Go Back   Armenian Knowledge Base > Technical sections > Languages, Compilers, Interpreters

Reply
 
Thread Tools

Code Injection
Old 16.04.2003, 08:22   #1
Младенец
 
Join Date: 10 2001
Location: Yerevan
Posts: 55
Rep Power: 0
Default Code Injection

hi...
i have some problem with code injection...
okay, say i have some process (ID and/or HANDLE) and some piece of code, that code creates new file and writes some info to it and closes... i injecting that code to working process which i have and all goes ok except writing to file.... so injected code crates file do other works but WriteFile function fails.... can someone help me ???
__________________
http://freenet.am/~softland

Old 16.04.2003, 14:59   #2
Академик
 
W_z_rd's Avatar
 
Join Date: 08 2002
Location: Yerevan, Armenia
Age: 54
Posts: 4,854
Rep Power: 5
Default

"code injection"... That's something new to me. Could you explain what is it, pls ?

Old 16.04.2003, 16:46   #3
Младенец
 
Join Date: 10 2001
Location: Yerevan
Posts: 55
Rep Power: 0
Default

i tho its self-explaining, but anyway....
code injection is a method of running some code (or DLL) in virtual memory space of other process... u INJECT that code to virtual memory of other process and let that code run, so u can now menage/debug that process, its kinda api hooking, instead of SetWindowsHookEx etc etc etc...

Old 16.04.2003, 17:20   #4
Академик
 
W_z_rd's Avatar
 
Join Date: 08 2002
Location: Yerevan, Armenia
Age: 54
Posts: 4,854
Rep Power: 5
Default

Ok, I got the idea. I don't really know what the problem is, but if I'm not mistaken, file handles are unique within the process (I'm not sure, though). So, if you open file in one process and then trying to work with the same file in another process using it's handle - it won't work. There must be some way of transferring handles or you should open the file again.
Hope, that this will help or at least give you some hint.
__________________
Женщин не надо понимать, их надо любить!

Old 16.04.2003, 17:48   #5
Младенец
 
Join Date: 10 2001
Location: Yerevan
Posts: 55
Rep Power: 0
Default

heh, thats the problem...
coz i creating file in injected code, in other process and do write file in that (same) process... file creating and writing is in the same process...

Old 17.04.2003, 17:37   #6
Академик
 
W_z_rd's Avatar
 
Join Date: 08 2002
Location: Yerevan, Armenia
Age: 54
Posts: 4,854
Rep Power: 5
Default

Well, then - sorry, I can't tell more without looking at the code, at least.

Old 17.04.2003, 17:51   #7
Младенец
 
Join Date: 10 2001
Location: Yerevan
Posts: 55
Rep Power: 0
Default

here the code snippet (if it will help you)...........


; ####### INJECTION CODE ######

InjCodeStart:
call Delta
Delta:
pop ebx
sub ebx, OFFSET Delta
push NULL
push FILE_ATTRIBUTE_NORMAL
push CREATE_ALWAYS
push NULL
push FILE_SHARE_WRITE
push GENERIC_WRITE
mov eax, OFFSET newFile
add eax, ebx
push eax ; last two lines for gettin relative address of newFile...
call [ebx + pCreateFileA]
mov [ebx + hFile], eax
; useless code.............
push NULL
push dword ptr [ebx + bwrite]
push dword ptr [ebx + buffSize]
push dword ptr [ebx + memBuff]
push eax
call [ebx + pWriteFile]
push dword ptr [ebx + hFile]
call [ebx + pCloseHandle]
ret

NOP

newFile db "new.bin",0
hFile dd 0
bwrite dd 0
pCreateFileA dd 0 ; address of CreateFileA
pWriteFile dd 0 ; '---'
pCloseHandle dd 0 ; '---'
memBuff dd 0 ; buffer with some info
buffSize dd 06000h

InjCodeEnd:

Old 18.04.2003, 14:41   #8
Младенец
 
Join Date: 10 2001
Location: Yerevan
Posts: 55
Rep Power: 0
Default

thanks to everybody, who helped and just viewed this post :)

i found whats wrong...

push dword ptr [ebx + bwrite]

this line pushes dword in bwrite (which is NULL at initialization-time), but need to push offset of bwrite, so rite code is...

mov eax, OFFSET bwrite
add eax, ebx
push eax

heh.....
Reply




Реклама:
реклама
Buy text link .

All times are GMT. The time now is 18:10.
Top

Powered by vBulletin® Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.