• <ins id="pjuwb"></ins>
    <blockquote id="pjuwb"><pre id="pjuwb"></pre></blockquote>
    <noscript id="pjuwb"></noscript>
          <sup id="pjuwb"><pre id="pjuwb"></pre></sup>
            <dd id="pjuwb"></dd>
            <abbr id="pjuwb"></abbr>

            S.l.e!ep.¢%

            像打了激速一樣,以四倍的速度運轉(zhuǎn),開心的工作
            簡單、開放、平等的公司文化;尊重個性、自由與個人價值;
            posts - 1098, comments - 335, trackbacks - 0, articles - 1
              C++博客 :: 首頁 :: 新隨筆 :: 聯(lián)系 :: 聚合  :: 管理
            DLL Inject -- 一、Windows 鉤子(Hooks) - (1)

            之前搞復雜了,其實可以很簡單

            有個要點:
            The global hooks are a shared resource, and installing one affects all applications in the same desktop as the calling thread. All global hook functions must be in libraries. Global hooks should be restricted to special-purpose applications or to use as a development aid during application debugging. Libraries that no longer need a hook should remove its hook procedure.

            作為一個全局或跨進程的鉤子,鉤子的實現(xiàn)函數(shù)必須在DLL中實現(xiàn),不然目標程序觸發(fā)到鉤子時就會掛掉

            DLL實現(xiàn)

            //?DLLInject.cpp?:?Defines?the?entry?point?for?the?DLL?application.
            //

            #include?
            "stdafx.h"
            #include?
            <stdio.h>

            LRESULT?CALLBACK?CallWndProc(
            int?code,?WPARAM?wParam,?LPARAM?lParam)
            {?
            ????
            return?CallNextHookEx?(NULL,?code,?wParam,?lParam);
            }

            BOOL?APIENTRY?DllMain(?HANDLE?hModule,?
            ??????????????????????DWORD??ul_reason_for_call,?
            ??????????????????????LPVOID?lpReserved
            ??????????????????????)
            {
            ????
            switch?(?ul_reason_for_call?)
            ????{
            ????
            case?DLL_PROCESS_ATTACH:
            ????????{
            ????????????
            char?szDllName[MAX_PATH]={0};
            ????????????GetModuleFileName((HMODULE)hModule,?szDllName,?MAX_PATH);
            ????????????LoadLibrary(szDllName);????????
            ????????????
            break;
            ????????}
            ????
            case?DLL_PROCESS_DETACH:
            ????????{
            ????????}
            ????????
            break;
            ????}
            ????
            ????
            return?TRUE;
            ????
            }

            在DLL加載時,調(diào)用多一次,LoadLibrary的目的,是為了增加引用計數(shù),這樣即使我們的程序關掉了,系統(tǒng)也不會卸載掉DLL,DLL還在內(nèi)存中(所以通常情況下 LoadLibrary 和 FreeLibrary 要成對調(diào)用, 具體可以了解下 Windows 的內(nèi)存管理機制)

            調(diào)用代碼:
            HHOOK?g_hHook?=?NULL;
            UINT??g_nHOOKMsg?
            =?0;

            //---------------------------------------------------------------------------
            //?ModuleFromAddress
            //
            //?Returns?the?HMODULE?that?contains?the?specified?memory?address
            //---------------------------------------------------------------------------
            static?HMODULE?ModuleFromAddress(PVOID?pv)?
            {
            ????MEMORY_BASIC_INFORMATION?mbi;
            ????
            ????
            return?((::VirtualQuery(pv,?&mbi,?sizeof(mbi))?!=?0)???(HMODULE)?mbi.AllocationBase?:?NULL);
            }

            void?CDLLInjectBySetHookDlg::OnButton1()?
            {????
            ????HMODULE?hModule?
            =?::LoadLibrary("DLLInject.dll");
            ????
            if?(?hModule?==?NULL?)
            ????{
            ????????AfxMessageBox(
            "Failed?to?LoadLibrary!");
            ????????
            return?;
            ????}

            ????typedef?LRESULT?(CALLBACK?
            *CallWndProc)(int?code,?WPARAM?wParam,?LPARAM?lParam);
            ????CallWndProc?pfnCallWndProc?
            =?(CallWndProc)::GetProcAddress(hModule,?"CallWndProc");

            ????
            if?(?pfnCallWndProc?==?NULL?)
            ????{
            ????????AfxMessageBox(
            "Failed?to?GetProcAddress!");
            ????????
            return?;
            ????}

            ????HWND?hWnd?
            =?::FindWindow(NULL,?"testHooked");
            ????
            if?(hWnd?==?NULL)
            ????{
            ????????AfxMessageBox(
            "Failed?to?Find?Window!");
            ????????
            return?;
            ????}

            ????DWORD?dwThreadID?
            =?::GetWindowThreadProcessId(hWnd,?NULL);
            ????
            if?(?dwThreadID?==?0?)
            ????{
            ????????AfxMessageBox(
            "Failed?to?Get?Window?Thread?Process?ID");
            ????????
            return?;
            ????}

            ????g_hHook?
            =?::SetWindowsHookEx(WH_CALLWNDPROC,?(HOOKPROC)(pfnCallWndProc),?ModuleFromAddress(pfnCallWndProc),?dwThreadID);

            ????
            if?(?g_hHook?==?NULL?)
            ????{
            ????????AfxMessageBox(
            "Failed?to?Set?Windows?Hook");
            ????????
            return?;
            ????}

            ????::SendMessage(::FindWindow(NULL,?
            "testHooked"),?WM_USER,?0,?0);
            ????::UnhookWindowsHookEx(g_hHook);
            }


            按下按鈕,使用工具查看,目標程序的加載模塊列表中已經(jīng)有了 DLLInject.dll ,注入成功!
            香蕉久久夜色精品国产小说| 99久久综合国产精品免费| 久久影院综合精品| 久久精品蜜芽亚洲国产AV| 91久久九九无码成人网站| 91精品国产91久久久久久青草 | 精品无码久久久久国产动漫3d| 模特私拍国产精品久久| 香蕉久久夜色精品国产尤物| 久久香蕉国产线看观看精品yw| 久久久久国产精品| 无码任你躁久久久久久老妇App| 久久久久亚洲AV无码永不| 久久人妻少妇嫩草AV蜜桃| 热re99久久6国产精品免费| 无码任你躁久久久久久久| 精品国产福利久久久| 浪潮AV色综合久久天堂| 久久这里只有精品首页| 国产 亚洲 欧美 另类 久久| 亚洲午夜无码久久久久小说| 亚洲国产精品久久久久网站| 欧美亚洲国产精品久久| 久久97久久97精品免视看秋霞| 久久精品桃花综合| 亚洲狠狠综合久久| 高清免费久久午夜精品| 久久精品国产免费观看三人同眠| 亚洲国产精品久久久久久| 久久久WWW成人免费精品| 亚洲国产精品久久久久久| 国产精品99久久久久久人| 久久香综合精品久久伊人| 潮喷大喷水系列无码久久精品| 欧美黑人激情性久久| 777米奇久久最新地址| 久久综合给合久久国产免费| 久久精品水蜜桃av综合天堂| 国产A级毛片久久久精品毛片| 精品伊人久久久| 囯产极品美女高潮无套久久久|