2019-01-31 11:41:43 -05:00
|
|
|
|
#include "util.h"
|
2018-11-27 15:54:04 -05:00
|
|
|
|
#include <Psapi.h>
|
2018-11-22 15:53:32 -05:00
|
|
|
|
|
2019-01-31 11:41:43 -05:00
|
|
|
|
namespace
|
|
|
|
|
{
|
|
|
|
|
std::optional<HookParam> ParseRCode(std::wstring RCode)
|
|
|
|
|
{
|
|
|
|
|
std::wsmatch match;
|
|
|
|
|
HookParam hp = {};
|
|
|
|
|
hp.type |= DIRECT_READ;
|
|
|
|
|
|
2020-01-19 14:23:30 -07:00
|
|
|
|
// {S|Q|V|M}
|
2019-01-31 11:41:43 -05:00
|
|
|
|
switch (RCode[0])
|
|
|
|
|
{
|
|
|
|
|
case L'S':
|
|
|
|
|
break;
|
|
|
|
|
case L'Q':
|
|
|
|
|
hp.type |= USING_UNICODE;
|
|
|
|
|
break;
|
|
|
|
|
case L'V':
|
|
|
|
|
hp.type |= USING_UTF8;
|
|
|
|
|
break;
|
2020-01-19 14:23:30 -07:00
|
|
|
|
case L'M':
|
|
|
|
|
hp.type |= USING_UNICODE | HEX_DUMP;
|
|
|
|
|
break;
|
2019-01-31 11:41:43 -05:00
|
|
|
|
default:
|
|
|
|
|
return {};
|
|
|
|
|
}
|
|
|
|
|
RCode.erase(0, 1);
|
|
|
|
|
|
2019-03-27 23:35:22 -04:00
|
|
|
|
// [null_length<]
|
|
|
|
|
if (std::regex_search(RCode, match, std::wregex(L"^([0-9]+)<")))
|
|
|
|
|
{
|
|
|
|
|
hp.null_length = std::stoi(match[1]);
|
|
|
|
|
RCode.erase(0, match[0].length());
|
|
|
|
|
}
|
|
|
|
|
|
2019-01-31 11:41:43 -05:00
|
|
|
|
// [codepage#]
|
|
|
|
|
if (std::regex_search(RCode, match, std::wregex(L"^([0-9]+)#")))
|
|
|
|
|
{
|
|
|
|
|
hp.codepage = std::stoi(match[1]);
|
|
|
|
|
RCode.erase(0, match[0].length());
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// @addr
|
|
|
|
|
if (!std::regex_match(RCode, match, std::wregex(L"@([[:xdigit:]]+)"))) return {};
|
|
|
|
|
hp.address = std::stoull(match[1], nullptr, 16);
|
|
|
|
|
return hp;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
std::optional<HookParam> ParseHCode(std::wstring HCode)
|
|
|
|
|
{
|
|
|
|
|
std::wsmatch match;
|
|
|
|
|
HookParam hp = {};
|
|
|
|
|
|
2020-01-19 14:23:30 -07:00
|
|
|
|
// {A|B|W|H|S|Q|V|M}
|
2019-01-31 11:41:43 -05:00
|
|
|
|
switch (HCode[0])
|
|
|
|
|
{
|
|
|
|
|
case L'A':
|
|
|
|
|
hp.type |= BIG_ENDIAN;
|
|
|
|
|
hp.length_offset = 1;
|
|
|
|
|
break;
|
|
|
|
|
case L'B':
|
|
|
|
|
hp.length_offset = 1;
|
|
|
|
|
break;
|
|
|
|
|
case L'W':
|
|
|
|
|
hp.type |= USING_UNICODE;
|
|
|
|
|
hp.length_offset = 1;
|
|
|
|
|
break;
|
2020-01-19 14:23:30 -07:00
|
|
|
|
case L'H':
|
|
|
|
|
hp.type |= USING_UNICODE | HEX_DUMP;
|
|
|
|
|
hp.length_offset = 1;
|
|
|
|
|
break;
|
|
|
|
|
case L'S':
|
|
|
|
|
hp.type |= USING_STRING;
|
|
|
|
|
break;
|
|
|
|
|
case L'Q':
|
|
|
|
|
hp.type |= USING_STRING | USING_UNICODE;
|
|
|
|
|
break;
|
2019-01-31 11:41:43 -05:00
|
|
|
|
case L'V':
|
|
|
|
|
hp.type |= USING_STRING | USING_UTF8;
|
|
|
|
|
break;
|
2020-01-19 14:23:30 -07:00
|
|
|
|
case L'M':
|
|
|
|
|
hp.type |= USING_STRING | USING_UNICODE | HEX_DUMP;
|
|
|
|
|
break;
|
2019-01-31 11:41:43 -05:00
|
|
|
|
default:
|
|
|
|
|
return {};
|
|
|
|
|
}
|
|
|
|
|
HCode.erase(0, 1);
|
|
|
|
|
|
2019-07-19 01:15:00 +03:00
|
|
|
|
if ((hp.type & USING_STRING))
|
2019-03-27 23:35:22 -04:00
|
|
|
|
{
|
2019-07-19 01:15:00 +03:00
|
|
|
|
if (HCode[0] == L'F')
|
|
|
|
|
{
|
|
|
|
|
hp.type |= FULL_STRING;
|
|
|
|
|
HCode.erase(0, 1);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// [null_length<]
|
|
|
|
|
if (std::regex_search(HCode, match, std::wregex(L"^([0-9]+)<")))
|
|
|
|
|
{
|
|
|
|
|
hp.null_length = std::stoi(match[1]);
|
|
|
|
|
HCode.erase(0, match[0].length());
|
|
|
|
|
}
|
2019-03-27 23:35:22 -04:00
|
|
|
|
}
|
|
|
|
|
|
2019-01-31 11:41:43 -05:00
|
|
|
|
// [N]
|
|
|
|
|
if (HCode[0] == L'N')
|
|
|
|
|
{
|
|
|
|
|
hp.type |= NO_CONTEXT;
|
|
|
|
|
HCode.erase(0, 1);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// [codepage#]
|
|
|
|
|
if (std::regex_search(HCode, match, std::wregex(L"^([0-9]+)#")))
|
|
|
|
|
{
|
|
|
|
|
hp.codepage = std::stoi(match[1]);
|
|
|
|
|
HCode.erase(0, match[0].length());
|
|
|
|
|
}
|
|
|
|
|
|
2019-06-09 00:48:30 -04:00
|
|
|
|
// [padding+]
|
|
|
|
|
if (std::regex_search(HCode, match, std::wregex(L"^([[:xdigit:]]+)\\+")))
|
|
|
|
|
{
|
|
|
|
|
hp.padding = std::stoull(match[1], nullptr, 16);
|
|
|
|
|
HCode.erase(0, match[0].length());
|
|
|
|
|
}
|
|
|
|
|
|
2019-01-31 11:41:43 -05:00
|
|
|
|
// data_offset
|
|
|
|
|
if (!std::regex_search(HCode, match, std::wregex(L"^-?[[:xdigit:]]+"))) return {};
|
|
|
|
|
hp.offset = std::stoi(match[0], nullptr, 16);
|
|
|
|
|
HCode.erase(0, match[0].length());
|
|
|
|
|
|
|
|
|
|
// [*deref_offset1]
|
|
|
|
|
if (std::regex_search(HCode, match, std::wregex(L"^\\*(-?[[:xdigit:]]+)")))
|
|
|
|
|
{
|
|
|
|
|
hp.type |= DATA_INDIRECT;
|
|
|
|
|
hp.index = std::stoi(match[1], nullptr, 16);
|
|
|
|
|
HCode.erase(0, match[0].length());
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// [:split_offset[*deref_offset2]]
|
|
|
|
|
if (std::regex_search(HCode, match, std::wregex(L"^:(-?[[:xdigit:]]+)")))
|
|
|
|
|
{
|
|
|
|
|
hp.type |= USING_SPLIT;
|
|
|
|
|
hp.split = std::stoi(match[1], nullptr, 16);
|
|
|
|
|
HCode.erase(0, match[0].length());
|
|
|
|
|
|
|
|
|
|
if (std::regex_search(HCode, match, std::wregex(L"^\\*(-?[[:xdigit:]]+)")))
|
|
|
|
|
{
|
|
|
|
|
hp.type |= SPLIT_INDIRECT;
|
|
|
|
|
hp.split_index = std::stoi(match[1], nullptr, 16);
|
|
|
|
|
HCode.erase(0, match[0].length());
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// @addr[:module[:func]]
|
|
|
|
|
if (!std::regex_match(HCode, match, std::wregex(L"@([[:xdigit:]]+)(:.+?)?(:.+)?"))) return {};
|
|
|
|
|
hp.address = std::stoull(match[1], nullptr, 16);
|
|
|
|
|
if (match[2].matched)
|
|
|
|
|
{
|
|
|
|
|
hp.type |= MODULE_OFFSET;
|
2019-02-13 16:45:00 -05:00
|
|
|
|
wcsncpy_s(hp.module, match[2].str().erase(0, 1).c_str(), MAX_MODULE_SIZE - 1);
|
2019-01-31 11:41:43 -05:00
|
|
|
|
}
|
|
|
|
|
if (match[3].matched)
|
|
|
|
|
{
|
|
|
|
|
hp.type |= FUNCTION_OFFSET;
|
|
|
|
|
std::wstring func = match[3];
|
2019-02-13 16:45:00 -05:00
|
|
|
|
strncpy_s(hp.function, std::string(func.begin(), func.end()).erase(0, 1).c_str(), MAX_MODULE_SIZE - 1);
|
2019-01-31 11:41:43 -05:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// ITH has registers offset by 4 vs AGTH: need this to correct
|
|
|
|
|
if (hp.offset < 0) hp.offset -= 4;
|
|
|
|
|
if (hp.split < 0) hp.split -= 4;
|
|
|
|
|
|
|
|
|
|
return hp;
|
|
|
|
|
}
|
|
|
|
|
|
2019-09-10 21:59:59 -04:00
|
|
|
|
std::wstring HexString(int64_t num)
|
2019-01-31 12:47:56 -05:00
|
|
|
|
{
|
2019-09-10 21:59:59 -04:00
|
|
|
|
if (num < 0) return FormatString(L"-%I64X", -num);
|
|
|
|
|
return FormatString(L"%I64X", num);
|
2019-01-31 12:47:56 -05:00
|
|
|
|
}
|
|
|
|
|
|
2019-01-31 11:41:43 -05:00
|
|
|
|
std::wstring GenerateRCode(HookParam hp)
|
|
|
|
|
{
|
2019-09-10 21:59:59 -04:00
|
|
|
|
std::wstring RCode = L"R";
|
2019-01-31 11:41:43 -05:00
|
|
|
|
|
|
|
|
|
if (hp.type & USING_UNICODE)
|
|
|
|
|
{
|
2020-01-19 14:23:30 -07:00
|
|
|
|
if (hp.type & HEX_DUMP) RCode += L'M';
|
|
|
|
|
else RCode += L'Q';
|
2019-09-10 21:59:59 -04:00
|
|
|
|
if (hp.null_length != 0) RCode += std::to_wstring(hp.null_length) + L'<';
|
2019-01-31 11:41:43 -05:00
|
|
|
|
}
|
|
|
|
|
else
|
|
|
|
|
{
|
2019-09-10 21:59:59 -04:00
|
|
|
|
RCode += L'S';
|
|
|
|
|
if (hp.null_length != 0) RCode += std::to_wstring(hp.null_length) + L'<';
|
|
|
|
|
if (hp.codepage != 0) RCode += std::to_wstring(hp.codepage) + L'#';
|
2019-01-31 11:41:43 -05:00
|
|
|
|
}
|
|
|
|
|
|
2019-09-10 21:59:59 -04:00
|
|
|
|
RCode += L'@' + HexString(hp.address);
|
2019-01-31 11:41:43 -05:00
|
|
|
|
|
2019-09-10 21:59:59 -04:00
|
|
|
|
return RCode;
|
2019-01-31 11:41:43 -05:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
std::wstring GenerateHCode(HookParam hp, DWORD processId)
|
|
|
|
|
{
|
2019-09-10 21:59:59 -04:00
|
|
|
|
std::wstring HCode = L"H";
|
2019-01-31 11:41:43 -05:00
|
|
|
|
|
|
|
|
|
if (hp.type & USING_UNICODE)
|
|
|
|
|
{
|
2020-01-19 14:23:30 -07:00
|
|
|
|
if (hp.type & HEX_DUMP)
|
|
|
|
|
{
|
|
|
|
|
if (hp.type & USING_STRING) HCode += L'M';
|
|
|
|
|
else HCode += L'H';
|
|
|
|
|
}
|
|
|
|
|
else
|
|
|
|
|
{
|
|
|
|
|
if (hp.type & USING_STRING) HCode += L'Q';
|
|
|
|
|
else HCode += L'W';
|
|
|
|
|
}
|
2019-01-31 11:41:43 -05:00
|
|
|
|
}
|
|
|
|
|
else
|
|
|
|
|
{
|
2019-09-10 21:59:59 -04:00
|
|
|
|
if (hp.type & USING_STRING) HCode += L'S';
|
|
|
|
|
else if (hp.type & BIG_ENDIAN) HCode += L'A';
|
|
|
|
|
else HCode += L'B';
|
2019-01-31 11:41:43 -05:00
|
|
|
|
}
|
2019-03-27 23:35:22 -04:00
|
|
|
|
|
2019-09-10 21:59:59 -04:00
|
|
|
|
if (hp.type & FULL_STRING) HCode += L'F';
|
2019-03-27 23:35:22 -04:00
|
|
|
|
|
2019-09-10 21:59:59 -04:00
|
|
|
|
if (hp.null_length != 0) HCode += std::to_wstring(hp.null_length) + L'<';
|
2019-01-31 11:41:43 -05:00
|
|
|
|
|
2019-09-10 21:59:59 -04:00
|
|
|
|
if (hp.type & NO_CONTEXT) HCode += L'N';
|
|
|
|
|
if (hp.text_fun || hp.filter_fun || hp.hook_fun || hp.length_fun) HCode += L'X'; // no AGTH equivalent
|
2019-01-31 11:41:43 -05:00
|
|
|
|
|
2019-09-10 21:59:59 -04:00
|
|
|
|
if (hp.codepage != 0 && !(hp.type & USING_UNICODE)) HCode += std::to_wstring(hp.codepage) + L'#';
|
2019-01-31 11:41:43 -05:00
|
|
|
|
|
2019-09-10 21:59:59 -04:00
|
|
|
|
if (hp.padding) HCode += HexString(hp.padding) + L'+';
|
2019-06-09 00:48:30 -04:00
|
|
|
|
|
2019-01-31 11:41:43 -05:00
|
|
|
|
if (hp.offset < 0) hp.offset += 4;
|
|
|
|
|
if (hp.split < 0) hp.split += 4;
|
|
|
|
|
|
2019-09-10 21:59:59 -04:00
|
|
|
|
HCode += HexString(hp.offset);
|
|
|
|
|
if (hp.type & DATA_INDIRECT) HCode += L'*' + HexString(hp.index);
|
|
|
|
|
if (hp.type & USING_SPLIT) HCode += L':' + HexString(hp.split);
|
|
|
|
|
if (hp.type & SPLIT_INDIRECT) HCode += L'*' + HexString(hp.split_index);
|
2019-01-31 11:41:43 -05:00
|
|
|
|
|
|
|
|
|
// Attempt to make the address relative
|
2019-09-10 21:59:59 -04:00
|
|
|
|
if (processId && !(hp.type & MODULE_OFFSET))
|
2019-01-31 11:41:43 -05:00
|
|
|
|
if (AutoHandle<> process = OpenProcess(PROCESS_VM_READ | PROCESS_QUERY_INFORMATION, FALSE, processId))
|
|
|
|
|
if (MEMORY_BASIC_INFORMATION info = {}; VirtualQueryEx(process, (LPCVOID)hp.address, &info, sizeof(info)))
|
|
|
|
|
if (auto moduleName = Util::GetModuleFilename(processId, (HMODULE)info.AllocationBase))
|
|
|
|
|
{
|
|
|
|
|
hp.type |= MODULE_OFFSET;
|
|
|
|
|
hp.address -= (uint64_t)info.AllocationBase;
|
2019-02-13 16:45:00 -05:00
|
|
|
|
wcsncpy_s(hp.module, moduleName->c_str() + moduleName->rfind(L'\\') + 1, MAX_MODULE_SIZE - 1);
|
2019-01-31 11:41:43 -05:00
|
|
|
|
}
|
|
|
|
|
|
2019-09-10 21:59:59 -04:00
|
|
|
|
HCode += L'@' + HexString(hp.address);
|
|
|
|
|
if (hp.type & MODULE_OFFSET) HCode += L':' + std::wstring(hp.module);
|
|
|
|
|
if (hp.type & FUNCTION_OFFSET) HCode += L':' + std::wstring(hp.function, hp.function + MAX_MODULE_SIZE);
|
2019-01-31 11:41:43 -05:00
|
|
|
|
|
2019-09-10 21:59:59 -04:00
|
|
|
|
return HCode;
|
2019-01-31 11:41:43 -05:00
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2018-11-22 15:53:32 -05:00
|
|
|
|
namespace Util
|
|
|
|
|
{
|
2018-12-22 13:05:01 -05:00
|
|
|
|
std::optional<std::wstring> GetModuleFilename(DWORD processId, HMODULE module)
|
2018-11-27 15:54:04 -05:00
|
|
|
|
{
|
2019-01-20 09:52:35 -05:00
|
|
|
|
std::vector<wchar_t> buffer(MAX_PATH);
|
|
|
|
|
if (AutoHandle<> process = OpenProcess(PROCESS_VM_READ | PROCESS_QUERY_INFORMATION, FALSE, processId))
|
2018-11-27 15:54:04 -05:00
|
|
|
|
if (GetModuleFileNameExW(process, module, buffer.data(), MAX_PATH)) return buffer.data();
|
|
|
|
|
return {};
|
|
|
|
|
}
|
|
|
|
|
|
2018-12-22 13:05:01 -05:00
|
|
|
|
std::optional<std::wstring> GetModuleFilename(HMODULE module)
|
2018-11-27 15:54:04 -05:00
|
|
|
|
{
|
|
|
|
|
std::vector<wchar_t> buffer(MAX_PATH);
|
2019-01-09 22:35:01 -05:00
|
|
|
|
if (GetModuleFileNameW(module, buffer.data(), MAX_PATH)) return buffer.data();
|
|
|
|
|
return {};
|
2018-11-27 15:54:04 -05:00
|
|
|
|
}
|
|
|
|
|
|
2019-06-27 12:39:44 +05:30
|
|
|
|
std::vector<std::pair<DWORD, std::optional<std::wstring>>> GetAllProcesses()
|
2019-02-18 22:39:04 -05:00
|
|
|
|
{
|
|
|
|
|
std::vector<DWORD> processIds(10000);
|
|
|
|
|
DWORD spaceUsed = 0;
|
|
|
|
|
EnumProcesses(processIds.data(), 10000 * sizeof(DWORD), &spaceUsed);
|
2019-06-27 12:39:44 +05:30
|
|
|
|
std::vector<std::pair<DWORD, std::optional<std::wstring>>> processes;
|
|
|
|
|
for (int i = 0; i < spaceUsed / sizeof(DWORD); ++i) processes.push_back({ processIds[i], Util::GetModuleFilename(processIds[i]) });
|
|
|
|
|
return processes;
|
2019-02-18 22:39:04 -05:00
|
|
|
|
}
|
|
|
|
|
|
2018-11-22 15:53:32 -05:00
|
|
|
|
std::optional<std::wstring> GetClipboardText()
|
|
|
|
|
{
|
|
|
|
|
if (!IsClipboardFormatAvailable(CF_UNICODETEXT)) return {};
|
|
|
|
|
if (!OpenClipboard(NULL)) return {};
|
|
|
|
|
|
2019-01-20 09:52:35 -05:00
|
|
|
|
std::optional<std::wstring> text;
|
|
|
|
|
if (AutoHandle<Functor<GlobalUnlock>> clipboard = GetClipboardData(CF_UNICODETEXT)) text = (wchar_t*)GlobalLock(clipboard);
|
2018-11-22 15:53:32 -05:00
|
|
|
|
CloseClipboard();
|
2019-01-20 09:52:35 -05:00
|
|
|
|
return text;
|
2018-11-22 15:53:32 -05:00
|
|
|
|
}
|
|
|
|
|
|
2019-02-16 00:33:38 -05:00
|
|
|
|
std::optional<std::wstring> StringToWideString(const std::string& text, UINT encoding)
|
2018-11-22 15:53:32 -05:00
|
|
|
|
{
|
2018-11-25 16:23:41 -05:00
|
|
|
|
std::vector<wchar_t> buffer(text.size() + 1);
|
2019-03-27 23:35:22 -04:00
|
|
|
|
if (int length = MultiByteToWideChar(encoding, 0, text.c_str(), text.size() + 1, buffer.data(), buffer.size()))
|
|
|
|
|
return std::wstring(buffer.data(), length - 1);
|
2019-01-09 22:35:01 -05:00
|
|
|
|
return {};
|
2018-11-22 15:53:32 -05:00
|
|
|
|
}
|
2018-11-22 16:02:45 -05:00
|
|
|
|
|
2019-01-31 11:41:43 -05:00
|
|
|
|
std::optional<HookParam> ParseCode(std::wstring code)
|
|
|
|
|
{
|
|
|
|
|
if (code[0] == L'/') code.erase(0, 1); // legacy/AGTH compatibility
|
|
|
|
|
if (code[0] == L'R') return ParseRCode(code.erase(0, 1));
|
|
|
|
|
else if (code[0] == L'H') return ParseHCode(code.erase(0, 1));
|
|
|
|
|
return {};
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
std::wstring GenerateCode(HookParam hp, DWORD processId)
|
|
|
|
|
{
|
|
|
|
|
return hp.type & DIRECT_READ ? GenerateRCode(hp) : GenerateHCode(hp, processId);
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
TEST(
|
|
|
|
|
assert(StringToWideString(u8"こんにちは").value() == L"こんにちは"),
|
2019-09-10 21:59:59 -04:00
|
|
|
|
assert(HexString(-12) == L"-C"),
|
|
|
|
|
assert(HexString(12) == L"C"),
|
2019-01-31 11:41:43 -05:00
|
|
|
|
assert(ParseCode(L"/HQN936#-c*C:C*1C@4AA:gdi.dll:GetTextOutA")),
|
|
|
|
|
assert(ParseCode(L"HB4@0")),
|
2019-06-09 00:48:30 -04:00
|
|
|
|
assert(ParseCode(L"/RS65001#@44")),
|
2019-01-31 11:41:43 -05:00
|
|
|
|
assert(!ParseCode(L"HQ@4")),
|
|
|
|
|
assert(!ParseCode(L"/RW@44")),
|
|
|
|
|
assert(!ParseCode(L"/HWG@33"))
|
|
|
|
|
);
|
2018-12-18 16:55:07 -05:00
|
|
|
|
}
|