上章我们讲到伪句柄带来的一系列麻烦,那么怎么办呢
一个方法是使用duplicateHandle把伪句柄转化程实句柄
DuplicateHandle原本是进程间复制句柄的函数,原理其实很简单把一个进程的句柄复制到另一个进程句柄表
在这里我们要说下,什么是伪句柄,伪句柄返回了对象的引用,但是,在句柄表中查找不到该句柄,所以,可用,但是在句柄表中找不到的句柄是伪句柄,反之能在句柄表中找到的句柄是真实的句柄
DuplicateHandle(GetCurrentProcess(),GetCurrentThread(),GetCurrentProcess(),&hThread,0,false,DUPLICATE_SAME_ACCESS);、
DuplicateHandle把本进程的某个线程的内核对象的引用复制到本进程的句柄表中,那么,返回的句柄当然是该线程的真实句柄
那么附上测试代码
#include <windows.h>
#include <iostream>
#include <process.h>
using namespace std;
unsigned int WINAPI WorkThread(void* param);
typedef HANDLE (WINAPI * OPENTHREADFUN)(DWORD dwDesiredAccess,BOOL bInheritHandle,DWORD dwThreadId);
int main()
{
FILETIME CreatTime;
FILETIME ExitTime;
FILETIME KernelTime;
FILETIME UserTime;
HANDLE hThread;
GetThreadTimes(GetCurrentThread(),&CreatTime,&ExitTime,&KernelTime,&UserTime);
cout<<"CreatTime:"<<CreatTime.dwHighDateTime<<","<<CreatTime.dwLowDateTime<<endl;
cout<<"ExitTime:"<<ExitTime.dwHighDateTime<<","<<ExitTime.dwLowDateTime<<endl;
cout<<"KernelTime:"<<KernelTime.dwHighDateTime<<","<<KernelTime.dwLowDateTime<<endl;
cout<<"UserTime:"<<UserTime.dwHighDateTime<<","<<UserTime.dwLowDateTime<<endl;
hThread=GetCurrentThread();
DuplicateHandle(GetCurrentProcess(),GetCurrentThread(),GetCurrentProcess(),&hThread,0,false,DUPLICATE_SAME_ACCESS);
HANDLE hThreadNew=(HANDLE) _beginthreadex(NULL,0,WorkThread,(void*)hThread,0,NULL);
WaitForSingleObject(hThreadNew,INFINITE);
CloseHandle(hThreadNew);
CloseHandle(hThread);
system("pause");
return 0;
}
unsigned int WINAPI WorkThread(void* param)
{
HANDLE hThread=(HANDLE)param;
//cout<<"ThreadHandle:"<<hThread<<endl;
FILETIME CreatTime;
FILETIME ExitTime;
FILETIME KernelTime;
FILETIME UserTime;
GetThreadTimes(hThread,&CreatTime,&ExitTime,&KernelTime,&UserTime);
cout<<"CreatTime:"<<CreatTime.dwHighDateTime<<","<<CreatTime.dwLowDateTime<<endl;
cout<<"ExitTime:"<<ExitTime.dwHighDateTime<<","<<ExitTime.dwLowDateTime<<endl;
cout<<"KernelTime:"<<KernelTime.dwHighDateTime<<","<<KernelTime.dwLowDateTime<<endl;
cout<<"UserTime:"<<UserTime.dwHighDateTime<<","<<UserTime.dwLowDateTime<<endl;
return 0;
}
,这样的话两个线程取主线程的相关的时间就都一样了
其实也可以不用转化的方法就是使用OpenThread方法,
首先DWORD id=GetCurrentThreadId来获取当前线程的ID
然后OpenThread(THREAD_ALL_ACCESS,FALSE,id)根据线程ID就可以得到当前线程的真实句柄了
使用这个方法的根据是线程id或者进程id是唯一的,所以,只要根据id就可以准确的定位到想要打开的那个对象,同理也可以根据当前进程的ID获取句柄