141 Commits

Author SHA1 Message Date
silverf0x 14d5e1a3b6 add runtime support by OS version 2023-05-31 14:14:28 +02:00
jmpoep 68aef3f2d8 Create cmake.yml 2023-01-02 14:06:14 +01:00
silverf0x 8ad8558760 fix 2022-10-24 21:49:47 +02:00
silverf0x 260e0331d6 fix 32bits QT deployment 2022-10-24 21:43:39 +02:00
silverf0x c460a9d363 add appveyor.yml 2022-06-04 15:07:45 +02:00
Sndav 67696389de Add support for 10.0.17763.1577 2021-10-26 20:50:11 +02:00
Sndav a8cf5f7639 Add support for 10.0.19041.1288 2021-10-26 20:50:11 +02:00
Leonid Shagiev a8e2643da4 Add support for 10.0.19041.1081, 10.0.21354.1, 10.0.21996.1, 10.0.22000.1 2021-08-17 13:44:05 +02:00
Andrey f2eedd35c4 Add support for 10.0.19041.1052 2021-07-14 18:31:40 +02:00
Benjamin DELPY 5851a13a7a Update RpcInternals.h
Add support for 10.0.17763.1999 x86
2021-07-14 18:31:02 +02:00
Benjamin DELPY 8c4207b6e4 Update RpcInternals.h
Add support for 10.0.17763.1999 x64
2021-07-14 18:31:02 +02:00
Alexander Chermyanin 79743458a8 add runtime 10.0.17763.1879 2021-05-23 14:27:26 +02:00
Alexander Chermyanin 18f1963950 add runtime 10.0.17763.1879 2021-05-23 14:27:26 +02:00
Alexander Chermyanin 66288f9366 add runtime 10.0.17763.1697 2021-03-25 21:40:42 +01:00
Alexander Chermyanin e29002562a add runtime 10.0.17763.1697 2021-03-25 21:40:42 +01:00
Alexander Chermyanin 181d018aa8 add runtime 10.0.17763.1697 2021-03-25 21:40:42 +01:00
Alexander Chermyanin 7c7fbb98f4 add runtime version 10.0.17763.1817 2021-03-25 21:40:42 +01:00
Alexander Chermyanin faf4b6a2d3 add runtime version 10.0.17763.1817 2021-03-25 21:40:42 +01:00
silverf0x 5e66d72f9e Disable warning 4714: function marked as __forceinline not inlined 2021-03-06 16:12:04 +01:00
silverf0x f708ab5b62 Update README.md with Visual Studio 2019 2021-03-06 15:27:57 +01:00
silverf0x e254e9ce56 Fix compilation with VS2019 and Qt5.15.2 2021-03-06 15:27:21 +01:00
silverf0x 3c2aaf2971 Merge pull request #47 from M3ikShizuka/master
Add runtime version 10.0.19041.746 and fix generation 'cmake -G \"Visual Studio 16 2019\" -A x64'.
2021-03-06 12:28:14 +01:00
silverf0x 8cd1676b5e Merge branch 'master' into master 2021-03-06 12:27:03 +01:00
Martin Rakhmanov eac145f455 Add runtime version 10.0.19041.630, got rid of Qt build warnings when
built against Qt 5.15.2 (deprecated APIs replaced with recommended
ones).
2021-03-06 12:19:25 +01:00
M3ik Shizuka 58a654aeea Add runtime version 10.0.19041.746 and fix generation cmake -G "Visual Studio 16 2019" -A x64. 2021-02-01 23:09:17 +03:00
silverf0x 9f24017edb Add runtime version 10.0.19041.630 2020-11-14 11:38:55 +01:00
silverf0x 0bec7930eb Add runtime versions 10.0.19041.508 and 10.0.19041.546 2020-10-29 11:11:36 +01:00
haroldm 60569c6e6d Add runtime version 10.0.17763.864 2020-07-20 09:10:13 +02:00
Daniel Hodson 25c9d7798e Add runtime version 10.0.19041.1 2020-05-28 10:47:45 +02:00
silverf0x bc0438014d Add runtime version 10.0.17134.1130 2020-04-03 09:09:01 +02:00
silverf0x b3885cfc56 Add runtime version 6.1.7601.24441 2020-03-26 09:22:38 +01:00
silverf0x c795134374 Add runtime version 10.0.18362.628 2020-02-16 15:46:30 +01:00
silverf0x e1a7e1f0a6 Add runtime version 6.3.9600.19538 2019-12-15 13:52:40 +01:00
silverf0x c8c35fa4c9 Add runtime version 10.0.10586.1176 2019-11-14 20:57:45 +01:00
silverf0x dfe9350716 Add runtime version 10.0.18362.476 2019-11-14 20:55:48 +01:00
silverf0x 972bb9f0ea Add runtime version 10.0.14393.3115 2019-11-14 20:54:43 +01:00
Martin Gallo 948b6cdbac Add runtime version 10.0.17763.719 2019-10-16 21:09:15 +02:00
silverf0x c7d3e3c1a6 Fix #36: UAF in InterfacesWidget_C::InterfaceSelected(const QModelIndex& Index) results in empty interface properties 2019-08-28 21:19:23 +02:00
silverf0x 2ce4f6f7a2 Fix #35: Hang with VBS enabled due to EnumProcessModulesEx ignored return value 2019-08-28 21:16:58 +02:00
Arnaud Gatignol d53fa65087 Add runtime 10.0.18362.1 2019-07-18 23:11:02 +02:00
silverf0x 899a7a7595 Add runtime 6.1.7601.24408 2019-05-02 21:10:13 +02:00
silverf0x ec12b31c1b Add runtime 10.0.17763.379 2019-03-23 22:39:18 +01:00
silverf0x a0dcff92f2 Merge branch 'master' of https://github.com/silverf0x/RpcView 2019-03-17 21:57:24 +01:00
silverf0x 6b8f0b6c87 Add runtime version 10.0.17134.648 2019-03-17 21:55:46 +01:00
silverf0x 8197fcdb45 Add runtime version 10.0.17763.648 2019-03-17 21:46:43 +01:00
silverf0x 43df9dfebf Add runtime version 10.0.10240.16841 2019-01-22 20:32:08 +01:00
silverf0x f98dad4db2 Fix call convension for the ProcexpOpenProcess function and support for the 32-bit version. 2019-01-20 18:04:09 +01:00
silverf0x 02d0fd419a Add runtime version 6.1.7601.24335 2019-01-20 17:55:15 +01:00
silverf0x 7302b614ce Add support for Protected and PPL processes with the ProcessExplorer driver.
REMARK: the feature requires the procexp.sys driver version 15.0.0.0
2019-01-20 17:51:12 +01:00
silverf0x 80fc306cac Fix typo in README.md 2019-01-16 21:03:59 +01:00
silverf0x d4632ac01c Fix #33: potential null pointer dereference in RpcCoreInit 2019-01-16 20:56:24 +01:00
silverf0x 341ab8196c Merge pull request #32 from hfiref0x/patch-gui
Update MainWindow.cpp
2019-01-16 14:13:24 +00:00
silverf0x f3aa3a581e Merge pull request #31 from hfiref0x/patch
Handle OS_ALLOC heap allocation potential failure in InitDecompilerInfo
2019-01-16 07:39:56 +00:00
hfiref0x bcf852a2bf Update MainWindow.cpp
Automatically show decompilation widget if "Decompile" popup menu was used and widget wasn't shown.
2019-01-16 14:39:01 +07:00
hfiref0x 6f8e8f45fc Update RpcView.cpp
Set formatting to original RpcView style.
2019-01-16 14:05:49 +07:00
hfiref0x 270401c658 Update RpcView.cpp
Handle OS_ALLOC heap allocation potential failure in InitDecompilerInfo
2019-01-16 14:03:21 +07:00
hfiref0x 79ea228d3e Merge pull request #2 from silverf0x/master
Merge upstream changes
2019-01-16 04:27:51 +07:00
silverf0x 91bf7750e6 Fix #30: potential null pointer dereference in GetRpcServerAddressInProcess and wWinMain 2019-01-15 21:31:40 +01:00
silverf0x 419a8e0856 Fix #29: remove unused RpcDecompilerPrintHiddenFUProcedure 2019-01-15 21:27:04 +01:00
silverf0x b6c7c32058 Fix #28: incorrect comparison in processComplexArray 2019-01-15 21:22:30 +01:00
silverf0x 7227826825 Fix #27: incorrect check of function return value in EnumProcess 2019-01-15 21:18:47 +01:00
silverf0x b495f68162 Fix #26: replace FC_POINTER_CONFORMANCE with FC_TOP_LEVEL_MULTID_CONFORMANCE 2019-01-15 21:16:46 +01:00
silverf0x c92891ea03 Fix #25: out of bounds read in RpcCoreInit 2019-01-15 21:13:03 +01:00
silverf0x b98ed0702f Fix #24: buffer overrun in GetUserAndDomainName 2019-01-15 21:09:26 +01:00
silverf0x b253c6e816 Fix #23: add missing break in switch statement 2019-01-15 21:04:39 +01:00
silverf0x 1526810cb8 Fix #22: remove useless functions 2019-01-15 21:02:10 +01:00
silverf0x 7939781867 Fix bug #21: build instructions 2019-01-15 20:51:51 +01:00
silverf0x ea1ce6667e Merge pull request #20 from jthuraisamy/patch-6
Add runtime version 6.1.7601.24308
2019-01-15 07:44:16 +00:00
silverf0x 39a4d9c1fd Merge pull request #19 from jthuraisamy/patch-5
Add runtime version 10.0.16299.846
2019-01-15 07:43:53 +00:00
hfiref0x 3bdfe86bc6 Merge pull request #1 from silverf0x/master
Merge upstream changes
2019-01-15 11:23:40 +07:00
Jackson 9558dabb29 Add runtime version 6.1.7601.24308 2019-01-14 16:04:23 -08:00
Jackson e56bea547a Add runtime version 6.1.7601.24308 2019-01-14 16:03:27 -08:00
Jackson 1dc0d79231 Add runtime version 10.0.16299.846 2019-01-14 16:00:40 -08:00
Jackson b92592abdc Add runtime version 10.0.16299.846 2019-01-14 15:58:15 -08:00
silverf0x 54b08a8ebd Merge pull request #18 from hfiref0x/patch
Add runtime support for 10.0.14393.2312, 10.0.14393.2665
2019-01-14 18:47:06 +00:00
hfiref0x 90eb7702d8 Add runtime support for 10.0.14393.2312, 10.0.14393.2665 2019-01-14 16:38:54 +07:00
silverf0x c513fb4fea Merge pull request #16 from jthuraisamy/patch-4
Add runtime version 10.0.16299.492
2018-12-29 13:16:05 +00:00
Jackson e33481bcd2 Add runtime version 10.0.16299.492
Fixed typo.
2018-12-27 10:30:28 -08:00
Jackson 7ed5d32592 Add runtime version 10.0.16299.492
Fixed typo.
2018-12-27 10:29:23 -08:00
silverf0x 49f4b764e4 Merge pull request #15 from jthuraisamy/patch-3
Add runtime version 10.0.16299.492
2018-12-27 16:39:31 +00:00
Jackson dbd228367c Add runtime version 10.0.16299.492 2018-12-26 16:05:06 -08:00
Jackson f34acc5dd2 Add runtime version 10.0.16299.492 2018-12-26 16:02:45 -08:00
silverf0x 88c179e4e6 minor fixes 2018-12-26 20:46:07 +01:00
silverf0x 66e2f506ae Merge pull request #14 from jthuraisamy/patch-2
Add runtime version 10.0.17763.194
2018-12-26 19:35:25 +00:00
Jackson 4a3d62d8c4 Add runtime version 10.0.17763.194 2018-12-25 20:40:52 -08:00
Jackson 896a5d4132 Add runtime version 10.0.17763.194 2018-12-25 20:39:43 -08:00
silverf0x 5524d14b5c Add runtime version 10.0.17134.471 2018-12-13 22:31:14 +01:00
silverf0x cd0e853418 Update README.md 2018-12-12 06:53:14 +00:00
silverf0x c8f7a23951 Update README.md 2018-12-12 06:52:58 +00:00
silverf0x 8d5b3c5020 Merge pull request #13 from jthuraisamy/patch-1
Add runtime version 6.1.7601.24260
2018-12-12 06:47:57 +00:00
Jackson e31bbaeabc Add runtime version 6.1.7601.24260 2018-12-11 18:58:39 -08:00
Jackson 4cbec1a0c7 Add runtime version 6.1.7601.24260 2018-12-10 20:28:44 -08:00
silverf0x f2a310644a add runtime version 6.3.9600.19176 2018-12-03 20:38:39 +01:00
silverf0x 96c645d8b5 add runtime version 6.1.7601.24291 2018-12-02 13:35:10 +01:00
silverf0x d3564617b1 Merge pull request #12 from chitoge/master
Add runtime version 10.0.17763.134
2018-11-23 08:41:32 +00:00
Thanh Do 9e1e971a1b add runtime version 10.0.17763.134 2018-11-23 14:40:49 +07:00
silverf0x a065327a51 Add runtime version 10.0.17134.407 2018-11-14 08:07:00 +01:00
silverf0x 1093c5ab65 Add runtime versions 10.0.17763.1 2018-11-01 15:05:44 +01:00
silverf0x 9bd35cdb84 Add runtime version 10.0.16299.726 2018-10-18 20:19:41 +02:00
silverf0x 685a4d5454 Add runtime versions 10.0.17134.1 2018-08-25 22:07:15 +02:00
silverf0x 7645b1c6a5 Complete bug fixed in pull request #11 2018-08-25 21:56:30 +02:00
silverf0x 29d8f7c734 Merge branch 'master' of https://github.com/silverf0x/RpcView 2018-08-25 21:53:35 +02:00
silverf0x daf87dcc99 Add runtime version 6.1.7601.24117 2018-08-25 21:48:04 +02:00
silverf0x d96e2fb6a4 Merge pull request #11 from wmliang/master
bug fixed
2018-08-25 21:42:29 +02:00
silverf0x ddd91d8735 Add runtime versions 10.0.17134.112 and 10.0.17134.228 2018-08-25 21:33:09 +02:00
wmliang a53bff717b bug fixed 2018-07-31 21:29:04 +08:00
silverf0x c108da277b Add runtime versions 10.0.17134.48 2018-06-07 21:18:17 +02:00
silverf0x 8cc56822ad Merge pull request #9 from 1orenz0/upstream
Fix size_is description when the parameter is out
2018-04-26 21:11:23 +02:00
1orenz0 39ded8c54d Fix size_is description when the parameter is out
When the argument using to describe size_is is an out parameter, we
don't know it's value and it cannot be used to describe the size of
another parameter. That's why in that case we can only set a max range
2018-04-25 20:33:57 +02:00
silverf0x 9f25e60e62 Add runtime versions 10.0.16299.309 and 10.0.16299.371 2018-04-18 21:44:01 +02:00
silverf0x 13b5819f56 Merge pull request #6 from TogDu/master
FEATURE/EXPERIMENTAL : Add /f flag to force runtime loading
2018-02-26 18:30:06 +01:00
TogDu b5d86817fc FIX : /f flag wasn't transmitted on runas 2018-02-17 19:31:06 +01:00
TogDu b2d5166e6f add /f flag support for debug mode 2018-02-17 19:29:24 +01:00
TogDu b168708bfa FIX : argv wasn't initialized so QApp cannot return valid argc value 2018-02-17 19:28:48 +01:00
TogDu 23fa0b517d FEATURE-EXPERIMENTAL : add /f flag to force loading for unsupported runtimes 2018-02-12 21:54:18 +01:00
TogDu e71f79cfb1 add support for 10.0.17074.1002
TODO add a f** \force flag
2018-02-12 19:16:41 +01:00
TogDu af13aed088 add support for 6.1.7601.23816 2018-02-12 19:15:53 +01:00
TogDu cc751f40f2 Merge branch 'remotes/silverf0x/master' 2018-01-24 19:40:35 +01:00
TogDu a5b789f1ba add support for 10.0.17025.1000 2018-01-24 19:38:53 +01:00
silverf0x 707aa7947c Add support for version 10.0.16299.192 2018-01-06 20:11:51 +01:00
silverf0x e71a2006b7 Add manual refresh option and configuration files to describe interfaces 2017-12-11 22:43:44 +01:00
silverf0x 940bff0824 Add support for version 10.0.14393.1770 2017-11-20 19:49:09 +01:00
silverf0x 3de26eaa04 Update README.md 2017-11-08 21:02:34 +01:00
silverf0x d796ddeeb3 Update Resource files to add build version 2017-11-08 20:52:59 +01:00
silverf0x 32b1f9c0d2 Update README.md 2017-11-08 20:27:13 +01:00
silverf0x cf5615c21c Fix unreachable code in RpcCoreManager.c when building the x86 version 2017-11-07 23:28:12 +01:00
silverf0x a5e4fd2c43 Increase compiler warning level to W4 with WX 2017-11-07 23:18:16 +01:00
silverf0x 0554224b54 Remove the /WX (warnings as errors) compiler option 2017-11-07 20:55:05 +01:00
silverf0x 9c0f46d029 Upgrade to Qt5 2017-11-07 20:25:01 +01:00
silverf0x 51e5b1e09f Add support for versions 6.3.9600.18292 and 10.0.17017.1000 2017-11-07 20:22:28 +01:00
silverf0x b8ff63ec59 Add support for version 6.1.7601.23915 2017-11-07 20:21:33 +01:00
silverf0x 30bfa47b8c Fix #4: v0.2.1hangs on Windows RS2 2017-11-07 20:19:28 +01:00
silverf0x 1ac3d4a63c Update CMakeLists.txt to version 0.2.2 2017-10-01 07:11:42 +00:00
silverf0x fa78abfb55 Fix the global RpcServer detection hang 2017-10-01 07:04:06 +00:00
silverf0x 362d32d98f Merge pull request #2 from TogDu/master
support for IDL without win32kExtension
2017-10-30 20:53:20 +00:00
TogDu 3eb61e7076 add support for 6.1.7601.23714 2017-10-30 18:51:24 +01:00
TogDu 99c858af98 Merge branch 'master' of https://github.com/silverf0x/RpcView 2017-10-30 18:36:00 +01:00
TogDu cce523d939 remove pedentic warning (%x / unsigned char* conflict) 2017-05-10 19:27:41 +02:00
TogDu 85ff861717 BUGFIX :
-duplicate type OIF_HEADER_T / Oif_Header_t (more to come)
-support for IDL without win32kExtension structure
2017-05-10 19:25:02 +02:00
TogDu 6b05426e63 CLEANING : break or return, one need to choose ;) 2017-05-10 19:20:05 +02:00
TogDu 6d5625087a support for 6.1.7601.19135 version 2017-05-10 19:17:57 +02:00
52 changed files with 735 additions and 528 deletions
+68
View File
@@ -0,0 +1,68 @@
name: CMake
on: [push, pull_request,workflow_dispatch]
env:
# Customize the CMake build type here (Release, Debug, RelWithDebInfo, etc.)
BUILD_TYPE: Release
CMAKE_PREFIX_PATH: ${{github.workspace}}\..\Qt\5.15.2\msvc2019_64
ProjectDir: ${{github.workspace}}\build\bin\Release\
PackDirName: RpcView64
PackDirPath: ${{github.workspace}}\build\bin\Release\RpcView64
jobs:
build:
# The CMake configure and build commands are platform agnostic and should work equally well on Windows or Mac.
# You can convert this to a matrix build if you need cross-platform coverage.
# See: https://docs.github.com/en/free-pro-team@latest/actions/learn-github-actions/managing-complex-workflows#using-a-build-matrix
runs-on: windows-2019
steps:
- uses: actions/checkout@v3
- name: Install Qt
# Installs the Qt SDK
uses: jurplel/install-qt-action@v3
with:
version: '5.15.2'
host: 'windows'
target: 'desktop'
arch: 'win64_msvc2019_64'
archives: 'qtbase qtwinextras qttools'
- name: Configure CMake
# Configure CMake in a 'build' subdirectory. `CMAKE_BUILD_TYPE` is only required if you are using a single-configuration generator such as make.
# See https://cmake.org/cmake/help/latest/variable/CMAKE_BUILD_TYPE.html?highlight=cmake_build_type
run: cmake -A x64 -B ${{github.workspace}}/build -DCMAKE_BUILD_TYPE=${{env.BUILD_TYPE}}
- name: Build
# Build your program with the given configuration
run: cmake --build ${{github.workspace}}/build --config ${{env.BUILD_TYPE}}
- name: Test
working-directory: ${{github.workspace}}/build
# Execute tests defined by the CMake configuration.
# See https://cmake.org/cmake/help/latest/manual/ctest.1.html for more detail
run: ctest -C ${{env.BUILD_TYPE}}
- name: Package
id: Package
shell: cmd
#call "C:\Program Files (x86)\Microsoft Visual Studio\2019\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
run: |
cd ${{env.ProjectDir}}
mkdir ${{env.PackDirName}}
copy *.dll ${{env.PackDirName}}\
copy *.exe ${{env.PackDirName}}\
${{env.CMAKE_PREFIX_PATH}}\bin\windeployqt.exe --no-angle --no-opengl-sw --no-system-d3d-compiler --no-translations --release ${{env.PackDirName}}\
- name: Prune
id: Prune
shell: cmd
run: |
rmdir /s /q ${{env.PackDirPath}}\imageformats
rmdir /s /q ${{env.PackDirPath}}\styles
- name: Upload Binaries
uses: actions/upload-artifact@v3
with:
name: RpcView64-windows
path: ${{env.PackDirPath}}\
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
+10 -5
View File
@@ -3,8 +3,13 @@ cmake_minimum_required (VERSION 3.0.2)
project(RpcView)
set(RPCVIEW_VERSION_MAJOR 0)
set(RPCVIEW_VERSION_MINOR 2)
set(RPCVIEW_VERSION_MINOR 3)
set(RPCVIEW_VERSION_RELEASE 1)
if($ENV{APPVEYOR_BUILD_NUMBER})
set(RPCVIEW_VERSION_BUILD $ENV{APPVEYOR_BUILD_NUMBER})
else()
set(RPCVIEW_VERSION_BUILD 0)
endif()
# configure a header file to pass some of the CMake settings to the source code
configure_file (
@@ -19,11 +24,11 @@ include_directories("${PROJECT_BINARY_DIR}")
set(EXECUTABLE_OUTPUT_PATH ${PROJECT_BINARY_DIR}/bin)
set(LIBRARY_OUTPUT_PATH ${PROJECT_BINARY_DIR}/bin)
set(CMAKE_CXX_FLAGS_DEBUG "/W3 /WX /MTd /EHsc /Zi")
set(CMAKE_C_FLAGS_DEBUG "/W4 /WX /MTd /EHsc /Zi")
set(CMAKE_CXX_FLAGS_DEBUG "/W4 /WX /MDd /EHsc /Zi")
set(CMAKE_C_FLAGS_DEBUG "/W4 /WX /MDd /EHsc /Zi")
set(CMAKE_CXX_FLAGS_RELEASE "/W3 /WX /O2 /Oi /Ot /Gy /MT /EHsc /MP")
set(CMAKE_C_FLAGS_RELEASE "/W4 /WX /O2 /Oi /Ot /Gy /MT /EHsc /MP")
set(CMAKE_CXX_FLAGS_RELEASE "/W4 /WX /O2 /Oi /Ot /Gy /MD /EHsc /MP")
set(CMAKE_C_FLAGS_RELEASE "/W4 /WX /O2 /Oi /Ot /Gy /MD /EHsc /MP")
set(CMAKE_EXE_LINKER_FLAGS "/INCREMENTAL:NO /OPT:REF /OPT:ICF")
+31 -30
View File
@@ -3,45 +3,46 @@
#define QT_BUILD_CONFIGURE
#define NOMINMAX
#include <QtGui/QSortFilterProxyModel>
#include <QtCore/QSortFilterProxyModel>
#include <QtGui/QStandardItemModel>
#include <QtGui/QDockWidget>
#include <QtGui/QLabel>
#include <QtGui/QTreeView>
#include <QtGui/QGridLayout>
#include <QtGui/QGroupBox>
#include <QtGui/QDockWidget>
#include <QtGui/QTextEdit>
#include <QtGui/QLineEdit>
#include <QtGui/QApplication>
#include <QtGui/QFormLayout>
#include <QtGui/QAbstractItemView>
#include <QtWidgets/QDockWidget>
#include <QtWidgets/QLabel>
#include <QtWidgets/QTreeView>
#include <QtWidgets/QGridLayout>
#include <QtWidgets/QGroupBox>
#include <QtWidgets/QDockWidget>
#include <QtWidgets/QTextEdit>
#include <QtWidgets/QLineEdit>
#include <QtWidgets/QApplication>
#include <QtWidgets/QFormLayout>
#include <QtWidgets/QAbstractItemView>
#include <QtCore/QTimer>
#include <QtGui/QMainWindow>
#include <QtGui/QStatusBar>
#include <QtGui/QAction>
#include <QtGui/QActionGroup>
#include <QtGui/QMenu>
#include <QtGui/QMenuBar>
#include <QtWidgets/QMainWindow>
#include <QtWidgets/QStatusBar>
#include <QtWidgets/QAction>
#include <QtWidgets/QActionGroup>
#include <QtWidgets/QMenu>
#include <QtWidgets/QMenuBar>
#include <QtGui/QPixmap>
#include <QtGui/QTreeWidgetItem>
#include <QtGui/QTreeWidget>
#include <QtGui/QMessageBox>
#include <QtWidgets/QTreeWidgetItem>
#include <QtWidgets/QTreeWidget>
#include <QtWidgets/QMessageBox>
#include <QtCore/QFile>
#include <QtCore/QProcess>
#include <QtGui/QSplashScreen>
#include <QtGui/QHeaderView>
#include <QtWidgets/QSplashScreen>
#include <QtWidgets/QHeaderView>
#include <QtGui/QSyntaxHighlighter>
#include <QtCore/QSettings>
#include <QtCore/QThread>
#include <QtGui/QColorDialog>
#include <QtGui/QInputDialog>
#include <QtGui/QCheckBox>
#include <QtGui/QPushButton>
#include <QtGui/QStackedWidget>
#include <QtWidgets/QColorDialog>
#include <QtWidgets/QInputDialog>
#include <QtWidgets/QCheckBox>
#include <QtWidgets/QPushButton>
#include <QtWidgets/QStackedWidget>
#include <QtGui/QKeyEvent>
#include <QtGui/QToolButton>
#include <QtGui/QDialogButtonBox>
#include <QtWidgets/QToolButton>
#include <QtWidgets/QDialogButtonBox>
#include <QtCore/QSignalMapper>
#include <QtWinExtras/qwinfunctions.h>
#endif
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
+50 -52
View File
@@ -1,10 +1,14 @@
RpcView
=======
# RpcView
RpcView is a free tool to explore and decompile all RPC functionalities present on a Microsoft system.
RpcView is an open-source tool to explore and decompile all RPC functionalities present on a Microsoft system.
How to add a new RPC runtime
----------------------------------
You can download the last [automatically built release](https://ci.appveyor.com/project/silverf0x/rpcview/build/artifacts)
[![Build status](https://ci.appveyor.com/api/projects/status/o5wy6mdk16tuht70?svg=true)](https://ci.appveyor.com/project/silverf0x/rpcview)
> **Warning**: you have to install "Microsoft Visual C++ 2019 Redistributable" to use RpcView.
## How to add a new RPC runtime
Basically you have two possibilities to support a new RPC runtime (rpcrt4.dll) version:
@@ -18,47 +22,43 @@ Currently, the supported versions are organized as follows:
- RpcCore3 for Windows 8
- RpcCore4 for Windows 8.1 and 10
Compilation
--------------
## Compilation
Required elements to compiled the project:
* Visual Studio (currently Visual Studio 2015 community)
* CMake (at least 3.0.2)
* Qt4 (currently 4.8.6)
* Visual Studio (currently Visual Studio 2019 Community)
* CMake (currently 3.13.2)
* Qt5 (currently 5.15.2)
Before running CMake you have to set the CMAKE_PREFIX_PATH environment variable with the current Qt path, for instance:
Before running CMake you have to set the CMAKE_PREFIX_PATH environment variable with the Qt **full path**, for instance (x64):
```
set CMAKE_PREFIX_PATH=C:\Qt\4.8.6
set CMAKE_PREFIX_PATH=C:\Qt\5.15.2\msvc2019_64\
```
Then you can run CMake to produce the project solution.
Here is an example to generate the x64 solution with Visual Studio 2015 from the ```RpcView/Build/x64``` directory:
Before running CMake to produce the project solution you have to create the build directories:
- ```RpcView/Build/x64``` for 64-bit targets
- ```RpcView/Build/x86``` for 32-bit targets.
Here is an example to generate the x64 solution with Visual Studio 2019 from the ```RpcView/Build/x64``` directory:
```cmake
cmake -G"Visual Studio 14 2015 Win64" ../../
-- The C compiler identification is MSVC 19.0.24215.1
-- The CXX compiler identification is MSVC 19.0.24215.1
-- Check for working C compiler: C:/Program Files (x86)/Microsoft Visual Studio 14.0/VC/bin/x86_amd64/cl.exe
-- Check for working C compiler: C:/Program Files (x86)/Microsoft Visual Studio 14.0/VC/bin/x86_amd64/cl.exe -- works
cmake ../../ -A x64
-- Building for: Visual Studio 16 2019
-- Selecting Windows SDK version 10.0.17763.0 to target Windows 10.0.19041.
-- The C compiler identification is MSVC 19.28.29334.0
-- The CXX compiler identification is MSVC 19.28.29334.0
-- Check for working C compiler: C:/Program Files (x86)/Microsoft Visual Studio/2019/Community/VC/Tools/MSVC/14.28.29333/bin/Hostx64/x64/cl.exe
-- Check for working C compiler: C:/Program Files (x86)/Microsoft Visual Studio/2019/Community/VC/Tools/MSVC/14.28.29333/bin/Hostx64/x64/cl.exe -- works
-- Detecting C compiler ABI info
-- Detecting C compiler ABI info - done
-- Check for working CXX compiler: C:/Program Files (x86)/Microsoft Visual Studio 14.0/VC/bin/x86_amd64/cl.exe
-- Check for working CXX compiler: C:/Program Files (x86)/Microsoft Visual Studio 14.0/VC/bin/x86_amd64/cl.exe -- works
-- Detecting C compile features
-- Detecting C compile features - done
-- Check for working CXX compiler: C:/Program Files (x86)/Microsoft Visual Studio/2019/Community/VC/Tools/MSVC/14.28.29333/bin/Hostx64/x64/cl.exe
-- Check for working CXX compiler: C:/Program Files (x86)/Microsoft Visual Studio/2019/Community/VC/Tools/MSVC/14.28.29333/bin/Hostx64/x64/cl.exe -- works
-- Detecting CXX compiler ABI info
-- Detecting CXX compiler ABI info - done
-- Detecting CXX compile features
-- Detecting CXX compile features - done
[RpcView]
-- Looking for Q_WS_X11
-- Looking for Q_WS_X11 - not found
-- Looking for Q_WS_WIN
-- Looking for Q_WS_WIN - found
-- Looking for Q_WS_QWS
-- Looking for Q_WS_QWS - not found
-- Looking for Q_WS_MAC
-- Looking for Q_WS_MAC - not found
-- Found Qt4: C:/Qt/4.8.6/bin/qmake.exe (found version "4.8.6")
-- Target is 64 bits
[RpcDecompiler]
[RpcCore1_32bits]
[RpcCore2_32bits]
@@ -72,32 +72,30 @@ cmake -G"Visual Studio 14 2015 Win64" ../../
-- Build files have been written to: C:/Dev/RpcView/Build/x64
```
To produce the Win32 solution with Visual Studio 2015 from the ```RpcView/Build/x86``` directory:
To produce the Win32 solution:
```
set CMAKE_PREFIX_PATH=C:\Qt\5.15.2\msvc2019
```
Then from the ```RpcView/Build/x86``` directory:
```cmake
cmake -G"Visual Studio 14 2015" ../../
-- The C compiler identification is MSVC 19.0.24215.1
-- The CXX compiler identification is MSVC 19.0.24215.1
-- Check for working C compiler: C:/Program Files (x86)/Microsoft Visual Studio 14.0/VC/bin/cl.exe
-- Check for working C compiler: C:/Program Files (x86)/Microsoft Visual Studio 14.0/VC/bin/cl.exe -- works
cmake ../../ -A win32
-- Building for: Visual Studio 16 2019
-- Selecting Windows SDK version 10.0.17763.0 to target Windows 10.0.19041.
-- The C compiler identification is MSVC 19.28.29334.0
-- The CXX compiler identification is MSVC 19.28.29334.0
-- Check for working C compiler: C:/Program Files (x86)/Microsoft Visual Studio/2019/Community/VC/Tools/MSVC/14.28.29333/bin/Hostx64/x86/cl.exe
-- Check for working C compiler: C:/Program Files (x86)/Microsoft Visual Studio/2019/Community/VC/Tools/MSVC/14.28.29333/bin/Hostx64/x86/cl.exe -- works
-- Detecting C compiler ABI info
-- Detecting C compiler ABI info - done
-- Check for working CXX compiler: C:/Program Files (x86)/Microsoft Visual Studio 14.0/VC/bin/cl.exe
-- Check for working CXX compiler: C:/Program Files (x86)/Microsoft Visual Studio 14.0/VC/bin/cl.exe -- works
-- Detecting C compile features
-- Detecting C compile features - done
-- Check for working CXX compiler: C:/Program Files (x86)/Microsoft Visual Studio/2019/Community/VC/Tools/MSVC/14.28.29333/bin/Hostx64/x86/cl.exe
-- Check for working CXX compiler: C:/Program Files (x86)/Microsoft Visual Studio/2019/Community/VC/Tools/MSVC/14.28.29333/bin/Hostx64/x86/cl.exe -- works
-- Detecting CXX compiler ABI info
-- Detecting CXX compiler ABI info - done
-- Detecting CXX compile features
-- Detecting CXX compile features - done
[RpcView]
-- Looking for Q_WS_X11
-- Looking for Q_WS_X11 - not found
-- Looking for Q_WS_WIN
-- Looking for Q_WS_WIN - found
-- Looking for Q_WS_QWS
-- Looking for Q_WS_QWS - not found
-- Looking for Q_WS_MAC
-- Looking for Q_WS_MAC - not found
-- Found Qt4: C:/Qt/4.8.6/bin/qmake.exe (found version "4.8.6")
-- Target is 32 bits
[RpcDecompiler]
[RpcCore1_32bits]
[RpcCore2_32bits]
@@ -115,9 +113,9 @@ cmake --build . --config Release
RpcView32 binaries are produced in the ```RpcView/Build/bin/x86``` directory and RpcView64 ones in the ```RpcView/Build/bin/x64```
Acknowledgements
----------------------
## Acknowledgements
* Jeremy
* Julien
* Yoanne
* Bruno
* Bruno
+47 -74
View File
@@ -18,6 +18,47 @@ typedef struct _LanguageCodePage_T {
WORD wCodePage;
} LanguageCodePage_T;
#define IOCTL_OPEN_PROCESS 0x8335003C
HANDLE hProcexp = NULL;
HANDLE WINAPI ProcexpOpenProcess(DWORD dwDesiredAccess, BOOL bInheritHandle, DWORD dwProcessId)
{
HANDLE hProcess = NULL;
HANDLE Pid = (HANDLE)(uintptr_t)dwProcessId;
DWORD Bytes;
hProcess = OpenProcess(dwDesiredAccess, bInheritHandle, dwProcessId);
if (hProcess != NULL) goto End;
if (hProcexp == NULL)
{
hProcexp = CreateFileA(
"\\\\.\\PROCEXP152",
GENERIC_READ,
0,
NULL,
OPEN_EXISTING,
FILE_ATTRIBUTE_NORMAL,
NULL
);
if (hProcexp == INVALID_HANDLE_VALUE)
{
goto End;
}
}
DeviceIoControl(
hProcexp,
IOCTL_OPEN_PROCESS,
&Pid,
sizeof(Pid),
&hProcess,
sizeof(hProcess),
&Bytes,
NULL
);
End:
return hProcess;
}
//------------------------------------------------------------------------------
BOOL WINAPI AdjustPrivilege(LPCTSTR lpPrivilegeName,BOOL bEnablePrivilege)
@@ -50,7 +91,7 @@ BOOL WINAPI EnumProcess(EnumProcessCallbackFn_T EnumProcessCallbackFn,void* pCal
BOOL bContinue=TRUE;
hSnapshot=CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS,0);
if (hSnapshot==NULL) goto End;
if (hSnapshot == INVALID_HANDLE_VALUE) goto End;
ProcessEntry.dwSize=sizeof(ProcessEntry);
if (!Process32FirstW(hSnapshot,&ProcessEntry)) goto End;
do
@@ -61,7 +102,7 @@ BOOL WINAPI EnumProcess(EnumProcessCallbackFn_T EnumProcessCallbackFn,void* pCal
}while(Process32NextW(hSnapshot,&ProcessEntry));
End:
if (hSnapshot!=NULL) CloseHandle(hSnapshot);
if (hSnapshot != INVALID_HANDLE_VALUE) CloseHandle(hSnapshot);
return (bResult);
}
@@ -162,74 +203,6 @@ End:
return (bResult);
}
typedef VOID (WINAPI* RtlGetUnloadEventTraceExFn_T)(
_Out_ PULONG *ElementSize,
_Out_ PULONG *ElementCount,
_Out_ PVOID *EventTrace
);
#pragma pack(1)
typedef struct _RTL_UNLOAD_EVENT_TRACE {
void* BaseAddress; // Base address of dll
SIZE_T SizeOfImage; // Size of image
ULONG Sequence; // Sequence number for this event
ULONG TimeDateStamp; // Time and date of image
ULONG CheckSum; // Image checksum
WCHAR ImageName[32]; // Image name
} RTL_UNLOAD_EVENT_TRACE, *PRTL_UNLOAD_EVENT_TRACE;
#pragma pack()
//------------------------------------------------------------------------------
BOOL WINAPI GetUnloadedLocationInfo(HANDLE hProcess, VOID* pAddress, LocationInfo_T* pLocationInfo)
{
RtlGetUnloadEventTraceExFn_T RtlGetUnloadEventTraceExFn = NULL;
ULONG* pElementSize = NULL;
ULONG* pElementCount = NULL;
UCHAR* pEventTrace = NULL;
RTL_UNLOAD_EVENT_TRACE* pUnloadEventTrace = NULL;
ULONG ElementSize = 0;
ULONG ElementCount = 0;
BOOL bResult = FALSE;
ULONG i = 0;
RtlGetUnloadEventTraceExFn = (RtlGetUnloadEventTraceExFn_T)GetProcAddress(GetModuleHandleA("ntdll.dll"), "RtlGetUnloadEventTraceEx");
if (RtlGetUnloadEventTraceExFn == NULL) goto End;
//
// Get addresses of ElementSize, ElementCount and pEventTrace in the ntdll
//
RtlGetUnloadEventTraceExFn(&pElementSize, &pElementCount, &pEventTrace);
//
// Read their values in the target process
//
if (!ReadProcessMemory(hProcess, pElementSize, &ElementSize, sizeof(ElementSize), NULL)) goto End;
pUnloadEventTrace = (RTL_UNLOAD_EVENT_TRACE*)OS_ALLOC(ElementSize);
if (pUnloadEventTrace == NULL) goto End;
if (!ReadProcessMemory(hProcess, pElementCount, &ElementCount, sizeof(ElementCount), NULL)) goto End;
if (!ReadProcessMemory(hProcess, pEventTrace, &pEventTrace, sizeof(pEventTrace), NULL)) goto End;
//
// Look for the unloaded module
//
for (i = 0; i < ElementCount; i++)
{
if (!ReadProcessMemory(hProcess, pEventTrace, pUnloadEventTrace, ElementSize, NULL)) goto End;
if (pUnloadEventTrace->BaseAddress == NULL) break;
if (((SIZE_T)pAddress >= (SIZE_T)pUnloadEventTrace->BaseAddress) &&
((SIZE_T)pAddress < ((SIZE_T)pUnloadEventTrace->BaseAddress + pUnloadEventTrace->SizeOfImage)))
{
pLocationInfo->pBaseAddress = pUnloadEventTrace->BaseAddress;
pLocationInfo->Size = pUnloadEventTrace->SizeOfImage;
memcpy(pLocationInfo->Location, pUnloadEventTrace->ImageName, sizeof(pLocationInfo->Location));
break;
}
pEventTrace += ElementSize;
}
End:
if (pUnloadEventTrace != NULL) OS_FREE(pUnloadEventTrace);
return (bResult);
}
//------------------------------------------------------------------------------
UINT64 WINAPI GetModuleVersion(WCHAR* pModulePath)
{
@@ -327,7 +300,7 @@ BOOL WINAPI GetProcessPath(DWORD Pid, WCHAR* pProcessPath, DWORD ProcessPathLeng
BOOL bResult = FALSE;
DWORD Size;
hProcess = OpenProcess(PROCESS_ALL_ACCESS, FALSE, Pid);
hProcess = ProcexpOpenProcess(PROCESS_ALL_ACCESS, FALSE, Pid);
if (hProcess == NULL) goto End;
Size = ProcessPathLength;
bResult = QueryFullProcessImageNameW(hProcess, 0, pProcessPath, &Size);
@@ -367,7 +340,7 @@ BOOL WINAPI GetUserAndDomainName(DWORD Pid, WCHAR* Buffer, ULONG BufferLengthInB
SID_NAME_USE SidType;
BOOL bResult = FALSE;
hProcess = OpenProcess(PROCESS_VM_OPERATION|PROCESS_QUERY_INFORMATION,FALSE,Pid);
hProcess = ProcexpOpenProcess(PROCESS_VM_OPERATION|PROCESS_QUERY_INFORMATION,FALSE,Pid);
if (hProcess==NULL) goto End;
if (!OpenProcessToken(hProcess,TOKEN_QUERY,&hToken)) goto End;
@@ -375,7 +348,7 @@ BOOL WINAPI GetUserAndDomainName(DWORD Pid, WCHAR* Buffer, ULONG BufferLengthInB
pTokenUser=(TOKEN_USER*)OS_ALLOC(Bytes);
if (pTokenUser==NULL) goto End;
if (!GetTokenInformation(hToken,TokenUser,pTokenUser,Bytes,&Bytes)) goto End;
dwSize=sizeof(UserName);
dwSize=_countof(UserName);
if (!LookupAccountSidW(NULL,pTokenUser->User.Sid,UserName,&dwSize,DomainName,&dwSize,&SidType)) goto End;
StringCbPrintfW(Buffer,BufferLengthInBytes,L"%s\\%s",DomainName,UserName);
bResult=TRUE;
@@ -393,7 +366,7 @@ BOOL WINAPI IsProcessWow64(ULONG Pid)
BOOL bWow64 = FALSE;
HANDLE hProcess = NULL;
hProcess = OpenProcess(PROCESS_VM_OPERATION|PROCESS_QUERY_INFORMATION,FALSE,Pid);
hProcess = ProcexpOpenProcess(PROCESS_VM_OPERATION|PROCESS_QUERY_INFORMATION,FALSE,Pid);
if (hProcess==NULL) goto End;
IsWow64Process(hProcess,&bWow64);
End:
+1 -4
View File
@@ -31,20 +31,17 @@ typedef struct _LocationInfo_T{
SIZE_T Size;
}LocationInfo_T;
HANDLE WINAPI ProcexpOpenProcess(DWORD dwDesiredAccess,BOOL bInheritHandle,DWORD dwProcessId);
BOOL WINAPI AdjustPrivilege(LPCTSTR lpPrivilegeName,BOOL bEnablePrivilege);
BOOL WINAPI GetModuleDescription(WCHAR* pModulePath,WCHAR* pDescription,UINT Bytes);
UINT64 WINAPI GetModuleVersion(WCHAR* pModulePath);
BOOL WINAPI GetLocationInfo(HANDLE hProcess, VOID* pAddress, LocationInfo_T* pLocationInfo);
BOOL WINAPI GetUnloadedLocationInfo(HANDLE hProcess, VOID* pAddress, LocationInfo_T* pLocationInfo);
BOOL WINAPI GetProcessNameFromPid(DWORD Pid,WCHAR* pName,UINT NameSizeInBytes);
BOOL WINAPI GetProcessPath(DWORD Pid, WCHAR* pProcessPath, DWORD ProcessPathLength);
BOOL WINAPI GetProcessPebInfo(HANDLE hProcess,WCHAR* pCmdLine,UINT CmdLineLength,WCHAR* pDesktop,UINT DesktopLength);
BOOL WINAPI GetRegValueData(HKEY hRootKey,WCHAR* pSubkeyName,WCHAR* pValueName,VOID* pData,UINT DataLength);
BOOL WINAPI GetUserAndDomainName(DWORD Pid, WCHAR* Buffer, ULONG BufferLengthInBytes);
BOOL WINAPI IsProcessWow64(ULONG Pid);
VOID WINAPI PrintUUID(UUID* pUUID);
HANDLE WINAPI KphOpenProcess(_In_ DWORD dwDesiredAccess, _In_ BOOL bInheritHandle, _In_ DWORD dwProcessId);
typedef BOOL (WINAPI* EnumProcessCallbackFn_T)(DWORD Pid, DWORD Ppid, VOID* pContext, BOOL* pbContinue);
BOOL WINAPI EnumProcess(EnumProcessCallbackFn_T EnumProcessCallbackFn, void* pCallbackCtxt);
+3 -3
View File
@@ -23,12 +23,12 @@ foreach(Files ${CoreFiles})
get_filename_component(Dir ${Files} NAME)
if(${CMAKE_GENERATOR} MATCHES "Win64")
if(${CMAKE_GENERATOR} MATCHES "Win64" OR ${CMAKE_GENERATOR_PLATFORM} MATCHES "x64")
AddRpcCore(${Dir})
else(${CMAKE_GENERATOR} MATCHES "Win64")
else(${CMAKE_GENERATOR} MATCHES "Win64" OR ${CMAKE_GENERATOR_PLATFORM} MATCHES "x64")
if(${Dir} MATCHES "32bits")
AddRpcCore(${Dir})
endif(${Dir} MATCHES "32bits")
endif(${CMAKE_GENERATOR} MATCHES "Win64")
endif(${CMAKE_GENERATOR} MATCHES "Win64" OR ${CMAKE_GENERATOR_PLATFORM} MATCHES "x64")
endif (IS_DIRECTORY ${Files} )
endforeach(Files)
+23 -14
View File
@@ -52,7 +52,7 @@ typedef BOOL (WINAPI* EnumSimpleDictCallbackFn_T)(HANDLE hProcess, UINT Index, V
BOOL WINAPI EnumSimpleDict(HANDLE hProcess, SIMPLE_DICT_T* pSimpleDict, EnumSimpleDictCallbackFn_T EnumSimpleDictCallbackFn, VOID* pContext);
// RpcCore
VOID* __fastcall RpcCoreInit(); //returns a private context for the RpcCoreEngine
VOID* __fastcall RpcCoreInit(BOOL bForce); //returns a private context for the RpcCoreEngine
VOID __fastcall RpcCoreUninit(VOID* pRpcCoreCtxt);
RpcProcessInfo_T* __fastcall RpcCoreGetProcessInfo(void* pRpcCoreCtxt,DWORD Pid,DWORD Ppid,ULONG ProcessInfoMask);
VOID __fastcall RpcCoreFreeProcessInfo(void* pRpcCoreCtxt,RpcProcessInfo_T* pRpcProcessInfo);
@@ -73,6 +73,7 @@ RpcCore_T RpcCoreHelper =
{
RPC_CORE_RUNTIME_VERSION,
RPC_CORE_IS_WOW64,
FALSE,
&RpcCoreInit,
&RpcCoreUninit,
&RpcCoreGetProcessInfo,
@@ -170,7 +171,8 @@ End:
typedef struct{
BOOL bFound;
BOOL bFound;
PRPC_SERVER_T pRpcServer;
}GetRpcServerAddressCallbackCtxt_T;
@@ -193,7 +195,8 @@ BOOL WINAPI GetRpcServerAddressCallback(HANDLE hProcess, UINT Index, VOID PTR_T
if (!ReadProcessMemory(hProcess,pSimpleDictEntry,&RpcInterface,sizeof(RpcInterface),NULL)) goto End;
if ( (RpcInterface.RpcServerInterface.Length==sizeof(RPC_SERVER_INTERFACE_T)) &&
(!memcmp(&RpcInterface.RpcServerInterface.TransferSyntax, &DceRpcSyntaxUuid, sizeof(DceRpcSyntaxUuid))))
(!memcmp(&RpcInterface.RpcServerInterface.TransferSyntax, &DceRpcSyntaxUuid, sizeof(DceRpcSyntaxUuid))) &&
RpcInterface.pRpcServer == pGetRpcServerAddressCallbackCtxt->pRpcServer)
{
pGetRpcServerAddressCallbackCtxt->bFound = TRUE;
*pbContinue=FALSE;
@@ -217,13 +220,13 @@ BOOL WINAPI GetRpcServerAddressInProcess(DWORD Pid,RpcCoreInternalCtxt_T* pRpcCo
CHAR ModuleFileName[MAX_PATH];
BOOL bResult=FALSE;
hProcess = OpenProcess(PROCESS_ALL_ACCESS, FALSE, Pid);
hProcess = ProcexpOpenProcess(PROCESS_ALL_ACCESS, FALSE, Pid);
if (hProcess == NULL) goto End;
EnumProcessModulesEx(hProcess, NULL, 0, &cbSize, LIST_MODULES_ALL);
if (cbSize == 0) goto End;
if (!EnumProcessModulesEx(hProcess, NULL, 0, &cbSize, LIST_MODULES_ALL)) goto End;
pHmodule = (HMODULE*)malloc(cbSize);
EnumProcessModulesEx(hProcess, pHmodule, cbSize, &cbSize, LIST_MODULES_ALL);
if (pHmodule == NULL) goto End;
if (!EnumProcessModulesEx(hProcess, pHmodule, cbSize, &cbSize, LIST_MODULES_ALL)) goto End;
for(ULONG i=0;i<cbSize/sizeof(*pHmodule);i++)
{
@@ -242,6 +245,7 @@ BOOL WINAPI GetRpcServerAddressInProcess(DWORD Pid,RpcCoreInternalCtxt_T* pRpcCo
{
if (!ReadProcessMemory(hProcess,pCandidate,&pRpcServer,sizeof(VOID PTR_T),NULL)) goto NextCandidate;
if (!ReadProcessMemory(hProcess,pRpcServer,&RpcServer,sizeof(RpcServer),NULL)) goto NextCandidate;
GetRpcServerAddressCallbackCtxt.pRpcServer = pRpcServer;
if (!EnumSimpleDict(hProcess,&RpcServer.InterfaceDict,&GetRpcServerAddressCallback,&GetRpcServerAddressCallbackCtxt)) goto End;
if (GetRpcServerAddressCallbackCtxt.bFound==TRUE)
{
@@ -267,7 +271,7 @@ End:
//------------------------------------------------------------------------------
VOID* __fastcall RpcCoreInit()
VOID* __fastcall RpcCoreInit(BOOL bForce)
{
UINT64 RuntimVersion;
RpcCoreInternalCtxt_T* pRpcCoreInternalCtxt=NULL;
@@ -285,8 +289,13 @@ VOID* __fastcall RpcCoreInit()
if (GetSystemDirectoryW(RpcRuntimePath,_countof(RpcRuntimePath))==0) goto End;
StringCbPrintfW(RpcRuntimePath,sizeof(RpcRuntimePath),L"%s\\rpcrt4.dll",RpcRuntimePath);
RuntimVersion=GetModuleVersion(RpcRuntimePath);
for (i = 0; i < sizeof(RPC_CORE_RUNTIME_VERSION); i++)
for (i = 0; i < _countof(RPC_CORE_RUNTIME_VERSION); i++)
{
if (bForce && ((RuntimVersion & 0xFFFFFFFF00000000) == (RPC_CORE_RUNTIME_VERSION[i] & 0xFFFFFFFF00000000)))
{
bFound = TRUE;
break;
}
if (RuntimVersion == RPC_CORE_RUNTIME_VERSION[i])
{
bFound = TRUE;
@@ -393,7 +402,7 @@ RpcProcessInfo_T* __fastcall RpcCoreGetProcessInfo(void* pRpcCoreCtxt,DWORD Pid,
pRpcProcessInfo->ParentPid = Ppid;
pRpcProcessInfo->RpcProcessType = RpcProcessType_UNKNOWN;
hProcess=OpenProcess(PROCESS_VM_READ|PROCESS_QUERY_INFORMATION,FALSE,Pid);
hProcess=ProcexpOpenProcess(PROCESS_VM_READ|PROCESS_QUERY_INFORMATION,FALSE,Pid);
if (hProcess!=NULL)
{
#ifdef _WIN64
@@ -813,7 +822,7 @@ RpcInterfaceInfo_T* __fastcall RpcCoreGetInterfaceInfo(void* pRpcCoreCtxt,DWORD
RpcInterfaceInfo_T* pRpcInterfaceInfo = NULL;
pRpcCoreInternalCtxt = (RpcCoreInternalCtxt_T*)pRpcCoreCtxt;
hProcess = OpenProcess(PROCESS_VM_READ | PROCESS_QUERY_INFORMATION, FALSE, Pid);
hProcess = ProcexpOpenProcess(PROCESS_VM_READ | PROCESS_QUERY_INFORMATION, FALSE, Pid);
if (hProcess == NULL) { DEBUG_BREAK(); goto End; }
pRpcInterface = GetProcessInterface(pRpcCoreInternalCtxt, hProcess, pIf);
@@ -855,7 +864,7 @@ BOOL __fastcall RpcCoreEnumProcessInterfaces(void* pRpcCoreCtxt,DWORD Pid,RpcCor
RpcInterfaceInfo_T* pRpcInterfaceInfo = NULL;
RpcCoreInternalCtxt_T* pRpcCoreInternalCtxt=(RpcCoreInternalCtxt_T*)pRpcCoreCtxt;
hProcess=OpenProcess(PROCESS_VM_READ|PROCESS_QUERY_INFORMATION,FALSE,Pid);
hProcess=ProcexpOpenProcess(PROCESS_VM_READ|PROCESS_QUERY_INFORMATION,FALSE,Pid);
if (hProcess==NULL) goto End;
if (!ReadProcessMemory(hProcess,pRpcCoreInternalCtxt->pGlobalRpcServer,&pRpcServer,sizeof(VOID PTR_T),NULL)) goto End;
@@ -907,7 +916,7 @@ BOOL __fastcall RpcCoreEnumProcessEndpoints(void* pRpcCoreCtxt,DWORD Pid,RpcCore
BOOL bContinue=TRUE;
RpcCoreInternalCtxt_T* pRpcCoreInternalCtxt=(RpcCoreInternalCtxt_T*)pRpcCoreCtxt;
hProcess=OpenProcess(PROCESS_VM_READ,FALSE,Pid);
hProcess=ProcexpOpenProcess(PROCESS_VM_READ,FALSE,Pid);
if (hProcess==NULL) goto End;
if (!ReadProcessMemory(hProcess,pRpcCoreInternalCtxt->pGlobalRpcServer,&pRpcServer,sizeof(VOID PTR_T),NULL)) goto End;
@@ -1006,7 +1015,7 @@ BOOL __fastcall RpcCoreEnumProcessAuthInfo(void* pRpcCoreCtxt,DWORD Pid,RpcCoreE
if (RegOpenKeyExW(HKEY_LOCAL_MACHINE,L"SOFTWARE\\Microsoft\\Rpc\\SecurityService",0,KEY_READ,&hKey)!=ERROR_SUCCESS) goto End;
if (EnumerateSecurityPackagesW(&PackagesCount,&SecurityPackageInfoTbl)!=SEC_E_OK) goto End;
hProcess=OpenProcess(PROCESS_VM_READ|PROCESS_QUERY_INFORMATION,FALSE,Pid);
hProcess=ProcexpOpenProcess(PROCESS_VM_READ|PROCESS_QUERY_INFORMATION,FALSE,Pid);
if (hProcess==NULL) goto End;
if (!ReadProcessMemory(hProcess,pRpcCoreInternalCtxt->pGlobalRpcServer,&pRpcServer,sizeof(VOID PTR_T), NULL)) goto End;
+2 -1
View File
@@ -178,7 +178,7 @@ typedef BOOL (__fastcall* RpcCoreEnumProcessAuthInfoCallbackFn_T)(DWORD Pid, Rpc
// Type definitions
////////////////////////////////////////////////////////////////////////////////
typedef VOID* (__fastcall* RpcCoreInitFn_T)();
typedef VOID* (__fastcall* RpcCoreInitFn_T)(BOOL bForce);
typedef VOID (__fastcall* RpcCoreUninitFn_T)(VOID* pRpcCoreCtxt);
typedef RpcProcessInfo_T* (__fastcall* RpcCoreGetProcessInfoFn_T)(void* pRpcCoreCtxt, DWORD Pid, DWORD Ppid,ULONG ProcessInfoMask);
typedef VOID (__fastcall* RpcCoreFreeProcessInfoFn_T)(void* pRpcCoreCtxt, RpcProcessInfo_T* pRpcProcessInfo);
@@ -193,6 +193,7 @@ typedef struct _RpcCore_T{
UINT64* RuntimeVersion; //the supported version (forx example 0x600011DB04001LL (6.1.7600.16385) for Windows 7 64bits )
//const char* pDescription;
BOOL bWow64Helper;
BOOL bForceLoading;
RpcCoreInitFn_T RpcCoreInitFn;
RpcCoreUninitFn_T RpcCoreUninitFn;
RpcCoreGetProcessInfoFn_T RpcCoreGetProcessInfoFn;
+13 -2
View File
@@ -13,7 +13,18 @@ static UINT64 RPC_CORE_RUNTIME_VERSION[] = {
0x600011DB149E0LL, //6.1.7601.18912
0x600011DB149F5LL, //6.1.7601.18933
0x600011DB149FBLL, //6.1.7601.18939
0x600011DB15B7BLL //6.1.7601.23419
0x600011DB14ABFLL, //6.1.7601.19135
0x600011DB15B7BLL, //6.1.7601.23419
0x600011DB15CA2LL, //6.1.7601.23714
0x600011DB15D08LL, //6.1.7601.23816
0x600011DB15D6BLL, //6.1.7601.23915
0x600011DB15E35LL, //6.1.7601.24117
0x600011DB15EC4LL, //6.1.7601.24260
0x600011DB15EE3LL, //6.1.7601.24291
0x600011DB15EF4LL, //6.1.7601.24308
0x600011DB15F0FLL, //6.1.7601.24335
0x600011DB15F58LL, //6.1.7601.24408
0x600011DB15F79LL //6.1.7601.24441
};
#ifdef _WIN64
@@ -112,4 +123,4 @@ typedef struct _RPC_ADDRESS_T {
#pragma pack()
#endif // _RPC_INTERNALS_H_
#endif // _RPC_INTERNALS_H_
+13 -2
View File
@@ -12,7 +12,18 @@ static UINT64 RPC_CORE_RUNTIME_VERSION[] = {
0x600011DB149E0LL, //6.1.7601.18912
0x600011DB149F5LL, //6.1.7601.18933
0x600011DB149FBLL, //6.1.7601.18939
0x600011DB15B7BLL //6.1.7601.23419
0x600011DB14ABFLL, //6.1.7601.19135
0x600011DB15B7BLL, //6.1.7601.23419
0x600011DB15CA2LL, //6.1.7601.23714
0x600011DB15D08LL, //6.1.7601.23816
0x600011DB15D6BLL, //6.1.7601.23915
0x600011DB15E35LL, //6.1.7601.24117
0x600011DB15EC4LL, //6.1.7601.24260
0x600011DB15EE3LL, //6.1.7601.24291
0x600011DB15EF4LL, //6.1.7601.24308
0x600011DB15F0FLL, //6.1.7601.24335
0x600011DB15F58LL, //6.1.7601.24408
0x600011DB15F79LL //6.1.7601.24441
};
#define RPC_CORE_DESCRIPTION "Windows 7 SP1 64bits runtime core"
@@ -116,4 +127,4 @@ typedef struct _RPC_ADDRESS_T {
#pragma pack()
#endif // _RPC_INTERNALS_H_
#endif // _RPC_INTERNALS_H_
+65 -16
View File
@@ -4,31 +4,80 @@
#include <windows.h>
#include <Rpc.h>
static UINT64 RPC_CORE_RUNTIME_VERSION[] = {
0x6000324D70000LL, //6.3.9431.0000
0x6000325804000LL, //6.3.9600.16384
0x6000325804340LL, //6.3.9600.17216
0x6000325804407LL, //6.3.9600.17415
0x60003258045FFLL, //6.3.9600.17919
0xA000028004000LL, //10.0.10240.16384
0x6000324D70000LL, //6.3.9431.0000
0x6000325804000LL, //6.3.9600.16384
0x6000325804340LL, //6.3.9600.17216
0x6000325804407LL, //6.3.9600.17415
0x60003258045FFLL, //6.3.9600.17919
0x6000325804774LL, //6.3.9600.18292
0x6000325804AE8LL, //6.3.9600.19176
0x6000325804C52LL, //6.3.9600.19538
0xA000028004000LL, //10.0.10240.16384
0xA00002800401CLL, //10.0.10240.16412
0xA0000295A0000LL, //10.0.10586.0
0xA0000295A0132LL, //10.0.10586.306
0xA0000380603E8LL, //10.0.14342.1000
0xA000038190000LL, //10.0.14361.0
0xA000038390000LL, //10.0.14393.0
0xA000038390052LL, //10.0.14393.82
0xA0000280041C9LL, //10.0.10240.16841
0xA0000295A0000LL, //10.0.10586.0
0xA0000295A0132LL, //10.0.10586.306
0xA0000295A0498LL, //10.0.10586.1176
0xA0000380603E8LL, //10.0.14342.1000
0xA000038190000LL, //10.0.14361.0
0xA000038390000LL, //10.0.14393.0
0xA000038390052LL, //10.0.14393.82
0xA0000383906EALL, //10.0.14393.1770
0xA000038390908LL, //10.0.14393.2312
0xA000038390A69LL, //10.0.14393.2665
0xA000038390C2BLL, //10.0.14393.3115
0xA00003AD70000LL, //10.0.15063.0
0xA00003AD701BFLL, //10.0.15063.447
0xA00003AD702A2LL, //10.0.15063.674
0xA00003F6803E8LL, //10.0.16232.1000
0xA00003FAB000FLL, //10.0.16299.15
0xA00003FAB00C0LL, //10.0.16299.192
0xA00003FAB0135LL, //10.0.16299.309
0xA00003FAB0173LL, //10.0.16299.371
0xA00003FAB01ECLL, //10.0.16299.492
0xA00003FAB02D6LL, //10.0.16299.726
0xA00003FAB034ELL, //10.0.16299.846
0xA0000427903E8LL, //10.0.17017.1000
0xA0000428103E8LL, //10.0.17025.1000
0xA000042B203EALL, //10.0.17074.1002
0xA000042EE0001LL, //10.0.17134.1
0xA000042EE0030LL, //10.0.17134.48
0xA000042EE0070LL, //10.0.17134.112
0xA000042EE00E4LL, //10.0.17134.228
0xA000042EE0197LL, //10.0.17134.407
0xA000042EE01D7LL, //10.0.17134.471
0xA000042EE0288LL, //10.0.17134.648
0xA000042EE046ALL, //10.0.17134.1130
0xA000045630001LL, //10.0.17763.1
0xA000045630086LL, //10.0.17763.134
0xA0000456300C2LL, //10.0.17763.194
0xA00004563017BLL, //10.0.17763.379
0xA0000456302CFLL, //10.0.17763.719
0xA000045630360LL, //10.0.17763.864
0xA000045630629LL, //10.0.17763.1577
0xA0000456306A1LL, //10.0.17763.1697
0xA000045630757LL, //10.0.17763.1879
0xA0000456307CFLL, //10.0.17763.1999
0xA000047BA0001LL, //10.0.18362.1
0xA000047BA01DCLL, //10.0.18362.476
0xA000047BA0274LL, //10.0.18362.628
0xA00004A610001LL, //10.0.19041.1
0xA00004A6101FCLL, //10.0.19041.508
0xA00004A610222LL, //10.0.19041.546
0xA00004A610276LL, //10.0.19041.630
0xA00004A610296LL, //10.0.19041.662
0xA00004A6102EALL, //10.0.19041.746
0xA00004A61041CLL, //10.0.19041.1052
0xA00004A610439LL, //10.0.19041.1081,
0xA00004A610508LL, //10.0.19041.1288,
0xA0000536A0001LL, //10.0.21354.1,
0xA000055EC0001LL, //10.0.21996.1,
0xA000055F00001LL //10.0.22000.1
};
#ifdef _WIN64
#define RPC_CORE_DESCRIPTION "Windows 10 64bits wow64 runtime core"
#define RPC_CORE_DESCRIPTION "Windows 10/11 64bits wow64 runtime core"
#define RPC_CORE_IS_WOW64 TRUE
#define PTR_T *__ptr32 //WOW64!!!
#define ULONG_PTR_T ULONG
@@ -131,4 +180,4 @@ typedef struct _RPC_ADDRESS_T{
#pragma pack()
#endif // _RPC_INTERNALS_H_
#endif // _RPC_INTERNALS_H_
+65 -14
View File
@@ -5,27 +5,78 @@
#include <Rpc.h>
static UINT64 RPC_CORE_RUNTIME_VERSION[] = {
0x6000324D70000LL, //6.3.9431.0000
0x6000325804000LL, //6.3.9600.16384
0x6000325804340LL, //6.3.9600.17216
0x6000325804407LL, //6.3.9600.17415
0x60003258045FFLL, //6.3.9600.17919
0xA000028004000LL, //10.0.10240.16384
0x6000324D70000LL, //6.3.9431.0000
0x6000325804000LL, //6.3.9600.16384
0x6000325804340LL, //6.3.9600.17216
0x6000325804407LL, //6.3.9600.17415
0x60003258045FFLL, //6.3.9600.17919
0x6000325804774LL, //6.3.9600.18292
0x6000325804AE8LL, //6.3.9600.19176
0x6000325804C52LL, //6.3.9600.19538
0xA000028004000LL, //10.0.10240.16384
0xA00002800401CLL, //10.0.10240.16412
0xA0000295A0000LL, //10.0.10586.0
0xA0000295A0132LL, //10.0.10586.306
0xA0000380603E8LL, //10.0.14342.1000
0xA000038190000LL, //10.0.14361.0
0xA000038390000LL, //10.0.14393.0
0xA0000280041C9LL, //10.0.10240.16841
0xA0000295A0000LL, //10.0.10586.0
0xA0000295A0132LL, //10.0.10586.306
0xA0000295A0498LL, //10.0.10586.1176
0xA0000380603E8LL, //10.0.14342.1000
0xA000038190000LL, //10.0.14361.0
0xA000038390000LL, //10.0.14393.0
0xA000038390052LL, //10.0.14393.82
0xA0000383906EALL, //10.0.14393.1770
0xA000038390908LL, //10.0.14393.2312
0xA000038390A69LL, //10.0.14393.2665
0xA000038390C2BLL, //10.0.14393.3115
0xA00003AD70000LL, //10.0.15063.0
0xA00003AD701BFLL, //10.0.15063.447
0xA00003AD702A2LL, //10.0.15063.674
0xA00003F6803E8LL, //10.0.16232.1000
0xA00003FAB000FLL, //10.0.16299.15
0xA00003FAB00C0LL, //10.0.16299.192
0xA00003FAB0135LL, //10.0.16299.309
0xA00003FAB0173LL, //10.0.16299.371
0xA00003FAB01ECLL, //10.0.16299.492
0xA00003FAB02D6LL, //10.0.16299.726
0xA00003FAB034ELL, //10.0.16299.846
0xA0000427903E8LL, //10.0.17017.1000
0xA0000428103E8LL, //10.0.17025.1000
0xA000042B203EALL, //10.0.17074.1002
0xA000042EE0001LL, //10.0.17134.1
0xA000042EE0030LL, //10.0.17134.48
0xA000042EE0070LL, //10.0.17134.112
0xA000042EE00E4LL, //10.0.17134.228
0xA000042EE0197LL, //10.0.17134.407
0xA000042EE01D7LL, //10.0.17134.471
0xA000042EE0288LL, //10.0.17134.648
0xA000042EE046ALL, //10.0.17134.1130
0xA000045630001LL, //10.0.17763.1
0xA000045630086LL, //10.0.17763.134
0xA0000456300C2LL, //10.0.17763.194
0xA00004563017BLL, //10.0.17763.379
0xA0000456302CFLL, //10.0.17763.719
0xA000045630360LL, //10.0.17763.864
0xA000045630629LL, //10.0.17763.1577
0xA0000456306A1LL, //10.0.17763.1697
0xA000045630757LL, //10.0.17763.1879
0xA0000456307CFLL, //10.0.17763.1999
0xA000047BA0001LL, //10.0.18362.1
0xA000047BA01DCLL, //10.0.18362.476
0xA000047BA0274LL, //10.0.18362.628
0xA00004A610001LL, //10.0.19041.1
0xA00004A6101FCLL, //10.0.19041.508
0xA00004A610222LL, //10.0.19041.546
0xA00004A610276LL, //10.0.19041.630
0xA00004A610296LL, //10.0.19041.662
0xA00004A6102EALL, //10.0.19041.746
0xA00004A61041CLL, //10.0.19041.1052
0xA00004A610439LL, //10.0.19041.1081,
0xA00004A610508LL, //10.0.19041.1288,
0xA0000536A0001LL, //10.0.21354.1
0xA000055EC0001LL, //10.0.21996.1,
0xA000055F00001LL //10.0.22000.1
};
#define RPC_CORE_DESCRIPTION "Windows 10 64bits runtime core"
#define RPC_CORE_DESCRIPTION "Windows 10/11 64bits runtime core"
#define RPC_CORE_IS_WOW64 FALSE
#define ULONG_PTR_T ULONG_PTR
@@ -131,4 +182,4 @@ typedef struct _RPC_ADDRESS_T{
#pragma pack()
#endif // _RPC_INTERNALS_H_
#endif // _RPC_INTERNALS_H_
+2 -2
View File
@@ -22,8 +22,8 @@
//
1 VERSIONINFO
FILEVERSION _RPCVIEW_VERSION_MAJOR_,_RPCVIEW_VERSION_MINOR_,_RPCVIEW_VERSION_RELEASE_,0
PRODUCTVERSION _RPCVIEW_VERSION_MAJOR_,_RPCVIEW_VERSION_MINOR_,_RPCVIEW_VERSION_RELEASE_,0
FILEVERSION _RPCVIEW_VERSION_MAJOR_,_RPCVIEW_VERSION_MINOR_,_RPCVIEW_VERSION_RELEASE_,_RPCVIEW_VERSION_BUILD_
PRODUCTVERSION _RPCVIEW_VERSION_MAJOR_,_RPCVIEW_VERSION_MINOR_,_RPCVIEW_VERSION_RELEASE_,_RPCVIEW_VERSION_BUILD_
FILEFLAGSMASK 0x0L
#ifdef _DEBUG
FILEFLAGS 0x1L
+34 -30
View File
@@ -30,7 +30,7 @@ IdlInterface* IdlFunction::getpIdlInterface() const
size_t IdlFunction::getNbArguments() const
{
return (size_t)m_ProcHeader.oifheader.bNumber_of_params;
return (size_t)m_ProcHeader.oifheader.number_of_param;
}
bool IdlFunction::hasRangeOnConformance() const
@@ -235,6 +235,7 @@ DECOMP_STATUS IdlFunction::decodeProcHeader(void* pCtx)
if(bResult == FALSE)
{
RPC_ERROR_FN("can not read explicit bind handle");
return DS_ERR_UNABLE_TO_READ_MEMORY;
}
@@ -244,7 +245,6 @@ DECOMP_STATUS IdlFunction::decodeProcHeader(void* pCtx)
default:
RPC_ERROR_FN("invalid explicit handle type\n");
return DS_ERR_INVALID_DATA;
break;
}
}
@@ -259,6 +259,7 @@ DECOMP_STATUS IdlFunction::decodeProcHeader(void* pCtx)
sizeof(this->m_ProcHeader.oifheader));
if (bResult == FALSE){
RPC_ERROR_FN("can not read oif header\n");
return DS_ERR_UNABLE_TO_READ_MEMORY; ;
}
@@ -267,42 +268,45 @@ DECOMP_STATUS IdlFunction::decodeProcHeader(void* pCtx)
//========================================================
// Read Win32Ext header part of header
//========================================================
// TODO : check under which condition win32Kext header is present
bResult = RPC_GET_PROCESS_DATA2(
(pRpcDecompilerCtxt->pRpcDecompilerInfo->pProcFormatString + uOffsetInProcFmtString),
&(this->m_ProcHeader.win2KextHeader.extension_version),
sizeof(this->m_ProcHeader.win2KextHeader.extension_version));
if (bResult == FALSE){
return DS_ERR_UNABLE_TO_READ_MEMORY; ;
}
switch (this->m_ProcHeader.win2KextHeader.extension_version)
if (this->m_ProcHeader.oifheader.interpreter_opt_flag.HasExtensions)
{
case WIN2K_EXT_HEADER_32B_SIZE:
bResult = RPC_GET_PROCESS_DATA2(
(pRpcDecompilerCtxt->pRpcDecompilerInfo->pProcFormatString + uOffsetInProcFmtString),
&(this->m_ProcHeader.win2KextHeader.extension_version),
WIN2K_EXT_HEADER_32B_SIZE
);
sizeof(this->m_ProcHeader.win2KextHeader.extension_version));
uOffsetInProcFmtString += WIN2K_EXT_HEADER_32B_SIZE;
if (bResult == FALSE){
RPC_ERROR_FN("can not read win32ext header\n");
return DS_ERR_UNABLE_TO_READ_MEMORY;
}
break;
case WIN2K_EXT_HEADER_64B_SIZE:
bResult = RPC_GET_PROCESS_DATA2(
(pRpcDecompilerCtxt->pRpcDecompilerInfo->pProcFormatString + uOffsetInProcFmtString),
&(this->m_ProcHeader.win2KextHeader.extension_version),
WIN2K_EXT_HEADER_64B_SIZE
);
uOffsetInProcFmtString += WIN2K_EXT_HEADER_64B_SIZE;
break;
switch (this->m_ProcHeader.win2KextHeader.extension_version)
{
case WIN2K_EXT_HEADER_32B_SIZE:
bResult = RPC_GET_PROCESS_DATA2(
(pRpcDecompilerCtxt->pRpcDecompilerInfo->pProcFormatString + uOffsetInProcFmtString),
&(this->m_ProcHeader.win2KextHeader.extension_version),
WIN2K_EXT_HEADER_32B_SIZE
);
default:
return DS_ERR_INVALID_DATA;
uOffsetInProcFmtString += WIN2K_EXT_HEADER_32B_SIZE;
break;
case WIN2K_EXT_HEADER_64B_SIZE:
bResult = RPC_GET_PROCESS_DATA2(
(pRpcDecompilerCtxt->pRpcDecompilerInfo->pProcFormatString + uOffsetInProcFmtString),
&(this->m_ProcHeader.win2KextHeader.extension_version),
WIN2K_EXT_HEADER_64B_SIZE
);
uOffsetInProcFmtString += WIN2K_EXT_HEADER_64B_SIZE;
break;
default:
RPC_ERROR_FN("invalid win32k header len");
return DS_ERR_INVALID_DATA;
}
}
m_uOffsetFirstArg = uOffsetInProcFmtString;
+20 -2
View File
@@ -546,7 +546,7 @@ BOOL __fastcall processCorrelationDescriptorNaked(
ss << "StructMember"<<std::dec<<uCorrDescMember;
strCorrelationItem = ss.str();
}
else if(confDesc.corrDesc.correlation_type & FC_POINTER_CONFORMANCE) // case of FC_TOP_LEVEL_MULTID_CONFORMANCE
else if(confDesc.corrDesc.correlation_type & FC_TOP_LEVEL_MULTID_CONFORMANCE) // case of FC_TOP_LEVEL_MULTID_CONFORMANCE
{
// currently not implemented
oss<<"/*FC_TOP_LEVEL_MULTID_CONFORMANCE not implemented */)]";
@@ -597,7 +597,25 @@ BOOL __fastcall processCorrelationDescriptorNaked(
{
case FC_DEREFERENCE:
oss << "*" << strCorrelationItem;
// the correlation item describing the size of the current item
// can derive from an out parameter. In that case, we can only set it
// has a max range and not the exact size since it's not known before the call.
// Ex :
// HRESULT Proc0 (
// [in] int arg1,
// [out] int *arg2,
// [out][size_is( , *arg2)] int **arg2
// );
if (paramDesc.isOut())
{
oss << ", *" << strCorrelationItem;
}
else
{
oss << "*" << strCorrelationItem;
}
break;
case FC_ADD_1:
+3 -7
View File
@@ -92,9 +92,9 @@ bool TypeToDefine::operator<( const TypeToDefine& right)
{
return (this->m_rva < right.m_rva);
}
bool TypeToDefine::operator== ( const TypeToDefine& right)
bool operator== ( const TypeToDefine& self, const TypeToDefine& right)
{
return (this->m_rva == right.m_rva);
return (self.m_rva == right.m_rva);
}
@@ -215,8 +215,4 @@ void ParamDesc::fillWithParamAttr(_In_ PARAM_ATTRIBUTES paramAttr)
// TODO how to handle simple ref ?
if(paramAttr.IsSimpleRef) m_uPtrLevel++;
//....
}
}
+4 -8
View File
@@ -1,7 +1,7 @@
#include "internalRpcUtils.h"
#include <list>
#include <sstream>
#include <codecvt>
//--------------------------------------------------------------------------
BOOL __fastcall isStandardCharacter(_In_ const WCHAR wc)
@@ -32,14 +32,10 @@ BOOL __fastcall isStandardCharacter(_In_ const WCHAR wc)
std::string narrow(
_In_ const std::wstring& ws)
{
//std::vector<char> buffer(ws.size());
////std::locale loc("english");
//std::locale loc;
//std::use_facet< std::ctype<wchar_t> > (loc).narrow(ws.data(), ws.data() + ws.size(), '?', &buffer[0]);
using convert_typeX = std::codecvt_utf8<wchar_t>;
std::wstring_convert<convert_typeX, wchar_t> converterX;
//return std::string(&buffer[0], buffer.size());
return std::string(ws.begin(), ws.end());
return converterX.to_bytes(ws);
}
-123
View File
@@ -39,7 +39,6 @@ extern "C" {
BOOL __fastcall RpcDecompilerPrintOneProcedure(VOID* pRpcDecompilerCtxt, UINT ProcIndex, std::list<TypeToDefine>& listProcType, std::ostringstream& ossProc);
BOOL __fastcall RpcDecompilerDecodeOneProcedureInlined(VOID* pContext, UINT ProcIndex, IdlFunctionDesc& IdlFunctionDesc, std::list<TypeToDefine>& listProcType);
BOOL __fastcall RpcDecompilerPrintOneProcedureInlined(VOID* pContext, UINT ProcOffset, IdlFunctionDesc& IdlFunctionDesc, std::list<TypeToDefine>& listProcType, std::ostringstream& ossProc);
BOOL __fastcall RpcDecompilerPrintHiddenFUProcedure(VOID* pRpcDecompilerCtxt, UINT * procOffset, std::list<TypeToDefine>& listProcType, std::ostringstream& ossProc);
BOOL __fastcall RpcDecompilerPrintAllProceduresNew(VOID* pRpcDecompilerCtxt);
@@ -445,128 +444,6 @@ End:
return (bResult);
}
BOOL __fastcall RpcDecompilerPrintHiddenFUProcedure(VOID* pContext, UINT * procOffset, std::list<TypeToDefine>& listProcType, std::ostringstream& ossProc)
{
UINT paramSizeInBytes = RPC_DECOMPILER_INVALID_PARAM_SIZE;
BOOL bResult = FALSE;
RpcDecompilerCtxt_T* pRpcDecompilerCtxt = (RpcDecompilerCtxt_T*)pContext;
UINT paramOffset = 0;
UINT numParam = 0;
BOOL isReturnParam = FALSE;
BOOL nextIsReturnParam = FALSE;
UINT sizeOfProcDescr = 0;
IdlFunctionDesc IdlFunctionDesc;
if (pRpcDecompilerCtxt == NULL) goto End;
if (pRpcDecompilerCtxt->pRpcViewHelper == NULL) goto End;
if (pRpcDecompilerCtxt->pRpcDecompilerInfo == NULL) goto End;
if (pRpcDecompilerCtxt->pRpcDecompilerInfo->pProcFormatString == NULL) goto End;
RVA_T pFunction = pRpcDecompilerCtxt->pRpcDecompilerInfo->pProcFormatString + *procOffset;
// carriage return before display function
//ossProc << "\t/* Function 0x" << std::hex << ProcIndex<< " */"<< std::endl;
ossProc << std::endl;
//RpcDecompilerPrintFunctionDbgInfo(pContext, *procOffset, ossProc);
ossProc << "\t /* Function index : 0x" << std::hex << *procOffset;
ossProc << "\t Module Base : 0x" << (unsigned long) pRpcDecompilerCtxt->pRpcDecompilerInfo->pModuleBase;
ossProc << "\t RVA of proc in format string : 0x" << (unsigned long) ((UINT64)pFunction - pRpcDecompilerCtxt->pRpcDecompilerInfo->pModuleBase);
ossProc << " */"<<std::endl;
//todo
bResult = RpcDecompilerDecodeAndPrintPrototypeReturnType(
/* in */ pRpcDecompilerCtxt,
/* in */ *procOffset,
/* out */ &paramOffset,
/* out */ &sizeOfProcDescr,
/* out */ IdlFunctionDesc,
/* in/out */listProcType,
/* in/out */ ossProc);
if (bResult == FALSE) goto End;
ossProc << " _HiddenFunction_" << std::dec << *procOffset << "(";
// Increment procOffset to read the next procedure description
*procOffset += sizeOfProcDescr;
if (bResult == FALSE) goto End;
RPC_DEBUG_FN((UCHAR*)"\nRpcDecompilerPrintProcedure: RpcDecompilerPrintPrototypeName returned nbParamToPrint = %d\n", IdlFunctionDesc.getNbParam());
if(IdlFunctionDesc.getNbParam() == 0)
{
//No parameter to be printed
ossProc << " void ";
}
//Print each parameter
while( (numParam < IdlFunctionDesc.getNbParam()) )
{
RPC_DEBUG_FN((UCHAR*)"\nRpcDecompilerPrintProcedure: numParam = 0x%x on total to print = 0x%x\n", numParam, IdlFunctionDesc.getNbParam());
bResult = RpcDecompilerGetReturnParamInfo(/* in */ pRpcDecompilerCtxt, /* in */ paramOffset, /* in */ paramDescrOif, /* out */ &isReturnParam);
if (bResult == FALSE) goto End;
if( ! isReturnParam)
{
//Print the parameter
bResult = RpcDecompilerPrintParam(
/* in */ pRpcDecompilerCtxt,
/* in */ paramOffset,
/* in */ paramDescrOif,
/* out */ &paramSizeInBytes,
/* in */ IdlFunctionDesc,
listProcType,
ossProc); //TODO : décompiler paramDescrOi en plus de paramDescrOif
if (bResult == FALSE || paramSizeInBytes == RPC_DECOMPILER_INVALID_PARAM_SIZE)
{
displayErrorMessage(ossProc, "RpcDecompilerPrintOneProcedure : unable to decode param");
goto End;
}
}
else
{
paramSizeInBytes = OIF_PARAM_SIZE; //TODO : traiter le cas où codage pas OIF
}
paramOffset += paramSizeInBytes;//paramSizeInBytes;
numParam++;
RPC_DEBUG_FN((UCHAR*)"\nRpcDecompilerPrintProcedure: paramOffset = %d, numParam = %d\n", paramOffset, numParam);
//Is there one additionnal parameter to be printed ?
if ( (! isReturnParam) && (numParam < IdlFunctionDesc.getNbParam()) )
{
//The last parameter has been printed because it was not a return parameter
//There is still at least 1 parameter to be printed
bResult = RpcDecompilerGetReturnParamInfo(/* in */ pRpcDecompilerCtxt, /* in */ paramOffset, /* in */ paramDescrOif, /* out */ &nextIsReturnParam);
if (bResult == FALSE) goto End;
if (! nextIsReturnParam)
{
//The next parameter will have to be printed because it is not a return parameter
ossProc << ", ";
}
}
}//while(numParam <= IdlFunctionDesc.getNbParam());
// Print the end of the procedure prototype
ossProc<<");"<<std::endl;
bResult = TRUE;
End:
return (bResult);
}
//------------------------------------------------------------------------------
VOID __fastcall RpcDecompilerPrintFunctionDbgInfo(VOID* pContext, UINT procIndex, std::ostringstream& oss)
{
+2 -2
View File
@@ -22,8 +22,8 @@
//
1 VERSIONINFO
FILEVERSION _RPCVIEW_VERSION_MAJOR_,_RPCVIEW_VERSION_MINOR_,_RPCVIEW_VERSION_RELEASE_,0
PRODUCTVERSION _RPCVIEW_VERSION_MAJOR_,_RPCVIEW_VERSION_MINOR_,_RPCVIEW_VERSION_RELEASE_,0
FILEVERSION _RPCVIEW_VERSION_MAJOR_,_RPCVIEW_VERSION_MINOR_,_RPCVIEW_VERSION_RELEASE_, _RPCVIEW_VERSION_BUILD_
PRODUCTVERSION _RPCVIEW_VERSION_MAJOR_,_RPCVIEW_VERSION_MINOR_,_RPCVIEW_VERSION_RELEASE_, _RPCVIEW_VERSION_BUILD_
FILEFLAGSMASK 0x0L
#ifdef _DEBUG
FILEFLAGS 0x1L
+2 -1
View File
@@ -1043,7 +1043,7 @@ BOOL __fastcall processComplexArray(
oss<<" /* ";
for(j; j<i; j++){
if(callbacksCalled[j] != -1)
if(callbacksCalled[j] != (UINT16)-1)
{
oss<<" callback_"<<std::dec<<callbacksCalled[j]<<" used, ";
}
@@ -1104,6 +1104,7 @@ UINT __fastcall getArrayMemorySize(
case FC_LGVARRAY:
RPC_GET_PROCESS_DATA(pType, &longArray, sizeof(LGFixedSizedArrayHeader_t));
arraySize = longArray.totalSize;
break;
default:
arraySize = POINTER_SIZE;
break;
+2 -11
View File
@@ -242,7 +242,7 @@ typedef struct Oif_Header_t
as the SERVER_MUST_SIZE flag triggers the sizing. */
INTERPRETER_OPT_FLAGS interpreter_opt_flag; // Voir interpreter_opt_flag values
unsigned char number_of_param; // Nombre de paramètres décrits de la procédure, return compris
}Oif_Header_t;
}Oif_Header_t, OIF_HEADER_T;
//------------------------------------------------------------------------------
// _MIDL_PROC_FORMAT_STRING types :
@@ -324,15 +324,6 @@ typedef struct _OI_HEADER_T
OI_HEADER_END_T end;
}OI_HEADER_T;
// Oif fields
typedef struct _OIF_HEADER_T
{
WORD wConstant_client_buffer_size;
WORD wConstant_server_buffer_size;
BYTE bINTERPRETER_OPT_FLAGS;
BYTE bNumber_of_params;
}OIF_HEADER_T;
//
// Procedure header
typedef struct _PROC_HEADER_T
@@ -1994,7 +1985,7 @@ public:
// operator
bool operator<( const TypeToDefine& right);
bool operator== ( const TypeToDefine& right);
friend bool operator==( const TypeToDefine& self, const TypeToDefine& right);
};
+1 -1
View File
@@ -248,7 +248,7 @@ BOOL __fastcall RpcDecompilerDecodeAndPrintPrototypeReturnType(
);
currentOffset += sizeof(Oi_Header_RpcFlags_t);
RPC_DEBUG_FN((UCHAR*)"\noiHeaderRpcFlagsToDecode->rpc_flags = 0x%x", oiHeaderRpcFlagsToDecode->rpc_flags);
//RPC_DEBUG_FN((UCHAR*)"\noiHeaderRpcFlagsToDecode->rpc_flags = 0x%x", oiHeaderRpcFlagsToDecode->rpc_flags);
}
+7 -11
View File
@@ -10,8 +10,8 @@ set(CMAKE_INCLUDE_CURRENT_DIR ON)
set(CMAKE_AUTOMOC ON)
# Find the QtWidgets library
# set CMAKE_PREFIX_PATH=c:\Qt\4.8.6
find_package(Qt4 REQUIRED QtGui QtCore)
# set CMAKE_PREFIX_PATH=C:\Qt\Qt5.9.1\5.9.1\msvc2015 or c:\Qt\Qt5.9.1\5.9.1\msvc2015_64
find_package(Qt5Widgets)
add_executable(
RpcView
@@ -43,12 +43,8 @@ add_executable(
RpcViewResource.rc
)
if(${CMAKE_GENERATOR} MATCHES "Win64")
message(STATUS "Target is 64 bits")
target_link_libraries(RpcView ../../../Qt/lib/x64/QtGui ../../../Qt/lib/x64/QtCore)
target_link_libraries(RpcView Qt4::QtGui Qt4::QtCore)
else(${CMAKE_GENERATOR} MATCHES "Win64")
message(STATUS "Target is 32 bits")
target_link_libraries(RpcView ../../../Qt/lib/x86/QtGui ../../../Qt/lib/x86/QtCore)
target_link_libraries(RpcView Qt4::QtGui Qt4::QtCore)
endif(${CMAKE_GENERATOR} MATCHES "Win64")
# Disable compiler warnings:
# C4091 in ShlObj.h and Dbghelp.h
# C4127 (conditional expression is constant) in qt headers
set_target_properties(${PROJECT_NAME} PROPERTIES COMPILE_FLAGS "/wd4091 /wd4127 /wd4714")
target_link_libraries(RpcView Qt5::Widgets $ENV{CMAKE_PREFIX_PATH}/lib/Qt5WinExtras.lib)
+1
View File
@@ -89,6 +89,7 @@ void ConfigurationVisitor_C::Visit(InterfaceInfoWidget_C* pInterfaceInfoWidget)
void ConfigurationVisitor_C::Visit(ProcessInfoWidget_C* pProcessInfoWidget)
{
//nothing to do here
UNREFERENCED_PARAMETER(pProcessInfoWidget);
}
//------------------------------------------------------------------------------
+4 -3
View File
@@ -10,10 +10,10 @@ void DecompilationWidget_C::InsertText(const char* Txt)
{
/*
pTextEdit->moveCursor(QTextCursor::End);
pTextEdit->append( QString::fromAscii(Txt) );
pTextEdit->append( QString::fromLatin1(Txt) );
pTextEdit->ensureCursorVisible();
*/
pTextEdit->setText( QString::fromAscii(Txt) );
pTextEdit->setText( QString::fromLatin1(Txt) );
pTextEdit->ensureCursorVisible();
}
@@ -22,6 +22,7 @@ DecompilationWidget_C::DecompilationWidget_C(QWidget *parent) : QDockWidget(Widg
{
QFont font;
UNREFERENCED_PARAMETER(parent);
setObjectName(WidgetName);
font.setFamily("Courier");
@@ -30,7 +31,7 @@ DecompilationWidget_C::DecompilationWidget_C(QWidget *parent) : QDockWidget(Widg
pTextEdit = new QTextEdit(this);
pTextEdit->setLineWrapMode(QTextEdit::NoWrap);
pTextEdit->setFont(font);
pTextEdit->setTabStopWidth(font.pointSize()*TAB_AS_CHARS);
pTextEdit->setTabStopDistance(font.pointSize()*TAB_AS_CHARS);
pIdlHighlighter = new IdlHighlighter_C(pTextEdit->document());
setWidget(pTextEdit);
+1
View File
@@ -26,6 +26,7 @@ EndpointSelectedVisitor_C::EndpointSelectedVisitor_C(quint32 Pid,RpcCore_T* pRpc
void EndpointSelectedVisitor_C::Visit(EndpointsWidget_C* pEndpointsWidget)
{
//nothing to do here
UNREFERENCED_PARAMETER(pEndpointsWidget);
}
+3 -1
View File
@@ -65,7 +65,7 @@ ULONG EndpointsWidget_C::GetTotalEndpoints()
//------------------------------------------------------------------------------
void EndpointsWidget_C::SnapEndpoint()
{
PrivateItemList = pModel->findItems(".*", Qt::MatchRegExp, Column_Name);
PrivateItemList = pModel->findItems(".*", Qt::MatchRegularExpression, Column_Name);
}
@@ -85,6 +85,8 @@ bool EndpointsWidget_C::IsEndpointsPresent(quint32 Pid, WCHAR* pName,WCHAR* pPro
QList<QStandardItem*> ItemList;
bool bResult = false;
UNREFERENCED_PARAMETER(Pid);
ItemList = pModel->findItems(QString::fromUtf16((const ushort*)pName), Qt::MatchFixedString, Column_Name);
if (ItemList.isEmpty()) goto End;
+5 -1
View File
@@ -18,6 +18,7 @@ typedef struct _EnumCtxt_T{
//------------------------------------------------------------------------------
static BOOL WINAPI EnumProc(DWORD Pid, DWORD Ppid, EnumCtxt_T* pEnumCtxt, BOOL* pbContinue)
{
UNREFERENCED_PARAMETER(pbContinue);
ProcessEntry_C* pProcessEntry = new ProcessEntry_C(Ppid,Pid);
pEnumCtxt->pInitViewsVisitor->ProcessVector.push_back(pProcessEntry);
@@ -33,7 +34,7 @@ InitViewsVisitor_C::InitViewsVisitor_C(RpcCore_T* pRpcCore,void** ppRpcCoreCtxt)
this->pRpcCore= pRpcCore;
this->NbOfInterfaces = 0;
this->pRpcCoreCtxt = pRpcCore->RpcCoreInitFn();
this->pRpcCoreCtxt = pRpcCore->RpcCoreInitFn(pRpcCore->bForceLoading);
if (this->pRpcCoreCtxt==NULL) goto End;
*ppRpcCoreCtxt = this->pRpcCoreCtxt;
@@ -126,6 +127,7 @@ void InitViewsVisitor_C::Visit(InterfacesWidget_C* pInterfacesWidget)
void InitViewsVisitor_C::Visit(InterfaceInfoWidget_C* pInterfaceInfoWidget)
{
//nothing to do here
UNREFERENCED_PARAMETER(pInterfaceInfoWidget);
}
@@ -133,6 +135,7 @@ void InitViewsVisitor_C::Visit(InterfaceInfoWidget_C* pInterfaceInfoWidget)
void InitViewsVisitor_C::Visit(ProcessInfoWidget_C* pProcessInfoWidget)
{
//nothing to do here
UNREFERENCED_PARAMETER(pProcessInfoWidget);
}
@@ -140,6 +143,7 @@ void InitViewsVisitor_C::Visit(ProcessInfoWidget_C* pProcessInfoWidget)
void InitViewsVisitor_C::Visit(ProceduresWidget_C* pProceduresWidget)
{
//nothing to do here
UNREFERENCED_PARAMETER(pProceduresWidget);
}
+5 -3
View File
@@ -158,15 +158,15 @@ End:
}
//------------------------------------------------------------------------------
void InterfaceInfoWidget_C::SetAddressRepresentation(AddressRepresentation_T AddressRepresentation)
void InterfaceInfoWidget_C::SetAddressRepresentation(AddressRepresentation_T AddrRepresentation)
{
this->AddressRepresentation = AddressRepresentation;
this->AddressRepresentation = AddrRepresentation;
pCallbackAddress->setText("");
pTypeFormatString->setText("");
pProcFormatString->setText("");
pExpressionEvaluation->setText("");
switch (AddressRepresentation)
switch (AddrRepresentation)
{
case AddressRepresentation_RVA:
if ((IfCallback != 0) && (IfCallback!=INVALID_IF_CALLBACK_ADDRESS)) pCallbackAddress->setText(QString("+0x%1").arg(IfCallback - Base, 8, 16, QLatin1Char('0')));
@@ -198,6 +198,8 @@ void InterfaceInfoWidget_C::AcceptVisitor(ViewVisitor_C* pVisitor)
//------------------------------------------------------------------------------
InterfaceInfoWidget_C::InterfaceInfoWidget_C(QWidget* pParent):QDockWidget(WidgetName)
{
UNREFERENCED_PARAMETER(pParent);
this->Pid = 0;
setObjectName(WidgetName);
+16 -4
View File
@@ -8,6 +8,10 @@
#include "../RpcCommon/Misc.h"
#include "Pdb.h"
#include <Dbghelp.h>
#include <strsafe.h>
static WCHAR FullPath[MAX_PATH];
static RPC_WSTR pUuidString = NULL;
//------------------------------------------------------------------------------
InterfaceSelectedVisitor_C::InterfaceSelectedVisitor_C(quint32 Pid, RPC_IF_ID* pIf,RpcCore_T* pRpcCore,void* pRpcCoreCtxt)
@@ -18,12 +22,15 @@ InterfaceSelectedVisitor_C::InterfaceSelectedVisitor_C(quint32 Pid, RPC_IF_ID* p
this->pRpcCoreCtxt = pRpcCoreCtxt;
this->pRpcInterfaceInfo = pRpcCore->RpcCoreGetInterfaceInfoFn( pRpcCoreCtxt, Pid, pIf, RPC_INTERFACE_INFO_ALL );
UuidToStringW(&pIf->Uuid, &pUuidString);
GetFullPathNameW(L"RpcView.ini", _countof(FullPath), FullPath, NULL);
}
//------------------------------------------------------------------------------
InterfaceSelectedVisitor_C::~InterfaceSelectedVisitor_C()
{
RpcStringFreeW(&pUuidString);
if (pRpcInterfaceInfo != NULL)
{
pRpcCore->RpcCoreFreeInterfaceInfoFn(pRpcCoreCtxt, pRpcInterfaceInfo);
@@ -43,6 +50,7 @@ void InterfaceSelectedVisitor_C::Visit(EndpointsWidget_C* pEndpointsWidget)
void InterfaceSelectedVisitor_C::Visit(InterfacesWidget_C* pInterfacesWidget)
{
//nothing todo
UNREFERENCED_PARAMETER(pInterfacesWidget);
}
//------------------------------------------------------------------------------
@@ -59,7 +67,7 @@ void InterfaceSelectedVisitor_C::Visit(InterfaceInfoWidget_C* pInterfaceInfoWidg
SymbolName[0]=0;
if (pRpcInterfaceInfo->pLocationBase!=NULL)
{
hProcess=OpenProcess(PROCESS_ALL_ACCESS,FALSE,Pid);
hProcess=ProcexpOpenProcess(PROCESS_ALL_ACCESS,FALSE,Pid);
if (hProcess==NULL) goto End;
hPdb = PdbInit(hProcess, pRpcInterfaceInfo->pLocationBase, pRpcInterfaceInfo->LocationSize);
@@ -119,9 +127,7 @@ void InterfaceSelectedVisitor_C::Visit(ProceduresWidget_C* pProceduresWidget)
WCHAR SymbolName[RPC_MAX_LENGTH];
ULONG ProcIdx;
VOID* ProcFormat = NULL;
LPCWSTR pProcName = NULL;
VOID* hPdb = NULL;
UCHAR* ProcAddress = NULL;
if (pRpcInterfaceInfo==NULL) goto End;
pProceduresWidget->reset(pRpcInterfaceInfo->Pid);
@@ -134,7 +140,7 @@ void InterfaceSelectedVisitor_C::Visit(ProceduresWidget_C* pProceduresWidget)
case IfType_RPC:
if (pRpcInterfaceInfo->pLocationBase==NULL) goto End;
hProcess=OpenProcess(PROCESS_ALL_ACCESS,FALSE,Pid);
hProcess=ProcexpOpenProcess(PROCESS_ALL_ACCESS,FALSE,Pid);
if (hProcess==NULL) goto End;
hPdb = PdbInit(hProcess, pRpcInterfaceInfo->pLocationBase, pRpcInterfaceInfo->LocationSize);
@@ -147,6 +153,12 @@ void InterfaceSelectedVisitor_C::Visit(ProceduresWidget_C* pProceduresWidget)
{
PdbGetSymbolName(hPdb, (UCHAR*)pRpcInterfaceInfo->pLocationBase + pRpcInterfaceInfo->ppProcAddressTable[ProcIdx], SymbolName, sizeof(SymbolName));
}
if (SymbolName[0] == 0) {
WCHAR ProcIdxName[10];
StringCbPrintfW(ProcIdxName, sizeof(ProcIdxName), L"Proc%u", ProcIdx);
GetPrivateProfileStringW((LPCWSTR)pUuidString, ProcIdxName, NULL, SymbolName, sizeof(SymbolName)/sizeof(SymbolName[0]), FullPath);
}
if ( (pRpcInterfaceInfo->pFormatStringOffsetTable==NULL)||
(pRpcInterfaceInfo->pProcFormatString==NULL))
{
+11 -10
View File
@@ -48,13 +48,15 @@ void InterfacesWidget_C::InterfaceSelected(const QModelIndex& Index)
{
QStringList PidStringList;
QStringList VersionStringList;
QByteArray UuidStringARef;
RPC_IF_ID RpcIfId;
UCHAR* pUuidStringA;
QString& PidString = pProxyModel->data( pProxyModel->index(Index.row(), Column_Pid) ).toString();
pUuidStringA = (UCHAR*)pProxyModel->data( pProxyModel->index(Index.row(), Column_Uuid) ).toString().toLatin1().data();
QString& VersionString = pProxyModel->data( pProxyModel->index(Index.row(), Column_Version) ).toString();
VersionStringList = VersionString.split(".", QString::SkipEmptyParts, Qt::CaseSensitive);
QString PidString = pProxyModel->data( pProxyModel->index(Index.row(), Column_Pid) ).toString();
UuidStringARef = pProxyModel->data(pProxyModel->index(Index.row(), Column_Uuid)).toString().toLatin1();
pUuidStringA = (UCHAR*)UuidStringARef.data();
QString VersionString = pProxyModel->data( pProxyModel->index(Index.row(), Column_Version) ).toString();
VersionStringList = VersionString.split(".", Qt::SkipEmptyParts, Qt::CaseSensitive);
if (VersionStringList.isEmpty())
{
@@ -107,7 +109,7 @@ void InterfacesWidget_C::ApplyProcessFilter(quint32 Pid)
//------------------------------------------------------------------------------
void InterfacesWidget_C::SnapInterfaces()
{
PrivateItemList = pModel->findItems(".*", Qt::MatchRegExp, Column_Uuid);
PrivateItemList = pModel->findItems(".*", Qt::MatchRegularExpression, Column_Uuid);
}
@@ -129,7 +131,7 @@ bool InterfacesWidget_C::IsInterfacePresent(quint32 Pid, RPC_IF_ID* pIfId)
if ( UuidToStringA(&pIfId->Uuid,&pUuidString)!=RPC_S_OK ) goto End;
ItemList = pModel->findItems(QString::fromAscii((const char*)pUuidString), Qt::MatchFixedString, Column_Uuid);
ItemList = pModel->findItems(QString::fromLatin1((const char*)pUuidString), Qt::MatchFixedString, Column_Uuid);
if (ItemList.isEmpty()) goto End;
for (auto Iter=ItemList.begin();Iter!=ItemList.end();Iter++)
@@ -248,7 +250,6 @@ bool InterfacesWidget_C::AddInterfaces(RpcInterfaceInfo_T* pRpcInterfaceInfo)
int Index;
QString PidString;
WCHAR* pUuidString = NULL;
WCHAR* pTransfertSyntaxString = NULL;
WCHAR* pTypeW = NULL;
WCHAR* pStubW = NULL;
@@ -324,7 +325,7 @@ bool InterfacesWidget_C::AddInterfaces(RpcInterfaceInfo_T* pRpcInterfaceInfo)
if (pRpcInterfaceInfo->LocationState & MEM_FREE) SetRowColor(Index, QColor(200, 200, 200, 180));
if (!memcmp(&pRpcInterfaceInfo->TransfertSyntax,&DceRpcSyntaxUuid,sizeof(DceRpcSyntaxUuid)))
pModel->setData(pModel->index(Index, Column_TransfertSyntax), QString::fromAscii("DCE"));
pModel->setData(pModel->index(Index, Column_TransfertSyntax), QString::fromLatin1("DCE"));
else if (!memcmp(&pRpcInterfaceInfo->TransfertSyntax,&Ndr64SyntaxUuid,sizeof(Ndr64SyntaxUuid)))
pModel->setData(pModel->index(Index, Column_TransfertSyntax), QString::fromUtf16((const ushort*)L"NDR64"));
else
@@ -396,9 +397,9 @@ void InterfacesWidget_C::UpdateColumnsVisibility()
//------------------------------------------------------------------------------
void InterfacesWidget_C::SetAddressRepresentation(AddressRepresentation_T AddressRepresentation)
void InterfacesWidget_C::SetAddressRepresentation(AddressRepresentation_T AddrRepresentation)
{
switch (AddressRepresentation)
switch (AddrRepresentation)
{
case AddressRepresentation_RVA:
for (int i = 0; i < pModel->rowCount(); i++)
+62 -28
View File
@@ -19,8 +19,18 @@
#define BELOW_NORMAL_REFRESH_SPEED 2000
#define SLOW_REFRESH_SPEED 5000
#define VERY_SLOW_REFRESH_SPEED 10000
#define MANUAL_REFRESH_SPEED 0
#define SHELL_EXECUTE_SUCCESS ((HINSTANCE)42) // According to the doc, welcome the 16-bit compatibilty
#ifdef __cplusplus
extern "C" {
#endif
extern RpcCore_T gRpcCoreManager;
#ifdef __cplusplus
}
#endif
extern ULONG NTAPI DecompilerExceptionFilter(EXCEPTION_POINTERS* pExceptionPointers);
extern HMODULE NTAPI LoadDecompilerEngine(RpcDecompilerHelper_T** ppRpcDecompilerHelper);
@@ -32,9 +42,9 @@ static const char WidgetName[] = "RpcView";
//------------------------------------------------------------------------------
void MainWindow_C::InterfaceSelected(quint32 Pid, RPC_IF_ID* pIf)
{
CHAR SymbolPath;
CHAR SymbolPath[MAX_PATH] = {0};
if (GetEnvironmentVariableA("RpcViewSymbolPath",&SymbolPath,sizeof(SymbolPath))==0)
if (GetEnvironmentVariableA("RpcViewSymbolPath",SymbolPath,sizeof(SymbolPath))==0)
{
StatusBar.showMessage("Symbol path not configured.");
}
@@ -132,7 +142,7 @@ bool MainWindow_C::eventFilter(QObject* pObject, QEvent* pEvent)
{
if (pEvent->type() == QEvent::ContextMenu)
{
QPoint& position = QCursor::pos();
QPoint position = QCursor::pos();
//
// Show the context menu associatd to columns
//
@@ -183,7 +193,7 @@ BOOL __fastcall RpcGetProcessData(RpcModuleInfo_T* pRpcModuleInfo, RVA_T Rva, VO
if (pRpcModuleInfo == NULL) goto End;
pAddress = (VOID*)(pRpcModuleInfo->pModuleBase + Rva);
hProcess = OpenProcess(PROCESS_VM_READ | PROCESS_QUERY_INFORMATION, FALSE, pRpcModuleInfo->Pid);
hProcess = ProcexpOpenProcess(PROCESS_VM_READ | PROCESS_QUERY_INFORMATION, FALSE, pRpcModuleInfo->Pid);
if (hProcess == NULL) goto End;
bResult = ReadProcessMemory(hProcess, pAddress, pBuffer, BufferLength, NULL);
End:
@@ -207,8 +217,9 @@ VOID __cdecl RpcPrint(void* pContext, const char* pTxt)
VOID __cdecl RpcDebug(const char* pFunction, ULONG Line, const char* pFormatString, ...)
{
va_list Arg;
va_start(Arg, pFormatString);
UNREFERENCED_PARAMETER(pFunction);
UNREFERENCED_PARAMETER(Line);
va_start(Arg, pFormatString);
_vcprintf(pFormatString, Arg);
}
@@ -260,6 +271,10 @@ void MainWindow_C::SlotDecompileInterface(quint32 Pid, RPC_IF_ID* pIf)
if (pRpcInterfaceInfo == NULL) goto End;
InitDecompilerInfo(pRpcInterfaceInfo, &RpcDecompilerInfo);
__try{
if (!this->pDecompilationWidget->isVisible())
this->pDecompilationWidget->show();
RpcViewHelper_T LocalRpcViewHelper = {
this->pDecompilationWidget,
&RpcAlloc,
@@ -298,7 +313,10 @@ void MainWindow_C::ViewDetailsForAllProcesses()
UCHAR FilePath[MAX_PATH];
GetModuleFileNameA(NULL,(LPSTR)FilePath,_countof(FilePath));
hInstance = ShellExecuteA(NULL, "runas", (LPCSTR)FilePath, 0, 0, SW_SHOWNORMAL);
if (gRpcCoreManager.bForceLoading)
hInstance = ShellExecuteA(NULL, "runas", (LPCSTR)FilePath, "/f", 0, SW_SHOWNORMAL);
else
hInstance = ShellExecuteA(NULL, "runas", (LPCSTR)FilePath, 0, 0, SW_SHOWNORMAL);
if ( hInstance == SHELL_EXECUTE_SUCCESS)
{
Exit();
@@ -384,7 +402,8 @@ void MainWindow_C::SendVisitor(ViewVisitor_C& Visitor)
//------------------------------------------------------------------------------
void MainWindow_C::closeEvent(QCloseEvent *event)
{
Exit();
UNREFERENCED_PARAMETER(event);
Exit();
}
@@ -447,7 +466,7 @@ void MainWindow_C::ConfigureSymbols()
if ( bOk )
{
pSettings->setValue("SymbolsPath",NewSymbolsPath);
SetEnvironmentVariableA("RpcViewSymbolPath",NewSymbolsPath.toAscii());
SetEnvironmentVariableA("RpcViewSymbolPath",NewSymbolsPath.toLatin1());
}
}
@@ -456,6 +475,7 @@ void MainWindow_C::ConfigureSymbols()
void MainWindow_C::SetUpdateSpeedAsFast()
{
this->RefreshSpeedInMs = FAST_REFRESH_SPEED;
pRefreshTimer->start();
pRefreshTimer->setInterval(this->RefreshSpeedInMs);
}
@@ -464,6 +484,7 @@ void MainWindow_C::SetUpdateSpeedAsFast()
void MainWindow_C::SetUpdateSpeedAsNormal()
{
this->RefreshSpeedInMs = NORMAL_REFRESH_SPEED;
pRefreshTimer->start();
pRefreshTimer->setInterval(this->RefreshSpeedInMs);
}
@@ -472,6 +493,7 @@ void MainWindow_C::SetUpdateSpeedAsNormal()
void MainWindow_C::SetUpdateSpeedAsBelowNormal()
{
this->RefreshSpeedInMs = BELOW_NORMAL_REFRESH_SPEED;
pRefreshTimer->start();
pRefreshTimer->setInterval(this->RefreshSpeedInMs);
}
@@ -480,6 +502,7 @@ void MainWindow_C::SetUpdateSpeedAsBelowNormal()
void MainWindow_C::SetUpdateSpeedAsSlow()
{
this->RefreshSpeedInMs = SLOW_REFRESH_SPEED;
pRefreshTimer->start();
pRefreshTimer->setInterval(this->RefreshSpeedInMs);
}
@@ -488,9 +511,17 @@ void MainWindow_C::SetUpdateSpeedAsSlow()
void MainWindow_C::SetUpdateSpeedAsVerySlow()
{
this->RefreshSpeedInMs = VERY_SLOW_REFRESH_SPEED;
pRefreshTimer->start();
pRefreshTimer->setInterval(this->RefreshSpeedInMs);
}
//------------------------------------------------------------------------------
void MainWindow_C::SetUpdateSpeedAsManual()
{
this->RefreshSpeedInMs = MANUAL_REFRESH_SPEED;
pRefreshTimer->stop();
}
//------------------------------------------------------------------------------
void MainWindow_C::InvokeFindShortcut()
@@ -554,15 +585,15 @@ void MainWindow_C::SetupMenu()
//
QMenu* pMenuFile = pMenuBar->addMenu("&File");
QAction* pActionAllProcessesDetails = pMenuFile->addAction("Show &Details for All Processes",this,SLOT(ViewDetailsForAllProcesses()));
QAction* pActionFileExit = pMenuFile->addAction("E&xit",this,SLOT(Exit()));
pMenuFile->addAction("E&xit",this,SLOT(Exit()));
//
// Option
//
QMenu* pMenuOptions = pMenuBar->addMenu("&Options");
QAction* pActionConfigureSymbols = pMenuOptions->addAction("Configure Sym&bols",this,SLOT(ConfigureSymbols()));
pMenuOptions->addAction("Configure Sym&bols",this,SLOT(ConfigureSymbols()));
QMenu* pSubMenupdateSpeed = pMenuOptions->addMenu("&Refresh Speed");
QAction* pActionRefresh = pMenuOptions->addAction("Refresh &Now", this, SLOT(RefreshViews()));
QAction* pActionViewSelectColumns = pMenuOptions->addAction("Select Col&umns", this, SLOT(ShowColumnsDialog()));
pMenuOptions->addAction("Select Col&umns", this, SLOT(ShowColumnsDialog()));
QMenu* pSubMenuAddress = pMenuOptions->addMenu("&Address");
pActionRefresh->setShortcut(Qt::Key_F5);
@@ -581,12 +612,14 @@ void MainWindow_C::SetupMenu()
pActionSpeedBelowNormal = pSubMenupdateSpeed->addAction("2 seconds", this, SLOT(SetUpdateSpeedAsBelowNormal()));
pActionSpeedSlow = pSubMenupdateSpeed->addAction("5 seconds", this, SLOT(SetUpdateSpeedAsSlow()));
pActionSpeedVerySlow = pSubMenupdateSpeed->addAction("10 seconds", this, SLOT(SetUpdateSpeedAsVerySlow()));
pActionSpeedManual = pSubMenupdateSpeed->addAction("manual", this, SLOT(SetUpdateSpeedAsManual()));
pActionSpeedFast->setCheckable(true);
pActionSpeedNormal->setCheckable(true);
pActionSpeedBelowNormal->setCheckable(true);
pActionSpeedSlow->setCheckable(true);
pActionSpeedVerySlow->setCheckable(true);
pActionSpeedManual->setCheckable(true);
QActionGroup* pSpeedActionGroup = new QActionGroup(this);
@@ -595,6 +628,7 @@ void MainWindow_C::SetupMenu()
pSpeedActionGroup->addAction(pActionSpeedBelowNormal);
pSpeedActionGroup->addAction(pActionSpeedSlow);
pSpeedActionGroup->addAction(pActionSpeedVerySlow);
pSpeedActionGroup->addAction(pActionSpeedManual);
//
// View
//
@@ -616,9 +650,9 @@ void MainWindow_C::SetupMenu()
// Filter
//
QMenu* pMenuFilter = pMenuBar->addMenu("Fil&ter");
QAction* pActionFilterProcesses = pMenuFilter->addAction("&Process", this, SLOT(FilterProcesses()));
QAction* pActionFilterEndpoints = pMenuFilter->addAction("&Endpoints", this, SLOT(FilterEndpoints()));
QAction* pActionFilterInterfaces = pMenuFilter->addAction("&Interfaces", this, SLOT(FilterInterfaces()));
pMenuFilter->addAction("&Process", this, SLOT(FilterProcesses()));
pMenuFilter->addAction("&Endpoints", this, SLOT(FilterEndpoints()));
pMenuFilter->addAction("&Interfaces", this, SLOT(FilterInterfaces()));
//
// Help
//
@@ -628,15 +662,15 @@ void MainWindow_C::SetupMenu()
//--
pMenuHelp->addSeparator();
//--
QAction* pActionAbout = pMenuHelp->addAction("&About", this, SLOT(About()));
pActionAboutQt = pMenuHelp->addAction("About &Qt", qApp, SLOT(aboutQt()));
pMenuHelp->addAction("&About", this, SLOT(About()));
pMenuHelp->addAction("About &Qt", qApp, SLOT(aboutQt()));
if (IsUserAnAdmin()) pActionAllProcessesDetails->setEnabled(false);
hUacIcon = LoadIcon(GetModuleHandle(NULL), MAKEINTRESOURCE(ID_UAC_ICON));
if (hUacIcon!=NULL)
{
pActionAllProcessesDetails->setIcon(QPixmap::fromWinHICON(hUacIcon));
pActionAllProcessesDetails->setIcon(QtWin::fromHICON(hUacIcon));
DestroyIcon(hUacIcon);
}
setMenuBar(pMenuBar);
@@ -653,6 +687,7 @@ void MainWindow_C::InitMenuRefreshSpeed()
case BELOW_NORMAL_REFRESH_SPEED : pActionSpeedBelowNormal->setChecked(true); break;
case SLOW_REFRESH_SPEED : pActionSpeedSlow->setChecked(true); break;
case VERY_SLOW_REFRESH_SPEED : pActionSpeedVerySlow->setChecked(true); break;
case MANUAL_REFRESH_SPEED : pActionSpeedManual->setChecked(true); break;
//--
default:
break;
@@ -729,12 +764,11 @@ MainWindow_C::MainWindow_C(RpcCore_T* pRpcCore)
setStatusBar(&StatusBar);
HANDLE hIcon = LoadImageA(GetModuleHandle(NULL), MAKEINTRESOURCE(ID_MAIN_ICON), IMAGE_ICON, 0, 0, 0);
QFont font("Helvetica", 20, QFont::Bold);
#ifndef _DEBUG
QSplashScreen SplashScreen(QPixmap::fromWinHICON((HICON)hIcon),Qt::WindowStaysOnTopHint);
HANDLE hIcon = LoadImageA(GetModuleHandle(NULL), MAKEINTRESOURCE(ID_MAIN_ICON), IMAGE_ICON, 0, 0, 0);
QSplashScreen SplashScreen(QtWin::fromHICON((HICON)hIcon),Qt::WindowStaysOnTopHint);
SplashScreen.showMessage(QString("RpcView"), Qt::AlignCenter, QColor(Qt::lightGray));
QFont font("Helvetica", 20, QFont::Bold);
SplashScreen.setFont(font);
SplashScreen.show();
#endif
@@ -780,12 +814,12 @@ MainWindow_C::MainWindow_C(RpcCore_T* pRpcCore)
restoreGeometry( pSettings->value("MainWindow/geometry").toByteArray() );
restoreState( pSettings->value("MainWindow/windowState").toByteArray() );
ConfigurationVisitor_C ConfigurationVisitor(ConfigurationVisitor_C::Load,pSettings);
SendVisitor(ConfigurationVisitor);
ConfigurationVisitor_C ConfigurationVisitorLoad(ConfigurationVisitor_C::Load,pSettings);
SendVisitor(ConfigurationVisitorLoad);
if (AddressRepresentation == AddressRepresentation_RVA)
{
ConfigurationVisitor_C ConfigurationVisitor(ConfigurationVisitor_C::AddressRVA, pSettings);
SendVisitor(ConfigurationVisitor);
ConfigurationVisitor_C ConfigurationVisitorAddr(ConfigurationVisitor_C::AddressRVA, pSettings);
SendVisitor(ConfigurationVisitorAddr);
}
SetEnvironmentVariableA( "RpcViewSymbolPath",pSettings->value("SymbolsPath").toByteArray() );
@@ -797,7 +831,7 @@ MainWindow_C::MainWindow_C(RpcCore_T* pRpcCore)
//
pRefreshTimer = new QTimer(this);
connect(pRefreshTimer, SIGNAL(timeout()), this, SLOT(RefreshViews()));
pRefreshTimer->start(this->RefreshSpeedInMs);
if (this->RefreshSpeedInMs) pRefreshTimer->start(this->RefreshSpeedInMs);
InitColumnsDialog();
}
}
+2 -1
View File
@@ -51,6 +51,7 @@ private slots:
void SetUpdateSpeedAsBelowNormal();
void SetUpdateSpeedAsSlow();
void SetUpdateSpeedAsVerySlow();
void SetUpdateSpeedAsManual();
void ShowColumnsDialog();
void UpdateColumns();
//--
@@ -81,12 +82,12 @@ private:
QAction* pActionViewProcedures;
QAction* pActionViewInterfaceInfo;
QAction* pActionViewProcessInfo;
QAction* pActionAboutQt;
QAction* pActionSpeedFast;
QAction* pActionSpeedNormal;
QAction* pActionSpeedBelowNormal;
QAction* pActionSpeedSlow;
QAction* pActionSpeedVerySlow;
QAction* pActionSpeedManual;
QAction* pAddressAbsolute;
QAction* pAddressRva;
+6 -6
View File
@@ -20,9 +20,9 @@ QString GetProceduresWidgetColumName(ProceduresWigetColumn_T ProceduresWigetColu
//------------------------------------------------------------------------------
void ProceduresWidget_C::reset(ULONG Pid)
void ProceduresWidget_C::reset(ULONG pid)
{
this->Pid = Pid;
this->Pid = pid;
pProcedures->clear();
}
@@ -82,14 +82,14 @@ bool ProceduresWidget_C::AddProcedure(quint32 ProcIdx, WCHAR* pSymbolName, VOID*
//------------------------------------------------------------------------------
void ProceduresWidget_C::SetAddressRepresentation(AddressRepresentation_T AddressRepresentation)
void ProceduresWidget_C::SetAddressRepresentation(AddressRepresentation_T AddrRepresentation)
{
QTreeWidgetItem* pProcedure;
quintptr AbsoluteAddr;
this->AddressRepresentation = AddressRepresentation;
this->AddressRepresentation = AddrRepresentation;
switch (AddressRepresentation)
switch (AddrRepresentation)
{
case AddressRepresentation_RVA:
for (int i = 0; i < pProcedures->topLevelItemCount(); i++)
@@ -207,7 +207,7 @@ ProceduresWidget_C::ProceduresWidget_C(QWidget* pParent):QDockWidget(WidgetName)
pProcedures->setColumnCount(ProceduresWigetColumn_Last);
pProcedures->setSortingEnabled(true);
pProcedures->sortByColumn(-1);
pProcedures->sortByColumn(-1, Qt::AscendingOrder);
pProcedures->setAnimated(true);
pProcedures->expandAll();
pProcedures->setAlternatingRowColors(true);
+4 -1
View File
@@ -122,7 +122,7 @@ void ProcessInfoWidget_C::UpdateProcessInfo(RpcProcessInfo_T* pRpcProcessInfo)
if (pRpcProcessInfo->hIcon!=NULL)
{
pIconLabel->setPixmap( QPixmap::fromWinHICON( pRpcProcessInfo->hIcon ) );
pIconLabel->setPixmap( QtWin::fromHICON( pRpcProcessInfo->hIcon ) );
pIconLabel->show();
DestroyIcon( pRpcProcessInfo->hIcon );
}
@@ -178,6 +178,9 @@ void ProcessInfoWidget_C::AcceptVisitor(ViewVisitor_C* pVisitor)
//------------------------------------------------------------------------------
ProcessInfoWidget_C::ProcessInfoWidget_C(QWidget* pParent):QDockWidget(WidgetName)
{
UNREFERENCED_PARAMETER(pParent);
setObjectName(WidgetName);
pTabWidget = new QTabWidget(this);
+16 -11
View File
@@ -77,8 +77,8 @@ void ProcessWidget_C::SelectProcess(quint32 Pid)
//------------------------------------------------------------------------------
void ProcessWidget_C::SnapProcesses()
{
PrivateTreeItemList = pProcessTree->findItems(".*", Qt::MatchRegExp|Qt::MatchRecursive, Column_Pid);
PrivateViewItemList = pModel->findItems(".*", Qt::MatchRegExp, Column_Pid);
PrivateTreeItemList = pProcessTree->findItems(".*", Qt::MatchRegularExpression |Qt::MatchRecursive, Column_Pid);
PrivateViewItemList = pModel->findItems(".*", Qt::MatchRegularExpression, Column_Pid);
}
@@ -146,6 +146,8 @@ void ProcessWidget_C::ProcessSelected(QTreeWidgetItem* pItem, int Column)
{
quint32 Pid;
UNREFERENCED_PARAMETER(Column);
Pid = pItem->data(Column_Pid,0).toInt();
emit ProcessSelected(Pid);
}
@@ -249,7 +251,7 @@ bool ProcessWidget_C::AddProcess(RpcProcessInfo_T* pRpcProcessInfo)
if ( pRpcProcessInfo->hIcon!=NULL )
{
AddProcessItem(pProcess,Index,Column_Name, Qt::DecorationRole, QIcon( QPixmap::fromWinHICON( pRpcProcessInfo->hIcon ) ) );
AddProcessItem(pProcess,Index,Column_Name, Qt::DecorationRole, QIcon( QtWin::fromHICON( pRpcProcessInfo->hIcon ) ) );
DestroyIcon( pRpcProcessInfo->hIcon );
}
@@ -339,13 +341,15 @@ void ProcessWidget_C::LoadConfiguration(QSettings* pSettings)
//
// Force Tree sorting by PID
//
pProcessTree->sortByColumn(Column_Pid);
pProcessTree->sortByColumn(-1);
pProcessTree->sortByColumn(Column_Pid, Qt::AscendingOrder);
pProcessTree->sortByColumn(-1, Qt::AscendingOrder);
}
//------------------------------------------------------------------------------
void ProcessWidget_C::InitProcessTreeWidget(QWidget* pParent)
{
UNREFERENCED_PARAMETER(pParent);
pProcessTree = new QTreeWidget(this);
QTreeWidgetItem* pHeaderItem = pProcessTree->headerItem();
@@ -354,8 +358,8 @@ void ProcessWidget_C::InitProcessTreeWidget(QWidget* pParent)
pHeaderItem->setText( Idx, GetColumName((Column_T)Idx) );
}
pProcessTree->setColumnCount(Column_Last);
pProcessTree->sortByColumn(Column_Pid);
pProcessTree->sortByColumn(-1);
pProcessTree->sortByColumn(Column_Pid, Qt::AscendingOrder);
pProcessTree->sortByColumn(-1, Qt::AscendingOrder);
pProcessTree->setAnimated(true);
pProcessTree->setSortingEnabled(true);
@@ -374,6 +378,7 @@ void ProcessWidget_C::InitProcessTreeWidget(QWidget* pParent)
//------------------------------------------------------------------------------
void ProcessWidget_C::InitProcessTreeView(QWidget* pParent)
{
UNREFERENCED_PARAMETER(pParent);
pProxyModel = new QSortFilterProxyModel(this);
pProxyModel->setDynamicSortFilter(true);
pProxyModel->setFilterKeyColumn(Column_Pid);
@@ -493,6 +498,8 @@ void ProcessWidget_C::UpdateColumnsVisibility()
// Switch to the view header
void ProcessWidget_C::TreeHeaderClicked(int logicalIndex)
{
UNREFERENCED_PARAMETER(logicalIndex);
if (pStackedWidget->currentWidget()!=pProcessView)
{
pStackedWidget->setCurrentWidget(pProcessView);
@@ -517,8 +524,8 @@ void ProcessWidget_C::ViewHeaderClicked(int logicalIndex)
pStackedWidget->setCurrentWidget(pProcessTree);
pProcessTree->header()->restoreState(pProcessView->header()->saveState());
pProcessTree->sortByColumn(Column_Pid);
pProcessTree->sortByColumn(-1);
pProcessTree->sortByColumn(Column_Pid,Qt::AscendingOrder);
pProcessTree->sortByColumn(-1, Qt::AscendingOrder);
pProcessTree->scrollToItem(pProcessTree->currentItem());
}
}
@@ -527,8 +534,6 @@ void ProcessWidget_C::ViewHeaderClicked(int logicalIndex)
//------------------------------------------------------------------------------
ProcessWidget_C::ProcessWidget_C(QWidget* pParent):QGroupBox(WidgetName)
{
QGridLayout* pGridLayout;
setObjectName(WidgetName);
pStackedWidget = new QStackedWidget(this);
+3
View File
@@ -23,6 +23,7 @@ typedef struct _EnumCtxt_T{
//------------------------------------------------------------------------------
static BOOL WINAPI EnumProc(DWORD Pid, DWORD Ppid, EnumCtxt_T* pEnumCtxt, BOOL* pbContinue)
{
UNREFERENCED_PARAMETER(pbContinue);
ProcessEntry_C* pProcessEntry = new ProcessEntry_C(Ppid,Pid);
pEnumCtxt->pRefreshVisitor->ProcessVector.push_back(pProcessEntry);
@@ -189,6 +190,7 @@ void RefreshVisitor_C::Visit(InterfacesWidget_C* pInterfacesWidget)
void RefreshVisitor_C::Visit(InterfaceInfoWidget_C* pInterfaceInfoWidget)
{
//nothing to do here
UNREFERENCED_PARAMETER(pInterfaceInfoWidget);
}
@@ -210,6 +212,7 @@ void RefreshVisitor_C::Visit(ProcessInfoWidget_C* pProcessInfoWidget)
void RefreshVisitor_C::Visit(ProceduresWidget_C* pProceduresWidget)
{
//nothing to do
UNREFERENCED_PARAMETER(pProceduresWidget);
}
+15 -19
View File
@@ -13,7 +13,7 @@ typedef struct _RpcCoreManager_T{
}RpcCoreManager_T;
// RpcCore
VOID* __fastcall RpcCoreInit(); //returns a private context for the RpcCoreEngine
VOID* __fastcall RpcCoreInit(BOOL bForce); //returns a private context for the RpcCoreEngine
VOID __fastcall RpcCoreUninit(VOID* pRpcCoreCtxt);
RpcProcessInfo_T* __fastcall RpcCoreGetProcessInfo(void* pRpcCoreCtxt, DWORD Pid, DWORD Ppid, ULONG ProcessInfoMask);
VOID __fastcall RpcCoreFreeProcessInfo(void* pRpcCoreCtxt, RpcProcessInfo_T* pRpcProcessInfo);
@@ -29,6 +29,7 @@ RpcCore_T gRpcCoreManager =
0,
//"Generic RpcCore Manager",
FALSE,
FALSE,
&RpcCoreInit,
&RpcCoreUninit,
&RpcCoreGetProcessInfo,
@@ -41,7 +42,7 @@ RpcCore_T gRpcCoreManager =
};
//------------------------------------------------------------------------------
BOOL NTAPI LoadCoreEngine(RpcCore_T** ppRpcCoreHelper, void** ppRpcCoreCtxt, BOOL bWow64Helper)
BOOL NTAPI LoadCoreEngine(RpcCore_T** ppRpcCoreHelper, void** ppRpcCoreCtxt, BOOL bWow64Helper, BOOL bForce)
{
WIN32_FIND_DATAA Win32FindData;
HMODULE hLib;
@@ -57,22 +58,19 @@ BOOL NTAPI LoadCoreEngine(RpcCore_T** ppRpcCoreHelper, void** ppRpcCoreCtxt, BOO
hLib = LoadLibraryA(Win32FindData.cFileName);
if (hLib != NULL)
{
pRpcCoreHelper = (RpcCore_T*)GetProcAddress(hLib, RPC_CORE_EXPORT_SYMBOL);
pRpcCoreHelper = (RpcCore_T*)(ULONG_PTR)GetProcAddress(hLib, RPC_CORE_EXPORT_SYMBOL);
if (pRpcCoreHelper != NULL)
{
*ppRpcCoreCtxt = pRpcCoreHelper->RpcCoreInitFn();
*ppRpcCoreCtxt = pRpcCoreHelper->RpcCoreInitFn(bForce);
if (*ppRpcCoreCtxt != NULL)
{
pRpcCoreHelper->RpcCoreUninitFn(*ppRpcCoreCtxt);
if (bWow64Helper == pRpcCoreHelper->bWow64Helper)
{
// Version.As64BitsValue = pRpcCoreHelper->RuntimeVersion;
_cprintf("RpcCore : %s\n", Win32FindData.cFileName);
// _cprintf("Version : %I64X (%u.%u.%u.%u)\n", Version.As64BitsValue, Version.As16BitsValues.Part4, Version.As16BitsValues.Part3, Version.As16BitsValues.Part2, Version.As16BitsValues.Part1);
_cprintf("Helper : 0x%p\n", pRpcCoreHelper);
_cprintf("Wow64 : ");
if (pRpcCoreHelper->bWow64Helper) _cprintf("TRUE\n"); else _cprintf("FALSE\n");
// _cprintf("Description: %s\n\n", pRpcCoreHelper->pDescription);
*ppRpcCoreHelper = pRpcCoreHelper;
bResult = TRUE;
goto End;
@@ -89,13 +87,14 @@ End:
//-----------------------------------------------------------------------------
VOID* __fastcall RpcCoreInit()
VOID* __fastcall RpcCoreInit(BOOL bForce)
{
RpcCoreManager_T* pRpcCoreManager;
pRpcCoreManager = (RpcCoreManager_T*)OS_ALLOC(sizeof(RpcCoreManager_T));
if (pRpcCoreManager == NULL) return NULL;
if (!LoadCoreEngine(&pRpcCoreManager->pNativeCore, &pRpcCoreManager->pNativeCoreCtxt, FALSE))
if (!LoadCoreEngine(&pRpcCoreManager->pNativeCore, &pRpcCoreManager->pNativeCoreCtxt, FALSE, bForce))
{
const char Caption[] = "Unsupported runtime version";
#ifdef _WIN64
@@ -110,19 +109,16 @@ VOID* __fastcall RpcCoreInit()
#endif
ExitProcess(0);
}
pRpcCoreManager->pNativeCoreCtxt = pRpcCoreManager->pNativeCore->RpcCoreInitFn();
pRpcCoreManager->pNativeCoreCtxt = pRpcCoreManager->pNativeCore->RpcCoreInitFn(bForce);
#ifdef _WIN64
if (!LoadCoreEngine(&pRpcCoreManager->pWow64Core, &pRpcCoreManager->pWow64CoreCtxt, TRUE)) goto Cleanup;
pRpcCoreManager->pWow64CoreCtxt = pRpcCoreManager->pWow64Core->RpcCoreInitFn();
if (!LoadCoreEngine(&pRpcCoreManager->pWow64Core, &pRpcCoreManager->pWow64CoreCtxt, TRUE,bForce))
{
OS_FREE(pRpcCoreManager);
return NULL;
}
pRpcCoreManager->pWow64CoreCtxt = pRpcCoreManager->pWow64Core->RpcCoreInitFn(bForce);
#endif
End:
return (pRpcCoreManager);
#ifdef _WIN64
Cleanup:
#endif
OS_FREE(pRpcCoreManager);
pRpcCoreManager = NULL;
goto End;
}
//-----------------------------------------------------------------------------
+50 -21
View File
@@ -154,7 +154,7 @@ void NTAPI InitDecompilerInfo(_In_ RpcInterfaceInfo_T* pRpcInterfaceInfo, _Out_
pRpcDecompilerInfo->ppProcNameTable = (WCHAR**)OS_ALLOC(pRpcDecompilerInfo->NumberOfProcedures*sizeof(UCHAR*));
if (pRpcDecompilerInfo->ppProcNameTable == NULL) goto End;
hProcess = OpenProcess(PROCESS_ALL_ACCESS, FALSE, pRpcInterfaceInfo->Pid);
hProcess = ProcexpOpenProcess(PROCESS_ALL_ACCESS, FALSE, pRpcInterfaceInfo->Pid);
if (hProcess == NULL) goto End;
#ifdef _WIN64
pRpcDecompilerInfo->bIs64Bits = !pRpcInterfaceInfo->bWow64Process;
@@ -189,7 +189,9 @@ void NTAPI InitDecompilerInfo(_In_ RpcInterfaceInfo_T* pRpcInterfaceInfo, _Out_
{
SymboleLength = ((UINT)wcslen(SymboleName) + 1)*sizeof(WCHAR);
pRpcDecompilerInfo->ppProcNameTable[i] = (WCHAR*)OS_ALLOC(SymboleLength);
memcpy(pRpcDecompilerInfo->ppProcNameTable[i], SymboleName, SymboleLength);
if (pRpcDecompilerInfo->ppProcNameTable[i] != NULL) {
memcpy(pRpcDecompilerInfo->ppProcNameTable[i], SymboleName, SymboleLength);
}
}
}
PdbUninit(hPdb);
@@ -230,6 +232,7 @@ typedef struct _EnumCtxt_T{
//------------------------------------------------------------------------------
VOID __cdecl RpcDbgPrint(void* pContext, const char* pTxt)
{
UNREFERENCED_PARAMETER(pContext);
printf("%s\n", pTxt);
}
@@ -292,7 +295,7 @@ End:
//------------------------------------------------------------------------------
int DecompileAllInterfaces(RpcCore_T* pRpcCore)
{
EnumCtxt_T EnumCtxt;
EnumCtxt_T EnumCtxt = {0};
RpcDecompilerHelper_T* pRpcDecompilerHelper;
HMODULE hDecompiler = NULL;
@@ -301,7 +304,7 @@ int DecompileAllInterfaces(RpcCore_T* pRpcCore)
EnumCtxt.pRpcDecompilerHelper = pRpcDecompilerHelper;
EnumCtxt.pRpcCore = pRpcCore;
EnumCtxt.pRpcCoreCtxt = pRpcCore->RpcCoreInitFn();
EnumCtxt.pRpcCoreCtxt = pRpcCore->RpcCoreInitFn(FALSE);
if (EnumCtxt.pRpcCoreCtxt==NULL) goto End;
_cprintf("Start scanning...\n");
@@ -327,16 +330,30 @@ End:
HICON hMainIcon;
UCHAR CurrentDirectory[MAX_PATH];
UCHAR* pSeparator;
int ret = 0;
#ifdef _DEBUG
_CrtSetReportMode(_CRT_WARN, _CRTDBG_MODE_FILE);
_CrtSetReportFile(_CRT_WARN, _CRTDBG_FILE_STDOUT);
#else
int argc = 1;
char* pCmdLineA = NULL;
char** argv = &pCmdLineA;
int argc = 0;
UNREFERENCED_PARAMETER(hInstance);
UNREFERENCED_PARAMETER(hPrevInstance);
UNREFERENCED_PARAMETER(nCmdShow);
pCmdLine = GetCommandLineW();
pCmdLineA = GetCommandLineA();
LPWSTR* argvw = CommandLineToArgvW(pCmdLine, &argc);
char** argv = (char**)malloc(argc*sizeof(char*));
if (argv == NULL) return ret;
for (int i = 0; i < argc; i++)
{
size_t tmpSize = lstrlenW(argvw[i]) * 2 + 2;
argv[i] = (char*)malloc(tmpSize);
wcstombs_s(&tmpSize, argv[i], tmpSize, argvw[i], tmpSize);
}
#endif
QApplication app(argc, argv);
QSettings Settings(RPC_VIEW_ORGANIZATION_NAME, RPC_VIEW_APPLICATION_NAME);
@@ -351,30 +368,42 @@ End:
_cprintf("%s\n",CurrentDirectory);
SetCurrentDirectoryA((LPCSTR)CurrentDirectory);
}
//
// Load unsupported runtim versions by default
//
gRpcCoreManager.bForceLoading = TRUE;
#ifdef _DEBUG
if (argc>1)
{
if (!_stricmp(argv[1],"/DA"))
for (int curArg = 1; curArg < argc; curArg++)
{
DecompileAllInterfaces(&gRpcCoreManager);
if (!_stricmp(argv[1], "/DA"))
{
DecompileAllInterfaces(&gRpcCoreManager);
_CrtDumpMemoryLeaks();
}
else
{
_cprintf("Usage %s: [/DA]\n", argv[0]);
_cprintf(" /DA : decompile all interfaces\n");
}
}
else
{
_cprintf("Usage %s: [/DA]\n",argv[0]);
_cprintf(" /DA : decompile all interfaces\n");
}
_CrtDumpMemoryLeaks();
return 0;
}
#endif
pMainWindow = new MainWindow_C(&gRpcCoreManager);
hMainIcon = LoadIcon(GetModuleHandle(NULL), MAKEINTRESOURCE(ID_MAIN_ICON));
if (hMainIcon!=NULL)
{
pMainWindow->setWindowIcon(QPixmap::fromWinHICON(hMainIcon));
pMainWindow->setWindowIcon(QtWin::fromHICON(hMainIcon));
DestroyIcon(hMainIcon);
}
return app.exec();
ret = app.exec();
#ifndef _DEBUG
for (int i = 0; i < argc; i++)
free(argv[i]);
free(argv);
#endif
return ret;
}
+2 -2
View File
@@ -23,8 +23,8 @@
//
1 VERSIONINFO
FILEVERSION _RPCVIEW_VERSION_MAJOR_,_RPCVIEW_VERSION_MINOR_,_RPCVIEW_VERSION_RELEASE_,0
PRODUCTVERSION _RPCVIEW_VERSION_MAJOR_,_RPCVIEW_VERSION_MINOR_,_RPCVIEW_VERSION_RELEASE_,0
FILEVERSION _RPCVIEW_VERSION_MAJOR_,_RPCVIEW_VERSION_MINOR_,_RPCVIEW_VERSION_RELEASE_, _RPCVIEW_VERSION_BUILD_
PRODUCTVERSION _RPCVIEW_VERSION_MAJOR_,_RPCVIEW_VERSION_MINOR_,_RPCVIEW_VERSION_RELEASE_, _RPCVIEW_VERSION_BUILD_
FILEFLAGSMASK 0x0L
#ifdef _DEBUG
FILEFLAGS 0x1L
+2 -1
View File
@@ -4,6 +4,7 @@
#define _RPCVIEW_VERSION_MAJOR_ @RPCVIEW_VERSION_MAJOR@
#define _RPCVIEW_VERSION_MINOR_ @RPCVIEW_VERSION_MINOR@
#define _RPCVIEW_VERSION_RELEASE_ @RPCVIEW_VERSION_RELEASE@
#define _RPCVIEW_PRODUCT_VERSION_ "@RPCVIEW_VERSION_MAJOR@.@RPCVIEW_VERSION_MINOR@.@RPCVIEW_VERSION_RELEASE@.0"
#define _RPCVIEW_VERSION_BUILD_ @RPCVIEW_VERSION_BUILD@
#define _RPCVIEW_PRODUCT_VERSION_ "@RPCVIEW_VERSION_MAJOR@.@RPCVIEW_VERSION_MINOR@.@RPCVIEW_VERSION_RELEASE@.@RPCVIEW_VERSION_BUILD@"
#endif
-1
View File
@@ -1 +0,0 @@
theme: jekyll-theme-tactile
+59
View File
@@ -0,0 +1,59 @@
version: 0.3.0.{build}
image: Visual Studio 2019
build_script:
- cmd: >-
cd C:\projects\RpcView
mkdir Build\x64
cd C:\projects\RpcView\Build\x64
set CMAKE_PREFIX_PATH=C:\Qt\5.15.2\msvc2019_64
cmake ..\.. -A x64 -T"v140_xp"
cmake --build . --config release
cd C:\projects\RpcView\Build\x64\bin\Release
mkdir RpcView64
copy *.dll RpcView64\
copy *.exe RpcView64\
C:\Qt\5.15.2\msvc2019_64\bin\windeployqt.exe --release RpcView64\
7z a RpcView64.7z RpcView64
cd C:\projects\RpcView
mkdir Build\x86
cd C:\projects\RpcView\Build\x86
set CMAKE_PREFIX_PATH=C:\Qt\5.15.2\msvc2019
cmake ..\.. -A win32 -T"v140_xp"
cmake --build . --config release
cd C:\projects\RpcView\Build\x86\bin\Release
mkdir RpcView32
copy *.exe RpcView32\
copy *.dll RpcView32\
C:\Qt\5.15.2\msvc2019\bin\windeployqt.exe --release RpcView32\
7z a RpcView32.7z RpcView32
artifacts:
- path: Build\x64\bin\Release\RpcView64.7z
name: RpcView64
- path: Build\x86\bin\Release\RpcView32.7z
name: RpcView32