_types.h => include/ps.h} (69%) create mode 100644 trunk/KProcessHacker/include/se.h create mode 100644 trunk/KProcessHacker/include/types.h create mode 100644 trunk/KProcessHacker/kph.c create mode 100644 trunk/KProcessHacker/mm.c create mode 100644 trunk/KProcessHacker/ob.c rename trunk/KProcessHacker/{kph_nt.c => ps.c} (61%) create mode 100644 trunk/KProcessHacker/se.c diff --git a/trunk/KProcessHacker/debug.h b/trunk/KProcessHacker/include/debug.h similarity index 100% rename from trunk/KProcessHacker/debug.h rename to trunk/KProcessHacker/include/debug.h diff --git a/trunk/KProcessHacker/include/ex.h b/trunk/KProcessHacker/include/ex.h new file mode 100644 index 000000000..dfb4c33ec --- /dev/null +++ b/trunk/KProcessHacker/include/ex.h @@ -0,0 +1,68 @@ +/* + * Process Hacker Driver - + * executive + * + * Copyright (C) 2009 wj32 + * + * This file is part of Process Hacker. + * + * Process Hacker is free software; you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * Process Hacker is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with Process Hacker. If not, see . + */ + +#ifndef _EX_H +#define _EX_H + +typedef struct _KGDTENTRY +{ + SHORT LimitLow; + SHORT BaseLow; + ULONG HighWord; +} KGDTENTRY, *PKGDTENTRY; + +typedef struct _KIDTENTRY +{ + SHORT Offset; + SHORT Selector; + SHORT Access; + SHORT ExtendedOffset; +} KIDTENTRY, *PKIDTENTRY; + +typedef struct _EX_FAST_REF +{ + union + { + PVOID Object; + ULONG RefCnt: 3; + ULONG Value; + }; +} EX_FAST_REF, *PEX_FAST_REF; + +typedef struct _EX_PUSH_LOCK2 +{ + union + { + struct + { + ULONG_PTR Locked:1; + ULONG_PTR Waiting:1; + ULONG_PTR Waking:1; + ULONG_PTR MultipleShared:1; + ULONG_PTR Shared: sizeof(ULONG_PTR) * 8 - 4; + }; + ULONG_PTR Value; + PVOID Ptr; + }; +} EX_PUSH_LOCK2, *PEX_PUSH_LOCK2; + +#endif \ No newline at end of file diff --git a/trunk/KProcessHacker/kph_nt.h b/trunk/KProcessHacker/include/kph.h similarity index 63% rename from trunk/KProcessHacker/kph_nt.h rename to trunk/KProcessHacker/include/kph.h index 3912a1591..bf7c0109d 100644 --- a/trunk/KProcessHacker/kph_nt.h +++ b/trunk/KProcessHacker/include/kph.h @@ -24,84 +24,43 @@ #define _KPH_NT_H #include "kprocesshacker.h" -#include "kernel_types.h" +#include "debug.h" +#include "mm.h" +#include "ps.h" -NTSTATUS NTAPI ObOpenObjectByName( - POBJECT_ATTRIBUTES ObjectAttributes, - POBJECT_TYPE ObjectType, - KPROCESSOR_MODE PreviousMode, - PACCESS_STATE AccessState, - ACCESS_MASK DesiredAccess, - PVOID ParseContext, - PHANDLE Handle - ); +extern int WindowsVersion; +extern ACCESS_MASK ProcessAllAccess; +extern ACCESS_MASK ThreadAllAccess; -NTSTATUS NTAPI PsGetContextThread( - PETHREAD Thread, - PCONTEXT ThreadContext, - KPROCESSOR_MODE PreviousMode - ); - -PVOID NTAPI PsGetThreadWin32Thread( - PETHREAD Thread - ); - -NTSTATUS NTAPI PsLookupProcessThreadByCid( - PCLIENT_ID ClientId, - PEPROCESS *Process, - PETHREAD *Thread - ); - -NTSTATUS NTAPI PsSetContextThread( - PETHREAD Thread, - PCONTEXT ThreadContext, - KPROCESSOR_MODE PreviousMode - ); - -NTKERNELAPI NTSTATUS NTAPI SeCreateAccessState( - PACCESS_STATE AccessState, - PAUX_ACCESS_DATA AuxData, - ACCESS_MASK DesiredAccess, - PGENERIC_MAPPING Mapping - ); - -NTKERNELAPI VOID NTAPI SeDeleteAccessState( - PACCESS_STATE AccessState - ); - -/* Dynamically linked API defs */ - -typedef NTSTATUS (NTAPI *_MmCopyVirtualMemory)( - PEPROCESS FromProcess, - PVOID FromAddress, - PEPROCESS ToProcess, - PVOID ToAddress, - ULONG BufferLength, - KPROCESSOR_MODE AccessMode, - PULONG ReturnLength - ); - -typedef PVOID (NTAPI *_PsGetProcessJob)( - PEPROCESS Process - ); - -typedef NTSTATUS (NTAPI *_PsResumeProcess)( - PEPROCESS Process - ); - -typedef NTSTATUS (NTAPI *_PsSuspendProcess)( - PEPROCESS Process - ); +extern _PsGetProcessJob PsGetProcessJob; +extern _PsSuspendProcess PsSuspendProcess; +extern _PsResumeProcess PsResumeProcess; +extern _MmCopyVirtualMemory MmCopyVirtualMemory; /* KProcessHacker */ NTSTATUS KphNtInit(); +PVOID GetSystemRoutineAddress( + WCHAR *Name + ); + NTSTATUS OpenProcess( PHANDLE ProcessHandle, int DesiredAccess, HANDLE ProcessId ); +NTSTATUS KphDuplicateObject( + HANDLE SourceProcessHandle, + HANDLE SourceHandle, + HANDLE TargetProcessHandle, + PHANDLE TargetHandle, + ACCESS_MASK DesiredAccess, + ULONG HandleAttributes, + ULONG Options, + KPROCESSOR_MODE AccessMode + ); + NTSTATUS KphGetContextThread( HANDLE ThreadHandle, PCONTEXT ThreadContext, @@ -182,4 +141,15 @@ NTSTATUS KphWriteVirtualMemory( KPROCESSOR_MODE AccessMode ); +NTSTATUS KphObDuplicateObject( + PEPROCESS SourceProcess, + PEPROCESS TargetProcess, + HANDLE SourceHandle, + PHANDLE TargetHandle, + ACCESS_MASK DesiredAccess, + ULONG HandleAttributes, + ULONG Options, + KPROCESSOR_MODE AccessMode + ); + #endif \ No newline at end of file diff --git a/trunk/KProcessHacker/kprocesshacker.h b/trunk/KProcessHacker/include/kprocesshacker.h similarity index 96% rename from trunk/KProcessHacker/kprocesshacker.h rename to trunk/KProcessHacker/include/kprocesshacker.h index d58a3d2fd..260497b0c 100644 --- a/trunk/KProcessHacker/kprocesshacker.h +++ b/trunk/KProcessHacker/include/kprocesshacker.h @@ -66,6 +66,7 @@ typedef struct _SYSTEM_HANDLE_INFORMATION #define KPH_GETCONTEXTTHREAD KPH_CTL_CODE(18) #define KPH_SETCONTEXTTHREAD KPH_CTL_CODE(19) #define KPH_GETTHREADWIN32THREAD KPH_CTL_CODE(20) +#define KPH_DUPLICATEOBJECT KPH_CTL_CODE(21) NTSTATUS KphCreate(PDEVICE_OBJECT DeviceObject, PIRP Irp); NTSTATUS KphClose(PDEVICE_OBJECT DeviceObject, PIRP Irp); diff --git a/trunk/KProcessHacker/include/mm.h b/trunk/KProcessHacker/include/mm.h new file mode 100644 index 000000000..2ee5d236c --- /dev/null +++ b/trunk/KProcessHacker/include/mm.h @@ -0,0 +1,122 @@ +/* + * Process Hacker Driver - + * memory manager + * + * Copyright (C) 2009 wj32 + * + * This file is part of Process Hacker. + * + * Process Hacker is free software; you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * Process Hacker is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with Process Hacker. If not, see . + */ + +#ifndef _MM_H +#define _MM_H + +/* FUNCTION TYPEDEFS */ + +typedef NTSTATUS (NTAPI *_MmCopyVirtualMemory)( + PEPROCESS FromProcess, + PVOID FromAddress, + PEPROCESS ToProcess, + PVOID ToAddress, + ULONG BufferLength, + KPROCESSOR_MODE AccessMode, + PULONG ReturnLength + ); + +/* STRUCTS */ +typedef struct _MMADDRESS_NODE +{ + ULONG u1; + struct _MMADDRESS_NODE *LeftChild; + struct _MMADDRESS_NODE *RightChild; + ULONG StartingVpn; + ULONG EndingVpn; +} MMADDRESS_NODE, *PMMADDRESS_NODE; + +typedef struct _MM_AVL_TABLE +{ + MMADDRESS_NODE BalancedRoot; + ULONG DepthOfTree: 5; + ULONG Unused: 3; + ULONG NumberGenericTableElements: 24; + PVOID NodeHint; + PVOID NodeFreeHint; +} MM_AVL_TABLE, *PMM_AVL_TABLE; + +typedef struct _HARDWARE_PTE +{ + union + { + ULONG Valid: 1; + ULONG Write: 1; + ULONG Owner: 1; + ULONG WriteThrough: 1; + ULONG CacheDisable: 1; + ULONG Accessed: 1; + ULONG Dirty: 1; + ULONG LargePage: 1; + ULONG Global: 1; + ULONG CopyOnWrite: 1; + ULONG Prototype: 1; + ULONG reserved0: 1; + ULONG PageFrameNumber: 26; + ULONG reserved1: 26; + ULONG LowPart; + }; + ULONG HighPart; +} HARDWARE_PTE, *PHARDWARE_PTE; + +typedef struct _MMSUPPORT_FLAGS +{ + ULONG SessionSpace: 1; + ULONG ModwriterAttached: 1; + ULONG TrimHard: 1; + ULONG MaximumWorkingSetHard: 1; + ULONG ForceTrim: 1; + ULONG MinimumWorkingSetHard: 1; + ULONG SessionMaster: 1; + ULONG TrimmerAttached: 1; + ULONG TrimmerDetaching: 1; + ULONG Reserved: 7; + ULONG MemoryPriority: 8; + ULONG WsleDeleted: 1; + ULONG VmExiting: 1; + ULONG Available: 6; +} MMSUPPORT_FLAGS, *PMMSUPPORT_FLAGS; + +typedef struct _MMSUPPORT +{ + LIST_ENTRY WorkingSetExpansionLinks; + SHORT LastTrimStamp; + SHORT NextPageColor; + MMSUPPORT_FLAGS Flags; + ULONG PageFaultCount; + ULONG PeakWorkingSetSize; + ULONG Spare0; + ULONG MinimumWorkingSetSize; + ULONG MaximumWorkingSetSize; + /* PMMWSL VmWorkingSetList; */ + PVOID VmWorkingSetList; + ULONG Claim; + ULONG Spare[1]; + ULONG WorkingSetPrivateSize; + ULONG WorkingSetSizeOverhead; + ULONG WorkingSetSize; + PKEVENT ExitEvent; + EX_PUSH_LOCK WorkingSetMutex; + PVOID AccessLog; +} MMSUPPORT, *PMMSUPPORT; + +#endif \ No newline at end of file diff --git a/trunk/KProcessHacker/include/ob.h b/trunk/KProcessHacker/include/ob.h new file mode 100644 index 000000000..91b3387ad --- /dev/null +++ b/trunk/KProcessHacker/include/ob.h @@ -0,0 +1,189 @@ +/* + * Process Hacker Driver - + * object manager + * + * Copyright (C) 2009 wj32 + * + * This file is part of Process Hacker. + * + * Process Hacker is free software; you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * Process Hacker is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with Process Hacker. If not, see . + */ + +#ifndef _OB_H +#define _OB_H + +#include "ex.h" + +#define OBJECT_TO_OBJECT_HEADER(o) \ + CONTAINING_RECORD((o), OBJECT_HEADER, Body) + +/* FUNCTION DEFS */ + +NTSTATUS NTAPI ObOpenObjectByName( + POBJECT_ATTRIBUTES ObjectAttributes, + POBJECT_TYPE ObjectType, + KPROCESSOR_MODE PreviousMode, + PACCESS_STATE AccessState, + ACCESS_MASK DesiredAccess, + PVOID ParseContext, + PHANDLE Handle + ); + +/* STRUCTS */ + +typedef struct _OBJECT_CREATE_INFORMATION +{ + ULONG Attributes; + PVOID RootDirectory; + PVOID ParseContext; + CHAR ProbeMode; + ULONG PagedPoolCharge; + ULONG NonPagedPoolCharge; + ULONG SecurityDescriptorCharge; + PVOID SecurityDescriptor; + PSECURITY_QUALITY_OF_SERVICE SecurityQos; + SECURITY_QUALITY_OF_SERVICE SecurityQualityOfService; +} OBJECT_CREATE_INFORMATION, *POBJECT_CREATE_INFORMATION; + +typedef struct _OBJECT_HEADER +{ + union + { + struct + { + LONG PointerCount; + LONG HandleCount; + }; + LIST_ENTRY Entry; + }; + POBJECT_TYPE Type; + UCHAR NameInfoOffset; + UCHAR HandleInfoOffset; + UCHAR QuotaInfoOffset; + UCHAR Flags; + union + { + POBJECT_CREATE_INFORMATION ObjectCreateInfo; + PVOID QuotaBlockCharged; + }; + PVOID SecurityDescriptor; + QUAD Body; +} OBJECT_HEADER, *POBJECT_HEADER; + +typedef struct _OBJECT_TYPE_INITIALIZER +{ + USHORT Length; + UCHAR ObjectTypeFlags; + ULONG CaseInsensitive: 1; + ULONG UnnamedObjectsOnly: 1; + ULONG UseDefaultObject: 1; + ULONG SecurityRequired: 1; + ULONG MaintainHandleCount: 1; + ULONG MaintainTypeList: 1; + ULONG ObjectTypeCode; + ULONG InvalidAttributes; + GENERIC_MAPPING GenericMapping; + ULONG ValidAccessMask; + POOL_TYPE PoolType; + ULONG DefaultPagedPoolCharge; + ULONG DefaultNonPagedPoolCharge; + PVOID DumpProcedure; + PVOID OpenProcedure; + PVOID CloseProcedure; + PVOID DeleteProcedure; + PVOID ParseProcedure; + PVOID SecurityProcedure; + PVOID QueryNameProcedure; + PVOID OkayToCloseProcedure; +} OBJECT_TYPE_INITIALIZER, *POBJECT_TYPE_INITIALIZER; + +typedef struct _OBJECT_TYPE +{ + ERESOURCE Mutex; + LIST_ENTRY TypeList; + UNICODE_STRING Name; + PVOID DefaultObject; + ULONG Index; + ULONG TotalNumberOfObjects; + ULONG TotalNumberOfHandles; + ULONG HighWaterNumberOfObjects; + ULONG HighWaterNumberOfHandles; + OBJECT_TYPE_INITIALIZER TypeInfo; + ULONG Key; + EX_PUSH_LOCK ObjectLocks[32]; +} OBJECT_TYPE; + +typedef struct _HANDLE_TRACE_DB_ENTRY +{ + CLIENT_ID ClientId; + PVOID Handle; + ULONG Type; + VOID *StackTrace[16]; +} HANDLE_TRACE_DB_ENTRY, *PHANDLE_TRACE_DB_ENTRY; + +typedef struct _HANDLE_TRACE_DEBUG_INFO +{ + LONG RefCount; + ULONG TableSize; + ULONG BitMaskFlags; + FAST_MUTEX CloseCompactionLock; + ULONG CurrentStackIndex; + HANDLE_TRACE_DB_ENTRY TraceDb[1]; +} HANDLE_TRACE_DEBUG_INFO, *PHANDLE_TRACE_DEBUG_INFO; + +typedef struct _HANDLE_TABLE_ENTRY_INFO +{ + ULONG AuditMask; +} HANDLE_TABLE_ENTRY_INFO, *PHANDLE_TABLE_ENTRY_INFO; + +typedef struct _HANDLE_TABLE_ENTRY +{ + union + { + PVOID Object; + ULONG ObAttributes; + PHANDLE_TABLE_ENTRY_INFO InfoTable; + ULONG Value; + }; + union + { + ULONG GrantedAccess; + struct + { + SHORT GrantedAccessIndex; + SHORT CreatorBackTraceIndex; + }; + LONG NextFreeTableEntry; + }; +} HANDLE_TABLE_ENTRY, *PHANDLE_TABLE_ENTRY; + +typedef struct _HANDLE_TABLE +{ + ULONG TableCode; + PEPROCESS QuotaProcess; + PVOID UniqueProcessId; + EX_PUSH_LOCK HandleLock; + LIST_ENTRY HandleTableList; + EX_PUSH_LOCK HandleContentionEvent; + PHANDLE_TRACE_DEBUG_INFO DebugInfo; + LONG ExtraInfoPages; + ULONG Flags; + ULONG StrictFIFO: 1; + LONG FirstFreeHandle; + PHANDLE_TABLE_ENTRY LastFreeHandleEntry; + LONG HandleCount; + ULONG NextHandleNeedingPool; +} HANDLE_TABLE, *PHANDLE_TABLE; + +#endif diff --git a/trunk/KProcessHacker/kernel_types.h b/trunk/KProcessHacker/include/ps.h similarity index 69% rename from trunk/KProcessHacker/kernel_types.h rename to trunk/KProcessHacker/include/ps.h index 2ab69856a..15b88ea97 100644 --- a/trunk/KProcessHacker/kernel_types.h +++ b/trunk/KProcessHacker/include/ps.h @@ -1,22 +1,75 @@ -#ifndef _KERNEL_TYPES_H -#define _KERNEL_TYPES_H +/* + * Process Hacker Driver - + * processes and threads + * + * Copyright (C) 2009 wj32 + * + * This file is part of Process Hacker. + * + * Process Hacker is free software; you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * Process Hacker is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with Process Hacker. If not, see . + */ -#include +#ifndef _PS_H +#define _PS_H -typedef struct _KGDTENTRY -{ - SHORT LimitLow; - SHORT BaseLow; - ULONG HighWord; -} KGDTENTRY, *PKGDTENTRY; +#include "types.h" +#include "ex.h" +#include "mm.h" +#include "ob.h" +#include "se.h" -typedef struct _KIDTENTRY -{ - SHORT Offset; - SHORT Selector; - SHORT Access; - SHORT ExtendedOffset; -} KIDTENTRY, *PKIDTENTRY; +extern POBJECT_TYPE *PsJobType; + +/* FUNCTION DEFS */ + +NTSTATUS NTAPI PsGetContextThread( + PETHREAD Thread, + PCONTEXT ThreadContext, + KPROCESSOR_MODE PreviousMode + ); + +PVOID NTAPI PsGetThreadWin32Thread( + PETHREAD Thread + ); + +NTSTATUS NTAPI PsLookupProcessThreadByCid( + PCLIENT_ID ClientId, + PEPROCESS *Process, + PETHREAD *Thread + ); + +NTSTATUS NTAPI PsSetContextThread( + PETHREAD Thread, + PCONTEXT ThreadContext, + KPROCESSOR_MODE PreviousMode + ); + +/* FUNCTION TYPEDEFS */ + +typedef PVOID (NTAPI *_PsGetProcessJob)( + PEPROCESS Process + ); + +typedef NTSTATUS (NTAPI *_PsResumeProcess)( + PEPROCESS Process + ); + +typedef NTSTATUS (NTAPI *_PsSuspendProcess)( + PEPROCESS Process + ); + +/* STRUCTS */ typedef struct _KEXECUTE_OPTIONS { @@ -29,69 +82,6 @@ typedef struct _KEXECUTE_OPTIONS ULONG Spare: 2; } KEXECUTE_OPTIONS, *PKEXECUTE_OPTIONS; -typedef struct _HANDLE_TRACE_DB_ENTRY -{ - CLIENT_ID ClientId; - PVOID Handle; - ULONG Type; - VOID *StackTrace[16]; -} HANDLE_TRACE_DB_ENTRY, *PHANDLE_TRACE_DB_ENTRY; - -typedef struct _HANDLE_TRACE_DEBUG_INFO -{ - LONG RefCount; - ULONG TableSize; - ULONG BitMaskFlags; - FAST_MUTEX CloseCompactionLock; - ULONG CurrentStackIndex; - HANDLE_TRACE_DB_ENTRY TraceDb[1]; -} HANDLE_TRACE_DEBUG_INFO, *PHANDLE_TRACE_DEBUG_INFO; - -typedef struct _HANDLE_TABLE_ENTRY_INFO -{ - ULONG AuditMask; -} HANDLE_TABLE_ENTRY_INFO, *PHANDLE_TABLE_ENTRY_INFO; - -typedef struct _HANDLE_TABLE_ENTRY -{ - union - { - PVOID Object; - ULONG ObAttributes; - PHANDLE_TABLE_ENTRY_INFO InfoTable; - ULONG Value; - }; - union - { - ULONG GrantedAccess; - struct - { - SHORT GrantedAccessIndex; - SHORT CreatorBackTraceIndex; - }; - LONG NextFreeTableEntry; - }; -} HANDLE_TABLE_ENTRY, *PHANDLE_TABLE_ENTRY; - -typedef struct _HANDLE_TABLE -{ - ULONG TableCode; - PEPROCESS QuotaProcess; - PVOID UniqueProcessId; - EX_PUSH_LOCK HandleLock; - LIST_ENTRY HandleTableList; - EX_PUSH_LOCK HandleContentionEvent; - PHANDLE_TRACE_DEBUG_INFO DebugInfo; - LONG ExtraInfoPages; - ULONG Flags; - ULONG StrictFIFO: 1; - LONG FirstFreeHandle; - PHANDLE_TABLE_ENTRY LastFreeHandleEntry; - LONG HandleCount; - ULONG NextHandleNeedingPool; -} HANDLE_TABLE, *PHANDLE_TABLE; - -/* from ReactOS */ typedef struct _KPROCESS2 { DISPATCHER_HEADER Header; @@ -146,104 +136,6 @@ typedef struct _KPROCESS2 ULONGLONG CycleTime; } KPROCESS2, *PKPROCESS2; -typedef struct _EX_FAST_REF -{ - union - { - PVOID Object; - ULONG RefCnt: 3; - ULONG Value; - }; -} EX_FAST_REF, *PEX_FAST_REF; - -typedef struct _MMADDRESS_NODE -{ - ULONG u1; - struct _MMADDRESS_NODE *LeftChild; - struct _MMADDRESS_NODE *RightChild; - ULONG StartingVpn; - ULONG EndingVpn; -} MMADDRESS_NODE, *PMMADDRESS_NODE; - -typedef struct _MM_AVL_TABLE -{ - MMADDRESS_NODE BalancedRoot; - ULONG DepthOfTree: 5; - ULONG Unused: 3; - ULONG NumberGenericTableElements: 24; - PVOID NodeHint; - PVOID NodeFreeHint; -} MM_AVL_TABLE, *PMM_AVL_TABLE; - -typedef struct _HARDWARE_PTE -{ - union - { - ULONG Valid: 1; - ULONG Write: 1; - ULONG Owner: 1; - ULONG WriteThrough: 1; - ULONG CacheDisable: 1; - ULONG Accessed: 1; - ULONG Dirty: 1; - ULONG LargePage: 1; - ULONG Global: 1; - ULONG CopyOnWrite: 1; - ULONG Prototype: 1; - ULONG reserved0: 1; - ULONG PageFrameNumber: 26; - ULONG reserved1: 26; - ULONG LowPart; - }; - ULONG HighPart; -} HARDWARE_PTE, *PHARDWARE_PTE; - -typedef struct _SE_AUDIT_PROCESS_CREATION_INFO -{ - POBJECT_NAME_INFORMATION ImageFileName; -} SE_AUDIT_PROCESS_CREATION_INFO, *PSE_AUDIT_PROCESS_CREATION_INFO; - -typedef struct _MMSUPPORT_FLAGS -{ - ULONG SessionSpace: 1; - ULONG ModwriterAttached: 1; - ULONG TrimHard: 1; - ULONG MaximumWorkingSetHard: 1; - ULONG ForceTrim: 1; - ULONG MinimumWorkingSetHard: 1; - ULONG SessionMaster: 1; - ULONG TrimmerAttached: 1; - ULONG TrimmerDetaching: 1; - ULONG Reserved: 7; - ULONG MemoryPriority: 8; - ULONG WsleDeleted: 1; - ULONG VmExiting: 1; - ULONG Available: 6; -} MMSUPPORT_FLAGS, *PMMSUPPORT_FLAGS; - -typedef struct _MMSUPPORT -{ - LIST_ENTRY WorkingSetExpansionLinks; - SHORT LastTrimStamp; - SHORT NextPageColor; - MMSUPPORT_FLAGS Flags; - ULONG PageFaultCount; - ULONG PeakWorkingSetSize; - ULONG Spare0; - ULONG MinimumWorkingSetSize; - ULONG MaximumWorkingSetSize; - /* PMMWSL VmWorkingSetList; */ - PVOID VmWorkingSetList; - ULONG Claim; - ULONG Spare[1]; - ULONG WorkingSetPrivateSize; - ULONG WorkingSetSizeOverhead; - ULONG WorkingSetSize; - PKEVENT ExitEvent; - EX_PUSH_LOCK WorkingSetMutex; - PVOID AccessLog; -} MMSUPPORT, *PMMSUPPORT; - typedef struct _PEB2 { UCHAR InheritedAddressSpace; @@ -506,49 +398,6 @@ typedef struct _EPROCESS2 ALPC_PROCESS_CONTEXT AlpcContext; } EPROCESS2, *PEPROCESS2; -typedef struct _OBJECT_TYPE_INITIALIZER -{ - USHORT Length; - UCHAR ObjectTypeFlags; - ULONG CaseInsensitive: 1; - ULONG UnnamedObjectsOnly: 1; - ULONG UseDefaultObject: 1; - ULONG SecurityRequired: 1; - ULONG MaintainHandleCount: 1; - ULONG MaintainTypeList: 1; - ULONG ObjectTypeCode; - ULONG InvalidAttributes; - GENERIC_MAPPING GenericMapping; - ULONG ValidAccessMask; - POOL_TYPE PoolType; - ULONG DefaultPagedPoolCharge; - ULONG DefaultNonPagedPoolCharge; - PVOID DumpProcedure; - PVOID OpenProcedure; - PVOID CloseProcedure; - PVOID DeleteProcedure; - PVOID ParseProcedure; - PVOID SecurityProcedure; - PVOID QueryNameProcedure; - PVOID OkayToCloseProcedure; -} OBJECT_TYPE_INITIALIZER, *POBJECT_TYPE_INITIALIZER; - -typedef struct _OBJECT_TYPE -{ - ERESOURCE Mutex; - LIST_ENTRY TypeList; - UNICODE_STRING Name; - PVOID DefaultObject; - ULONG Index; - ULONG TotalNumberOfObjects; - ULONG TotalNumberOfHandles; - ULONG HighWaterNumberOfObjects; - ULONG HighWaterNumberOfHandles; - OBJECT_TYPE_INITIALIZER TypeInfo; - ULONG Key; - EX_PUSH_LOCK ObjectLocks[32]; -} OBJECT_TYPE; - typedef struct _EXCEPTION_REGISTRATION_RECORD { struct _EXCEPTION_REGISTRATION_RECORD *Next; @@ -899,65 +748,4 @@ typedef struct _ETHREAD2 ULONG CacheManagerCount; } ETHREAD2, *PETHREAD2; -typedef struct _EX_PUSH_LOCK2 -{ - union - { - struct - { - ULONG_PTR Locked:1; - ULONG_PTR Waiting:1; - ULONG_PTR Waking:1; - ULONG_PTR MultipleShared:1; - ULONG_PTR Shared: sizeof(ULONG_PTR) * 8 - 4; - }; - ULONG_PTR Value; - PVOID Ptr; - }; -} EX_PUSH_LOCK2, *PEX_PUSH_LOCK2; - -typedef struct _OBJECT_CREATE_INFORMATION -{ - ULONG Attributes; - PVOID RootDirectory; - PVOID ParseContext; - CHAR ProbeMode; - ULONG PagedPoolCharge; - ULONG NonPagedPoolCharge; - ULONG SecurityDescriptorCharge; - PVOID SecurityDescriptor; - PSECURITY_QUALITY_OF_SERVICE SecurityQos; - SECURITY_QUALITY_OF_SERVICE SecurityQualityOfService; -} OBJECT_CREATE_INFORMATION, *POBJECT_CREATE_INFORMATION; - -typedef struct _OBJECT_HEADER -{ - LONG PointerCount; - union - { - LONG HandleCount; - PVOID NextToFree; - }; - POBJECT_TYPE Type; - UCHAR NameInfoOffset; - UCHAR HandleInfoOffset; - UCHAR QuotaInfoOffset; - UCHAR Flags; - union - { - POBJECT_CREATE_INFORMATION ObjectCreateInfo; - PVOID QuotaBlockCharged; - }; - PVOID SecurityDescriptor; - QUAD Body; -} OBJECT_HEADER, *POBJECT_HEADER; - -typedef struct _AUX_ACCESS_DATA -{ - /* PPRIVILEGE_SET PrivilegeSet; */ - PVOID PrivilegeSet; - GENERIC_MAPPING GenericMapping; - ULONG Reserved; -} AUX_ACCESS_DATA, *PAUX_ACCESS_DATA; - -#endif +#endif \ No newline at end of file diff --git a/trunk/KProcessHacker/include/se.h b/trunk/KProcessHacker/include/se.h new file mode 100644 index 000000000..df3135147 --- /dev/null +++ b/trunk/KProcessHacker/include/se.h @@ -0,0 +1,51 @@ +/* + * Process Hacker Driver - + * memory manager + * + * Copyright (C) 2009 wj32 + * + * This file is part of Process Hacker. + * + * Process Hacker is free software; you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * Process Hacker is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with Process Hacker. If not, see . + */ + +#ifndef _SE_H +#define _SE_H + +#include "types.h" + +extern POBJECT_TYPE *SeTokenObjectType; + +typedef PVOID PAUX_ACCESS_DATA; + +/* FUNCTION DEFS */ +NTKERNELAPI NTSTATUS NTAPI SeCreateAccessState( + PACCESS_STATE AccessState, + PAUX_ACCESS_DATA AuxData, + ACCESS_MASK DesiredAccess, + PGENERIC_MAPPING Mapping + ); + +NTKERNELAPI VOID NTAPI SeDeleteAccessState( + PACCESS_STATE AccessState + ); + +/* STRUCTS */ + +typedef struct _SE_AUDIT_PROCESS_CREATION_INFO +{ + POBJECT_NAME_INFORMATION ImageFileName; +} SE_AUDIT_PROCESS_CREATION_INFO, *PSE_AUDIT_PROCESS_CREATION_INFO; + +#endif \ No newline at end of file diff --git a/trunk/KProcessHacker/include/types.h b/trunk/KProcessHacker/include/types.h new file mode 100644 index 000000000..31aa13df3 --- /dev/null +++ b/trunk/KProcessHacker/include/types.h @@ -0,0 +1,6 @@ +#ifndef _TYPES_H +#define _TYPES_H + +#include + +#endif diff --git a/trunk/KProcessHacker/kph.c b/trunk/KProcessHacker/kph.c new file mode 100644 index 000000000..a13a8ed65 --- /dev/null +++ b/trunk/KProcessHacker/kph.c @@ -0,0 +1,71 @@ +/* + * Process Hacker Driver - + * custom APIs + * + * Copyright (C) 2009 wj32 + * + * This file is part of Process Hacker. + * + * Process Hacker is free software; you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * Process Hacker is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with Process Hacker. If not, see . + */ + +#include "include/kph.h" + +_PsGetProcessJob PsGetProcessJob = NULL; +_PsSuspendProcess PsSuspendProcess = NULL; +_PsResumeProcess PsResumeProcess = NULL; +_MmCopyVirtualMemory MmCopyVirtualMemory = NULL; + +PVOID GetSystemRoutineAddress(WCHAR *Name) +{ + UNICODE_STRING routineName; + PVOID routineAddress = NULL; + + RtlInitUnicodeString(&routineName, Name); + + __try + { + routineAddress = MmGetSystemRoutineAddress(&routineName); + } + __except (EXCEPTION_EXECUTE_HANDLER) + { + routineAddress = NULL; + } + + return routineAddress; +} + +NTSTATUS KphNtInit() +{ + NTSTATUS status = STATUS_SUCCESS; + + MmCopyVirtualMemory = GetSystemRoutineAddress(L"MmCopyVirtualMemory"); + PsGetProcessJob = GetSystemRoutineAddress(L"PsGetProcessJob"); + PsResumeProcess = GetSystemRoutineAddress(L"PsResumeProcess"); + PsSuspendProcess = GetSystemRoutineAddress(L"PsSuspendProcess"); + + return status; +} + +NTSTATUS OpenProcess(PHANDLE ProcessHandle, int DesiredAccess, HANDLE ProcessId) +{ + OBJECT_ATTRIBUTES objAttr = { 0 }; + CLIENT_ID clientId; + + objAttr.Length = sizeof(objAttr); + clientId.UniqueThread = 0; + clientId.UniqueProcess = (HANDLE)ProcessId; + + return KphOpenProcess(ProcessHandle, DesiredAccess, &objAttr, &clientId, KernelMode); +} diff --git a/trunk/KProcessHacker/kprocesshacker.c b/trunk/KProcessHacker/kprocesshacker.c index c891b78d2..06d7a5d2b 100644 --- a/trunk/KProcessHacker/kprocesshacker.c +++ b/trunk/KProcessHacker/kprocesshacker.c @@ -20,10 +20,10 @@ * along with Process Hacker. If not, see . */ -#include "kprocesshacker.h" -#include "kph_nt.h" -#include "kernel_types.h" -#include "debug.h" +#include "include/kprocesshacker.h" +#include "include/kph.h" +#include "include/ps.h" +#include "include/debug.h" #define ALLOW_UNLOAD @@ -288,6 +288,8 @@ char *GetIoControlName(ULONG ControlCode) return "KphSetContextThread"; else if (ControlCode == KPH_GETTHREADWIN32THREAD) return "KphGetThreadWin32Thread"; + else if (ControlCode == KPH_DUPLICATEOBJECT) + return "KphDuplicateObject"; else return "Unknown"; } @@ -867,6 +869,43 @@ NTSTATUS KphIoControl(PDEVICE_OBJECT DeviceObject, PIRP Irp) } break; + case KPH_DUPLICATEOBJECT: + { + HANDLE sourceProcessHandle; + HANDLE sourceHandle; + HANDLE targetProcessHandle; + PHANDLE targetHandle; + ACCESS_MASK desiredAccess; + ULONG handleAttributes; + ULONG options; + + if (inLength < 7 * 4) + { + status = STATUS_BUFFER_TOO_SMALL; + goto IoControlEnd; + } + + sourceProcessHandle = *(HANDLE *)dataBuffer; + sourceHandle = *(HANDLE *)(dataBuffer + 0x4); + targetProcessHandle = *(HANDLE *)(dataBuffer + 0x8); + targetHandle = *(PHANDLE *)(dataBuffer + 0xc); + desiredAccess = *(ACCESS_MASK *)(dataBuffer + 0x10); + handleAttributes = *(ULONG *)(dataBuffer + 0x14); + options = *(ULONG *)(dataBuffer + 0x18); + + status = KphDuplicateObject( + sourceProcessHandle, + sourceHandle, + targetProcessHandle, + targetHandle, + desiredAccess, + handleAttributes, + options, + UserMode + ); + } + break; + default: { dprintf("KProcessHacker: unrecognized IOCTL code 0x%08x\n", controlCode); diff --git a/trunk/KProcessHacker/mm.c b/trunk/KProcessHacker/mm.c new file mode 100644 index 000000000..9b1333711 --- /dev/null +++ b/trunk/KProcessHacker/mm.c @@ -0,0 +1,166 @@ +/* + * Process Hacker Driver - + * memory manager + * + * Copyright (C) 2009 wj32 + * + * This file is part of Process Hacker. + * + * Process Hacker is free software; you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * Process Hacker is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with Process Hacker. If not, see . + */ + +#include "include/kph.h" +#include "include/mm.h" + +NTSTATUS KphReadVirtualMemory( + HANDLE ProcessHandle, + PVOID BaseAddress, + PVOID Buffer, + ULONG BufferLength, + PULONG ReturnLength, + KPROCESSOR_MODE AccessMode + ) +{ + NTSTATUS status = STATUS_SUCCESS; + PEPROCESS processObject; + ULONG returnLength = 0; + + if (MmCopyVirtualMemory == NULL) + return STATUS_NOT_SUPPORTED; + + if (AccessMode != KernelMode) + { + if ((((ULONG_PTR)BaseAddress + BufferLength) < (ULONG_PTR)BaseAddress) || + (((ULONG_PTR)Buffer + BufferLength) < (ULONG_PTR)Buffer) || + (((ULONG_PTR)BaseAddress + BufferLength) > MmUserProbeAddress) || + (((ULONG_PTR)Buffer + BufferLength) > MmUserProbeAddress)) + { + return STATUS_ACCESS_VIOLATION; + } + + __try + { + if (ReturnLength) + ProbeForWrite(ReturnLength, sizeof(ULONG), 1); + } + __except (EXCEPTION_EXECUTE_HANDLER) + { + return STATUS_ACCESS_VIOLATION; + } + } + + if (BufferLength) + { + status = ObReferenceObjectByHandle(ProcessHandle, 0, *PsProcessType, KernelMode, &processObject, NULL); + + if (!NT_SUCCESS(status)) + return status; + + status = MmCopyVirtualMemory( + processObject, + BaseAddress, + PsGetCurrentProcess(), + Buffer, + BufferLength, + AccessMode, + &returnLength + ); + ObDereferenceObject(processObject); + } + + if (ReturnLength) + { + __try + { + *ReturnLength = returnLength; + } + __except (EXCEPTION_EXECUTE_HANDLER) + { + status = STATUS_ACCESS_VIOLATION; + } + } + + return status; +} + +NTSTATUS KphWriteVirtualMemory( + HANDLE ProcessHandle, + PVOID BaseAddress, + PVOID Buffer, + ULONG BufferLength, + PULONG ReturnLength, + KPROCESSOR_MODE AccessMode + ) +{ + NTSTATUS status = STATUS_SUCCESS; + PEPROCESS processObject; + ULONG returnLength = 0; + + if (MmCopyVirtualMemory == NULL) + return STATUS_NOT_SUPPORTED; + + if (AccessMode != KernelMode) + { + if ((((ULONG_PTR)BaseAddress + BufferLength) < (ULONG_PTR)BaseAddress) || + (((ULONG_PTR)Buffer + BufferLength) < (ULONG_PTR)Buffer) || + (((ULONG_PTR)BaseAddress + BufferLength) > MmUserProbeAddress) || + (((ULONG_PTR)Buffer + BufferLength) > MmUserProbeAddress)) + { + return STATUS_ACCESS_VIOLATION; + } + + __try + { + if (ReturnLength) + ProbeForWrite(ReturnLength, sizeof(ULONG), 1); + } + __except (EXCEPTION_EXECUTE_HANDLER) + { + return STATUS_ACCESS_VIOLATION; + } + } + + if (BufferLength) + { + status = ObReferenceObjectByHandle(ProcessHandle, 0, *PsProcessType, KernelMode, &processObject, NULL); + + if (!NT_SUCCESS(status)) + return status; + + status = MmCopyVirtualMemory( + PsGetCurrentProcess(), + Buffer, + processObject, + BaseAddress, + BufferLength, + AccessMode, + &returnLength + ); + ObDereferenceObject(processObject); + } + + if (ReturnLength) + { + __try + { + *ReturnLength = returnLength; + } + __except (EXCEPTION_EXECUTE_HANDLER) + { + status = STATUS_ACCESS_VIOLATION; + } + } + + return status; +} diff --git a/trunk/KProcessHacker/ob.c b/trunk/KProcessHacker/ob.c new file mode 100644 index 000000000..4fdc69ad4 --- /dev/null +++ b/trunk/KProcessHacker/ob.c @@ -0,0 +1,186 @@ +/* + * Process Hacker Driver - + * object manager + * + * Copyright (C) 2009 wj32 + * + * This file is part of Process Hacker. + * + * Process Hacker is free software; you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * Process Hacker is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with Process Hacker. If not, see . + */ + +#include "include/kph.h" +#include "include/ob.h" + +NTSTATUS KphDuplicateObject( + HANDLE SourceProcessHandle, + HANDLE SourceHandle, + HANDLE TargetProcessHandle, + PHANDLE TargetHandle, + ACCESS_MASK DesiredAccess, + ULONG HandleAttributes, + ULONG Options, + KPROCESSOR_MODE AccessMode + ) +{ + NTSTATUS status = STATUS_SUCCESS; + PEPROCESS sourceProcess = NULL; + PEPROCESS targetProcess = NULL; + HANDLE targetHandle; + + if (TargetHandle && AccessMode != KernelMode) + { + __try + { + ProbeForWrite(TargetHandle, sizeof(HANDLE), 1); + *TargetHandle = NULL; + } + __except (EXCEPTION_EXECUTE_HANDLER) + { + return STATUS_ACCESS_VIOLATION; + } + } + + status = ObReferenceObjectByHandle( + SourceProcessHandle, + PROCESS_DUP_HANDLE, + *PsProcessType, + KernelMode, + &sourceProcess, + NULL + ); + + if (!NT_SUCCESS(status)) + return status; + + /* Target handle is optional */ + if (TargetProcessHandle) + { + status = ObReferenceObjectByHandle( + TargetProcessHandle, + PROCESS_DUP_HANDLE, + *PsProcessType, + KernelMode, + &targetProcess, + NULL + ); + + if (!NT_SUCCESS(status)) + return status; + } + + /* Call the internal function */ + status = KphObDuplicateObject( + sourceProcess, + targetProcess, + SourceHandle, + &targetHandle, + DesiredAccess, + HandleAttributes, + Options, + AccessMode + ); + + if (TargetHandle) + { + __try + { + *TargetHandle = targetHandle; + } + __except (EXCEPTION_EXECUTE_HANDLER) + { + status = STATUS_ACCESS_VIOLATION; + } + } + + ObDereferenceObject(sourceProcess); + if (targetProcess) + ObDereferenceObject(targetProcess); + + return status; +} + +NTSTATUS KphObDuplicateObject( + PEPROCESS SourceProcess, + PEPROCESS TargetProcess, + HANDLE SourceHandle, + PHANDLE TargetHandle, + ACCESS_MASK DesiredAccess, + ULONG HandleAttributes, + ULONG Options, + KPROCESSOR_MODE AccessMode + ) +{ + NTSTATUS status = STATUS_SUCCESS; + KAPC_STATE apcState; + PVOID object; + HANDLE objectHandle; + + /* Validate the parameters */ + if (!TargetProcess || !TargetHandle) + { + if (!(Options & DUPLICATE_CLOSE_SOURCE)) + return STATUS_INVALID_PARAMETER; + } + + /* Check if we need to attach to the source process */ + if (SourceProcess != PsGetCurrentProcess()) + KeStackAttachProcess(SourceProcess, &apcState); + + /* If the caller wants us to close the source handle, do it now */ + if (Options & DUPLICATE_CLOSE_SOURCE) + { + status = NtClose(SourceHandle); + KeUnstackDetachProcess(&apcState); + + return status; + } + + /* Reference the object and detach from the source process */ + status = ObReferenceObjectByHandle( + SourceHandle, + 0, + NULL, + KernelMode, + &object, + NULL + ); + KeUnstackDetachProcess(&apcState); + + if (!NT_SUCCESS(status)) + return status; + + /* Check if we need to attach to the target process */ + if (TargetProcess != PsGetCurrentProcess()) + KeStackAttachProcess(TargetProcess, &apcState); + + /* Open the object and detach from the target process */ + status = ObOpenObjectByPointer( + object, + HandleAttributes, + NULL, + DesiredAccess, + OBJECT_TO_OBJECT_HEADER(object)->Type, + AccessMode, + &objectHandle + ); + KeUnstackDetachProcess(&apcState); + + if (NT_SUCCESS(status)) + *TargetHandle = objectHandle; + else + *TargetHandle = 0; + + return status; +} diff --git a/trunk/KProcessHacker/kph_nt.c b/trunk/KProcessHacker/ps.c similarity index 61% rename from trunk/KProcessHacker/kph_nt.c rename to trunk/KProcessHacker/ps.c index bc7ae6a5d..353a454b4 100644 --- a/trunk/KProcessHacker/kph_nt.c +++ b/trunk/KProcessHacker/ps.c @@ -1,6 +1,6 @@ /* * Process Hacker Driver - - * custom APIs + * processes and threads * * Copyright (C) 2009 wj32 * @@ -20,62 +20,8 @@ * along with Process Hacker. If not, see . */ -#include "kph_nt.h" -#include "debug.h" - -extern int WindowsVersion; -extern ACCESS_MASK ProcessAllAccess; -extern ACCESS_MASK ThreadAllAccess; -extern POBJECT_TYPE *PsJobType; -extern POBJECT_TYPE *SeTokenObjectType; - -_PsGetProcessJob PsGetProcessJob = NULL; -_PsSuspendProcess PsSuspendProcess = NULL; -_PsResumeProcess PsResumeProcess = NULL; -_MmCopyVirtualMemory MmCopyVirtualMemory = NULL; - -PVOID GetSystemRoutineAddress(WCHAR *Name) -{ - UNICODE_STRING routineName; - PVOID routineAddress = NULL; - - RtlInitUnicodeString(&routineName, Name); - - __try - { - routineAddress = MmGetSystemRoutineAddress(&routineName); - } - __except (EXCEPTION_EXECUTE_HANDLER) - { - routineAddress = NULL; - } - - return routineAddress; -} - -NTSTATUS KphNtInit() -{ - NTSTATUS status = STATUS_SUCCESS; - - MmCopyVirtualMemory = GetSystemRoutineAddress(L"MmCopyVirtualMemory"); - PsGetProcessJob = GetSystemRoutineAddress(L"PsGetProcessJob"); - PsResumeProcess = GetSystemRoutineAddress(L"PsResumeProcess"); - PsSuspendProcess = GetSystemRoutineAddress(L"PsSuspendProcess"); - - return status; -} - -NTSTATUS OpenProcess(PHANDLE ProcessHandle, int DesiredAccess, HANDLE ProcessId) -{ - OBJECT_ATTRIBUTES objAttr = { 0 }; - CLIENT_ID clientId; - - objAttr.Length = sizeof(objAttr); - clientId.UniqueThread = 0; - clientId.UniqueProcess = (HANDLE)ProcessId; - - return KphOpenProcess(ProcessHandle, DesiredAccess, &objAttr, &clientId, KernelMode); -} +#include "include/kph.h" +#include "include/ps.h" NTSTATUS KphGetContextThread( HANDLE ThreadHandle, @@ -327,69 +273,6 @@ NTSTATUS KphOpenProcessJob( return status; } -NTSTATUS KphOpenProcessTokenEx( - HANDLE ProcessHandle, - ACCESS_MASK DesiredAccess, - ULONG ObjectAttributes, - PHANDLE TokenHandle, - KPROCESSOR_MODE AccessMode - ) -{ - NTSTATUS status = STATUS_SUCCESS; - PEPROCESS processObject; - PVOID tokenObject; - HANDLE tokenHandle; - ACCESS_STATE accessState; - char auxData[0x34]; - - status = SeCreateAccessState( - &accessState, - (PAUX_ACCESS_DATA)auxData, - DesiredAccess, - (PGENERIC_MAPPING)((PCHAR)*SeTokenObjectType + 52) - ); - - if (!NT_SUCCESS(status)) - { - return status; - } - - if (accessState.RemainingDesiredAccess & MAXIMUM_ALLOWED) - accessState.PreviouslyGrantedAccess |= TOKEN_ALL_ACCESS; - else - accessState.PreviouslyGrantedAccess |= accessState.RemainingDesiredAccess; - - accessState.RemainingDesiredAccess = 0; - - status = ObReferenceObjectByHandle(ProcessHandle, 0, *PsProcessType, KernelMode, &processObject, 0); - - if (!NT_SUCCESS(status)) - { - SeDeleteAccessState(&accessState); - return status; - } - - tokenObject = PsReferencePrimaryToken(processObject); - ObDereferenceObject(processObject); - - status = ObOpenObjectByPointer( - tokenObject, - ObjectAttributes, - &accessState, - 0, - *SeTokenObjectType, - AccessMode, - &tokenHandle - ); - SeDeleteAccessState(&accessState); - ObDereferenceObject(tokenObject); - - if (NT_SUCCESS(status)) - *TokenHandle = tokenHandle; - - return status; -} - NTSTATUS KphOpenThread( PHANDLE ThreadHandle, ACCESS_MASK DesiredAccess, @@ -485,77 +368,6 @@ NTSTATUS KphOpenThread( return status; } -NTSTATUS KphReadVirtualMemory( - HANDLE ProcessHandle, - PVOID BaseAddress, - PVOID Buffer, - ULONG BufferLength, - PULONG ReturnLength, - KPROCESSOR_MODE AccessMode - ) -{ - NTSTATUS status = STATUS_SUCCESS; - PEPROCESS processObject; - ULONG returnLength = 0; - - if (MmCopyVirtualMemory == NULL) - return STATUS_NOT_SUPPORTED; - - if (AccessMode != KernelMode) - { - if ((((ULONG_PTR)BaseAddress + BufferLength) < (ULONG_PTR)BaseAddress) || - (((ULONG_PTR)Buffer + BufferLength) < (ULONG_PTR)Buffer) || - (((ULONG_PTR)BaseAddress + BufferLength) > MmUserProbeAddress) || - (((ULONG_PTR)Buffer + BufferLength) > MmUserProbeAddress)) - { - return STATUS_ACCESS_VIOLATION; - } - - __try - { - if (ReturnLength) - ProbeForWrite(ReturnLength, sizeof(ULONG), 1); - } - __except (EXCEPTION_EXECUTE_HANDLER) - { - return STATUS_ACCESS_VIOLATION; - } - } - - if (BufferLength) - { - status = ObReferenceObjectByHandle(ProcessHandle, 0, *PsProcessType, KernelMode, &processObject, NULL); - - if (!NT_SUCCESS(status)) - return status; - - status = MmCopyVirtualMemory( - processObject, - BaseAddress, - PsGetCurrentProcess(), - Buffer, - BufferLength, - AccessMode, - &returnLength - ); - ObDereferenceObject(processObject); - } - - if (ReturnLength) - { - __try - { - *ReturnLength = returnLength; - } - __except (EXCEPTION_EXECUTE_HANDLER) - { - status = STATUS_ACCESS_VIOLATION; - } - } - - return status; -} - NTSTATUS KphResumeProcess( HANDLE ProcessHandle ) @@ -655,74 +467,3 @@ NTSTATUS KphTerminateProcess( return status; } - -NTSTATUS KphWriteVirtualMemory( - HANDLE ProcessHandle, - PVOID BaseAddress, - PVOID Buffer, - ULONG BufferLength, - PULONG ReturnLength, - KPROCESSOR_MODE AccessMode - ) -{ - NTSTATUS status = STATUS_SUCCESS; - PEPROCESS processObject; - ULONG returnLength = 0; - - if (MmCopyVirtualMemory == NULL) - return STATUS_NOT_SUPPORTED; - - if (AccessMode != KernelMode) - { - if ((((ULONG_PTR)BaseAddress + BufferLength) < (ULONG_PTR)BaseAddress) || - (((ULONG_PTR)Buffer + BufferLength) < (ULONG_PTR)Buffer) || - (((ULONG_PTR)BaseAddress + BufferLength) > MmUserProbeAddress) || - (((ULONG_PTR)Buffer + BufferLength) > MmUserProbeAddress)) - { - return STATUS_ACCESS_VIOLATION; - } - - __try - { - if (ReturnLength) - ProbeForWrite(ReturnLength, sizeof(ULONG), 1); - } - __except (EXCEPTION_EXECUTE_HANDLER) - { - return STATUS_ACCESS_VIOLATION; - } - } - - if (BufferLength) - { - status = ObReferenceObjectByHandle(ProcessHandle, 0, *PsProcessType, KernelMode, &processObject, NULL); - - if (!NT_SUCCESS(status)) - return status; - - status = MmCopyVirtualMemory( - PsGetCurrentProcess(), - Buffer, - processObject, - BaseAddress, - BufferLength, - AccessMode, - &returnLength - ); - ObDereferenceObject(processObject); - } - - if (ReturnLength) - { - __try - { - *ReturnLength = returnLength; - } - __except (EXCEPTION_EXECUTE_HANDLER) - { - status = STATUS_ACCESS_VIOLATION; - } - } - - return status; -} diff --git a/trunk/KProcessHacker/se.c b/trunk/KProcessHacker/se.c new file mode 100644 index 000000000..3df69e317 --- /dev/null +++ b/trunk/KProcessHacker/se.c @@ -0,0 +1,87 @@ +/* + * Process Hacker Driver - + * security + * + * Copyright (C) 2009 wj32 + * + * This file is part of Process Hacker. + * + * Process Hacker is free software; you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * Process Hacker is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with Process Hacker. If not, see . + */ + +#include "include/kph.h" +#include "include/se.h" + +NTSTATUS KphOpenProcessTokenEx( + HANDLE ProcessHandle, + ACCESS_MASK DesiredAccess, + ULONG ObjectAttributes, + PHANDLE TokenHandle, + KPROCESSOR_MODE AccessMode + ) +{ + NTSTATUS status = STATUS_SUCCESS; + PEPROCESS processObject; + PVOID tokenObject; + HANDLE tokenHandle; + ACCESS_STATE accessState; + char auxData[0x34]; + + status = SeCreateAccessState( + &accessState, + (PAUX_ACCESS_DATA)auxData, + DesiredAccess, + (PGENERIC_MAPPING)((PCHAR)*SeTokenObjectType + 52) + ); + + if (!NT_SUCCESS(status)) + { + return status; + } + + if (accessState.RemainingDesiredAccess & MAXIMUM_ALLOWED) + accessState.PreviouslyGrantedAccess |= TOKEN_ALL_ACCESS; + else + accessState.PreviouslyGrantedAccess |= accessState.RemainingDesiredAccess; + + accessState.RemainingDesiredAccess = 0; + + status = ObReferenceObjectByHandle(ProcessHandle, 0, *PsProcessType, KernelMode, &processObject, 0); + + if (!NT_SUCCESS(status)) + { + SeDeleteAccessState(&accessState); + return status; + } + + tokenObject = PsReferencePrimaryToken(processObject); + ObDereferenceObject(processObject); + + status = ObOpenObjectByPointer( + tokenObject, + ObjectAttributes, + &accessState, + 0, + *SeTokenObjectType, + AccessMode, + &tokenHandle + ); + SeDeleteAccessState(&accessState); + ObDereferenceObject(tokenObject); + + if (NT_SUCCESS(status)) + *TokenHandle = tokenHandle; + + return status; +} diff --git a/trunk/KProcessHacker/sources b/trunk/KProcessHacker/sources index 493f53529..ad806a230 100644 --- a/trunk/KProcessHacker/sources +++ b/trunk/KProcessHacker/sources @@ -7,5 +7,9 @@ LIBS=%BUILD%\lib SOURCES= \ kprocesshacker.c \ - kph_nt.c \ + kph.c \ + mm.c \ + ob.c \ + ps.c \ + se.c \ resource.rc