hook/peb.c: Add Process Environment Block helpers

This commit is contained in:
Decaf Code
2018-11-01 18:18:44 -04:00
parent 0c5dd7e193
commit b4926fd597
3 changed files with 63 additions and 0 deletions
+2
View File
@@ -3,6 +3,8 @@ hook_lib = static_library(
include_directories : inc,
c_pch : '../precompiled.h',
sources : [
'peb.c',
'peb.h',
],
)
+50
View File
@@ -0,0 +1,50 @@
#include <windows.h>
#include <winternl.h>
#include <assert.h>
#include "hook/peb.h"
static const PEB *peb_get(void)
{
#ifdef __amd64
return (const PEB *) __readgsqword(0x60);
#else
return (const PEB *) __readfsdword(0x30);
#endif
}
const peb_dll_t *peb_dll_get_first(void)
{
const PEB *peb;
const LIST_ENTRY *node;
peb = peb_get();
node = peb->Ldr->InMemoryOrderModuleList.Flink;
return CONTAINING_RECORD(node, LDR_DATA_TABLE_ENTRY, InMemoryOrderLinks);
}
const peb_dll_t *peb_dll_get_next(const peb_dll_t *dll)
{
const PEB *peb;
const LIST_ENTRY *node;
assert(dll != NULL);
peb = peb_get();
node = dll->InMemoryOrderLinks.Flink;
if (node == peb->Ldr->InMemoryOrderModuleList.Flink) {
return NULL;
}
return CONTAINING_RECORD(node, LDR_DATA_TABLE_ENTRY, InMemoryOrderLinks);
}
HMODULE peb_dll_get_base(const peb_dll_t *dll)
{
assert(dll != NULL);
return dll->DllBase;
}
+11
View File
@@ -0,0 +1,11 @@
#pragma once
#include <windows.h>
#include <winternl.h>
typedef LDR_DATA_TABLE_ENTRY peb_dll_t;
const peb_dll_t *peb_dll_get_first(void);
const peb_dll_t *peb_dll_get_next(const peb_dll_t *dll);
HMODULE peb_dll_get_base(const peb_dll_t *dll);
char *peb_dll_dup_name(const peb_dll_t *dll);