2024-03-29 15:24:31 +08:00
|
|
|
/**
|
|
|
|
veh_hook Vectored Exception Handler hooking library
|
|
|
|
Version: 24-March-2008
|
|
|
|
**/
|
|
|
|
// #define WINVER 0x0501
|
|
|
|
// #define _WIN32_WINNT 0x0501
|
|
|
|
#include <windows.h>
|
|
|
|
#include "veh_hook.h"
|
2024-04-02 15:36:52 +08:00
|
|
|
#include <mutex>
|
|
|
|
static veh_list_t *list = NULL;
|
2024-03-29 15:24:31 +08:00
|
|
|
char int3bp[] = "\xCC";
|
2024-04-02 15:36:52 +08:00
|
|
|
std::mutex vehlistlock;
|
|
|
|
bool add_veh_hook(void *origFunc, newFuncType newFunc, DWORD hook_type)
|
2024-03-29 15:24:31 +08:00
|
|
|
{
|
|
|
|
std::lock_guard _(vehlistlock);
|
2024-04-02 15:36:52 +08:00
|
|
|
// static veh_list_t* list = NULL;
|
2024-03-29 15:24:31 +08:00
|
|
|
DWORD oldProtect;
|
2024-04-02 15:36:52 +08:00
|
|
|
if (list == NULL)
|
|
|
|
list = new_veh_list();
|
|
|
|
if (list == NULL)
|
|
|
|
return false;
|
|
|
|
void *handle = AddVectoredExceptionHandler(1, (PVECTORED_EXCEPTION_HANDLER)veh_dispatch);
|
|
|
|
veh_node_t *newnode = insert_veh_node(list, origFunc, newFunc, handle, hook_type);
|
2024-03-29 15:24:31 +08:00
|
|
|
|
|
|
|
// For memory hooks especially, we need to know the address of the start of the relevant page.
|
|
|
|
MEMORY_BASIC_INFORMATION mem_info;
|
|
|
|
VirtualQuery(origFunc, &mem_info, sizeof(MEMORY_BASIC_INFORMATION));
|
|
|
|
newnode->baseAddr = mem_info.BaseAddress;
|
|
|
|
|
|
|
|
VirtualProtect(origFunc, sizeof(int), PAGE_EXECUTE_READWRITE, &newnode->OldProtect);
|
2024-04-02 15:36:52 +08:00
|
|
|
memcpy((void *)(&newnode->origBaseByte), (const void *)origFunc, sizeof(BYTE));
|
|
|
|
memcpy((void *)origFunc, (const void *)&int3bp, sizeof(BYTE));
|
2024-03-29 15:24:31 +08:00
|
|
|
VirtualProtect(origFunc, sizeof(int), newnode->OldProtect, &oldProtect);
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2024-04-02 15:36:52 +08:00
|
|
|
bool remove_veh_hook(void *origFunc)
|
2024-03-29 15:24:31 +08:00
|
|
|
{
|
|
|
|
std::lock_guard _(vehlistlock);
|
2024-04-02 15:36:52 +08:00
|
|
|
if (list == NULL)
|
|
|
|
return false;
|
|
|
|
veh_node_t *node = get_veh_node(list, origFunc);
|
|
|
|
if (node == NULL)
|
|
|
|
return false;
|
2024-03-29 15:24:31 +08:00
|
|
|
DWORD _p;
|
|
|
|
VirtualProtect(node->origFunc, sizeof(int), PAGE_EXECUTE_READWRITE, &_p);
|
2024-04-02 15:36:52 +08:00
|
|
|
memcpy((void *)node->origFunc, (const void *)(&node->origBaseByte), sizeof(char));
|
2024-03-29 15:24:31 +08:00
|
|
|
VirtualProtect(node->origFunc, sizeof(int), node->OldProtect, &_p);
|
|
|
|
RemoveVectoredExceptionHandler(node->handle);
|
|
|
|
return remove_veh_node(list, origFunc);
|
|
|
|
}
|
|
|
|
|
2024-04-02 15:36:52 +08:00
|
|
|
bool remove_veh_node(veh_list_t *list, void *origFunc)
|
2024-03-29 15:24:31 +08:00
|
|
|
{
|
2024-04-02 15:36:52 +08:00
|
|
|
veh_node_t *searchnode;
|
|
|
|
veh_node_t *lastsearchnode = NULL;
|
2024-03-29 15:24:31 +08:00
|
|
|
searchnode = list->head;
|
|
|
|
|
|
|
|
while (searchnode != NULL)
|
|
|
|
{
|
|
|
|
if (searchnode->origFunc == origFunc)
|
|
|
|
{
|
|
|
|
if (lastsearchnode == NULL)
|
|
|
|
{
|
|
|
|
list->head = searchnode->next;
|
2024-04-02 15:36:52 +08:00
|
|
|
if (list->tail == searchnode)
|
|
|
|
list->tail = searchnode->next;
|
2024-03-29 15:24:31 +08:00
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
|
|
|
lastsearchnode->next = searchnode->next;
|
|
|
|
}
|
|
|
|
delete (searchnode);
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
lastsearchnode = searchnode;
|
|
|
|
searchnode = searchnode->next;
|
|
|
|
}
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
LONG CALLBACK veh_dispatch(PEXCEPTION_POINTERS ExceptionInfo)
|
|
|
|
{
|
2024-04-02 15:36:52 +08:00
|
|
|
|
2024-03-29 15:24:31 +08:00
|
|
|
DWORD oldProtect;
|
2024-04-02 15:36:52 +08:00
|
|
|
void *Addr = ExceptionInfo->ExceptionRecord->ExceptionAddress;
|
2024-03-29 15:24:31 +08:00
|
|
|
ULONG Code = ExceptionInfo->ExceptionRecord->ExceptionCode;
|
|
|
|
|
2024-04-02 15:36:52 +08:00
|
|
|
if (Code != STATUS_BREAKPOINT && Code != STATUS_SINGLE_STEP)
|
|
|
|
return EXCEPTION_CONTINUE_SEARCH;
|
2024-03-29 15:24:31 +08:00
|
|
|
// Try to find the node associated with the address of the current exception, continue searching for handlers if not found;
|
|
|
|
std::lock_guard _(vehlistlock);
|
2024-04-02 15:36:52 +08:00
|
|
|
if (Code == STATUS_BREAKPOINT) //&& hooktype == VEH_HK_INT3)
|
2024-03-29 15:24:31 +08:00
|
|
|
{
|
2024-04-02 15:36:52 +08:00
|
|
|
veh_node_t *currnode = get_veh_node(list, Addr);
|
|
|
|
if (currnode == NULL)
|
|
|
|
return EXCEPTION_CONTINUE_SEARCH;
|
|
|
|
|
2024-03-29 15:24:31 +08:00
|
|
|
VirtualProtect(Addr, sizeof(int), PAGE_EXECUTE_READWRITE, &currnode->OldProtect);
|
2024-04-02 15:36:52 +08:00
|
|
|
memcpy((void *)Addr, (const void *)(&currnode->origBaseByte), sizeof(char));
|
2024-03-29 15:24:31 +08:00
|
|
|
currnode->newFunc(ExceptionInfo->ContextRecord);
|
|
|
|
VirtualProtect(Addr, sizeof(int), currnode->OldProtect, &oldProtect);
|
|
|
|
ExceptionInfo->ContextRecord->EFlags |= 0x100;
|
|
|
|
}
|
2024-04-02 15:36:52 +08:00
|
|
|
else if (Code == STATUS_SINGLE_STEP) //&& hooktype == VEH_HK_INT3)
|
2024-03-29 15:24:31 +08:00
|
|
|
{
|
2024-04-02 15:36:52 +08:00
|
|
|
veh_node_t *currnode = get_veh_node(list, Addr, 0x10);
|
|
|
|
if (currnode == NULL)
|
|
|
|
return EXCEPTION_CONTINUE_SEARCH;
|
|
|
|
|
2024-03-29 15:24:31 +08:00
|
|
|
VirtualProtect(Addr, sizeof(int), PAGE_EXECUTE_READWRITE, &currnode->OldProtect);
|
2024-04-02 15:36:52 +08:00
|
|
|
memcpy((void *)currnode->origFunc, (const void *)&int3bp, sizeof(BYTE));
|
2024-03-29 15:24:31 +08:00
|
|
|
VirtualProtect(Addr, sizeof(int), currnode->OldProtect, &oldProtect);
|
|
|
|
ExceptionInfo->ContextRecord->EFlags &= ~0x00000100; // Remove TRACE from EFLAGS
|
|
|
|
}
|
|
|
|
// else if (Code == STATUS_SINGLE_STEP && hooktype == VEH_HK_HW)
|
|
|
|
// {
|
|
|
|
// currnode->newFunc(ExceptionInfo->ContextRecord);
|
|
|
|
// }
|
|
|
|
// else if (Code == STATUS_SINGLE_STEP && hooktype == VEH_HK_MEM)
|
|
|
|
// {
|
|
|
|
|
|
|
|
// currnode->newFunc(ExceptionInfo->ContextRecord);
|
|
|
|
// }
|
|
|
|
return EXCEPTION_CONTINUE_EXECUTION;
|
|
|
|
}
|
|
|
|
|
2024-04-02 15:36:52 +08:00
|
|
|
veh_list_t *new_veh_list()
|
2024-03-29 15:24:31 +08:00
|
|
|
{
|
2024-04-02 15:36:52 +08:00
|
|
|
veh_list_t *newlist = (veh_list_t *)malloc(sizeof(veh_list_t));
|
|
|
|
if (newlist == NULL)
|
|
|
|
return NULL;
|
2024-03-29 15:24:31 +08:00
|
|
|
newlist->head = NULL;
|
|
|
|
newlist->tail = NULL;
|
|
|
|
return newlist;
|
|
|
|
}
|
2024-04-02 15:36:52 +08:00
|
|
|
veh_node_t *insert_veh_node(veh_list_t *list, void *origFunc, newFuncType newFunc, void *handle, DWORD hook_type)
|
2024-03-29 15:24:31 +08:00
|
|
|
{
|
2024-04-02 15:36:52 +08:00
|
|
|
if (list == NULL)
|
|
|
|
return NULL;
|
2024-03-29 15:24:31 +08:00
|
|
|
/* create a new node and fill in the blanks */
|
2024-04-02 15:36:52 +08:00
|
|
|
veh_node_t *newnode = new veh_node_t;
|
|
|
|
if (newnode == NULL)
|
|
|
|
return NULL;
|
2024-03-29 15:24:31 +08:00
|
|
|
newnode->origFunc = origFunc;
|
|
|
|
newnode->newFunc = newFunc;
|
|
|
|
newnode->handle = handle;
|
|
|
|
newnode->OldProtect = PAGE_EXECUTE_READWRITE;
|
|
|
|
newnode->next = NULL;
|
2024-04-02 15:36:52 +08:00
|
|
|
newnode->hooktype = hook_type;
|
2024-03-29 15:24:31 +08:00
|
|
|
if (list->head == NULL)
|
|
|
|
{
|
|
|
|
list->head = newnode;
|
|
|
|
list->tail = newnode;
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
|
|
|
list->tail->next = newnode;
|
|
|
|
list->tail = newnode;
|
|
|
|
}
|
|
|
|
return newnode;
|
|
|
|
}
|
|
|
|
|
2024-04-02 15:36:52 +08:00
|
|
|
veh_node_t *get_veh_node(veh_list_t *list, void *origFunc, int range)
|
2024-03-29 15:24:31 +08:00
|
|
|
{
|
2024-04-02 15:36:52 +08:00
|
|
|
veh_node_t *newnode;
|
|
|
|
veh_node_t *closestnode = NULL;
|
|
|
|
if (list == NULL)
|
|
|
|
return NULL;
|
2024-03-29 15:24:31 +08:00
|
|
|
newnode = list->head;
|
|
|
|
while (newnode != NULL)
|
|
|
|
{
|
2024-04-02 15:36:52 +08:00
|
|
|
if (((uintptr_t)origFunc - (uintptr_t)newnode->origFunc) <= range)
|
2024-03-29 15:24:31 +08:00
|
|
|
{
|
2024-04-02 15:36:52 +08:00
|
|
|
closestnode = newnode;
|
|
|
|
if (range == 0)
|
|
|
|
break;
|
|
|
|
range = ((uintptr_t)origFunc - (uintptr_t)newnode->origFunc);
|
2024-03-29 15:24:31 +08:00
|
|
|
}
|
|
|
|
newnode = newnode->next;
|
|
|
|
}
|
|
|
|
return closestnode;
|
|
|
|
}
|