EAT/IAT Hook

标 题: EAT/IAT Hook

作 者: Y4ng

时 间: 2013-08-21

链 接: http://www.cnblogs.com/Y4ng/p/EAT_IAT_HOOK.html 

#include <windows.h>
#include <shlwapi.h>
#include <wchar.h>
DWORD MyZwGetContextThread(HANDLE Thread,LPCONTEXT lpContext)
{
  memset(lpContext,0,sizeof(CONTEXT));
  return 0;
}
DWORD MyZwSetContextThread(HANDLE Thread,LPCONTEXT lpContext)
{
  memset(lpContext,0,sizeof(CONTEXT));
  return 0;
}
/**********************************************************
IAT Hook :挂钩目标输入表中的函数地址
参数:
char *szDLLName 函数所在的DLL
char *szName    函数名字
void *Addr      新函数地址
***********************************************************/
DWORD IATHook(char *szDLLName,char *szName,void *Addr)
{
  DWORD Protect;
  HMODULE hMod=LoadLibrary(szDLLName);
  DWORD RealAddr=(DWORD)GetProcAddress(hMod,szName);
  hMod=GetModuleHandle(NULL);
    IMAGE_DOS_HEADER * DosHeader   =(PIMAGE_DOS_HEADER)hMod;
    IMAGE_OPTIONAL_HEADER * Opthdr =(PIMAGE_OPTIONAL_HEADER)((DWORD)hMod+DosHeader->e_lfanew+24);
    IMAGE_IMPORT_DESCRIPTOR *pImport =(IMAGE_IMPORT_DESCRIPTOR*)((BYTE*)DosHeader+Opthdr->DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT].VirtualAddress);                                           
    if(pImport==NULL)
    {
        return FALSE;
    } 
    IMAGE_THUNK_DATA32 *Pthunk=(IMAGE_THUNK_DATA32*)((DWORD)hMod+pImport->FirstThunk);
  while(Pthunk->u1.Function)
  {
    if(RealAddr==Pthunk->u1.Function)
    {
      VirtualProtect(&Pthunk->u1.Function,0x1000,PAGE_READWRITE,&Protect);
      Pthunk->u1.Function=(DWORD)Addr;
      break;
    }
    Pthunk++;
  }
  return TRUE;
}
/**********************************************************
EAT Hook :挂钩目标输出表中的函数地址
***********************************************************/
BOOL EATHook(char *szDLLName,char *szFunName,DWORD NewFun)
{
  DWORD addr=0;
  DWORD index=0;
  HMODULE hMod=LoadLibrary(szDLLName);
    DWORD Protect;
    IMAGE_DOS_HEADER * DosHeader   =(PIMAGE_DOS_HEADER)hMod;
    IMAGE_OPTIONAL_HEADER * Opthdr =(PIMAGE_OPTIONAL_HEADER)((DWORD)hMod+DosHeader->e_lfanew+24);
    PIMAGE_EXPORT_DIRECTORY Export =(PIMAGE_EXPORT_DIRECTORY)((BYTE*)DosHeader+ Opthdr->DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress);
    PULONG pAddressOfFunctions     =(ULONG*)((BYTE*)hMod+Export->AddressOfFunctions); 
    PULONG pAddressOfNames         =(ULONG*)((BYTE*)hMod+Export->AddressOfNames); 
    PUSHORT  pAddressOfNameOrdinals=(USHORT*)((BYTE*)hMod+Export->AddressOfNameOrdinals); 
    for (int i=0;i <Export->NumberOfNames; i++) 
    {
        index=pAddressOfNameOrdinals[i];
        char *pFuncName = (char*)( (BYTE*)hMod + pAddressOfNames[i]);
        if (_stricmp( (char*)pFuncName,szFunName) == 0)
        {
            addr=pAddressOfFunctions[index];
            break;
        }
    }
  VirtualProtect(&pAddressOfFunctions[index],0x1000,PAGE_READWRITE,&Protect);
    pAddressOfFunctions[index] =(DWORD)NewFun - (DWORD)hMod;
  return TRUE;
}
BOOL WINAPI DllMain(HMODULE hModule, DWORD dwReason, PVOID pvReserved)
{
  if (dwReason == DLL_PROCESS_ATTACH)
  {
    DisableThreadLibraryCalls(hModule);
    IATHook("kernel32.dll","ExitProcess",MyZwGetContextThread);
    //GetProcAddress(LoadLibrary("ntdll.dll"),"NtSetInformationFile");         /** Test EAT HOOK **/
    //ExitThread(0);                                                           /** Test IAT HOOK**/
  }
  return TRUE;
} 

转自邓韬

转载于:https://www.cnblogs.com/Y4ng/p/EAT_IAT_HOOK.html

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值