2016-01-05 23:01:17 +08:00
|
|
|
#include "host.h"
|
2018-08-23 23:53:23 +08:00
|
|
|
#include "const.h"
|
2018-11-23 04:53:32 +08:00
|
|
|
#include "text.h"
|
2018-08-23 23:53:23 +08:00
|
|
|
#include "defs.h"
|
2018-11-23 04:53:32 +08:00
|
|
|
#include "util.h"
|
2018-11-11 12:29:12 +08:00
|
|
|
#include "../vnrhook/texthook.h"
|
2016-01-05 23:01:17 +08:00
|
|
|
|
2018-08-25 00:50:20 +08:00
|
|
|
namespace
|
2018-08-23 23:53:23 +08:00
|
|
|
{
|
2018-11-01 00:04:32 +08:00
|
|
|
class ProcessRecord
|
2018-08-25 00:50:20 +08:00
|
|
|
{
|
2018-11-01 00:04:32 +08:00
|
|
|
public:
|
2018-11-28 04:54:04 +08:00
|
|
|
inline static Host::ProcessEventCallback OnConnect, OnDisconnect;
|
2018-11-01 00:04:32 +08:00
|
|
|
|
2018-11-28 04:54:04 +08:00
|
|
|
ProcessRecord(DWORD processId, HANDLE pipe) :
|
|
|
|
processId(processId),
|
|
|
|
pipe(pipe),
|
|
|
|
fileMapping(OpenFileMappingW(FILE_MAP_READ, FALSE, (ITH_SECTION_ + std::to_wstring(processId)).c_str())),
|
|
|
|
mappedView(MapViewOfFile(fileMapping, FILE_MAP_READ, 0, 0, HOOK_SECTION_SIZE / 2)), // jichi 1/16/2015: Changed to half to hook section size
|
|
|
|
sectionMutex(ITH_HOOKMAN_MUTEX_ + std::to_wstring(processId))
|
|
|
|
{
|
|
|
|
OnConnect(processId);
|
|
|
|
}
|
2018-11-23 04:53:32 +08:00
|
|
|
|
2018-11-01 00:04:32 +08:00
|
|
|
~ProcessRecord()
|
|
|
|
{
|
2018-11-28 04:54:04 +08:00
|
|
|
OnDisconnect(processId);
|
|
|
|
UnmapViewOfFile(mappedView);
|
2018-11-01 00:04:32 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
TextHook GetHook(uint64_t addr)
|
|
|
|
{
|
2018-11-28 04:54:04 +08:00
|
|
|
if (mappedView == nullptr) return {};
|
2018-11-01 00:04:32 +08:00
|
|
|
LOCK(sectionMutex);
|
2018-11-28 04:54:04 +08:00
|
|
|
auto hooks = (const TextHook*)mappedView;
|
2018-11-01 00:04:32 +08:00
|
|
|
for (int i = 0; i < MAX_HOOK; ++i)
|
|
|
|
if (hooks[i].hp.insertion_address == addr) return hooks[i];
|
|
|
|
return {};
|
|
|
|
}
|
|
|
|
|
2018-11-28 04:54:04 +08:00
|
|
|
template <typename T>
|
|
|
|
void Send(T data)
|
|
|
|
{
|
|
|
|
DWORD DUMMY;
|
|
|
|
WriteFile(pipe, &data, sizeof(data), &DUMMY, nullptr);
|
|
|
|
}
|
2018-11-01 00:04:32 +08:00
|
|
|
|
|
|
|
private:
|
2018-11-28 04:54:04 +08:00
|
|
|
DWORD processId;
|
|
|
|
HANDLE pipe;
|
|
|
|
AutoHandle<> fileMapping;
|
|
|
|
LPCVOID mappedView;
|
2018-11-01 00:04:32 +08:00
|
|
|
WinMutex sectionMutex;
|
2018-08-25 00:50:20 +08:00
|
|
|
};
|
|
|
|
|
2018-11-28 04:54:04 +08:00
|
|
|
ThreadSafePtr<std::unordered_map<ThreadParam, std::shared_ptr<TextThread>>> textThreadsByParams;
|
|
|
|
ThreadSafePtr<std::unordered_map<DWORD, std::unique_ptr<ProcessRecord>>> processRecordsByIds;
|
2018-08-23 09:31:15 +08:00
|
|
|
|
2018-11-02 07:51:23 +08:00
|
|
|
ThreadParam CONSOLE{ 0, -1ULL, -1ULL, -1ULL }, CLIPBOARD{ 0, 0, -1ULL, -1ULL };
|
2018-08-25 00:50:20 +08:00
|
|
|
|
|
|
|
void RemoveThreads(std::function<bool(ThreadParam)> removeIf)
|
|
|
|
{
|
2018-11-28 04:54:04 +08:00
|
|
|
auto lockedTextThreadsByParams = textThreadsByParams.operator->();
|
|
|
|
for (auto it = lockedTextThreadsByParams->begin(); it != lockedTextThreadsByParams->end(); removeIf(it->first) ? it = lockedTextThreadsByParams->erase(it) : ++it);
|
2018-08-25 00:50:20 +08:00
|
|
|
}
|
|
|
|
|
2018-11-04 14:34:49 +08:00
|
|
|
void CreatePipe()
|
2018-08-25 00:50:20 +08:00
|
|
|
{
|
2018-09-02 02:11:48 +08:00
|
|
|
std::thread([]
|
2018-08-25 00:50:20 +08:00
|
|
|
{
|
2018-09-21 11:04:11 +08:00
|
|
|
SECURITY_DESCRIPTOR pipeSD = {};
|
|
|
|
InitializeSecurityDescriptor(&pipeSD, SECURITY_DESCRIPTOR_REVISION);
|
|
|
|
SetSecurityDescriptorDacl(&pipeSD, TRUE, NULL, FALSE); // Allow non-admin processes to connect to pipe created by admin host
|
|
|
|
SECURITY_ATTRIBUTES pipeSA = { sizeof(SECURITY_ATTRIBUTES), &pipeSD, FALSE };
|
2018-11-28 04:54:04 +08:00
|
|
|
AutoHandle<Util::NamedPipeHandleCloser>
|
|
|
|
hookPipe = CreateNamedPipeW(HOOK_PIPE, PIPE_ACCESS_INBOUND, PIPE_TYPE_MESSAGE | PIPE_READMODE_MESSAGE, PIPE_UNLIMITED_INSTANCES, 0, PIPE_BUFFER_SIZE, MAXDWORD, &pipeSA),
|
|
|
|
hostPipe = CreateNamedPipeW(HOST_PIPE, PIPE_ACCESS_OUTBOUND, PIPE_TYPE_MESSAGE | PIPE_READMODE_MESSAGE, PIPE_UNLIMITED_INSTANCES, PIPE_BUFFER_SIZE, 0, MAXDWORD, &pipeSA);
|
2018-08-25 00:50:20 +08:00
|
|
|
ConnectNamedPipe(hookPipe, nullptr);
|
|
|
|
|
2018-11-23 04:53:32 +08:00
|
|
|
BYTE buffer[PIPE_BUFFER_SIZE] = {};
|
2018-08-25 00:50:20 +08:00
|
|
|
DWORD bytesRead, processId;
|
|
|
|
ReadFile(hookPipe, &processId, sizeof(processId), &bytesRead, nullptr);
|
2018-11-28 04:54:04 +08:00
|
|
|
processRecordsByIds->insert({ processId, std::make_unique<ProcessRecord>(processId, hostPipe) });
|
2018-08-25 00:50:20 +08:00
|
|
|
|
2018-11-04 14:34:49 +08:00
|
|
|
CreatePipe();
|
2018-09-10 10:37:48 +08:00
|
|
|
|
2018-08-25 00:50:20 +08:00
|
|
|
while (ReadFile(hookPipe, buffer, PIPE_BUFFER_SIZE, &bytesRead, nullptr))
|
2018-11-11 12:29:12 +08:00
|
|
|
switch (*(HostNotificationType*)buffer)
|
2018-08-25 00:50:20 +08:00
|
|
|
{
|
|
|
|
case HOST_NOTIFICATION_RMVHOOK:
|
|
|
|
{
|
|
|
|
auto info = *(HookRemovedNotif*)buffer;
|
2018-11-05 09:48:46 +08:00
|
|
|
RemoveThreads([&](ThreadParam tp) { return tp.processId == processId && tp.addr == info.address; });
|
2018-08-25 00:50:20 +08:00
|
|
|
}
|
|
|
|
break;
|
|
|
|
case HOST_NOTIFICATION_TEXT:
|
|
|
|
{
|
|
|
|
auto info = *(ConsoleOutputNotif*)buffer;
|
2018-11-26 05:23:41 +08:00
|
|
|
Host::AddConsoleOutput(Util::StringToWideString(info.message).value());
|
2018-08-25 00:50:20 +08:00
|
|
|
}
|
|
|
|
break;
|
|
|
|
default:
|
|
|
|
{
|
2018-11-19 21:17:00 +08:00
|
|
|
auto tp = *(ThreadParam*)buffer;
|
2018-11-28 04:54:04 +08:00
|
|
|
if (textThreadsByParams->count(tp) == 0)
|
|
|
|
{
|
|
|
|
auto textThread = textThreadsByParams->insert({ tp, std::make_shared<TextThread>(tp, Host::GetHookParam(tp), Host::GetHookName(tp)) }).first->second;
|
|
|
|
if (textThreadsByParams->size() > MAX_THREAD_COUNT) Host::AddConsoleOutput(TOO_MANY_THREADS);
|
|
|
|
else textThread->Start();
|
|
|
|
}
|
|
|
|
textThreadsByParams->at(tp)->Push(buffer + sizeof(tp), bytesRead - sizeof(tp));
|
2018-08-25 00:50:20 +08:00
|
|
|
}
|
|
|
|
break;
|
|
|
|
}
|
2018-08-23 06:05:45 +08:00
|
|
|
|
2018-11-28 04:54:04 +08:00
|
|
|
RemoveThreads([&](ThreadParam tp) { return tp.processId == processId; });
|
|
|
|
processRecordsByIds->erase(processId);
|
2018-08-25 00:50:20 +08:00
|
|
|
}).detach();
|
|
|
|
}
|
2018-11-02 07:51:23 +08:00
|
|
|
|
|
|
|
void StartCapturingClipboard()
|
|
|
|
{
|
|
|
|
std::thread([]
|
|
|
|
{
|
2018-11-19 21:17:00 +08:00
|
|
|
for (std::wstring last; true; Sleep(50))
|
2018-11-23 04:53:32 +08:00
|
|
|
if (auto text = Util::GetClipboardText())
|
2018-11-15 13:16:12 +08:00
|
|
|
if (last != text.value())
|
|
|
|
Host::GetThread(CLIPBOARD)->AddSentence(last = text.value());
|
2018-11-02 07:51:23 +08:00
|
|
|
}).detach();
|
|
|
|
}
|
2018-08-25 00:50:20 +08:00
|
|
|
}
|
2016-01-05 23:01:17 +08:00
|
|
|
|
2018-07-24 03:25:02 +08:00
|
|
|
namespace Host
|
2016-01-05 23:01:17 +08:00
|
|
|
{
|
2018-11-28 04:54:04 +08:00
|
|
|
void Start(ProcessEventCallback OnConnect, ProcessEventCallback OnDisconnect, TextThread::EventCallback OnCreate, TextThread::EventCallback OnDestroy, TextThread::OutputCallback Output)
|
|
|
|
{
|
|
|
|
ProcessRecord::OnConnect = OnConnect;
|
|
|
|
ProcessRecord::OnDisconnect = OnDisconnect;
|
|
|
|
TextThread::OnCreate = OnCreate;
|
|
|
|
TextThread::OnDestroy = OnDestroy;
|
|
|
|
TextThread::Output = Output;
|
|
|
|
processRecordsByIds->insert({ CONSOLE.processId, std::make_unique<ProcessRecord>(CONSOLE.processId, INVALID_HANDLE_VALUE) });
|
|
|
|
textThreadsByParams->insert({ CONSOLE, std::make_shared<TextThread>(CONSOLE, HookParam{}, L"Console") });
|
|
|
|
textThreadsByParams->insert({ CLIPBOARD, std::make_shared<TextThread>(CLIPBOARD, HookParam{}, L"Clipboard") });
|
2018-11-02 07:51:23 +08:00
|
|
|
StartCapturingClipboard();
|
2018-11-04 14:34:49 +08:00
|
|
|
CreatePipe();
|
2018-07-24 03:25:02 +08:00
|
|
|
}
|
|
|
|
|
2018-08-25 00:50:20 +08:00
|
|
|
bool InjectProcess(DWORD processId, DWORD timeout)
|
2018-07-24 03:25:02 +08:00
|
|
|
{
|
|
|
|
if (processId == GetCurrentProcessId()) return false;
|
|
|
|
|
2018-11-28 04:54:04 +08:00
|
|
|
WinMutex(ITH_HOOKMAN_MUTEX_ + std::to_wstring(processId));
|
2018-07-24 03:25:02 +08:00
|
|
|
if (GetLastError() == ERROR_ALREADY_EXISTS)
|
|
|
|
{
|
2018-11-04 15:13:51 +08:00
|
|
|
AddConsoleOutput(ALREADY_INJECTED);
|
2018-07-24 03:25:02 +08:00
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
2018-11-28 04:54:04 +08:00
|
|
|
static HMODULE vnrhook = LoadLibraryExW(ITH_DLL, nullptr, DONT_RESOLVE_DLL_REFERENCES);
|
|
|
|
static std::wstring location = Util::GetModuleFileName(vnrhook).value();
|
2018-07-24 03:25:02 +08:00
|
|
|
|
2018-11-28 04:54:04 +08:00
|
|
|
if (AutoHandle<> process = OpenProcess(PROCESS_ALL_ACCESS, FALSE, processId))
|
2018-08-23 03:11:58 +08:00
|
|
|
{
|
|
|
|
#ifdef _WIN64
|
|
|
|
BOOL invalidProcess = FALSE;
|
2018-11-28 04:54:04 +08:00
|
|
|
IsWow64Process(process, &invalidProcess);
|
2018-08-23 03:11:58 +08:00
|
|
|
if (invalidProcess)
|
|
|
|
{
|
2018-11-04 15:13:51 +08:00
|
|
|
AddConsoleOutput(ARCHITECTURE_MISMATCH);
|
2018-08-23 03:11:58 +08:00
|
|
|
return false;
|
|
|
|
}
|
|
|
|
#endif
|
2018-11-28 04:54:04 +08:00
|
|
|
if (LPVOID remoteData = VirtualAllocEx(process, nullptr, location.size() * 2 + 2, MEM_RESERVE | MEM_COMMIT, PAGE_READWRITE))
|
2018-08-23 03:11:58 +08:00
|
|
|
{
|
2018-11-28 04:54:04 +08:00
|
|
|
WriteProcessMemory(process, remoteData, location.c_str(), location.size() * 2 + 2, nullptr);
|
|
|
|
if (AutoHandle<> thread = CreateRemoteThread(process, nullptr, 0, (LPTHREAD_START_ROUTINE)LoadLibraryW, remoteData, 0, nullptr))
|
2018-08-23 03:11:58 +08:00
|
|
|
{
|
|
|
|
WaitForSingleObject(thread, timeout);
|
2018-11-28 04:54:04 +08:00
|
|
|
VirtualFreeEx(process, remoteData, 0, MEM_RELEASE);
|
2018-08-23 03:11:58 +08:00
|
|
|
return true;
|
|
|
|
}
|
2018-11-28 04:54:04 +08:00
|
|
|
VirtualFreeEx(process, remoteData, 0, MEM_RELEASE);
|
2018-08-23 03:11:58 +08:00
|
|
|
}
|
|
|
|
}
|
2018-07-24 03:25:02 +08:00
|
|
|
|
2018-11-04 15:13:51 +08:00
|
|
|
AddConsoleOutput(INJECT_FAILED);
|
2018-07-18 05:01:56 +08:00
|
|
|
return false;
|
2018-05-12 04:46:05 +08:00
|
|
|
}
|
2018-07-24 03:25:02 +08:00
|
|
|
|
2018-08-25 02:04:23 +08:00
|
|
|
void DetachProcess(DWORD processId)
|
2018-05-12 04:46:05 +08:00
|
|
|
{
|
2018-11-28 04:54:04 +08:00
|
|
|
processRecordsByIds->at(processId)->Send(HostCommandType(HOST_COMMAND_DETACH));
|
2018-07-24 03:25:02 +08:00
|
|
|
}
|
|
|
|
|
2018-11-01 00:04:32 +08:00
|
|
|
void InsertHook(DWORD processId, HookParam hp, std::string name)
|
2018-07-24 03:25:02 +08:00
|
|
|
{
|
2018-11-28 04:54:04 +08:00
|
|
|
processRecordsByIds->at(processId)->Send(InsertHookCmd(hp, name));
|
2018-07-24 03:25:02 +08:00
|
|
|
}
|
|
|
|
|
2018-11-01 00:04:32 +08:00
|
|
|
HookParam GetHookParam(DWORD processId, uint64_t addr)
|
2018-07-24 03:25:02 +08:00
|
|
|
{
|
2018-11-28 04:54:04 +08:00
|
|
|
return processRecordsByIds->at(processId)->GetHook(addr).hp;
|
2018-07-24 03:25:02 +08:00
|
|
|
}
|
2016-01-05 23:01:17 +08:00
|
|
|
|
2018-11-01 00:04:32 +08:00
|
|
|
std::wstring GetHookName(DWORD processId, uint64_t addr)
|
2018-05-12 04:46:05 +08:00
|
|
|
{
|
2018-11-28 04:54:04 +08:00
|
|
|
return Util::StringToWideString(processRecordsByIds->at(processId)->GetHook(addr).hookName).value();
|
2018-05-12 04:46:05 +08:00
|
|
|
}
|
2016-01-05 23:01:17 +08:00
|
|
|
|
2018-10-31 13:20:44 +08:00
|
|
|
std::shared_ptr<TextThread> GetThread(ThreadParam tp)
|
2018-07-24 03:25:02 +08:00
|
|
|
{
|
2018-11-28 04:54:04 +08:00
|
|
|
return textThreadsByParams->at(tp);
|
2018-07-24 03:25:02 +08:00
|
|
|
}
|
2018-05-12 04:46:05 +08:00
|
|
|
|
2018-11-02 03:03:30 +08:00
|
|
|
void AddConsoleOutput(std::wstring text)
|
|
|
|
{
|
|
|
|
GetThread(CONSOLE)->AddSentence(text);
|
|
|
|
}
|
2016-01-05 23:01:17 +08:00
|
|
|
}
|