Refactor hash functions and update types in api_resolver

This commit is contained in:
exsangui
2025-09-23 01:31:51 +02:00
committed by GitHub
parent b8e78e3025
commit 06c0f3dd47
+15 -16
View File
@@ -1,30 +1,29 @@
#include "api_resolver.h"
DWORD compute_custom_hash(const char* str) {
DWORD hash = 0xDEADBEEF;
while (*str) {
unsigned long hashstr(const char* s) {
unsigned long hash = 0xDEADBEEF;
while (*s) {
hash = (hash >> 3) | (hash << 29);
hash ^= *str++;
hash ^= *s++;
hash += 0x55555555;
}
return hash;
}
PVOID get_function_by_hash(HMODULE module, DWORD hash) {
PIMAGE_DOS_HEADER dos_header = (PIMAGE_DOS_HEADER)module;
PIMAGE_NT_HEADERS nt_headers = (PIMAGE_NT_HEADERS)((BYTE*)module + dos_header->e_lfanew);
PIMAGE_EXPORT_DIRECTORY export_dir = (PIMAGE_EXPORT_DIRECTORY)(
(BYTE*)module + nt_headers->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress);
void* findfunc(void* module, unsigned long hash) {
auto dos = (IMAGE_DOS_HEADER*)module;
auto nt = (IMAGE_NT_HEADERS*)((char*)module + dos->e_lfanew);
auto exportdir = (IMAGE_EXPORT_DIRECTORY*)((char*)module + nt->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress);
DWORD* functions = (DWORD*)((BYTE*)module + export_dir->AddressOfFunctions);
DWORD* names = (DWORD*)((BYTE*)module + export_dir->AddressOfNames);
WORD* ordinals = (WORD*)((BYTE*)module + export_dir->AddressOfNameOrdinals);
unsigned long* functions = (unsigned long*)((char*)module + exportdir->AddressOfFunctions);
unsigned long* names = (unsigned long*)((char*)module + exportdir->AddressOfNames);
unsigned short* ordinals = (unsigned short*)((char*)module + exportdir->AddressOfNameOrdinals);
for (DWORD i = 0; i < export_dir->NumberOfNames; i++) {
for (unsigned long i = 0; i < exportdir->NumberOfNames; i++) {
const char* name = (const char*)module + names[i];
if (compute_custom_hash(name) == hash) {
return (PVOID)((BYTE*)module + functions[ordinals[i]]);
if (hashstr(name) == hash) {
return (void*)((char*)module + functions[ordinals[i]]);
}
}
return NULL;
}
}