2016-01-06 00:01:17 +09:00
|
|
|
// host.cc
|
|
|
|
// 8/24/2013 jichi
|
|
|
|
// Branch IHF/main.cpp, rev 111
|
|
|
|
|
|
|
|
#include "host.h"
|
2018-08-23 11:53:23 -04:00
|
|
|
#include "const.h"
|
|
|
|
#include "defs.h"
|
|
|
|
#include "../vnrhook/hijack/texthook.h"
|
2016-01-06 00:01:17 +09:00
|
|
|
|
2018-08-24 12:50:20 -04:00
|
|
|
namespace
|
2018-08-23 11:53:23 -04:00
|
|
|
{
|
2018-10-31 12:04:32 -04:00
|
|
|
class ProcessRecord
|
2018-08-24 12:50:20 -04:00
|
|
|
{
|
2018-10-31 12:04:32 -04:00
|
|
|
public:
|
|
|
|
ProcessRecord(DWORD processId, HANDLE hostPipe) :
|
|
|
|
hostPipe(hostPipe),
|
|
|
|
section(OpenFileMappingW(FILE_MAP_READ, FALSE, (ITH_SECTION_ + std::to_wstring(processId)).c_str())),
|
|
|
|
sectionMap(MapViewOfFile(section, FILE_MAP_READ, 0, 0, HOOK_SECTION_SIZE / 2)), // jichi 1/16/2015: Changed to half to hook section size
|
|
|
|
sectionMutex(ITH_HOOKMAN_MUTEX_ + std::to_wstring(processId))
|
|
|
|
{}
|
|
|
|
|
|
|
|
~ProcessRecord()
|
|
|
|
{
|
|
|
|
UnmapViewOfFile(sectionMap);
|
|
|
|
CloseHandle(section);
|
|
|
|
}
|
|
|
|
|
|
|
|
TextHook GetHook(uint64_t addr)
|
|
|
|
{
|
|
|
|
if (sectionMap == nullptr) return {};
|
|
|
|
LOCK(sectionMutex);
|
|
|
|
auto hooks = (const TextHook*)sectionMap;
|
|
|
|
for (int i = 0; i < MAX_HOOK; ++i)
|
|
|
|
if (hooks[i].hp.insertion_address == addr) return hooks[i];
|
|
|
|
return {};
|
|
|
|
}
|
|
|
|
|
|
|
|
HANDLE hostPipe;
|
|
|
|
|
|
|
|
private:
|
2018-08-24 12:50:20 -04:00
|
|
|
HANDLE section;
|
|
|
|
LPVOID sectionMap;
|
2018-10-31 12:04:32 -04:00
|
|
|
WinMutex sectionMutex;
|
2018-08-24 12:50:20 -04:00
|
|
|
};
|
|
|
|
|
|
|
|
ThreadEventCallback OnCreate, OnRemove;
|
|
|
|
ProcessEventCallback OnAttach, OnDetach;
|
2018-08-22 21:31:15 -04:00
|
|
|
|
2018-10-31 01:20:44 -04:00
|
|
|
std::unordered_map<ThreadParam, std::shared_ptr<TextThread>> textThreadsByParams;
|
2018-10-31 12:04:32 -04:00
|
|
|
std::unordered_map<DWORD, std::unique_ptr<ProcessRecord>> processRecordsByIds;
|
2016-01-06 00:01:17 +09:00
|
|
|
|
2018-08-28 16:25:08 -04:00
|
|
|
std::recursive_mutex hostMutex;
|
2018-07-23 12:25:02 -07:00
|
|
|
|
2018-10-08 00:26:43 -04:00
|
|
|
DWORD DUMMY[1];
|
2018-08-24 12:50:20 -04:00
|
|
|
ThreadParam CONSOLE{ 0, -1ULL, -1ULL, -1ULL };
|
|
|
|
|
|
|
|
void DispatchText(ThreadParam tp, const BYTE* text, int len)
|
|
|
|
{
|
2018-08-28 17:21:20 -04:00
|
|
|
LOCK(hostMutex);
|
2018-10-30 20:50:50 -04:00
|
|
|
if (textThreadsByParams[tp] == nullptr)
|
|
|
|
{
|
|
|
|
if (textThreadsByParams.size() > MAX_THREAD_COUNT) return Host::AddConsoleOutput(L"too many text threads: can't create more");
|
2018-10-31 01:20:44 -04:00
|
|
|
OnCreate(textThreadsByParams[tp] = std::make_shared<TextThread>(tp));
|
2018-10-30 20:50:50 -04:00
|
|
|
}
|
|
|
|
textThreadsByParams[tp]->AddText(text, len);
|
2018-08-24 12:50:20 -04:00
|
|
|
}
|
2018-07-23 12:25:02 -07:00
|
|
|
|
2018-08-24 12:50:20 -04:00
|
|
|
void RemoveThreads(std::function<bool(ThreadParam)> removeIf)
|
|
|
|
{
|
2018-08-28 17:21:20 -04:00
|
|
|
LOCK(hostMutex);
|
2018-10-31 01:20:44 -04:00
|
|
|
for (auto it = textThreadsByParams.begin(); it != textThreadsByParams.end();)
|
|
|
|
if (auto curr = it++; removeIf(curr->first))
|
2018-08-24 12:50:20 -04:00
|
|
|
{
|
2018-10-31 01:20:44 -04:00
|
|
|
OnRemove(curr->second);
|
|
|
|
textThreadsByParams.erase(curr->first);
|
2018-08-24 12:50:20 -04:00
|
|
|
}
|
|
|
|
}
|
2018-07-23 12:25:02 -07:00
|
|
|
|
2018-10-31 12:04:32 -04:00
|
|
|
void RegisterProcess(DWORD processId, HANDLE hostPipe)
|
2018-08-24 12:50:20 -04:00
|
|
|
{
|
2018-08-28 17:21:20 -04:00
|
|
|
LOCK(hostMutex);
|
2018-10-31 12:04:32 -04:00
|
|
|
processRecordsByIds.insert({ processId, std::make_unique<ProcessRecord>(processId, hostPipe) });
|
|
|
|
OnAttach(processId);
|
2018-08-24 12:50:20 -04:00
|
|
|
}
|
|
|
|
|
2018-10-31 12:04:32 -04:00
|
|
|
void UnregisterProcess(DWORD processId)
|
2018-08-24 12:50:20 -04:00
|
|
|
{
|
2018-10-31 12:04:32 -04:00
|
|
|
OnDetach(processId);
|
2018-08-28 17:21:20 -04:00
|
|
|
LOCK(hostMutex);
|
2018-10-31 12:04:32 -04:00
|
|
|
processRecordsByIds.erase(processId);
|
|
|
|
RemoveThreads([&](ThreadParam tp) { return tp.pid == processId; });
|
2018-08-24 12:50:20 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
void StartPipe()
|
|
|
|
{
|
2018-09-01 14:11:48 -04:00
|
|
|
std::thread([]
|
2018-08-24 12:50:20 -04:00
|
|
|
{
|
2018-09-20 23:04:11 -04:00
|
|
|
SECURITY_DESCRIPTOR pipeSD = {};
|
|
|
|
InitializeSecurityDescriptor(&pipeSD, SECURITY_DESCRIPTOR_REVISION);
|
|
|
|
SetSecurityDescriptorDacl(&pipeSD, TRUE, NULL, FALSE); // Allow non-admin processes to connect to pipe created by admin host
|
|
|
|
SECURITY_ATTRIBUTES pipeSA = { sizeof(SECURITY_ATTRIBUTES), &pipeSD, FALSE };
|
2018-10-31 20:09:29 -04:00
|
|
|
HANDLE hookPipe = CreateNamedPipeW(HOOK_PIPE, PIPE_ACCESS_INBOUND, PIPE_TYPE_MESSAGE | PIPE_READMODE_MESSAGE, PIPE_UNLIMITED_INSTANCES, 0, PIPE_BUFFER_SIZE, MAXDWORD, &pipeSA);
|
|
|
|
HANDLE hostPipe = CreateNamedPipeW(HOST_PIPE, PIPE_ACCESS_OUTBOUND, PIPE_TYPE_MESSAGE | PIPE_READMODE_MESSAGE, PIPE_UNLIMITED_INSTANCES, PIPE_BUFFER_SIZE, 0, MAXDWORD, &pipeSA);
|
2018-08-24 12:50:20 -04:00
|
|
|
ConnectNamedPipe(hookPipe, nullptr);
|
|
|
|
|
|
|
|
BYTE buffer[PIPE_BUFFER_SIZE + 1] = {};
|
|
|
|
DWORD bytesRead, processId;
|
|
|
|
ReadFile(hookPipe, &processId, sizeof(processId), &bytesRead, nullptr);
|
|
|
|
RegisterProcess(processId, hostPipe);
|
|
|
|
|
2018-09-09 22:37:48 -04:00
|
|
|
// jichi 9/27/2013: why recursion?
|
|
|
|
// Artikash 5/20/2018: Easy way to create a new pipe for another process
|
|
|
|
StartPipe();
|
|
|
|
|
2018-08-24 12:50:20 -04:00
|
|
|
while (ReadFile(hookPipe, buffer, PIPE_BUFFER_SIZE, &bytesRead, nullptr))
|
|
|
|
switch (*(int*)buffer)
|
|
|
|
{
|
|
|
|
//case HOST_NOTIFICATION_NEWHOOK: // Artikash 7/18/2018: Useless for now, but could be used to implement smth later
|
|
|
|
//break;
|
|
|
|
case HOST_NOTIFICATION_RMVHOOK:
|
|
|
|
{
|
|
|
|
auto info = *(HookRemovedNotif*)buffer;
|
2018-09-01 14:11:48 -04:00
|
|
|
RemoveThreads([&](ThreadParam tp) { return tp.pid == processId && tp.hook == info.address; });
|
2018-08-24 12:50:20 -04:00
|
|
|
}
|
|
|
|
break;
|
|
|
|
case HOST_NOTIFICATION_TEXT:
|
|
|
|
{
|
|
|
|
auto info = *(ConsoleOutputNotif*)buffer;
|
2018-09-23 01:08:33 -04:00
|
|
|
Host::AddConsoleOutput(StringToWideString(info.message, CP_UTF8));
|
2018-08-24 12:50:20 -04:00
|
|
|
}
|
|
|
|
break;
|
|
|
|
default:
|
|
|
|
{
|
|
|
|
ThreadParam tp = *(ThreadParam*)buffer;
|
2018-08-27 20:49:33 -04:00
|
|
|
buffer[bytesRead] = 0;
|
|
|
|
buffer[bytesRead + 1] = 0;
|
2018-08-24 12:50:20 -04:00
|
|
|
DispatchText(tp, buffer + sizeof(tp), bytesRead - sizeof(tp));
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
}
|
2018-08-22 18:05:45 -04:00
|
|
|
|
2018-08-24 12:50:20 -04:00
|
|
|
DisconnectNamedPipe(hookPipe);
|
|
|
|
DisconnectNamedPipe(hostPipe);
|
|
|
|
UnregisterProcess(processId);
|
|
|
|
CloseHandle(hookPipe);
|
|
|
|
CloseHandle(hostPipe);
|
|
|
|
}).detach();
|
|
|
|
}
|
|
|
|
}
|
2016-01-06 00:01:17 +09:00
|
|
|
|
2018-07-23 12:25:02 -07:00
|
|
|
namespace Host
|
2016-01-06 00:01:17 +09:00
|
|
|
{
|
2018-10-08 00:26:43 -04:00
|
|
|
void Start(ProcessEventCallback onAttach, ProcessEventCallback onDetach, ThreadEventCallback onCreate, ThreadEventCallback onRemove, TextThread::OutputCallback output)
|
2018-05-11 16:46:05 -04:00
|
|
|
{
|
2018-10-08 00:26:43 -04:00
|
|
|
OnAttach = onAttach; OnDetach = onDetach; OnCreate = onCreate; OnRemove = onRemove; TextThread::Output = output;
|
2018-10-31 01:20:44 -04:00
|
|
|
OnCreate(textThreadsByParams[CONSOLE] = std::make_shared<TextThread>(CONSOLE));
|
2018-08-24 12:50:20 -04:00
|
|
|
StartPipe();
|
2018-07-23 12:25:02 -07:00
|
|
|
}
|
|
|
|
|
2018-08-24 12:50:20 -04:00
|
|
|
void Close()
|
2018-07-23 12:25:02 -07:00
|
|
|
{
|
2018-09-29 16:05:08 -04:00
|
|
|
// Artikash 7/25/2018: This is only called when Textractor is closed, at which point Windows should free everything itself...right?
|
2018-08-22 18:25:23 -04:00
|
|
|
#ifdef _DEBUG // Check memory leaks
|
2018-08-28 17:21:20 -04:00
|
|
|
LOCK(hostMutex);
|
2018-10-31 12:04:32 -04:00
|
|
|
processRecordsByIds.clear();
|
2018-10-31 01:20:44 -04:00
|
|
|
textThreadsByParams.clear();
|
2018-08-22 18:05:45 -04:00
|
|
|
#endif
|
2018-07-23 12:25:02 -07:00
|
|
|
}
|
|
|
|
|
2018-08-24 12:50:20 -04:00
|
|
|
bool InjectProcess(DWORD processId, DWORD timeout)
|
2018-07-23 12:25:02 -07:00
|
|
|
{
|
|
|
|
if (processId == GetCurrentProcessId()) return false;
|
|
|
|
|
|
|
|
CloseHandle(CreateMutexW(nullptr, FALSE, (ITH_HOOKMAN_MUTEX_ + std::to_wstring(processId)).c_str()));
|
|
|
|
if (GetLastError() == ERROR_ALREADY_EXISTS)
|
|
|
|
{
|
2018-07-28 12:41:21 -07:00
|
|
|
AddConsoleOutput(L"already injected");
|
2018-07-23 12:25:02 -07:00
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
HMODULE textHooker = LoadLibraryExW(ITH_DLL, nullptr, DONT_RESOLVE_DLL_REFERENCES);
|
|
|
|
wchar_t textHookerPath[MAX_PATH];
|
2018-09-20 21:59:07 -04:00
|
|
|
DWORD textHookerPathSize = GetModuleFileNameW(textHooker, textHookerPath, MAX_PATH) * 2 + 2;
|
2018-07-23 12:25:02 -07:00
|
|
|
FreeLibrary(textHooker);
|
|
|
|
|
|
|
|
if (HANDLE processHandle = OpenProcess(PROCESS_ALL_ACCESS, FALSE, processId))
|
2018-08-22 15:11:58 -04:00
|
|
|
{
|
|
|
|
#ifdef _WIN64
|
|
|
|
BOOL invalidProcess = FALSE;
|
|
|
|
IsWow64Process(processHandle, &invalidProcess);
|
|
|
|
if (invalidProcess)
|
|
|
|
{
|
2018-09-29 16:05:08 -04:00
|
|
|
AddConsoleOutput(L"architecture mismatch: try 32 bit Textractor instead");
|
2018-08-22 15:11:58 -04:00
|
|
|
CloseHandle(processHandle);
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
#endif
|
2018-07-23 12:25:02 -07:00
|
|
|
if (LPVOID remoteData = VirtualAllocEx(processHandle, nullptr, textHookerPathSize, MEM_RESERVE | MEM_COMMIT, PAGE_READWRITE))
|
2018-08-22 15:11:58 -04:00
|
|
|
{
|
|
|
|
WriteProcessMemory(processHandle, remoteData, textHookerPath, textHookerPathSize, nullptr);
|
|
|
|
if (HANDLE thread = CreateRemoteThread(processHandle, nullptr, 0, (LPTHREAD_START_ROUTINE)LoadLibraryW, remoteData, 0, nullptr))
|
|
|
|
{
|
|
|
|
WaitForSingleObject(thread, timeout);
|
|
|
|
CloseHandle(thread);
|
|
|
|
VirtualFreeEx(processHandle, remoteData, 0, MEM_RELEASE);
|
|
|
|
CloseHandle(processHandle);
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
VirtualFreeEx(processHandle, remoteData, 0, MEM_RELEASE);
|
|
|
|
CloseHandle(processHandle);
|
|
|
|
}
|
|
|
|
}
|
2018-07-23 12:25:02 -07:00
|
|
|
|
|
|
|
AddConsoleOutput(L"couldn't inject dll");
|
2018-07-17 17:01:56 -04:00
|
|
|
return false;
|
2018-05-11 16:46:05 -04:00
|
|
|
}
|
2018-07-23 12:25:02 -07:00
|
|
|
|
2018-08-24 14:04:23 -04:00
|
|
|
void DetachProcess(DWORD processId)
|
2018-05-11 16:46:05 -04:00
|
|
|
{
|
2018-10-31 12:04:32 -04:00
|
|
|
LOCK(hostMutex);
|
2018-10-28 02:35:19 -04:00
|
|
|
auto command = HOST_COMMAND_DETACH;
|
2018-10-31 12:04:32 -04:00
|
|
|
WriteFile(processRecordsByIds.at(processId)->hostPipe, &command, sizeof(command), DUMMY, nullptr);
|
2018-07-23 12:25:02 -07:00
|
|
|
}
|
|
|
|
|
2018-10-31 12:04:32 -04:00
|
|
|
void InsertHook(DWORD processId, HookParam hp, std::string name)
|
2018-07-23 12:25:02 -07:00
|
|
|
{
|
2018-10-31 12:04:32 -04:00
|
|
|
LOCK(hostMutex);
|
2018-10-08 00:26:43 -04:00
|
|
|
auto command = InsertHookCmd(hp, name);
|
2018-10-31 12:04:32 -04:00
|
|
|
WriteFile(processRecordsByIds.at(processId)->hostPipe, &command, sizeof(command), DUMMY, nullptr);
|
2018-07-23 12:25:02 -07:00
|
|
|
}
|
|
|
|
|
2018-10-31 12:04:32 -04:00
|
|
|
void RemoveHook(DWORD processId, uint64_t addr)
|
2018-07-23 12:25:02 -07:00
|
|
|
{
|
2018-10-31 12:04:32 -04:00
|
|
|
LOCK(hostMutex);
|
2018-10-08 00:26:43 -04:00
|
|
|
auto command = RemoveHookCmd(addr);
|
2018-10-31 12:04:32 -04:00
|
|
|
WriteFile(processRecordsByIds.at(processId)->hostPipe, &command, sizeof(command), DUMMY, nullptr);
|
2018-05-11 16:46:05 -04:00
|
|
|
}
|
2016-01-06 00:01:17 +09:00
|
|
|
|
2018-10-31 12:04:32 -04:00
|
|
|
HookParam GetHookParam(DWORD processId, uint64_t addr)
|
2018-07-23 12:25:02 -07:00
|
|
|
{
|
2018-10-31 12:04:32 -04:00
|
|
|
if (processId == 0) return {};
|
2018-08-28 17:21:20 -04:00
|
|
|
LOCK(hostMutex);
|
2018-10-31 12:04:32 -04:00
|
|
|
return processRecordsByIds.at(processId)->GetHook(addr).hp;
|
2018-07-23 12:25:02 -07:00
|
|
|
}
|
2016-01-06 00:01:17 +09:00
|
|
|
|
2018-10-31 12:04:32 -04:00
|
|
|
std::wstring GetHookName(DWORD processId, uint64_t addr)
|
2018-05-11 16:46:05 -04:00
|
|
|
{
|
2018-10-31 12:04:32 -04:00
|
|
|
if (processId == 0) return L"Console";
|
2018-08-28 17:21:20 -04:00
|
|
|
LOCK(hostMutex);
|
2018-10-31 12:04:32 -04:00
|
|
|
return StringToWideString(processRecordsByIds.at(processId)->GetHook(addr).hookName, CP_UTF8);
|
2018-05-11 16:46:05 -04:00
|
|
|
}
|
2016-01-06 00:01:17 +09:00
|
|
|
|
2018-10-31 01:20:44 -04:00
|
|
|
std::shared_ptr<TextThread> GetThread(ThreadParam tp)
|
2018-07-23 12:25:02 -07:00
|
|
|
{
|
2018-08-28 17:21:20 -04:00
|
|
|
LOCK(hostMutex);
|
2018-08-21 22:43:30 -04:00
|
|
|
return textThreadsByParams[tp];
|
2018-07-23 12:25:02 -07:00
|
|
|
}
|
2018-05-11 16:46:05 -04:00
|
|
|
|
2018-10-08 00:26:43 -04:00
|
|
|
void AddConsoleOutput(std::wstring text) { GetThread(CONSOLE)->AddSentence(text); }
|
2016-01-06 00:01:17 +09:00
|
|
|
}
|
|
|
|
|
2018-07-24 10:39:02 -07:00
|
|
|
// EOF
|