mirror of
https://github.com/tlsbollei/KittyLoader
synced 2026-06-21 14:11:21 +00:00
Refactor hash functions and update types in api_resolver
This commit is contained in:
+15
-16
@@ -1,30 +1,29 @@
|
||||
#include "api_resolver.h"
|
||||
|
||||
DWORD compute_custom_hash(const char* str) {
|
||||
DWORD hash = 0xDEADBEEF;
|
||||
while (*str) {
|
||||
unsigned long hashstr(const char* s) {
|
||||
unsigned long hash = 0xDEADBEEF;
|
||||
while (*s) {
|
||||
hash = (hash >> 3) | (hash << 29);
|
||||
hash ^= *str++;
|
||||
hash ^= *s++;
|
||||
hash += 0x55555555;
|
||||
}
|
||||
return hash;
|
||||
}
|
||||
|
||||
PVOID get_function_by_hash(HMODULE module, DWORD hash) {
|
||||
PIMAGE_DOS_HEADER dos_header = (PIMAGE_DOS_HEADER)module;
|
||||
PIMAGE_NT_HEADERS nt_headers = (PIMAGE_NT_HEADERS)((BYTE*)module + dos_header->e_lfanew);
|
||||
PIMAGE_EXPORT_DIRECTORY export_dir = (PIMAGE_EXPORT_DIRECTORY)(
|
||||
(BYTE*)module + nt_headers->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress);
|
||||
void* findfunc(void* module, unsigned long hash) {
|
||||
auto dos = (IMAGE_DOS_HEADER*)module;
|
||||
auto nt = (IMAGE_NT_HEADERS*)((char*)module + dos->e_lfanew);
|
||||
auto exportdir = (IMAGE_EXPORT_DIRECTORY*)((char*)module + nt->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress);
|
||||
|
||||
DWORD* functions = (DWORD*)((BYTE*)module + export_dir->AddressOfFunctions);
|
||||
DWORD* names = (DWORD*)((BYTE*)module + export_dir->AddressOfNames);
|
||||
WORD* ordinals = (WORD*)((BYTE*)module + export_dir->AddressOfNameOrdinals);
|
||||
unsigned long* functions = (unsigned long*)((char*)module + exportdir->AddressOfFunctions);
|
||||
unsigned long* names = (unsigned long*)((char*)module + exportdir->AddressOfNames);
|
||||
unsigned short* ordinals = (unsigned short*)((char*)module + exportdir->AddressOfNameOrdinals);
|
||||
|
||||
for (DWORD i = 0; i < export_dir->NumberOfNames; i++) {
|
||||
for (unsigned long i = 0; i < exportdir->NumberOfNames; i++) {
|
||||
const char* name = (const char*)module + names[i];
|
||||
if (compute_custom_hash(name) == hash) {
|
||||
return (PVOID)((BYTE*)module + functions[ordinals[i]]);
|
||||
if (hashstr(name) == hash) {
|
||||
return (void*)((char*)module + functions[ordinals[i]]);
|
||||
}
|
||||
}
|
||||
return NULL;
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user