• <ins id="pjuwb"></ins>
    <blockquote id="pjuwb"><pre id="pjuwb"></pre></blockquote>
    <noscript id="pjuwb"></noscript>
          <sup id="pjuwb"><pre id="pjuwb"></pre></sup>
            <dd id="pjuwb"></dd>
            <abbr id="pjuwb"></abbr>

            S.l.e!ep.¢%

            像打了激速一樣,以四倍的速度運轉(zhuǎn),開心的工作
            簡單、開放、平等的公司文化;尊重個性、自由與個人價值;
            posts - 1098, comments - 335, trackbacks - 0, articles - 1
              C++博客 :: 首頁 :: 新隨筆 :: 聯(lián)系 :: 聚合  :: 管理
            DLL Inject -- 一、Windows 鉤子(Hooks) - (1)

            之前搞復雜了,其實可以很簡單

            有個要點:
            The global hooks are a shared resource, and installing one affects all applications in the same desktop as the calling thread. All global hook functions must be in libraries. Global hooks should be restricted to special-purpose applications or to use as a development aid during application debugging. Libraries that no longer need a hook should remove its hook procedure.

            作為一個全局或跨進程的鉤子,鉤子的實現(xiàn)函數(shù)必須在DLL中實現(xiàn),不然目標程序觸發(fā)到鉤子時就會掛掉

            DLL實現(xiàn)

            //?DLLInject.cpp?:?Defines?the?entry?point?for?the?DLL?application.
            //

            #include?
            "stdafx.h"
            #include?
            <stdio.h>

            LRESULT?CALLBACK?CallWndProc(
            int?code,?WPARAM?wParam,?LPARAM?lParam)
            {?
            ????
            return?CallNextHookEx?(NULL,?code,?wParam,?lParam);
            }

            BOOL?APIENTRY?DllMain(?HANDLE?hModule,?
            ??????????????????????DWORD??ul_reason_for_call,?
            ??????????????????????LPVOID?lpReserved
            ??????????????????????)
            {
            ????
            switch?(?ul_reason_for_call?)
            ????{
            ????
            case?DLL_PROCESS_ATTACH:
            ????????{
            ????????????
            char?szDllName[MAX_PATH]={0};
            ????????????GetModuleFileName((HMODULE)hModule,?szDllName,?MAX_PATH);
            ????????????LoadLibrary(szDllName);????????
            ????????????
            break;
            ????????}
            ????
            case?DLL_PROCESS_DETACH:
            ????????{
            ????????}
            ????????
            break;
            ????}
            ????
            ????
            return?TRUE;
            ????
            }

            在DLL加載時,調(diào)用多一次,LoadLibrary的目的,是為了增加引用計數(shù),這樣即使我們的程序關掉了,系統(tǒng)也不會卸載掉DLL,DLL還在內(nèi)存中(所以通常情況下 LoadLibrary 和 FreeLibrary 要成對調(diào)用, 具體可以了解下 Windows 的內(nèi)存管理機制)

            調(diào)用代碼:
            HHOOK?g_hHook?=?NULL;
            UINT??g_nHOOKMsg?
            =?0;

            //---------------------------------------------------------------------------
            //?ModuleFromAddress
            //
            //?Returns?the?HMODULE?that?contains?the?specified?memory?address
            //---------------------------------------------------------------------------
            static?HMODULE?ModuleFromAddress(PVOID?pv)?
            {
            ????MEMORY_BASIC_INFORMATION?mbi;
            ????
            ????
            return?((::VirtualQuery(pv,?&mbi,?sizeof(mbi))?!=?0)???(HMODULE)?mbi.AllocationBase?:?NULL);
            }

            void?CDLLInjectBySetHookDlg::OnButton1()?
            {????
            ????HMODULE?hModule?
            =?::LoadLibrary("DLLInject.dll");
            ????
            if?(?hModule?==?NULL?)
            ????{
            ????????AfxMessageBox(
            "Failed?to?LoadLibrary!");
            ????????
            return?;
            ????}

            ????typedef?LRESULT?(CALLBACK?
            *CallWndProc)(int?code,?WPARAM?wParam,?LPARAM?lParam);
            ????CallWndProc?pfnCallWndProc?
            =?(CallWndProc)::GetProcAddress(hModule,?"CallWndProc");

            ????
            if?(?pfnCallWndProc?==?NULL?)
            ????{
            ????????AfxMessageBox(
            "Failed?to?GetProcAddress!");
            ????????
            return?;
            ????}

            ????HWND?hWnd?
            =?::FindWindow(NULL,?"testHooked");
            ????
            if?(hWnd?==?NULL)
            ????{
            ????????AfxMessageBox(
            "Failed?to?Find?Window!");
            ????????
            return?;
            ????}

            ????DWORD?dwThreadID?
            =?::GetWindowThreadProcessId(hWnd,?NULL);
            ????
            if?(?dwThreadID?==?0?)
            ????{
            ????????AfxMessageBox(
            "Failed?to?Get?Window?Thread?Process?ID");
            ????????
            return?;
            ????}

            ????g_hHook?
            =?::SetWindowsHookEx(WH_CALLWNDPROC,?(HOOKPROC)(pfnCallWndProc),?ModuleFromAddress(pfnCallWndProc),?dwThreadID);

            ????
            if?(?g_hHook?==?NULL?)
            ????{
            ????????AfxMessageBox(
            "Failed?to?Set?Windows?Hook");
            ????????
            return?;
            ????}

            ????::SendMessage(::FindWindow(NULL,?
            "testHooked"),?WM_USER,?0,?0);
            ????::UnhookWindowsHookEx(g_hHook);
            }


            按下按鈕,使用工具查看,目標程序的加載模塊列表中已經(jīng)有了 DLLInject.dll ,注入成功!
            99久久精品免费观看国产| 久久久一本精品99久久精品88| 久久亚洲国产欧洲精品一| 伊人 久久 精品| 色综合久久综合网观看| 欧美日韩精品久久久久| 久久99精品久久久久久不卡| 97超级碰碰碰碰久久久久| 中文字幕亚洲综合久久菠萝蜜| 欧美午夜精品久久久久免费视| 久久婷婷色香五月综合激情| 色8激情欧美成人久久综合电| 午夜天堂精品久久久久| 久久婷婷激情综合色综合俺也去 | 久久久久亚洲av毛片大| 91精品国产高清久久久久久io| 久久夜色精品国产噜噜亚洲AV| 国产高清美女一级a毛片久久w| 久久精品国产精品亚洲下载| 久久久久久A亚洲欧洲AV冫| 久久精品无码一区二区无码| 久久WWW免费人成一看片| 亚洲色大成网站www久久九| 日韩人妻无码精品久久久不卡| 久久亚洲国产精品123区| 国产精品99久久久久久www| 国产欧美久久一区二区| 91精品国产91久久久久久| 久久精品aⅴ无码中文字字幕不卡| 蜜桃麻豆WWW久久囤产精品| 久久精品99久久香蕉国产色戒 | 国内精品久久久久久不卡影院| 91久久婷婷国产综合精品青草| 无遮挡粉嫩小泬久久久久久久| 狠狠色丁香久久婷婷综合图片| 欧美日韩中文字幕久久久不卡 | 久久免费国产精品一区二区| 久久99国产精品99久久 | 亚洲人成网站999久久久综合 | 一级做a爰片久久毛片免费陪| 日韩久久无码免费毛片软件|