122 Commits

Author SHA1 Message Date
silverf0x 14d5e1a3b6 add runtime support by OS version 2023-05-31 14:14:28 +02:00
jmpoep 68aef3f2d8 Create cmake.yml 2023-01-02 14:06:14 +01:00
silverf0x 8ad8558760 fix 2022-10-24 21:49:47 +02:00
silverf0x 260e0331d6 fix 32bits QT deployment 2022-10-24 21:43:39 +02:00
silverf0x c460a9d363 add appveyor.yml 2022-06-04 15:07:45 +02:00
Sndav 67696389de Add support for 10.0.17763.1577 2021-10-26 20:50:11 +02:00
Sndav a8cf5f7639 Add support for 10.0.19041.1288 2021-10-26 20:50:11 +02:00
Leonid Shagiev a8e2643da4 Add support for 10.0.19041.1081, 10.0.21354.1, 10.0.21996.1, 10.0.22000.1 2021-08-17 13:44:05 +02:00
Andrey f2eedd35c4 Add support for 10.0.19041.1052 2021-07-14 18:31:40 +02:00
Benjamin DELPY 5851a13a7a Update RpcInternals.h
Add support for 10.0.17763.1999 x86
2021-07-14 18:31:02 +02:00
Benjamin DELPY 8c4207b6e4 Update RpcInternals.h
Add support for 10.0.17763.1999 x64
2021-07-14 18:31:02 +02:00
Alexander Chermyanin 79743458a8 add runtime 10.0.17763.1879 2021-05-23 14:27:26 +02:00
Alexander Chermyanin 18f1963950 add runtime 10.0.17763.1879 2021-05-23 14:27:26 +02:00
Alexander Chermyanin 66288f9366 add runtime 10.0.17763.1697 2021-03-25 21:40:42 +01:00
Alexander Chermyanin e29002562a add runtime 10.0.17763.1697 2021-03-25 21:40:42 +01:00
Alexander Chermyanin 181d018aa8 add runtime 10.0.17763.1697 2021-03-25 21:40:42 +01:00
Alexander Chermyanin 7c7fbb98f4 add runtime version 10.0.17763.1817 2021-03-25 21:40:42 +01:00
Alexander Chermyanin faf4b6a2d3 add runtime version 10.0.17763.1817 2021-03-25 21:40:42 +01:00
silverf0x 5e66d72f9e Disable warning 4714: function marked as __forceinline not inlined 2021-03-06 16:12:04 +01:00
silverf0x f708ab5b62 Update README.md with Visual Studio 2019 2021-03-06 15:27:57 +01:00
silverf0x e254e9ce56 Fix compilation with VS2019 and Qt5.15.2 2021-03-06 15:27:21 +01:00
silverf0x 3c2aaf2971 Merge pull request #47 from M3ikShizuka/master
Add runtime version 10.0.19041.746 and fix generation 'cmake -G \"Visual Studio 16 2019\" -A x64'.
2021-03-06 12:28:14 +01:00
silverf0x 8cd1676b5e Merge branch 'master' into master 2021-03-06 12:27:03 +01:00
Martin Rakhmanov eac145f455 Add runtime version 10.0.19041.630, got rid of Qt build warnings when
built against Qt 5.15.2 (deprecated APIs replaced with recommended
ones).
2021-03-06 12:19:25 +01:00
M3ik Shizuka 58a654aeea Add runtime version 10.0.19041.746 and fix generation cmake -G "Visual Studio 16 2019" -A x64. 2021-02-01 23:09:17 +03:00
silverf0x 9f24017edb Add runtime version 10.0.19041.630 2020-11-14 11:38:55 +01:00
silverf0x 0bec7930eb Add runtime versions 10.0.19041.508 and 10.0.19041.546 2020-10-29 11:11:36 +01:00
haroldm 60569c6e6d Add runtime version 10.0.17763.864 2020-07-20 09:10:13 +02:00
Daniel Hodson 25c9d7798e Add runtime version 10.0.19041.1 2020-05-28 10:47:45 +02:00
silverf0x bc0438014d Add runtime version 10.0.17134.1130 2020-04-03 09:09:01 +02:00
silverf0x b3885cfc56 Add runtime version 6.1.7601.24441 2020-03-26 09:22:38 +01:00
silverf0x c795134374 Add runtime version 10.0.18362.628 2020-02-16 15:46:30 +01:00
silverf0x e1a7e1f0a6 Add runtime version 6.3.9600.19538 2019-12-15 13:52:40 +01:00
silverf0x c8c35fa4c9 Add runtime version 10.0.10586.1176 2019-11-14 20:57:45 +01:00
silverf0x dfe9350716 Add runtime version 10.0.18362.476 2019-11-14 20:55:48 +01:00
silverf0x 972bb9f0ea Add runtime version 10.0.14393.3115 2019-11-14 20:54:43 +01:00
Martin Gallo 948b6cdbac Add runtime version 10.0.17763.719 2019-10-16 21:09:15 +02:00
silverf0x c7d3e3c1a6 Fix #36: UAF in InterfacesWidget_C::InterfaceSelected(const QModelIndex& Index) results in empty interface properties 2019-08-28 21:19:23 +02:00
silverf0x 2ce4f6f7a2 Fix #35: Hang with VBS enabled due to EnumProcessModulesEx ignored return value 2019-08-28 21:16:58 +02:00
Arnaud Gatignol d53fa65087 Add runtime 10.0.18362.1 2019-07-18 23:11:02 +02:00
silverf0x 899a7a7595 Add runtime 6.1.7601.24408 2019-05-02 21:10:13 +02:00
silverf0x ec12b31c1b Add runtime 10.0.17763.379 2019-03-23 22:39:18 +01:00
silverf0x a0dcff92f2 Merge branch 'master' of https://github.com/silverf0x/RpcView 2019-03-17 21:57:24 +01:00
silverf0x 6b8f0b6c87 Add runtime version 10.0.17134.648 2019-03-17 21:55:46 +01:00
silverf0x 8197fcdb45 Add runtime version 10.0.17763.648 2019-03-17 21:46:43 +01:00
silverf0x 43df9dfebf Add runtime version 10.0.10240.16841 2019-01-22 20:32:08 +01:00
silverf0x f98dad4db2 Fix call convension for the ProcexpOpenProcess function and support for the 32-bit version. 2019-01-20 18:04:09 +01:00
silverf0x 02d0fd419a Add runtime version 6.1.7601.24335 2019-01-20 17:55:15 +01:00
silverf0x 7302b614ce Add support for Protected and PPL processes with the ProcessExplorer driver.
REMARK: the feature requires the procexp.sys driver version 15.0.0.0
2019-01-20 17:51:12 +01:00
silverf0x 80fc306cac Fix typo in README.md 2019-01-16 21:03:59 +01:00
silverf0x d4632ac01c Fix #33: potential null pointer dereference in RpcCoreInit 2019-01-16 20:56:24 +01:00
silverf0x 341ab8196c Merge pull request #32 from hfiref0x/patch-gui
Update MainWindow.cpp
2019-01-16 14:13:24 +00:00
silverf0x f3aa3a581e Merge pull request #31 from hfiref0x/patch
Handle OS_ALLOC heap allocation potential failure in InitDecompilerInfo
2019-01-16 07:39:56 +00:00
hfiref0x bcf852a2bf Update MainWindow.cpp
Automatically show decompilation widget if "Decompile" popup menu was used and widget wasn't shown.
2019-01-16 14:39:01 +07:00
hfiref0x 6f8e8f45fc Update RpcView.cpp
Set formatting to original RpcView style.
2019-01-16 14:05:49 +07:00
hfiref0x 270401c658 Update RpcView.cpp
Handle OS_ALLOC heap allocation potential failure in InitDecompilerInfo
2019-01-16 14:03:21 +07:00
hfiref0x 79ea228d3e Merge pull request #2 from silverf0x/master
Merge upstream changes
2019-01-16 04:27:51 +07:00
silverf0x 91bf7750e6 Fix #30: potential null pointer dereference in GetRpcServerAddressInProcess and wWinMain 2019-01-15 21:31:40 +01:00
silverf0x 419a8e0856 Fix #29: remove unused RpcDecompilerPrintHiddenFUProcedure 2019-01-15 21:27:04 +01:00
silverf0x b6c7c32058 Fix #28: incorrect comparison in processComplexArray 2019-01-15 21:22:30 +01:00
silverf0x 7227826825 Fix #27: incorrect check of function return value in EnumProcess 2019-01-15 21:18:47 +01:00
silverf0x b495f68162 Fix #26: replace FC_POINTER_CONFORMANCE with FC_TOP_LEVEL_MULTID_CONFORMANCE 2019-01-15 21:16:46 +01:00
silverf0x c92891ea03 Fix #25: out of bounds read in RpcCoreInit 2019-01-15 21:13:03 +01:00
silverf0x b98ed0702f Fix #24: buffer overrun in GetUserAndDomainName 2019-01-15 21:09:26 +01:00
silverf0x b253c6e816 Fix #23: add missing break in switch statement 2019-01-15 21:04:39 +01:00
silverf0x 1526810cb8 Fix #22: remove useless functions 2019-01-15 21:02:10 +01:00
silverf0x 7939781867 Fix bug #21: build instructions 2019-01-15 20:51:51 +01:00
silverf0x ea1ce6667e Merge pull request #20 from jthuraisamy/patch-6
Add runtime version 6.1.7601.24308
2019-01-15 07:44:16 +00:00
silverf0x 39a4d9c1fd Merge pull request #19 from jthuraisamy/patch-5
Add runtime version 10.0.16299.846
2019-01-15 07:43:53 +00:00
hfiref0x 3bdfe86bc6 Merge pull request #1 from silverf0x/master
Merge upstream changes
2019-01-15 11:23:40 +07:00
Jackson 9558dabb29 Add runtime version 6.1.7601.24308 2019-01-14 16:04:23 -08:00
Jackson e56bea547a Add runtime version 6.1.7601.24308 2019-01-14 16:03:27 -08:00
Jackson 1dc0d79231 Add runtime version 10.0.16299.846 2019-01-14 16:00:40 -08:00
Jackson b92592abdc Add runtime version 10.0.16299.846 2019-01-14 15:58:15 -08:00
silverf0x 54b08a8ebd Merge pull request #18 from hfiref0x/patch
Add runtime support for 10.0.14393.2312, 10.0.14393.2665
2019-01-14 18:47:06 +00:00
hfiref0x 90eb7702d8 Add runtime support for 10.0.14393.2312, 10.0.14393.2665 2019-01-14 16:38:54 +07:00
silverf0x c513fb4fea Merge pull request #16 from jthuraisamy/patch-4
Add runtime version 10.0.16299.492
2018-12-29 13:16:05 +00:00
Jackson e33481bcd2 Add runtime version 10.0.16299.492
Fixed typo.
2018-12-27 10:30:28 -08:00
Jackson 7ed5d32592 Add runtime version 10.0.16299.492
Fixed typo.
2018-12-27 10:29:23 -08:00
silverf0x 49f4b764e4 Merge pull request #15 from jthuraisamy/patch-3
Add runtime version 10.0.16299.492
2018-12-27 16:39:31 +00:00
Jackson dbd228367c Add runtime version 10.0.16299.492 2018-12-26 16:05:06 -08:00
Jackson f34acc5dd2 Add runtime version 10.0.16299.492 2018-12-26 16:02:45 -08:00
silverf0x 88c179e4e6 minor fixes 2018-12-26 20:46:07 +01:00
silverf0x 66e2f506ae Merge pull request #14 from jthuraisamy/patch-2
Add runtime version 10.0.17763.194
2018-12-26 19:35:25 +00:00
Jackson 4a3d62d8c4 Add runtime version 10.0.17763.194 2018-12-25 20:40:52 -08:00
Jackson 896a5d4132 Add runtime version 10.0.17763.194 2018-12-25 20:39:43 -08:00
silverf0x 5524d14b5c Add runtime version 10.0.17134.471 2018-12-13 22:31:14 +01:00
silverf0x cd0e853418 Update README.md 2018-12-12 06:53:14 +00:00
silverf0x c8f7a23951 Update README.md 2018-12-12 06:52:58 +00:00
silverf0x 8d5b3c5020 Merge pull request #13 from jthuraisamy/patch-1
Add runtime version 6.1.7601.24260
2018-12-12 06:47:57 +00:00
Jackson e31bbaeabc Add runtime version 6.1.7601.24260 2018-12-11 18:58:39 -08:00
Jackson 4cbec1a0c7 Add runtime version 6.1.7601.24260 2018-12-10 20:28:44 -08:00
silverf0x f2a310644a add runtime version 6.3.9600.19176 2018-12-03 20:38:39 +01:00
silverf0x 96c645d8b5 add runtime version 6.1.7601.24291 2018-12-02 13:35:10 +01:00
silverf0x d3564617b1 Merge pull request #12 from chitoge/master
Add runtime version 10.0.17763.134
2018-11-23 08:41:32 +00:00
Thanh Do 9e1e971a1b add runtime version 10.0.17763.134 2018-11-23 14:40:49 +07:00
silverf0x a065327a51 Add runtime version 10.0.17134.407 2018-11-14 08:07:00 +01:00
silverf0x 1093c5ab65 Add runtime versions 10.0.17763.1 2018-11-01 15:05:44 +01:00
silverf0x 9bd35cdb84 Add runtime version 10.0.16299.726 2018-10-18 20:19:41 +02:00
silverf0x 685a4d5454 Add runtime versions 10.0.17134.1 2018-08-25 22:07:15 +02:00
silverf0x 7645b1c6a5 Complete bug fixed in pull request #11 2018-08-25 21:56:30 +02:00
silverf0x 29d8f7c734 Merge branch 'master' of https://github.com/silverf0x/RpcView 2018-08-25 21:53:35 +02:00
silverf0x daf87dcc99 Add runtime version 6.1.7601.24117 2018-08-25 21:48:04 +02:00
silverf0x d96e2fb6a4 Merge pull request #11 from wmliang/master
bug fixed
2018-08-25 21:42:29 +02:00
silverf0x ddd91d8735 Add runtime versions 10.0.17134.112 and 10.0.17134.228 2018-08-25 21:33:09 +02:00
wmliang a53bff717b bug fixed 2018-07-31 21:29:04 +08:00
silverf0x c108da277b Add runtime versions 10.0.17134.48 2018-06-07 21:18:17 +02:00
silverf0x 8cc56822ad Merge pull request #9 from 1orenz0/upstream
Fix size_is description when the parameter is out
2018-04-26 21:11:23 +02:00
1orenz0 39ded8c54d Fix size_is description when the parameter is out
When the argument using to describe size_is is an out parameter, we
don't know it's value and it cannot be used to describe the size of
another parameter. That's why in that case we can only set a max range
2018-04-25 20:33:57 +02:00
silverf0x 9f25e60e62 Add runtime versions 10.0.16299.309 and 10.0.16299.371 2018-04-18 21:44:01 +02:00
silverf0x 13b5819f56 Merge pull request #6 from TogDu/master
FEATURE/EXPERIMENTAL : Add /f flag to force runtime loading
2018-02-26 18:30:06 +01:00
TogDu b5d86817fc FIX : /f flag wasn't transmitted on runas 2018-02-17 19:31:06 +01:00
TogDu b2d5166e6f add /f flag support for debug mode 2018-02-17 19:29:24 +01:00
TogDu b168708bfa FIX : argv wasn't initialized so QApp cannot return valid argc value 2018-02-17 19:28:48 +01:00
TogDu 23fa0b517d FEATURE-EXPERIMENTAL : add /f flag to force loading for unsupported runtimes 2018-02-12 21:54:18 +01:00
TogDu e71f79cfb1 add support for 10.0.17074.1002
TODO add a f** \force flag
2018-02-12 19:16:41 +01:00
TogDu af13aed088 add support for 6.1.7601.23816 2018-02-12 19:15:53 +01:00
TogDu cc751f40f2 Merge branch 'remotes/silverf0x/master' 2018-01-24 19:40:35 +01:00
TogDu a5b789f1ba add support for 10.0.17025.1000 2018-01-24 19:38:53 +01:00
silverf0x 707aa7947c Add support for version 10.0.16299.192 2018-01-06 20:11:51 +01:00
silverf0x e71a2006b7 Add manual refresh option and configuration files to describe interfaces 2017-12-11 22:43:44 +01:00
silverf0x 940bff0824 Add support for version 10.0.14393.1770 2017-11-20 19:49:09 +01:00
32 changed files with 549 additions and 364 deletions
+68
View File
@@ -0,0 +1,68 @@
name: CMake
on: [push, pull_request,workflow_dispatch]
env:
# Customize the CMake build type here (Release, Debug, RelWithDebInfo, etc.)
BUILD_TYPE: Release
CMAKE_PREFIX_PATH: ${{github.workspace}}\..\Qt\5.15.2\msvc2019_64
ProjectDir: ${{github.workspace}}\build\bin\Release\
PackDirName: RpcView64
PackDirPath: ${{github.workspace}}\build\bin\Release\RpcView64
jobs:
build:
# The CMake configure and build commands are platform agnostic and should work equally well on Windows or Mac.
# You can convert this to a matrix build if you need cross-platform coverage.
# See: https://docs.github.com/en/free-pro-team@latest/actions/learn-github-actions/managing-complex-workflows#using-a-build-matrix
runs-on: windows-2019
steps:
- uses: actions/checkout@v3
- name: Install Qt
# Installs the Qt SDK
uses: jurplel/install-qt-action@v3
with:
version: '5.15.2'
host: 'windows'
target: 'desktop'
arch: 'win64_msvc2019_64'
archives: 'qtbase qtwinextras qttools'
- name: Configure CMake
# Configure CMake in a 'build' subdirectory. `CMAKE_BUILD_TYPE` is only required if you are using a single-configuration generator such as make.
# See https://cmake.org/cmake/help/latest/variable/CMAKE_BUILD_TYPE.html?highlight=cmake_build_type
run: cmake -A x64 -B ${{github.workspace}}/build -DCMAKE_BUILD_TYPE=${{env.BUILD_TYPE}}
- name: Build
# Build your program with the given configuration
run: cmake --build ${{github.workspace}}/build --config ${{env.BUILD_TYPE}}
- name: Test
working-directory: ${{github.workspace}}/build
# Execute tests defined by the CMake configuration.
# See https://cmake.org/cmake/help/latest/manual/ctest.1.html for more detail
run: ctest -C ${{env.BUILD_TYPE}}
- name: Package
id: Package
shell: cmd
#call "C:\Program Files (x86)\Microsoft Visual Studio\2019\Enterprise\VC\Auxiliary\Build\vcvarsall.bat" x64
run: |
cd ${{env.ProjectDir}}
mkdir ${{env.PackDirName}}
copy *.dll ${{env.PackDirName}}\
copy *.exe ${{env.PackDirName}}\
${{env.CMAKE_PREFIX_PATH}}\bin\windeployqt.exe --no-angle --no-opengl-sw --no-system-d3d-compiler --no-translations --release ${{env.PackDirName}}\
- name: Prune
id: Prune
shell: cmd
run: |
rmdir /s /q ${{env.PackDirPath}}\imageformats
rmdir /s /q ${{env.PackDirPath}}\styles
- name: Upload Binaries
uses: actions/upload-artifact@v3
with:
name: RpcView64-windows
path: ${{env.PackDirPath}}\
+1 -1
View File
@@ -4,7 +4,7 @@ project(RpcView)
set(RPCVIEW_VERSION_MAJOR 0)
set(RPCVIEW_VERSION_MINOR 3)
set(RPCVIEW_VERSION_RELEASE 0)
set(RPCVIEW_VERSION_RELEASE 1)
if($ENV{APPVEYOR_BUILD_NUMBER})
set(RPCVIEW_VERSION_BUILD $ENV{APPVEYOR_BUILD_NUMBER})
else()
+41 -35
View File
@@ -1,18 +1,14 @@
RpcView
=======
# RpcView
RpcView is an open-source tool to explore and decompile all RPC functionalities present on a Microsoft system.
You can get the last [official release](https://github.com/silverf0x/RpcView/releases).
Or you can download the last [automatically built release](https://ci.appveyor.com/project/silverf0x/rpcview/build/artifacts)
You can download the last [automatically built release](https://ci.appveyor.com/project/silverf0x/rpcview/build/artifacts)
[![Build status](https://ci.appveyor.com/api/projects/status/o5wy6mdk16tuht70?svg=true)](https://ci.appveyor.com/project/silverf0x/rpcview)
**Warning**: you have to install "Microsoft Visual C++ 2015 Redistributable" to use RpcView.
> **Warning**: you have to install "Microsoft Visual C++ 2019 Redistributable" to use RpcView.
How to add a new RPC runtime
----------------------------------
## How to add a new RPC runtime
Basically you have two possibilities to support a new RPC runtime (rpcrt4.dll) version:
@@ -26,32 +22,38 @@ Currently, the supported versions are organized as follows:
- RpcCore3 for Windows 8
- RpcCore4 for Windows 8.1 and 10
Compilation
--------------
## Compilation
Required elements to compiled the project:
* Visual Studio (currently Visual Studio 2015 community)
* CMake (at least 3.0.2)
* Qt5 (currently 5.9.1)
* Visual Studio (currently Visual Studio 2019 Community)
* CMake (currently 3.13.2)
* Qt5 (currently 5.15.2)
Before running CMake you have to set the CMAKE_PREFIX_PATH environment variable with the current Qt path, for instance (x64):
Before running CMake you have to set the CMAKE_PREFIX_PATH environment variable with the Qt **full path**, for instance (x64):
```
set CMAKE_PREFIX_PATH=C:\Qt\Qt5.9.1\5.9.1\msvc2015_64
set CMAKE_PREFIX_PATH=C:\Qt\5.15.2\msvc2019_64\
```
Then you can run CMake to produce the project solution.
Here is an example to generate the x64 solution with Visual Studio 2015 from the ```RpcView/Build/x64``` directory:
Before running CMake to produce the project solution you have to create the build directories:
- ```RpcView/Build/x64``` for 64-bit targets
- ```RpcView/Build/x86``` for 32-bit targets.
Here is an example to generate the x64 solution with Visual Studio 2019 from the ```RpcView/Build/x64``` directory:
```cmake
cmake -G"Visual Studio 14 2015 Win64" ../../
-- The C compiler identification is MSVC 19.0.24215.1
-- The CXX compiler identification is MSVC 19.0.24215.1
-- Check for working C compiler: C:/Program Files (x86)/Microsoft Visual Studio 14.0/VC/bin/x86_amd64/cl.exe
-- Check for working C compiler: C:/Program Files (x86)/Microsoft Visual Studio 14.0/VC/bin/x86_amd64/cl.exe -- works
cmake ../../ -A x64
-- Building for: Visual Studio 16 2019
-- Selecting Windows SDK version 10.0.17763.0 to target Windows 10.0.19041.
-- The C compiler identification is MSVC 19.28.29334.0
-- The CXX compiler identification is MSVC 19.28.29334.0
-- Check for working C compiler: C:/Program Files (x86)/Microsoft Visual Studio/2019/Community/VC/Tools/MSVC/14.28.29333/bin/Hostx64/x64/cl.exe
-- Check for working C compiler: C:/Program Files (x86)/Microsoft Visual Studio/2019/Community/VC/Tools/MSVC/14.28.29333/bin/Hostx64/x64/cl.exe -- works
-- Detecting C compiler ABI info
-- Detecting C compiler ABI info - done
-- Check for working CXX compiler: C:/Program Files (x86)/Microsoft Visual Studio 14.0/VC/bin/x86_amd64/cl.exe
-- Check for working CXX compiler: C:/Program Files (x86)/Microsoft Visual Studio 14.0/VC/bin/x86_amd64/cl.exe -- works
-- Detecting C compile features
-- Detecting C compile features - done
-- Check for working CXX compiler: C:/Program Files (x86)/Microsoft Visual Studio/2019/Community/VC/Tools/MSVC/14.28.29333/bin/Hostx64/x64/cl.exe
-- Check for working CXX compiler: C:/Program Files (x86)/Microsoft Visual Studio/2019/Community/VC/Tools/MSVC/14.28.29333/bin/Hostx64/x64/cl.exe -- works
-- Detecting CXX compiler ABI info
-- Detecting CXX compiler ABI info - done
-- Detecting CXX compile features
@@ -72,19 +74,23 @@ cmake -G"Visual Studio 14 2015 Win64" ../../
To produce the Win32 solution:
```
set CMAKE_PREFIX_PATH=C:\Qt\Qt5.9.1\5.9.1\msvc2015
set CMAKE_PREFIX_PATH=C:\Qt\5.15.2\msvc2019
```
Then from the ```RpcView/Build/x86``` directory:
```cmake
cmake -G"Visual Studio 14 2015" ../../
-- The C compiler identification is MSVC 19.0.24215.1
-- The CXX compiler identification is MSVC 19.0.24215.1
-- Check for working C compiler: C:/Program Files (x86)/Microsoft Visual Studio 14.0/VC/bin/cl.exe
-- Check for working C compiler: C:/Program Files (x86)/Microsoft Visual Studio 14.0/VC/bin/cl.exe -- works
cmake ../../ -A win32
-- Building for: Visual Studio 16 2019
-- Selecting Windows SDK version 10.0.17763.0 to target Windows 10.0.19041.
-- The C compiler identification is MSVC 19.28.29334.0
-- The CXX compiler identification is MSVC 19.28.29334.0
-- Check for working C compiler: C:/Program Files (x86)/Microsoft Visual Studio/2019/Community/VC/Tools/MSVC/14.28.29333/bin/Hostx64/x86/cl.exe
-- Check for working C compiler: C:/Program Files (x86)/Microsoft Visual Studio/2019/Community/VC/Tools/MSVC/14.28.29333/bin/Hostx64/x86/cl.exe -- works
-- Detecting C compiler ABI info
-- Detecting C compiler ABI info - done
-- Check for working CXX compiler: C:/Program Files (x86)/Microsoft Visual Studio 14.0/VC/bin/cl.exe
-- Check for working CXX compiler: C:/Program Files (x86)/Microsoft Visual Studio 14.0/VC/bin/cl.exe -- works
-- Detecting C compile features
-- Detecting C compile features - done
-- Check for working CXX compiler: C:/Program Files (x86)/Microsoft Visual Studio/2019/Community/VC/Tools/MSVC/14.28.29333/bin/Hostx64/x86/cl.exe
-- Check for working CXX compiler: C:/Program Files (x86)/Microsoft Visual Studio/2019/Community/VC/Tools/MSVC/14.28.29333/bin/Hostx64/x86/cl.exe -- works
-- Detecting CXX compiler ABI info
-- Detecting CXX compiler ABI info - done
-- Detecting CXX compile features
@@ -107,9 +113,9 @@ cmake --build . --config Release
RpcView32 binaries are produced in the ```RpcView/Build/bin/x86``` directory and RpcView64 ones in the ```RpcView/Build/bin/x64```
Acknowledgements
----------------------
## Acknowledgements
* Jeremy
* Julien
* Yoanne
* Bruno
* Bruno
+47 -74
View File
@@ -18,6 +18,47 @@ typedef struct _LanguageCodePage_T {
WORD wCodePage;
} LanguageCodePage_T;
#define IOCTL_OPEN_PROCESS 0x8335003C
HANDLE hProcexp = NULL;
HANDLE WINAPI ProcexpOpenProcess(DWORD dwDesiredAccess, BOOL bInheritHandle, DWORD dwProcessId)
{
HANDLE hProcess = NULL;
HANDLE Pid = (HANDLE)(uintptr_t)dwProcessId;
DWORD Bytes;
hProcess = OpenProcess(dwDesiredAccess, bInheritHandle, dwProcessId);
if (hProcess != NULL) goto End;
if (hProcexp == NULL)
{
hProcexp = CreateFileA(
"\\\\.\\PROCEXP152",
GENERIC_READ,
0,
NULL,
OPEN_EXISTING,
FILE_ATTRIBUTE_NORMAL,
NULL
);
if (hProcexp == INVALID_HANDLE_VALUE)
{
goto End;
}
}
DeviceIoControl(
hProcexp,
IOCTL_OPEN_PROCESS,
&Pid,
sizeof(Pid),
&hProcess,
sizeof(hProcess),
&Bytes,
NULL
);
End:
return hProcess;
}
//------------------------------------------------------------------------------
BOOL WINAPI AdjustPrivilege(LPCTSTR lpPrivilegeName,BOOL bEnablePrivilege)
@@ -50,7 +91,7 @@ BOOL WINAPI EnumProcess(EnumProcessCallbackFn_T EnumProcessCallbackFn,void* pCal
BOOL bContinue=TRUE;
hSnapshot=CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS,0);
if (hSnapshot==NULL) goto End;
if (hSnapshot == INVALID_HANDLE_VALUE) goto End;
ProcessEntry.dwSize=sizeof(ProcessEntry);
if (!Process32FirstW(hSnapshot,&ProcessEntry)) goto End;
do
@@ -61,7 +102,7 @@ BOOL WINAPI EnumProcess(EnumProcessCallbackFn_T EnumProcessCallbackFn,void* pCal
}while(Process32NextW(hSnapshot,&ProcessEntry));
End:
if (hSnapshot!=NULL) CloseHandle(hSnapshot);
if (hSnapshot != INVALID_HANDLE_VALUE) CloseHandle(hSnapshot);
return (bResult);
}
@@ -162,74 +203,6 @@ End:
return (bResult);
}
typedef VOID (WINAPI* RtlGetUnloadEventTraceExFn_T)(
_Out_ PULONG *ElementSize,
_Out_ PULONG *ElementCount,
_Out_ PVOID *EventTrace
);
#pragma pack(1)
typedef struct _RTL_UNLOAD_EVENT_TRACE {
void* BaseAddress; // Base address of dll
SIZE_T SizeOfImage; // Size of image
ULONG Sequence; // Sequence number for this event
ULONG TimeDateStamp; // Time and date of image
ULONG CheckSum; // Image checksum
WCHAR ImageName[32]; // Image name
} RTL_UNLOAD_EVENT_TRACE, *PRTL_UNLOAD_EVENT_TRACE;
#pragma pack()
//------------------------------------------------------------------------------
BOOL WINAPI GetUnloadedLocationInfo(HANDLE hProcess, VOID* pAddress, LocationInfo_T* pLocationInfo)
{
RtlGetUnloadEventTraceExFn_T RtlGetUnloadEventTraceExFn = NULL;
ULONG* pElementSize = NULL;
ULONG* pElementCount = NULL;
UCHAR* pEventTrace = NULL;
RTL_UNLOAD_EVENT_TRACE* pUnloadEventTrace = NULL;
ULONG ElementSize = 0;
ULONG ElementCount = 0;
BOOL bResult = FALSE;
ULONG i = 0;
RtlGetUnloadEventTraceExFn = (RtlGetUnloadEventTraceExFn_T)GetProcAddress(GetModuleHandleA("ntdll.dll"), "RtlGetUnloadEventTraceEx");
if (RtlGetUnloadEventTraceExFn == NULL) goto End;
//
// Get addresses of ElementSize, ElementCount and pEventTrace in the ntdll
//
RtlGetUnloadEventTraceExFn(&pElementSize, &pElementCount, &pEventTrace);
//
// Read their values in the target process
//
if (!ReadProcessMemory(hProcess, pElementSize, &ElementSize, sizeof(ElementSize), NULL)) goto End;
pUnloadEventTrace = (RTL_UNLOAD_EVENT_TRACE*)OS_ALLOC(ElementSize);
if (pUnloadEventTrace == NULL) goto End;
if (!ReadProcessMemory(hProcess, pElementCount, &ElementCount, sizeof(ElementCount), NULL)) goto End;
if (!ReadProcessMemory(hProcess, pEventTrace, &pEventTrace, sizeof(pEventTrace), NULL)) goto End;
//
// Look for the unloaded module
//
for (i = 0; i < ElementCount; i++)
{
if (!ReadProcessMemory(hProcess, pEventTrace, pUnloadEventTrace, ElementSize, NULL)) goto End;
if (pUnloadEventTrace->BaseAddress == NULL) break;
if (((SIZE_T)pAddress >= (SIZE_T)pUnloadEventTrace->BaseAddress) &&
((SIZE_T)pAddress < ((SIZE_T)pUnloadEventTrace->BaseAddress + pUnloadEventTrace->SizeOfImage)))
{
pLocationInfo->pBaseAddress = pUnloadEventTrace->BaseAddress;
pLocationInfo->Size = pUnloadEventTrace->SizeOfImage;
memcpy(pLocationInfo->Location, pUnloadEventTrace->ImageName, sizeof(pLocationInfo->Location));
break;
}
pEventTrace += ElementSize;
}
End:
if (pUnloadEventTrace != NULL) OS_FREE(pUnloadEventTrace);
return (bResult);
}
//------------------------------------------------------------------------------
UINT64 WINAPI GetModuleVersion(WCHAR* pModulePath)
{
@@ -327,7 +300,7 @@ BOOL WINAPI GetProcessPath(DWORD Pid, WCHAR* pProcessPath, DWORD ProcessPathLeng
BOOL bResult = FALSE;
DWORD Size;
hProcess = OpenProcess(PROCESS_ALL_ACCESS, FALSE, Pid);
hProcess = ProcexpOpenProcess(PROCESS_ALL_ACCESS, FALSE, Pid);
if (hProcess == NULL) goto End;
Size = ProcessPathLength;
bResult = QueryFullProcessImageNameW(hProcess, 0, pProcessPath, &Size);
@@ -367,7 +340,7 @@ BOOL WINAPI GetUserAndDomainName(DWORD Pid, WCHAR* Buffer, ULONG BufferLengthInB
SID_NAME_USE SidType;
BOOL bResult = FALSE;
hProcess = OpenProcess(PROCESS_VM_OPERATION|PROCESS_QUERY_INFORMATION,FALSE,Pid);
hProcess = ProcexpOpenProcess(PROCESS_VM_OPERATION|PROCESS_QUERY_INFORMATION,FALSE,Pid);
if (hProcess==NULL) goto End;
if (!OpenProcessToken(hProcess,TOKEN_QUERY,&hToken)) goto End;
@@ -375,7 +348,7 @@ BOOL WINAPI GetUserAndDomainName(DWORD Pid, WCHAR* Buffer, ULONG BufferLengthInB
pTokenUser=(TOKEN_USER*)OS_ALLOC(Bytes);
if (pTokenUser==NULL) goto End;
if (!GetTokenInformation(hToken,TokenUser,pTokenUser,Bytes,&Bytes)) goto End;
dwSize=sizeof(UserName);
dwSize=_countof(UserName);
if (!LookupAccountSidW(NULL,pTokenUser->User.Sid,UserName,&dwSize,DomainName,&dwSize,&SidType)) goto End;
StringCbPrintfW(Buffer,BufferLengthInBytes,L"%s\\%s",DomainName,UserName);
bResult=TRUE;
@@ -393,7 +366,7 @@ BOOL WINAPI IsProcessWow64(ULONG Pid)
BOOL bWow64 = FALSE;
HANDLE hProcess = NULL;
hProcess = OpenProcess(PROCESS_VM_OPERATION|PROCESS_QUERY_INFORMATION,FALSE,Pid);
hProcess = ProcexpOpenProcess(PROCESS_VM_OPERATION|PROCESS_QUERY_INFORMATION,FALSE,Pid);
if (hProcess==NULL) goto End;
IsWow64Process(hProcess,&bWow64);
End:
+1 -4
View File
@@ -31,20 +31,17 @@ typedef struct _LocationInfo_T{
SIZE_T Size;
}LocationInfo_T;
HANDLE WINAPI ProcexpOpenProcess(DWORD dwDesiredAccess,BOOL bInheritHandle,DWORD dwProcessId);
BOOL WINAPI AdjustPrivilege(LPCTSTR lpPrivilegeName,BOOL bEnablePrivilege);
BOOL WINAPI GetModuleDescription(WCHAR* pModulePath,WCHAR* pDescription,UINT Bytes);
UINT64 WINAPI GetModuleVersion(WCHAR* pModulePath);
BOOL WINAPI GetLocationInfo(HANDLE hProcess, VOID* pAddress, LocationInfo_T* pLocationInfo);
BOOL WINAPI GetUnloadedLocationInfo(HANDLE hProcess, VOID* pAddress, LocationInfo_T* pLocationInfo);
BOOL WINAPI GetProcessNameFromPid(DWORD Pid,WCHAR* pName,UINT NameSizeInBytes);
BOOL WINAPI GetProcessPath(DWORD Pid, WCHAR* pProcessPath, DWORD ProcessPathLength);
BOOL WINAPI GetProcessPebInfo(HANDLE hProcess,WCHAR* pCmdLine,UINT CmdLineLength,WCHAR* pDesktop,UINT DesktopLength);
BOOL WINAPI GetRegValueData(HKEY hRootKey,WCHAR* pSubkeyName,WCHAR* pValueName,VOID* pData,UINT DataLength);
BOOL WINAPI GetUserAndDomainName(DWORD Pid, WCHAR* Buffer, ULONG BufferLengthInBytes);
BOOL WINAPI IsProcessWow64(ULONG Pid);
VOID WINAPI PrintUUID(UUID* pUUID);
HANDLE WINAPI KphOpenProcess(_In_ DWORD dwDesiredAccess, _In_ BOOL bInheritHandle, _In_ DWORD dwProcessId);
typedef BOOL (WINAPI* EnumProcessCallbackFn_T)(DWORD Pid, DWORD Ppid, VOID* pContext, BOOL* pbContinue);
BOOL WINAPI EnumProcess(EnumProcessCallbackFn_T EnumProcessCallbackFn, void* pCallbackCtxt);
+3 -3
View File
@@ -23,12 +23,12 @@ foreach(Files ${CoreFiles})
get_filename_component(Dir ${Files} NAME)
if(${CMAKE_GENERATOR} MATCHES "Win64")
if(${CMAKE_GENERATOR} MATCHES "Win64" OR ${CMAKE_GENERATOR_PLATFORM} MATCHES "x64")
AddRpcCore(${Dir})
else(${CMAKE_GENERATOR} MATCHES "Win64")
else(${CMAKE_GENERATOR} MATCHES "Win64" OR ${CMAKE_GENERATOR_PLATFORM} MATCHES "x64")
if(${Dir} MATCHES "32bits")
AddRpcCore(${Dir})
endif(${Dir} MATCHES "32bits")
endif(${CMAKE_GENERATOR} MATCHES "Win64")
endif(${CMAKE_GENERATOR} MATCHES "Win64" OR ${CMAKE_GENERATOR_PLATFORM} MATCHES "x64")
endif (IS_DIRECTORY ${Files} )
endforeach(Files)
+18 -12
View File
@@ -52,7 +52,7 @@ typedef BOOL (WINAPI* EnumSimpleDictCallbackFn_T)(HANDLE hProcess, UINT Index, V
BOOL WINAPI EnumSimpleDict(HANDLE hProcess, SIMPLE_DICT_T* pSimpleDict, EnumSimpleDictCallbackFn_T EnumSimpleDictCallbackFn, VOID* pContext);
// RpcCore
VOID* __fastcall RpcCoreInit(); //returns a private context for the RpcCoreEngine
VOID* __fastcall RpcCoreInit(BOOL bForce); //returns a private context for the RpcCoreEngine
VOID __fastcall RpcCoreUninit(VOID* pRpcCoreCtxt);
RpcProcessInfo_T* __fastcall RpcCoreGetProcessInfo(void* pRpcCoreCtxt,DWORD Pid,DWORD Ppid,ULONG ProcessInfoMask);
VOID __fastcall RpcCoreFreeProcessInfo(void* pRpcCoreCtxt,RpcProcessInfo_T* pRpcProcessInfo);
@@ -73,6 +73,7 @@ RpcCore_T RpcCoreHelper =
{
RPC_CORE_RUNTIME_VERSION,
RPC_CORE_IS_WOW64,
FALSE,
&RpcCoreInit,
&RpcCoreUninit,
&RpcCoreGetProcessInfo,
@@ -219,13 +220,13 @@ BOOL WINAPI GetRpcServerAddressInProcess(DWORD Pid,RpcCoreInternalCtxt_T* pRpcCo
CHAR ModuleFileName[MAX_PATH];
BOOL bResult=FALSE;
hProcess = OpenProcess(PROCESS_ALL_ACCESS, FALSE, Pid);
hProcess = ProcexpOpenProcess(PROCESS_ALL_ACCESS, FALSE, Pid);
if (hProcess == NULL) goto End;
EnumProcessModulesEx(hProcess, NULL, 0, &cbSize, LIST_MODULES_ALL);
if (cbSize == 0) goto End;
if (!EnumProcessModulesEx(hProcess, NULL, 0, &cbSize, LIST_MODULES_ALL)) goto End;
pHmodule = (HMODULE*)malloc(cbSize);
EnumProcessModulesEx(hProcess, pHmodule, cbSize, &cbSize, LIST_MODULES_ALL);
if (pHmodule == NULL) goto End;
if (!EnumProcessModulesEx(hProcess, pHmodule, cbSize, &cbSize, LIST_MODULES_ALL)) goto End;
for(ULONG i=0;i<cbSize/sizeof(*pHmodule);i++)
{
@@ -270,7 +271,7 @@ End:
//------------------------------------------------------------------------------
VOID* __fastcall RpcCoreInit()
VOID* __fastcall RpcCoreInit(BOOL bForce)
{
UINT64 RuntimVersion;
RpcCoreInternalCtxt_T* pRpcCoreInternalCtxt=NULL;
@@ -288,8 +289,13 @@ VOID* __fastcall RpcCoreInit()
if (GetSystemDirectoryW(RpcRuntimePath,_countof(RpcRuntimePath))==0) goto End;
StringCbPrintfW(RpcRuntimePath,sizeof(RpcRuntimePath),L"%s\\rpcrt4.dll",RpcRuntimePath);
RuntimVersion=GetModuleVersion(RpcRuntimePath);
for (i = 0; i < sizeof(RPC_CORE_RUNTIME_VERSION); i++)
for (i = 0; i < _countof(RPC_CORE_RUNTIME_VERSION); i++)
{
if (bForce && ((RuntimVersion & 0xFFFFFFFF00000000) == (RPC_CORE_RUNTIME_VERSION[i] & 0xFFFFFFFF00000000)))
{
bFound = TRUE;
break;
}
if (RuntimVersion == RPC_CORE_RUNTIME_VERSION[i])
{
bFound = TRUE;
@@ -396,7 +402,7 @@ RpcProcessInfo_T* __fastcall RpcCoreGetProcessInfo(void* pRpcCoreCtxt,DWORD Pid,
pRpcProcessInfo->ParentPid = Ppid;
pRpcProcessInfo->RpcProcessType = RpcProcessType_UNKNOWN;
hProcess=OpenProcess(PROCESS_VM_READ|PROCESS_QUERY_INFORMATION,FALSE,Pid);
hProcess=ProcexpOpenProcess(PROCESS_VM_READ|PROCESS_QUERY_INFORMATION,FALSE,Pid);
if (hProcess!=NULL)
{
#ifdef _WIN64
@@ -816,7 +822,7 @@ RpcInterfaceInfo_T* __fastcall RpcCoreGetInterfaceInfo(void* pRpcCoreCtxt,DWORD
RpcInterfaceInfo_T* pRpcInterfaceInfo = NULL;
pRpcCoreInternalCtxt = (RpcCoreInternalCtxt_T*)pRpcCoreCtxt;
hProcess = OpenProcess(PROCESS_VM_READ | PROCESS_QUERY_INFORMATION, FALSE, Pid);
hProcess = ProcexpOpenProcess(PROCESS_VM_READ | PROCESS_QUERY_INFORMATION, FALSE, Pid);
if (hProcess == NULL) { DEBUG_BREAK(); goto End; }
pRpcInterface = GetProcessInterface(pRpcCoreInternalCtxt, hProcess, pIf);
@@ -858,7 +864,7 @@ BOOL __fastcall RpcCoreEnumProcessInterfaces(void* pRpcCoreCtxt,DWORD Pid,RpcCor
RpcInterfaceInfo_T* pRpcInterfaceInfo = NULL;
RpcCoreInternalCtxt_T* pRpcCoreInternalCtxt=(RpcCoreInternalCtxt_T*)pRpcCoreCtxt;
hProcess=OpenProcess(PROCESS_VM_READ|PROCESS_QUERY_INFORMATION,FALSE,Pid);
hProcess=ProcexpOpenProcess(PROCESS_VM_READ|PROCESS_QUERY_INFORMATION,FALSE,Pid);
if (hProcess==NULL) goto End;
if (!ReadProcessMemory(hProcess,pRpcCoreInternalCtxt->pGlobalRpcServer,&pRpcServer,sizeof(VOID PTR_T),NULL)) goto End;
@@ -910,7 +916,7 @@ BOOL __fastcall RpcCoreEnumProcessEndpoints(void* pRpcCoreCtxt,DWORD Pid,RpcCore
BOOL bContinue=TRUE;
RpcCoreInternalCtxt_T* pRpcCoreInternalCtxt=(RpcCoreInternalCtxt_T*)pRpcCoreCtxt;
hProcess=OpenProcess(PROCESS_VM_READ,FALSE,Pid);
hProcess=ProcexpOpenProcess(PROCESS_VM_READ,FALSE,Pid);
if (hProcess==NULL) goto End;
if (!ReadProcessMemory(hProcess,pRpcCoreInternalCtxt->pGlobalRpcServer,&pRpcServer,sizeof(VOID PTR_T),NULL)) goto End;
@@ -1009,7 +1015,7 @@ BOOL __fastcall RpcCoreEnumProcessAuthInfo(void* pRpcCoreCtxt,DWORD Pid,RpcCoreE
if (RegOpenKeyExW(HKEY_LOCAL_MACHINE,L"SOFTWARE\\Microsoft\\Rpc\\SecurityService",0,KEY_READ,&hKey)!=ERROR_SUCCESS) goto End;
if (EnumerateSecurityPackagesW(&PackagesCount,&SecurityPackageInfoTbl)!=SEC_E_OK) goto End;
hProcess=OpenProcess(PROCESS_VM_READ|PROCESS_QUERY_INFORMATION,FALSE,Pid);
hProcess=ProcexpOpenProcess(PROCESS_VM_READ|PROCESS_QUERY_INFORMATION,FALSE,Pid);
if (hProcess==NULL) goto End;
if (!ReadProcessMemory(hProcess,pRpcCoreInternalCtxt->pGlobalRpcServer,&pRpcServer,sizeof(VOID PTR_T), NULL)) goto End;
+2 -1
View File
@@ -178,7 +178,7 @@ typedef BOOL (__fastcall* RpcCoreEnumProcessAuthInfoCallbackFn_T)(DWORD Pid, Rpc
// Type definitions
////////////////////////////////////////////////////////////////////////////////
typedef VOID* (__fastcall* RpcCoreInitFn_T)();
typedef VOID* (__fastcall* RpcCoreInitFn_T)(BOOL bForce);
typedef VOID (__fastcall* RpcCoreUninitFn_T)(VOID* pRpcCoreCtxt);
typedef RpcProcessInfo_T* (__fastcall* RpcCoreGetProcessInfoFn_T)(void* pRpcCoreCtxt, DWORD Pid, DWORD Ppid,ULONG ProcessInfoMask);
typedef VOID (__fastcall* RpcCoreFreeProcessInfoFn_T)(void* pRpcCoreCtxt, RpcProcessInfo_T* pRpcProcessInfo);
@@ -193,6 +193,7 @@ typedef struct _RpcCore_T{
UINT64* RuntimeVersion; //the supported version (forx example 0x600011DB04001LL (6.1.7600.16385) for Windows 7 64bits )
//const char* pDescription;
BOOL bWow64Helper;
BOOL bForceLoading;
RpcCoreInitFn_T RpcCoreInitFn;
RpcCoreUninitFn_T RpcCoreUninitFn;
RpcCoreGetProcessInfoFn_T RpcCoreGetProcessInfoFn;
+10 -2
View File
@@ -16,7 +16,15 @@ static UINT64 RPC_CORE_RUNTIME_VERSION[] = {
0x600011DB14ABFLL, //6.1.7601.19135
0x600011DB15B7BLL, //6.1.7601.23419
0x600011DB15CA2LL, //6.1.7601.23714
0x600011DB15D6BLL, //6.1.7601.23915
0x600011DB15D08LL, //6.1.7601.23816
0x600011DB15D6BLL, //6.1.7601.23915
0x600011DB15E35LL, //6.1.7601.24117
0x600011DB15EC4LL, //6.1.7601.24260
0x600011DB15EE3LL, //6.1.7601.24291
0x600011DB15EF4LL, //6.1.7601.24308
0x600011DB15F0FLL, //6.1.7601.24335
0x600011DB15F58LL, //6.1.7601.24408
0x600011DB15F79LL //6.1.7601.24441
};
#ifdef _WIN64
@@ -115,4 +123,4 @@ typedef struct _RPC_ADDRESS_T {
#pragma pack()
#endif // _RPC_INTERNALS_H_
#endif // _RPC_INTERNALS_H_
+10 -2
View File
@@ -15,7 +15,15 @@ static UINT64 RPC_CORE_RUNTIME_VERSION[] = {
0x600011DB14ABFLL, //6.1.7601.19135
0x600011DB15B7BLL, //6.1.7601.23419
0x600011DB15CA2LL, //6.1.7601.23714
0x600011DB15D6BLL, //6.1.7601.23915
0x600011DB15D08LL, //6.1.7601.23816
0x600011DB15D6BLL, //6.1.7601.23915
0x600011DB15E35LL, //6.1.7601.24117
0x600011DB15EC4LL, //6.1.7601.24260
0x600011DB15EE3LL, //6.1.7601.24291
0x600011DB15EF4LL, //6.1.7601.24308
0x600011DB15F0FLL, //6.1.7601.24335
0x600011DB15F58LL, //6.1.7601.24408
0x600011DB15F79LL //6.1.7601.24441
};
#define RPC_CORE_DESCRIPTION "Windows 7 SP1 64bits runtime core"
@@ -119,4 +127,4 @@ typedef struct _RPC_ADDRESS_T {
#pragma pack()
#endif // _RPC_INTERNALS_H_
#endif // _RPC_INTERNALS_H_
+65 -17
View File
@@ -5,31 +5,79 @@
#include <Rpc.h>
static UINT64 RPC_CORE_RUNTIME_VERSION[] = {
0x6000324D70000LL, //6.3.9431.0000
0x6000325804000LL, //6.3.9600.16384
0x6000325804340LL, //6.3.9600.17216
0x6000325804407LL, //6.3.9600.17415
0x60003258045FFLL, //6.3.9600.17919
0x6000325804774LL, //6.3.9600.18292
0xA000028004000LL, //10.0.10240.16384
0x6000324D70000LL, //6.3.9431.0000
0x6000325804000LL, //6.3.9600.16384
0x6000325804340LL, //6.3.9600.17216
0x6000325804407LL, //6.3.9600.17415
0x60003258045FFLL, //6.3.9600.17919
0x6000325804774LL, //6.3.9600.18292
0x6000325804AE8LL, //6.3.9600.19176
0x6000325804C52LL, //6.3.9600.19538
0xA000028004000LL, //10.0.10240.16384
0xA00002800401CLL, //10.0.10240.16412
0xA0000295A0000LL, //10.0.10586.0
0xA0000295A0132LL, //10.0.10586.306
0xA0000380603E8LL, //10.0.14342.1000
0xA000038190000LL, //10.0.14361.0
0xA000038390000LL, //10.0.14393.0
0xA000038390052LL, //10.0.14393.82
0xA0000280041C9LL, //10.0.10240.16841
0xA0000295A0000LL, //10.0.10586.0
0xA0000295A0132LL, //10.0.10586.306
0xA0000295A0498LL, //10.0.10586.1176
0xA0000380603E8LL, //10.0.14342.1000
0xA000038190000LL, //10.0.14361.0
0xA000038390000LL, //10.0.14393.0
0xA000038390052LL, //10.0.14393.82
0xA0000383906EALL, //10.0.14393.1770
0xA000038390908LL, //10.0.14393.2312
0xA000038390A69LL, //10.0.14393.2665
0xA000038390C2BLL, //10.0.14393.3115
0xA00003AD70000LL, //10.0.15063.0
0xA00003AD701BFLL, //10.0.15063.447
0xA00003AD702A2LL, //10.0.15063.674
0xA00003F6803E8LL, //10.0.16232.1000
0xA00003FAB000FLL, //10.0.16299.15
0xA0000427903E8LL, //10.0.17017.1000
0xA00003FAB00C0LL, //10.0.16299.192
0xA00003FAB0135LL, //10.0.16299.309
0xA00003FAB0173LL, //10.0.16299.371
0xA00003FAB01ECLL, //10.0.16299.492
0xA00003FAB02D6LL, //10.0.16299.726
0xA00003FAB034ELL, //10.0.16299.846
0xA0000427903E8LL, //10.0.17017.1000
0xA0000428103E8LL, //10.0.17025.1000
0xA000042B203EALL, //10.0.17074.1002
0xA000042EE0001LL, //10.0.17134.1
0xA000042EE0030LL, //10.0.17134.48
0xA000042EE0070LL, //10.0.17134.112
0xA000042EE00E4LL, //10.0.17134.228
0xA000042EE0197LL, //10.0.17134.407
0xA000042EE01D7LL, //10.0.17134.471
0xA000042EE0288LL, //10.0.17134.648
0xA000042EE046ALL, //10.0.17134.1130
0xA000045630001LL, //10.0.17763.1
0xA000045630086LL, //10.0.17763.134
0xA0000456300C2LL, //10.0.17763.194
0xA00004563017BLL, //10.0.17763.379
0xA0000456302CFLL, //10.0.17763.719
0xA000045630360LL, //10.0.17763.864
0xA000045630629LL, //10.0.17763.1577
0xA0000456306A1LL, //10.0.17763.1697
0xA000045630757LL, //10.0.17763.1879
0xA0000456307CFLL, //10.0.17763.1999
0xA000047BA0001LL, //10.0.18362.1
0xA000047BA01DCLL, //10.0.18362.476
0xA000047BA0274LL, //10.0.18362.628
0xA00004A610001LL, //10.0.19041.1
0xA00004A6101FCLL, //10.0.19041.508
0xA00004A610222LL, //10.0.19041.546
0xA00004A610276LL, //10.0.19041.630
0xA00004A610296LL, //10.0.19041.662
0xA00004A6102EALL, //10.0.19041.746
0xA00004A61041CLL, //10.0.19041.1052
0xA00004A610439LL, //10.0.19041.1081,
0xA00004A610508LL, //10.0.19041.1288,
0xA0000536A0001LL, //10.0.21354.1,
0xA000055EC0001LL, //10.0.21996.1,
0xA000055F00001LL //10.0.22000.1
};
#ifdef _WIN64
#define RPC_CORE_DESCRIPTION "Windows 10 64bits wow64 runtime core"
#define RPC_CORE_DESCRIPTION "Windows 10/11 64bits wow64 runtime core"
#define RPC_CORE_IS_WOW64 TRUE
#define PTR_T *__ptr32 //WOW64!!!
#define ULONG_PTR_T ULONG
@@ -132,4 +180,4 @@ typedef struct _RPC_ADDRESS_T{
#pragma pack()
#endif // _RPC_INTERNALS_H_
#endif // _RPC_INTERNALS_H_
+65 -17
View File
@@ -5,30 +5,78 @@
#include <Rpc.h>
static UINT64 RPC_CORE_RUNTIME_VERSION[] = {
0x6000324D70000LL, //6.3.9431.0000
0x6000325804000LL, //6.3.9600.16384
0x6000325804340LL, //6.3.9600.17216
0x6000325804407LL, //6.3.9600.17415
0x60003258045FFLL, //6.3.9600.17919
0x6000325804774LL, //6.3.9600.18292
0xA000028004000LL, //10.0.10240.16384
0x6000324D70000LL, //6.3.9431.0000
0x6000325804000LL, //6.3.9600.16384
0x6000325804340LL, //6.3.9600.17216
0x6000325804407LL, //6.3.9600.17415
0x60003258045FFLL, //6.3.9600.17919
0x6000325804774LL, //6.3.9600.18292
0x6000325804AE8LL, //6.3.9600.19176
0x6000325804C52LL, //6.3.9600.19538
0xA000028004000LL, //10.0.10240.16384
0xA00002800401CLL, //10.0.10240.16412
0xA0000295A0000LL, //10.0.10586.0
0xA0000295A0132LL, //10.0.10586.306
0xA0000380603E8LL, //10.0.14342.1000
0xA000038190000LL, //10.0.14361.0
0xA000038390000LL, //10.0.14393.0
0xA000038390052LL, //10.0.14393.82
0xA0000280041C9LL, //10.0.10240.16841
0xA0000295A0000LL, //10.0.10586.0
0xA0000295A0132LL, //10.0.10586.306
0xA0000295A0498LL, //10.0.10586.1176
0xA0000380603E8LL, //10.0.14342.1000
0xA000038190000LL, //10.0.14361.0
0xA000038390000LL, //10.0.14393.0
0xA000038390052LL, //10.0.14393.82
0xA0000383906EALL, //10.0.14393.1770
0xA000038390908LL, //10.0.14393.2312
0xA000038390A69LL, //10.0.14393.2665
0xA000038390C2BLL, //10.0.14393.3115
0xA00003AD70000LL, //10.0.15063.0
0xA00003AD701BFLL, //10.0.15063.447
0xA00003AD702A2LL, //10.0.15063.674
0xA00003F6803E8LL, //10.0.16232.1000
0xA00003FAB000FLL, //10.0.16299.15
0xA0000427903E8LL, //10.0.17017.1000
0xA00003FAB00C0LL, //10.0.16299.192
0xA00003FAB0135LL, //10.0.16299.309
0xA00003FAB0173LL, //10.0.16299.371
0xA00003FAB01ECLL, //10.0.16299.492
0xA00003FAB02D6LL, //10.0.16299.726
0xA00003FAB034ELL, //10.0.16299.846
0xA0000427903E8LL, //10.0.17017.1000
0xA0000428103E8LL, //10.0.17025.1000
0xA000042B203EALL, //10.0.17074.1002
0xA000042EE0001LL, //10.0.17134.1
0xA000042EE0030LL, //10.0.17134.48
0xA000042EE0070LL, //10.0.17134.112
0xA000042EE00E4LL, //10.0.17134.228
0xA000042EE0197LL, //10.0.17134.407
0xA000042EE01D7LL, //10.0.17134.471
0xA000042EE0288LL, //10.0.17134.648
0xA000042EE046ALL, //10.0.17134.1130
0xA000045630001LL, //10.0.17763.1
0xA000045630086LL, //10.0.17763.134
0xA0000456300C2LL, //10.0.17763.194
0xA00004563017BLL, //10.0.17763.379
0xA0000456302CFLL, //10.0.17763.719
0xA000045630360LL, //10.0.17763.864
0xA000045630629LL, //10.0.17763.1577
0xA0000456306A1LL, //10.0.17763.1697
0xA000045630757LL, //10.0.17763.1879
0xA0000456307CFLL, //10.0.17763.1999
0xA000047BA0001LL, //10.0.18362.1
0xA000047BA01DCLL, //10.0.18362.476
0xA000047BA0274LL, //10.0.18362.628
0xA00004A610001LL, //10.0.19041.1
0xA00004A6101FCLL, //10.0.19041.508
0xA00004A610222LL, //10.0.19041.546
0xA00004A610276LL, //10.0.19041.630
0xA00004A610296LL, //10.0.19041.662
0xA00004A6102EALL, //10.0.19041.746
0xA00004A61041CLL, //10.0.19041.1052
0xA00004A610439LL, //10.0.19041.1081,
0xA00004A610508LL, //10.0.19041.1288,
0xA0000536A0001LL, //10.0.21354.1
0xA000055EC0001LL, //10.0.21996.1,
0xA000055F00001LL //10.0.22000.1
};
#define RPC_CORE_DESCRIPTION "Windows 10 64bits runtime core"
#define RPC_CORE_DESCRIPTION "Windows 10/11 64bits runtime core"
#define RPC_CORE_IS_WOW64 FALSE
#define ULONG_PTR_T ULONG_PTR
@@ -134,4 +182,4 @@ typedef struct _RPC_ADDRESS_T{
#pragma pack()
#endif // _RPC_INTERNALS_H_
#endif // _RPC_INTERNALS_H_
+20 -2
View File
@@ -546,7 +546,7 @@ BOOL __fastcall processCorrelationDescriptorNaked(
ss << "StructMember"<<std::dec<<uCorrDescMember;
strCorrelationItem = ss.str();
}
else if(confDesc.corrDesc.correlation_type & FC_POINTER_CONFORMANCE) // case of FC_TOP_LEVEL_MULTID_CONFORMANCE
else if(confDesc.corrDesc.correlation_type & FC_TOP_LEVEL_MULTID_CONFORMANCE) // case of FC_TOP_LEVEL_MULTID_CONFORMANCE
{
// currently not implemented
oss<<"/*FC_TOP_LEVEL_MULTID_CONFORMANCE not implemented */)]";
@@ -597,7 +597,25 @@ BOOL __fastcall processCorrelationDescriptorNaked(
{
case FC_DEREFERENCE:
oss << "*" << strCorrelationItem;
// the correlation item describing the size of the current item
// can derive from an out parameter. In that case, we can only set it
// has a max range and not the exact size since it's not known before the call.
// Ex :
// HRESULT Proc0 (
// [in] int arg1,
// [out] int *arg2,
// [out][size_is( , *arg2)] int **arg2
// );
if (paramDesc.isOut())
{
oss << ", *" << strCorrelationItem;
}
else
{
oss << "*" << strCorrelationItem;
}
break;
case FC_ADD_1:
+3 -7
View File
@@ -92,9 +92,9 @@ bool TypeToDefine::operator<( const TypeToDefine& right)
{
return (this->m_rva < right.m_rva);
}
bool TypeToDefine::operator== ( const TypeToDefine& right)
bool operator== ( const TypeToDefine& self, const TypeToDefine& right)
{
return (this->m_rva == right.m_rva);
return (self.m_rva == right.m_rva);
}
@@ -215,8 +215,4 @@ void ParamDesc::fillWithParamAttr(_In_ PARAM_ATTRIBUTES paramAttr)
// TODO how to handle simple ref ?
if(paramAttr.IsSimpleRef) m_uPtrLevel++;
//....
}
}
+4 -8
View File
@@ -1,7 +1,7 @@
#include "internalRpcUtils.h"
#include <list>
#include <sstream>
#include <codecvt>
//--------------------------------------------------------------------------
BOOL __fastcall isStandardCharacter(_In_ const WCHAR wc)
@@ -32,14 +32,10 @@ BOOL __fastcall isStandardCharacter(_In_ const WCHAR wc)
std::string narrow(
_In_ const std::wstring& ws)
{
//std::vector<char> buffer(ws.size());
////std::locale loc("english");
//std::locale loc;
//std::use_facet< std::ctype<wchar_t> > (loc).narrow(ws.data(), ws.data() + ws.size(), '?', &buffer[0]);
using convert_typeX = std::codecvt_utf8<wchar_t>;
std::wstring_convert<convert_typeX, wchar_t> converterX;
//return std::string(&buffer[0], buffer.size());
return std::string(ws.begin(), ws.end());
return converterX.to_bytes(ws);
}
-123
View File
@@ -39,7 +39,6 @@ extern "C" {
BOOL __fastcall RpcDecompilerPrintOneProcedure(VOID* pRpcDecompilerCtxt, UINT ProcIndex, std::list<TypeToDefine>& listProcType, std::ostringstream& ossProc);
BOOL __fastcall RpcDecompilerDecodeOneProcedureInlined(VOID* pContext, UINT ProcIndex, IdlFunctionDesc& IdlFunctionDesc, std::list<TypeToDefine>& listProcType);
BOOL __fastcall RpcDecompilerPrintOneProcedureInlined(VOID* pContext, UINT ProcOffset, IdlFunctionDesc& IdlFunctionDesc, std::list<TypeToDefine>& listProcType, std::ostringstream& ossProc);
BOOL __fastcall RpcDecompilerPrintHiddenFUProcedure(VOID* pRpcDecompilerCtxt, UINT * procOffset, std::list<TypeToDefine>& listProcType, std::ostringstream& ossProc);
BOOL __fastcall RpcDecompilerPrintAllProceduresNew(VOID* pRpcDecompilerCtxt);
@@ -445,128 +444,6 @@ End:
return (bResult);
}
BOOL __fastcall RpcDecompilerPrintHiddenFUProcedure(VOID* pContext, UINT * procOffset, std::list<TypeToDefine>& listProcType, std::ostringstream& ossProc)
{
UINT paramSizeInBytes = RPC_DECOMPILER_INVALID_PARAM_SIZE;
BOOL bResult = FALSE;
RpcDecompilerCtxt_T* pRpcDecompilerCtxt = (RpcDecompilerCtxt_T*)pContext;
UINT paramOffset = 0;
UINT numParam = 0;
BOOL isReturnParam = FALSE;
BOOL nextIsReturnParam = FALSE;
UINT sizeOfProcDescr = 0;
IdlFunctionDesc IdlFunctionDesc;
if (pRpcDecompilerCtxt == NULL) goto End;
if (pRpcDecompilerCtxt->pRpcViewHelper == NULL) goto End;
if (pRpcDecompilerCtxt->pRpcDecompilerInfo == NULL) goto End;
if (pRpcDecompilerCtxt->pRpcDecompilerInfo->pProcFormatString == NULL) goto End;
RVA_T pFunction = pRpcDecompilerCtxt->pRpcDecompilerInfo->pProcFormatString + *procOffset;
// carriage return before display function
//ossProc << "\t/* Function 0x" << std::hex << ProcIndex<< " */"<< std::endl;
ossProc << std::endl;
//RpcDecompilerPrintFunctionDbgInfo(pContext, *procOffset, ossProc);
ossProc << "\t /* Function index : 0x" << std::hex << *procOffset;
ossProc << "\t Module Base : 0x" << (unsigned long) pRpcDecompilerCtxt->pRpcDecompilerInfo->pModuleBase;
ossProc << "\t RVA of proc in format string : 0x" << (unsigned long) ((UINT64)pFunction - pRpcDecompilerCtxt->pRpcDecompilerInfo->pModuleBase);
ossProc << " */"<<std::endl;
//todo
bResult = RpcDecompilerDecodeAndPrintPrototypeReturnType(
/* in */ pRpcDecompilerCtxt,
/* in */ *procOffset,
/* out */ &paramOffset,
/* out */ &sizeOfProcDescr,
/* out */ IdlFunctionDesc,
/* in/out */listProcType,
/* in/out */ ossProc);
if (bResult == FALSE) goto End;
ossProc << " _HiddenFunction_" << std::dec << *procOffset << "(";
// Increment procOffset to read the next procedure description
*procOffset += sizeOfProcDescr;
if (bResult == FALSE) goto End;
RPC_DEBUG_FN((UCHAR*)"\nRpcDecompilerPrintProcedure: RpcDecompilerPrintPrototypeName returned nbParamToPrint = %d\n", IdlFunctionDesc.getNbParam());
if(IdlFunctionDesc.getNbParam() == 0)
{
//No parameter to be printed
ossProc << " void ";
}
//Print each parameter
while( (numParam < IdlFunctionDesc.getNbParam()) )
{
RPC_DEBUG_FN((UCHAR*)"\nRpcDecompilerPrintProcedure: numParam = 0x%x on total to print = 0x%x\n", numParam, IdlFunctionDesc.getNbParam());
bResult = RpcDecompilerGetReturnParamInfo(/* in */ pRpcDecompilerCtxt, /* in */ paramOffset, /* in */ paramDescrOif, /* out */ &isReturnParam);
if (bResult == FALSE) goto End;
if( ! isReturnParam)
{
//Print the parameter
bResult = RpcDecompilerPrintParam(
/* in */ pRpcDecompilerCtxt,
/* in */ paramOffset,
/* in */ paramDescrOif,
/* out */ &paramSizeInBytes,
/* in */ IdlFunctionDesc,
listProcType,
ossProc); //TODO : décompiler paramDescrOi en plus de paramDescrOif
if (bResult == FALSE || paramSizeInBytes == RPC_DECOMPILER_INVALID_PARAM_SIZE)
{
displayErrorMessage(ossProc, "RpcDecompilerPrintOneProcedure : unable to decode param");
goto End;
}
}
else
{
paramSizeInBytes = OIF_PARAM_SIZE; //TODO : traiter le cas où codage pas OIF
}
paramOffset += paramSizeInBytes;//paramSizeInBytes;
numParam++;
RPC_DEBUG_FN((UCHAR*)"\nRpcDecompilerPrintProcedure: paramOffset = %d, numParam = %d\n", paramOffset, numParam);
//Is there one additionnal parameter to be printed ?
if ( (! isReturnParam) && (numParam < IdlFunctionDesc.getNbParam()) )
{
//The last parameter has been printed because it was not a return parameter
//There is still at least 1 parameter to be printed
bResult = RpcDecompilerGetReturnParamInfo(/* in */ pRpcDecompilerCtxt, /* in */ paramOffset, /* in */ paramDescrOif, /* out */ &nextIsReturnParam);
if (bResult == FALSE) goto End;
if (! nextIsReturnParam)
{
//The next parameter will have to be printed because it is not a return parameter
ossProc << ", ";
}
}
}//while(numParam <= IdlFunctionDesc.getNbParam());
// Print the end of the procedure prototype
ossProc<<");"<<std::endl;
bResult = TRUE;
End:
return (bResult);
}
//------------------------------------------------------------------------------
VOID __fastcall RpcDecompilerPrintFunctionDbgInfo(VOID* pContext, UINT procIndex, std::ostringstream& oss)
{
+2 -1
View File
@@ -1043,7 +1043,7 @@ BOOL __fastcall processComplexArray(
oss<<" /* ";
for(j; j<i; j++){
if(callbacksCalled[j] != -1)
if(callbacksCalled[j] != (UINT16)-1)
{
oss<<" callback_"<<std::dec<<callbacksCalled[j]<<" used, ";
}
@@ -1104,6 +1104,7 @@ UINT __fastcall getArrayMemorySize(
case FC_LGVARRAY:
RPC_GET_PROCESS_DATA(pType, &longArray, sizeof(LGFixedSizedArrayHeader_t));
arraySize = longArray.totalSize;
break;
default:
arraySize = POINTER_SIZE;
break;
+1 -1
View File
@@ -1985,7 +1985,7 @@ public:
// operator
bool operator<( const TypeToDefine& right);
bool operator== ( const TypeToDefine& right);
friend bool operator==( const TypeToDefine& self, const TypeToDefine& right);
};
+1 -1
View File
@@ -46,5 +46,5 @@ add_executable(
# Disable compiler warnings:
# C4091 in ShlObj.h and Dbghelp.h
# C4127 (conditional expression is constant) in qt headers
set_target_properties(${PROJECT_NAME} PROPERTIES COMPILE_FLAGS "/wd4091 /wd4127")
set_target_properties(${PROJECT_NAME} PROPERTIES COMPILE_FLAGS "/wd4091 /wd4127 /wd4714")
target_link_libraries(RpcView Qt5::Widgets $ENV{CMAKE_PREFIX_PATH}/lib/Qt5WinExtras.lib)
+1 -1
View File
@@ -31,7 +31,7 @@ DecompilationWidget_C::DecompilationWidget_C(QWidget *parent) : QDockWidget(Widg
pTextEdit = new QTextEdit(this);
pTextEdit->setLineWrapMode(QTextEdit::NoWrap);
pTextEdit->setFont(font);
pTextEdit->setTabStopWidth(font.pointSize()*TAB_AS_CHARS);
pTextEdit->setTabStopDistance(font.pointSize()*TAB_AS_CHARS);
pIdlHighlighter = new IdlHighlighter_C(pTextEdit->document());
setWidget(pTextEdit);
+1 -1
View File
@@ -65,7 +65,7 @@ ULONG EndpointsWidget_C::GetTotalEndpoints()
//------------------------------------------------------------------------------
void EndpointsWidget_C::SnapEndpoint()
{
PrivateItemList = pModel->findItems(".*", Qt::MatchRegExp, Column_Name);
PrivateItemList = pModel->findItems(".*", Qt::MatchRegularExpression, Column_Name);
}
+1 -1
View File
@@ -34,7 +34,7 @@ InitViewsVisitor_C::InitViewsVisitor_C(RpcCore_T* pRpcCore,void** ppRpcCoreCtxt)
this->pRpcCore= pRpcCore;
this->NbOfInterfaces = 0;
this->pRpcCoreCtxt = pRpcCore->RpcCoreInitFn();
this->pRpcCoreCtxt = pRpcCore->RpcCoreInitFn(pRpcCore->bForceLoading);
if (this->pRpcCoreCtxt==NULL) goto End;
*ppRpcCoreCtxt = this->pRpcCoreCtxt;
+15 -2
View File
@@ -8,6 +8,10 @@
#include "../RpcCommon/Misc.h"
#include "Pdb.h"
#include <Dbghelp.h>
#include <strsafe.h>
static WCHAR FullPath[MAX_PATH];
static RPC_WSTR pUuidString = NULL;
//------------------------------------------------------------------------------
InterfaceSelectedVisitor_C::InterfaceSelectedVisitor_C(quint32 Pid, RPC_IF_ID* pIf,RpcCore_T* pRpcCore,void* pRpcCoreCtxt)
@@ -18,12 +22,15 @@ InterfaceSelectedVisitor_C::InterfaceSelectedVisitor_C(quint32 Pid, RPC_IF_ID* p
this->pRpcCoreCtxt = pRpcCoreCtxt;
this->pRpcInterfaceInfo = pRpcCore->RpcCoreGetInterfaceInfoFn( pRpcCoreCtxt, Pid, pIf, RPC_INTERFACE_INFO_ALL );
UuidToStringW(&pIf->Uuid, &pUuidString);
GetFullPathNameW(L"RpcView.ini", _countof(FullPath), FullPath, NULL);
}
//------------------------------------------------------------------------------
InterfaceSelectedVisitor_C::~InterfaceSelectedVisitor_C()
{
RpcStringFreeW(&pUuidString);
if (pRpcInterfaceInfo != NULL)
{
pRpcCore->RpcCoreFreeInterfaceInfoFn(pRpcCoreCtxt, pRpcInterfaceInfo);
@@ -60,7 +67,7 @@ void InterfaceSelectedVisitor_C::Visit(InterfaceInfoWidget_C* pInterfaceInfoWidg
SymbolName[0]=0;
if (pRpcInterfaceInfo->pLocationBase!=NULL)
{
hProcess=OpenProcess(PROCESS_ALL_ACCESS,FALSE,Pid);
hProcess=ProcexpOpenProcess(PROCESS_ALL_ACCESS,FALSE,Pid);
if (hProcess==NULL) goto End;
hPdb = PdbInit(hProcess, pRpcInterfaceInfo->pLocationBase, pRpcInterfaceInfo->LocationSize);
@@ -133,7 +140,7 @@ void InterfaceSelectedVisitor_C::Visit(ProceduresWidget_C* pProceduresWidget)
case IfType_RPC:
if (pRpcInterfaceInfo->pLocationBase==NULL) goto End;
hProcess=OpenProcess(PROCESS_ALL_ACCESS,FALSE,Pid);
hProcess=ProcexpOpenProcess(PROCESS_ALL_ACCESS,FALSE,Pid);
if (hProcess==NULL) goto End;
hPdb = PdbInit(hProcess, pRpcInterfaceInfo->pLocationBase, pRpcInterfaceInfo->LocationSize);
@@ -146,6 +153,12 @@ void InterfaceSelectedVisitor_C::Visit(ProceduresWidget_C* pProceduresWidget)
{
PdbGetSymbolName(hPdb, (UCHAR*)pRpcInterfaceInfo->pLocationBase + pRpcInterfaceInfo->ppProcAddressTable[ProcIdx], SymbolName, sizeof(SymbolName));
}
if (SymbolName[0] == 0) {
WCHAR ProcIdxName[10];
StringCbPrintfW(ProcIdxName, sizeof(ProcIdxName), L"Proc%u", ProcIdx);
GetPrivateProfileStringW((LPCWSTR)pUuidString, ProcIdxName, NULL, SymbolName, sizeof(SymbolName)/sizeof(SymbolName[0]), FullPath);
}
if ( (pRpcInterfaceInfo->pFormatStringOffsetTable==NULL)||
(pRpcInterfaceInfo->pProcFormatString==NULL))
{
+5 -3
View File
@@ -48,13 +48,15 @@ void InterfacesWidget_C::InterfaceSelected(const QModelIndex& Index)
{
QStringList PidStringList;
QStringList VersionStringList;
QByteArray UuidStringARef;
RPC_IF_ID RpcIfId;
UCHAR* pUuidStringA;
QString PidString = pProxyModel->data( pProxyModel->index(Index.row(), Column_Pid) ).toString();
pUuidStringA = (UCHAR*)pProxyModel->data( pProxyModel->index(Index.row(), Column_Uuid) ).toString().toLatin1().data();
UuidStringARef = pProxyModel->data(pProxyModel->index(Index.row(), Column_Uuid)).toString().toLatin1();
pUuidStringA = (UCHAR*)UuidStringARef.data();
QString VersionString = pProxyModel->data( pProxyModel->index(Index.row(), Column_Version) ).toString();
VersionStringList = VersionString.split(".", QString::SkipEmptyParts, Qt::CaseSensitive);
VersionStringList = VersionString.split(".", Qt::SkipEmptyParts, Qt::CaseSensitive);
if (VersionStringList.isEmpty())
{
@@ -107,7 +109,7 @@ void InterfacesWidget_C::ApplyProcessFilter(quint32 Pid)
//------------------------------------------------------------------------------
void InterfacesWidget_C::SnapInterfaces()
{
PrivateItemList = pModel->findItems(".*", Qt::MatchRegExp, Column_Uuid);
PrivateItemList = pModel->findItems(".*", Qt::MatchRegularExpression, Column_Uuid);
}
+39 -6
View File
@@ -19,8 +19,18 @@
#define BELOW_NORMAL_REFRESH_SPEED 2000
#define SLOW_REFRESH_SPEED 5000
#define VERY_SLOW_REFRESH_SPEED 10000
#define MANUAL_REFRESH_SPEED 0
#define SHELL_EXECUTE_SUCCESS ((HINSTANCE)42) // According to the doc, welcome the 16-bit compatibilty
#ifdef __cplusplus
extern "C" {
#endif
extern RpcCore_T gRpcCoreManager;
#ifdef __cplusplus
}
#endif
extern ULONG NTAPI DecompilerExceptionFilter(EXCEPTION_POINTERS* pExceptionPointers);
extern HMODULE NTAPI LoadDecompilerEngine(RpcDecompilerHelper_T** ppRpcDecompilerHelper);
@@ -32,9 +42,9 @@ static const char WidgetName[] = "RpcView";
//------------------------------------------------------------------------------
void MainWindow_C::InterfaceSelected(quint32 Pid, RPC_IF_ID* pIf)
{
CHAR SymbolPath;
CHAR SymbolPath[MAX_PATH] = {0};
if (GetEnvironmentVariableA("RpcViewSymbolPath",&SymbolPath,sizeof(SymbolPath))==0)
if (GetEnvironmentVariableA("RpcViewSymbolPath",SymbolPath,sizeof(SymbolPath))==0)
{
StatusBar.showMessage("Symbol path not configured.");
}
@@ -183,7 +193,7 @@ BOOL __fastcall RpcGetProcessData(RpcModuleInfo_T* pRpcModuleInfo, RVA_T Rva, VO
if (pRpcModuleInfo == NULL) goto End;
pAddress = (VOID*)(pRpcModuleInfo->pModuleBase + Rva);
hProcess = OpenProcess(PROCESS_VM_READ | PROCESS_QUERY_INFORMATION, FALSE, pRpcModuleInfo->Pid);
hProcess = ProcexpOpenProcess(PROCESS_VM_READ | PROCESS_QUERY_INFORMATION, FALSE, pRpcModuleInfo->Pid);
if (hProcess == NULL) goto End;
bResult = ReadProcessMemory(hProcess, pAddress, pBuffer, BufferLength, NULL);
End:
@@ -261,6 +271,10 @@ void MainWindow_C::SlotDecompileInterface(quint32 Pid, RPC_IF_ID* pIf)
if (pRpcInterfaceInfo == NULL) goto End;
InitDecompilerInfo(pRpcInterfaceInfo, &RpcDecompilerInfo);
__try{
if (!this->pDecompilationWidget->isVisible())
this->pDecompilationWidget->show();
RpcViewHelper_T LocalRpcViewHelper = {
this->pDecompilationWidget,
&RpcAlloc,
@@ -299,7 +313,10 @@ void MainWindow_C::ViewDetailsForAllProcesses()
UCHAR FilePath[MAX_PATH];
GetModuleFileNameA(NULL,(LPSTR)FilePath,_countof(FilePath));
hInstance = ShellExecuteA(NULL, "runas", (LPCSTR)FilePath, 0, 0, SW_SHOWNORMAL);
if (gRpcCoreManager.bForceLoading)
hInstance = ShellExecuteA(NULL, "runas", (LPCSTR)FilePath, "/f", 0, SW_SHOWNORMAL);
else
hInstance = ShellExecuteA(NULL, "runas", (LPCSTR)FilePath, 0, 0, SW_SHOWNORMAL);
if ( hInstance == SHELL_EXECUTE_SUCCESS)
{
Exit();
@@ -458,6 +475,7 @@ void MainWindow_C::ConfigureSymbols()
void MainWindow_C::SetUpdateSpeedAsFast()
{
this->RefreshSpeedInMs = FAST_REFRESH_SPEED;
pRefreshTimer->start();
pRefreshTimer->setInterval(this->RefreshSpeedInMs);
}
@@ -466,6 +484,7 @@ void MainWindow_C::SetUpdateSpeedAsFast()
void MainWindow_C::SetUpdateSpeedAsNormal()
{
this->RefreshSpeedInMs = NORMAL_REFRESH_SPEED;
pRefreshTimer->start();
pRefreshTimer->setInterval(this->RefreshSpeedInMs);
}
@@ -474,6 +493,7 @@ void MainWindow_C::SetUpdateSpeedAsNormal()
void MainWindow_C::SetUpdateSpeedAsBelowNormal()
{
this->RefreshSpeedInMs = BELOW_NORMAL_REFRESH_SPEED;
pRefreshTimer->start();
pRefreshTimer->setInterval(this->RefreshSpeedInMs);
}
@@ -482,6 +502,7 @@ void MainWindow_C::SetUpdateSpeedAsBelowNormal()
void MainWindow_C::SetUpdateSpeedAsSlow()
{
this->RefreshSpeedInMs = SLOW_REFRESH_SPEED;
pRefreshTimer->start();
pRefreshTimer->setInterval(this->RefreshSpeedInMs);
}
@@ -490,9 +511,17 @@ void MainWindow_C::SetUpdateSpeedAsSlow()
void MainWindow_C::SetUpdateSpeedAsVerySlow()
{
this->RefreshSpeedInMs = VERY_SLOW_REFRESH_SPEED;
pRefreshTimer->start();
pRefreshTimer->setInterval(this->RefreshSpeedInMs);
}
//------------------------------------------------------------------------------
void MainWindow_C::SetUpdateSpeedAsManual()
{
this->RefreshSpeedInMs = MANUAL_REFRESH_SPEED;
pRefreshTimer->stop();
}
//------------------------------------------------------------------------------
void MainWindow_C::InvokeFindShortcut()
@@ -583,12 +612,14 @@ void MainWindow_C::SetupMenu()
pActionSpeedBelowNormal = pSubMenupdateSpeed->addAction("2 seconds", this, SLOT(SetUpdateSpeedAsBelowNormal()));
pActionSpeedSlow = pSubMenupdateSpeed->addAction("5 seconds", this, SLOT(SetUpdateSpeedAsSlow()));
pActionSpeedVerySlow = pSubMenupdateSpeed->addAction("10 seconds", this, SLOT(SetUpdateSpeedAsVerySlow()));
pActionSpeedManual = pSubMenupdateSpeed->addAction("manual", this, SLOT(SetUpdateSpeedAsManual()));
pActionSpeedFast->setCheckable(true);
pActionSpeedNormal->setCheckable(true);
pActionSpeedBelowNormal->setCheckable(true);
pActionSpeedSlow->setCheckable(true);
pActionSpeedVerySlow->setCheckable(true);
pActionSpeedManual->setCheckable(true);
QActionGroup* pSpeedActionGroup = new QActionGroup(this);
@@ -597,6 +628,7 @@ void MainWindow_C::SetupMenu()
pSpeedActionGroup->addAction(pActionSpeedBelowNormal);
pSpeedActionGroup->addAction(pActionSpeedSlow);
pSpeedActionGroup->addAction(pActionSpeedVerySlow);
pSpeedActionGroup->addAction(pActionSpeedManual);
//
// View
//
@@ -655,6 +687,7 @@ void MainWindow_C::InitMenuRefreshSpeed()
case BELOW_NORMAL_REFRESH_SPEED : pActionSpeedBelowNormal->setChecked(true); break;
case SLOW_REFRESH_SPEED : pActionSpeedSlow->setChecked(true); break;
case VERY_SLOW_REFRESH_SPEED : pActionSpeedVerySlow->setChecked(true); break;
case MANUAL_REFRESH_SPEED : pActionSpeedManual->setChecked(true); break;
//--
default:
break;
@@ -798,7 +831,7 @@ MainWindow_C::MainWindow_C(RpcCore_T* pRpcCore)
//
pRefreshTimer = new QTimer(this);
connect(pRefreshTimer, SIGNAL(timeout()), this, SLOT(RefreshViews()));
pRefreshTimer->start(this->RefreshSpeedInMs);
if (this->RefreshSpeedInMs) pRefreshTimer->start(this->RefreshSpeedInMs);
InitColumnsDialog();
}
}
+2
View File
@@ -51,6 +51,7 @@ private slots:
void SetUpdateSpeedAsBelowNormal();
void SetUpdateSpeedAsSlow();
void SetUpdateSpeedAsVerySlow();
void SetUpdateSpeedAsManual();
void ShowColumnsDialog();
void UpdateColumns();
//--
@@ -86,6 +87,7 @@ private:
QAction* pActionSpeedBelowNormal;
QAction* pActionSpeedSlow;
QAction* pActionSpeedVerySlow;
QAction* pActionSpeedManual;
QAction* pAddressAbsolute;
QAction* pAddressRva;
+1 -1
View File
@@ -207,7 +207,7 @@ ProceduresWidget_C::ProceduresWidget_C(QWidget* pParent):QDockWidget(WidgetName)
pProcedures->setColumnCount(ProceduresWigetColumn_Last);
pProcedures->setSortingEnabled(true);
pProcedures->sortByColumn(-1);
pProcedures->sortByColumn(-1, Qt::AscendingOrder);
pProcedures->setAnimated(true);
pProcedures->expandAll();
pProcedures->setAlternatingRowColors(true);
+8 -8
View File
@@ -77,8 +77,8 @@ void ProcessWidget_C::SelectProcess(quint32 Pid)
//------------------------------------------------------------------------------
void ProcessWidget_C::SnapProcesses()
{
PrivateTreeItemList = pProcessTree->findItems(".*", Qt::MatchRegExp|Qt::MatchRecursive, Column_Pid);
PrivateViewItemList = pModel->findItems(".*", Qt::MatchRegExp, Column_Pid);
PrivateTreeItemList = pProcessTree->findItems(".*", Qt::MatchRegularExpression |Qt::MatchRecursive, Column_Pid);
PrivateViewItemList = pModel->findItems(".*", Qt::MatchRegularExpression, Column_Pid);
}
@@ -341,8 +341,8 @@ void ProcessWidget_C::LoadConfiguration(QSettings* pSettings)
//
// Force Tree sorting by PID
//
pProcessTree->sortByColumn(Column_Pid);
pProcessTree->sortByColumn(-1);
pProcessTree->sortByColumn(Column_Pid, Qt::AscendingOrder);
pProcessTree->sortByColumn(-1, Qt::AscendingOrder);
}
//------------------------------------------------------------------------------
@@ -358,8 +358,8 @@ void ProcessWidget_C::InitProcessTreeWidget(QWidget* pParent)
pHeaderItem->setText( Idx, GetColumName((Column_T)Idx) );
}
pProcessTree->setColumnCount(Column_Last);
pProcessTree->sortByColumn(Column_Pid);
pProcessTree->sortByColumn(-1);
pProcessTree->sortByColumn(Column_Pid, Qt::AscendingOrder);
pProcessTree->sortByColumn(-1, Qt::AscendingOrder);
pProcessTree->setAnimated(true);
pProcessTree->setSortingEnabled(true);
@@ -524,8 +524,8 @@ void ProcessWidget_C::ViewHeaderClicked(int logicalIndex)
pStackedWidget->setCurrentWidget(pProcessTree);
pProcessTree->header()->restoreState(pProcessView->header()->saveState());
pProcessTree->sortByColumn(Column_Pid);
pProcessTree->sortByColumn(-1);
pProcessTree->sortByColumn(Column_Pid,Qt::AscendingOrder);
pProcessTree->sortByColumn(-1, Qt::AscendingOrder);
pProcessTree->scrollToItem(pProcessTree->currentItem());
}
}
+10 -8
View File
@@ -13,7 +13,7 @@ typedef struct _RpcCoreManager_T{
}RpcCoreManager_T;
// RpcCore
VOID* __fastcall RpcCoreInit(); //returns a private context for the RpcCoreEngine
VOID* __fastcall RpcCoreInit(BOOL bForce); //returns a private context for the RpcCoreEngine
VOID __fastcall RpcCoreUninit(VOID* pRpcCoreCtxt);
RpcProcessInfo_T* __fastcall RpcCoreGetProcessInfo(void* pRpcCoreCtxt, DWORD Pid, DWORD Ppid, ULONG ProcessInfoMask);
VOID __fastcall RpcCoreFreeProcessInfo(void* pRpcCoreCtxt, RpcProcessInfo_T* pRpcProcessInfo);
@@ -29,6 +29,7 @@ RpcCore_T gRpcCoreManager =
0,
//"Generic RpcCore Manager",
FALSE,
FALSE,
&RpcCoreInit,
&RpcCoreUninit,
&RpcCoreGetProcessInfo,
@@ -41,7 +42,7 @@ RpcCore_T gRpcCoreManager =
};
//------------------------------------------------------------------------------
BOOL NTAPI LoadCoreEngine(RpcCore_T** ppRpcCoreHelper, void** ppRpcCoreCtxt, BOOL bWow64Helper)
BOOL NTAPI LoadCoreEngine(RpcCore_T** ppRpcCoreHelper, void** ppRpcCoreCtxt, BOOL bWow64Helper, BOOL bForce)
{
WIN32_FIND_DATAA Win32FindData;
HMODULE hLib;
@@ -60,7 +61,7 @@ BOOL NTAPI LoadCoreEngine(RpcCore_T** ppRpcCoreHelper, void** ppRpcCoreCtxt, BOO
pRpcCoreHelper = (RpcCore_T*)(ULONG_PTR)GetProcAddress(hLib, RPC_CORE_EXPORT_SYMBOL);
if (pRpcCoreHelper != NULL)
{
*ppRpcCoreCtxt = pRpcCoreHelper->RpcCoreInitFn();
*ppRpcCoreCtxt = pRpcCoreHelper->RpcCoreInitFn(bForce);
if (*ppRpcCoreCtxt != NULL)
{
pRpcCoreHelper->RpcCoreUninitFn(*ppRpcCoreCtxt);
@@ -86,13 +87,14 @@ End:
//-----------------------------------------------------------------------------
VOID* __fastcall RpcCoreInit()
VOID* __fastcall RpcCoreInit(BOOL bForce)
{
RpcCoreManager_T* pRpcCoreManager;
pRpcCoreManager = (RpcCoreManager_T*)OS_ALLOC(sizeof(RpcCoreManager_T));
if (pRpcCoreManager == NULL) return NULL;
if (!LoadCoreEngine(&pRpcCoreManager->pNativeCore, &pRpcCoreManager->pNativeCoreCtxt, FALSE))
if (!LoadCoreEngine(&pRpcCoreManager->pNativeCore, &pRpcCoreManager->pNativeCoreCtxt, FALSE, bForce))
{
const char Caption[] = "Unsupported runtime version";
#ifdef _WIN64
@@ -107,14 +109,14 @@ VOID* __fastcall RpcCoreInit()
#endif
ExitProcess(0);
}
pRpcCoreManager->pNativeCoreCtxt = pRpcCoreManager->pNativeCore->RpcCoreInitFn();
pRpcCoreManager->pNativeCoreCtxt = pRpcCoreManager->pNativeCore->RpcCoreInitFn(bForce);
#ifdef _WIN64
if (!LoadCoreEngine(&pRpcCoreManager->pWow64Core, &pRpcCoreManager->pWow64CoreCtxt, TRUE))
if (!LoadCoreEngine(&pRpcCoreManager->pWow64Core, &pRpcCoreManager->pWow64CoreCtxt, TRUE,bForce))
{
OS_FREE(pRpcCoreManager);
return NULL;
}
pRpcCoreManager->pWow64CoreCtxt = pRpcCoreManager->pWow64Core->RpcCoreInitFn();
pRpcCoreManager->pWow64CoreCtxt = pRpcCoreManager->pWow64Core->RpcCoreInitFn(bForce);
#endif
return (pRpcCoreManager);
}
+45 -21
View File
@@ -154,7 +154,7 @@ void NTAPI InitDecompilerInfo(_In_ RpcInterfaceInfo_T* pRpcInterfaceInfo, _Out_
pRpcDecompilerInfo->ppProcNameTable = (WCHAR**)OS_ALLOC(pRpcDecompilerInfo->NumberOfProcedures*sizeof(UCHAR*));
if (pRpcDecompilerInfo->ppProcNameTable == NULL) goto End;
hProcess = OpenProcess(PROCESS_ALL_ACCESS, FALSE, pRpcInterfaceInfo->Pid);
hProcess = ProcexpOpenProcess(PROCESS_ALL_ACCESS, FALSE, pRpcInterfaceInfo->Pid);
if (hProcess == NULL) goto End;
#ifdef _WIN64
pRpcDecompilerInfo->bIs64Bits = !pRpcInterfaceInfo->bWow64Process;
@@ -189,7 +189,9 @@ void NTAPI InitDecompilerInfo(_In_ RpcInterfaceInfo_T* pRpcInterfaceInfo, _Out_
{
SymboleLength = ((UINT)wcslen(SymboleName) + 1)*sizeof(WCHAR);
pRpcDecompilerInfo->ppProcNameTable[i] = (WCHAR*)OS_ALLOC(SymboleLength);
memcpy(pRpcDecompilerInfo->ppProcNameTable[i], SymboleName, SymboleLength);
if (pRpcDecompilerInfo->ppProcNameTable[i] != NULL) {
memcpy(pRpcDecompilerInfo->ppProcNameTable[i], SymboleName, SymboleLength);
}
}
}
PdbUninit(hPdb);
@@ -302,7 +304,7 @@ int DecompileAllInterfaces(RpcCore_T* pRpcCore)
EnumCtxt.pRpcDecompilerHelper = pRpcDecompilerHelper;
EnumCtxt.pRpcCore = pRpcCore;
EnumCtxt.pRpcCoreCtxt = pRpcCore->RpcCoreInitFn();
EnumCtxt.pRpcCoreCtxt = pRpcCore->RpcCoreInitFn(FALSE);
if (EnumCtxt.pRpcCoreCtxt==NULL) goto End;
_cprintf("Start scanning...\n");
@@ -328,20 +330,30 @@ End:
HICON hMainIcon;
UCHAR CurrentDirectory[MAX_PATH];
UCHAR* pSeparator;
int ret = 0;
#ifdef _DEBUG
_CrtSetReportMode(_CRT_WARN, _CRTDBG_MODE_FILE);
_CrtSetReportFile(_CRT_WARN, _CRTDBG_FILE_STDOUT);
#else
int argc = 1;
char* pCmdLineA = NULL;
char** argv = &pCmdLineA;
UNREFERENCED_PARAMETER(pCmdLine);
int argc = 0;
UNREFERENCED_PARAMETER(hInstance);
UNREFERENCED_PARAMETER(hPrevInstance);
UNREFERENCED_PARAMETER(nCmdShow);
pCmdLineA = GetCommandLineA();
pCmdLine = GetCommandLineW();
LPWSTR* argvw = CommandLineToArgvW(pCmdLine, &argc);
char** argv = (char**)malloc(argc*sizeof(char*));
if (argv == NULL) return ret;
for (int i = 0; i < argc; i++)
{
size_t tmpSize = lstrlenW(argvw[i]) * 2 + 2;
argv[i] = (char*)malloc(tmpSize);
wcstombs_s(&tmpSize, argv[i], tmpSize, argvw[i], tmpSize);
}
#endif
QApplication app(argc, argv);
QSettings Settings(RPC_VIEW_ORGANIZATION_NAME, RPC_VIEW_APPLICATION_NAME);
@@ -356,23 +368,28 @@ End:
_cprintf("%s\n",CurrentDirectory);
SetCurrentDirectoryA((LPCSTR)CurrentDirectory);
}
//
// Load unsupported runtim versions by default
//
gRpcCoreManager.bForceLoading = TRUE;
#ifdef _DEBUG
if (argc>1)
{
if (!_stricmp(argv[1],"/DA"))
for (int curArg = 1; curArg < argc; curArg++)
{
DecompileAllInterfaces(&gRpcCoreManager);
if (!_stricmp(argv[1], "/DA"))
{
DecompileAllInterfaces(&gRpcCoreManager);
_CrtDumpMemoryLeaks();
}
else
{
_cprintf("Usage %s: [/DA]\n", argv[0]);
_cprintf(" /DA : decompile all interfaces\n");
}
}
else
{
_cprintf("Usage %s: [/DA]\n",argv[0]);
_cprintf(" /DA : decompile all interfaces\n");
}
_CrtDumpMemoryLeaks();
return 0;
}
#endif
pMainWindow = new MainWindow_C(&gRpcCoreManager);
hMainIcon = LoadIcon(GetModuleHandle(NULL), MAKEINTRESOURCE(ID_MAIN_ICON));
@@ -381,5 +398,12 @@ End:
pMainWindow->setWindowIcon(QtWin::fromHICON(hMainIcon));
DestroyIcon(hMainIcon);
}
return app.exec();
ret = app.exec();
#ifndef _DEBUG
for (int i = 0; i < argc; i++)
free(argv[i]);
free(argv);
#endif
return ret;
}
-1
View File
@@ -1 +0,0 @@
theme: jekyll-theme-tactile
+59
View File
@@ -0,0 +1,59 @@
version: 0.3.0.{build}
image: Visual Studio 2019
build_script:
- cmd: >-
cd C:\projects\RpcView
mkdir Build\x64
cd C:\projects\RpcView\Build\x64
set CMAKE_PREFIX_PATH=C:\Qt\5.15.2\msvc2019_64
cmake ..\.. -A x64 -T"v140_xp"
cmake --build . --config release
cd C:\projects\RpcView\Build\x64\bin\Release
mkdir RpcView64
copy *.dll RpcView64\
copy *.exe RpcView64\
C:\Qt\5.15.2\msvc2019_64\bin\windeployqt.exe --release RpcView64\
7z a RpcView64.7z RpcView64
cd C:\projects\RpcView
mkdir Build\x86
cd C:\projects\RpcView\Build\x86
set CMAKE_PREFIX_PATH=C:\Qt\5.15.2\msvc2019
cmake ..\.. -A win32 -T"v140_xp"
cmake --build . --config release
cd C:\projects\RpcView\Build\x86\bin\Release
mkdir RpcView32
copy *.exe RpcView32\
copy *.dll RpcView32\
C:\Qt\5.15.2\msvc2019\bin\windeployqt.exe --release RpcView32\
7z a RpcView32.7z RpcView32
artifacts:
- path: Build\x64\bin\Release\RpcView64.7z
name: RpcView64
- path: Build\x86\bin\Release\RpcView32.7z
name: RpcView32