212 lines
6.8 KiB
C++
Raw Normal View History

#include "host.h"
2018-08-23 11:53:23 -04:00
#include "const.h"
#include "text.h"
2018-08-23 11:53:23 -04:00
#include "defs.h"
#include "util.h"
2018-11-10 23:29:12 -05:00
#include "../vnrhook/texthook.h"
2018-08-24 12:50:20 -04:00
namespace
2018-08-23 11:53:23 -04:00
{
class ProcessRecord
2018-08-24 12:50:20 -04:00
{
public:
inline static Host::ProcessEventCallback OnConnect, OnDisconnect;
ProcessRecord(DWORD processId, HANDLE pipe) :
processId(processId),
pipe(pipe),
mappedFile(OpenFileMappingW(FILE_MAP_READ, FALSE, (ITH_SECTION_ + std::to_wstring(processId)).c_str())),
view(MapViewOfFile(mappedFile, FILE_MAP_READ, 0, 0, HOOK_SECTION_SIZE / 2)), // jichi 1/16/2015: Changed to half to hook section size
viewMutex(ITH_HOOKMAN_MUTEX_ + std::to_wstring(processId))
{
OnConnect(processId);
}
~ProcessRecord()
{
OnDisconnect(processId);
UnmapViewOfFile(view);
}
TextHook GetHook(uint64_t addr)
{
if (view == nullptr) return {};
LOCK(viewMutex);
auto hooks = (const TextHook*)view;
for (int i = 0; i < MAX_HOOK; ++i)
if (hooks[i].address == addr) return hooks[i];
return {};
}
template <typename T>
void Send(T data)
{
std::enable_if_t<sizeof(data) < PIPE_BUFFER_SIZE, DWORD> DUMMY;
WriteFile(pipe, &data, sizeof(data), &DUMMY, nullptr);
}
private:
DWORD processId;
HANDLE pipe;
AutoHandle<> mappedFile;
LPCVOID view;
WinMutex viewMutex;
2018-08-24 12:50:20 -04:00
};
2018-12-21 14:11:40 -05:00
ThreadSafe<std::unordered_map<ThreadParam, std::shared_ptr<TextThread>>> textThreadsByParams;
ThreadSafe<std::unordered_map<DWORD, ProcessRecord>> processRecordsByIds;
2018-08-22 21:31:15 -04:00
2018-11-01 19:51:23 -04:00
ThreadParam CONSOLE{ 0, -1ULL, -1ULL, -1ULL }, CLIPBOARD{ 0, 0, -1ULL, -1ULL };
2018-08-24 12:50:20 -04:00
void RemoveThreads(std::function<bool(ThreadParam)> removeIf)
{
auto[lock, textThreadsByParams] = ::textThreadsByParams.operator->();
for (auto it = textThreadsByParams->begin(); it != textThreadsByParams->end(); removeIf(it->first) ? it = textThreadsByParams->erase(it) : ++it);
2018-08-24 12:50:20 -04:00
}
2018-11-04 01:34:49 -05:00
void CreatePipe()
2018-08-24 12:50:20 -04:00
{
2018-09-01 14:11:48 -04:00
std::thread([]
2018-08-24 12:50:20 -04:00
{
2018-09-20 23:04:11 -04:00
SECURITY_DESCRIPTOR pipeSD = {};
InitializeSecurityDescriptor(&pipeSD, SECURITY_DESCRIPTOR_REVISION);
SetSecurityDescriptorDacl(&pipeSD, TRUE, NULL, FALSE); // Allow non-admin processes to connect to pipe created by admin host
SECURITY_ATTRIBUTES pipeSA = { sizeof(SECURITY_ATTRIBUTES), &pipeSD, FALSE };
2018-12-02 15:55:02 -05:00
struct NamedPipeHandleCloser { void operator()(void* h) { DisconnectNamedPipe(h); CloseHandle(h); } };
AutoHandle<NamedPipeHandleCloser>
hookPipe = CreateNamedPipeW(HOOK_PIPE, PIPE_ACCESS_INBOUND, PIPE_TYPE_MESSAGE | PIPE_READMODE_MESSAGE, PIPE_UNLIMITED_INSTANCES, 0, PIPE_BUFFER_SIZE, MAXDWORD, &pipeSA),
hostPipe = CreateNamedPipeW(HOST_PIPE, PIPE_ACCESS_OUTBOUND, PIPE_TYPE_MESSAGE | PIPE_READMODE_MESSAGE, PIPE_UNLIMITED_INSTANCES, PIPE_BUFFER_SIZE, 0, MAXDWORD, &pipeSA);
2018-08-24 12:50:20 -04:00
ConnectNamedPipe(hookPipe, nullptr);
BYTE buffer[PIPE_BUFFER_SIZE] = {};
2018-08-24 12:50:20 -04:00
DWORD bytesRead, processId;
ReadFile(hookPipe, &processId, sizeof(processId), &bytesRead, nullptr);
2018-12-17 21:03:42 -05:00
processRecordsByIds->try_emplace(processId, processId, hostPipe);
2018-08-24 12:50:20 -04:00
2018-11-04 01:34:49 -05:00
CreatePipe();
2018-09-09 22:37:48 -04:00
2018-08-24 12:50:20 -04:00
while (ReadFile(hookPipe, buffer, PIPE_BUFFER_SIZE, &bytesRead, nullptr))
2018-11-10 23:29:12 -05:00
switch (*(HostNotificationType*)buffer)
2018-08-24 12:50:20 -04:00
{
case HOST_NOTIFICATION_RMVHOOK:
{
auto info = *(HookRemovedNotif*)buffer;
2018-11-04 20:48:46 -05:00
RemoveThreads([&](ThreadParam tp) { return tp.processId == processId && tp.addr == info.address; });
2018-08-24 12:50:20 -04:00
}
break;
case HOST_NOTIFICATION_TEXT:
{
auto info = *(ConsoleOutputNotif*)buffer;
2018-11-25 16:23:41 -05:00
Host::AddConsoleOutput(Util::StringToWideString(info.message).value());
2018-08-24 12:50:20 -04:00
}
break;
default:
{
2018-11-19 08:17:00 -05:00
auto tp = *(ThreadParam*)buffer;
if (textThreadsByParams->count(tp) == 0) textThreadsByParams->insert({ tp, std::make_shared<TextThread>(tp, Host::GetHookParam(tp)) });
textThreadsByParams->at(tp)->Push(buffer + sizeof(tp), bytesRead - sizeof(tp));
2018-08-24 12:50:20 -04:00
}
break;
}
2018-08-22 18:05:45 -04:00
RemoveThreads([&](ThreadParam tp) { return tp.processId == processId; });
processRecordsByIds->erase(processId);
2018-08-24 12:50:20 -04:00
}).detach();
}
2018-11-01 19:51:23 -04:00
void StartCapturingClipboard()
{
SetWindowsHookExW(WH_GETMESSAGE, [](int statusCode, WPARAM wParam, LPARAM lParam)
2018-11-01 19:51:23 -04:00
{
if (statusCode == HC_ACTION && wParam == PM_REMOVE && ((MSG*)lParam)->message == WM_CLIPBOARDUPDATE)
if (auto text = Util::GetClipboardText()) Host::GetThread(CLIPBOARD)->PushSentence(text.value());
return CallNextHookEx(NULL, statusCode, wParam, lParam);
}, NULL, GetCurrentThreadId());
2018-11-01 19:51:23 -04:00
}
2018-08-24 12:50:20 -04:00
}
2018-07-23 12:25:02 -07:00
namespace Host
{
void Start(ProcessEventCallback OnConnect, ProcessEventCallback OnDisconnect, TextThread::EventCallback OnCreate, TextThread::EventCallback OnDestroy, TextThread::OutputCallback Output)
{
ProcessRecord::OnConnect = OnConnect;
ProcessRecord::OnDisconnect = OnDisconnect;
TextThread::OnCreate = OnCreate;
TextThread::OnDestroy = OnDestroy;
TextThread::Output = Output;
2018-12-17 21:03:42 -05:00
processRecordsByIds->try_emplace(CONSOLE.processId, CONSOLE.processId, INVALID_HANDLE_VALUE);
textThreadsByParams->insert({ CONSOLE, std::make_shared<TextThread>(CONSOLE, HookParam{}, L"Console") });
textThreadsByParams->insert({ CLIPBOARD, std::make_shared<TextThread>(CLIPBOARD, HookParam{}, L"Clipboard") });
2018-11-01 19:51:23 -04:00
StartCapturingClipboard();
2018-11-04 01:34:49 -05:00
CreatePipe();
2018-07-23 12:25:02 -07:00
}
2018-08-24 12:50:20 -04:00
bool InjectProcess(DWORD processId, DWORD timeout)
2018-07-23 12:25:02 -07:00
{
if (processId == GetCurrentProcessId()) return false;
WinMutex(ITH_HOOKMAN_MUTEX_ + std::to_wstring(processId));
2018-07-23 12:25:02 -07:00
if (GetLastError() == ERROR_ALREADY_EXISTS)
{
2018-11-04 02:13:51 -05:00
AddConsoleOutput(ALREADY_INJECTED);
2018-07-23 12:25:02 -07:00
return false;
}
static HMODULE vnrhook = LoadLibraryExW(ITH_DLL, nullptr, DONT_RESOLVE_DLL_REFERENCES);
static std::wstring location = Util::GetModuleFilename(vnrhook).value();
2018-07-23 12:25:02 -07:00
if (AutoHandle<> process = OpenProcess(PROCESS_ALL_ACCESS, FALSE, processId))
2018-08-22 15:11:58 -04:00
{
#ifdef _WIN64
BOOL invalidProcess = FALSE;
IsWow64Process(process, &invalidProcess);
2018-08-22 15:11:58 -04:00
if (invalidProcess)
{
2018-11-04 02:13:51 -05:00
AddConsoleOutput(ARCHITECTURE_MISMATCH);
2018-08-22 15:11:58 -04:00
return false;
}
#endif
if (LPVOID remoteData = VirtualAllocEx(process, nullptr, location.size() * 2 + 2, MEM_RESERVE | MEM_COMMIT, PAGE_READWRITE))
2018-08-22 15:11:58 -04:00
{
WriteProcessMemory(process, remoteData, location.c_str(), location.size() * 2 + 2, nullptr);
if (AutoHandle<> thread = CreateRemoteThread(process, nullptr, 0, (LPTHREAD_START_ROUTINE)LoadLibraryW, remoteData, 0, nullptr))
2018-08-22 15:11:58 -04:00
{
WaitForSingleObject(thread, timeout);
VirtualFreeEx(process, remoteData, 0, MEM_RELEASE);
2018-08-22 15:11:58 -04:00
return true;
}
VirtualFreeEx(process, remoteData, 0, MEM_RELEASE);
2018-08-22 15:11:58 -04:00
}
}
2018-07-23 12:25:02 -07:00
2018-11-04 02:13:51 -05:00
AddConsoleOutput(INJECT_FAILED);
2018-07-17 17:01:56 -04:00
return false;
}
2018-07-23 12:25:02 -07:00
2018-08-24 14:04:23 -04:00
void DetachProcess(DWORD processId)
{
2018-12-17 21:03:42 -05:00
processRecordsByIds->at(processId).Send(HostCommandType(HOST_COMMAND_DETACH));
2018-07-23 12:25:02 -07:00
}
void InsertHook(DWORD processId, HookParam hp)
2018-07-23 12:25:02 -07:00
{
2018-12-17 21:03:42 -05:00
processRecordsByIds->at(processId).Send(InsertHookCmd(hp));
2018-07-23 12:25:02 -07:00
}
HookParam GetHookParam(ThreadParam tp)
{
2018-12-17 21:03:42 -05:00
return processRecordsByIds->at(tp.processId).GetHook(tp.addr).hp;
}
std::shared_ptr<TextThread> GetThread(ThreadParam tp)
2018-07-23 12:25:02 -07:00
{
return textThreadsByParams->at(tp);
2018-07-23 12:25:02 -07:00
}
2018-12-28 12:14:56 -05:00
void AddConsoleOutput(std::wstring text)
{
GetThread(CONSOLE)->PushSentence(text);
2018-11-01 15:03:30 -04:00
}
}