chore: Apply code formatting on entire codebase for consistent style

This commit is contained in:
icex2
2023-04-06 15:39:53 +02:00
committed by icex2
parent a1a849aef3
commit 031836ef0e
186 changed files with 2446 additions and 1979 deletions
+93 -65
View File
@@ -30,13 +30,11 @@ static HANDLE debugger_ready_event;
static PROCESS_INFORMATION pi;
static PVOID load_nt_header_from_process(HANDLE hProcess,
HMODULE hModule,
PIMAGE_NT_HEADERS32 pNtHeader);
static PVOID load_nt_header_from_process(
HANDLE hProcess, HMODULE hModule, PIMAGE_NT_HEADERS32 pNtHeader);
static HMODULE enumerate_modules_in_process(HANDLE hProcess,
HMODULE hModuleLast,
PIMAGE_NT_HEADERS32 pNtHeader);
static HMODULE enumerate_modules_in_process(
HANDLE hProcess, HMODULE hModuleLast, PIMAGE_NT_HEADERS32 pNtHeader);
// Source:
// https://docs.microsoft.com/en-us/windows/win32/memory/obtaining-a-file-name-from-a-file-handle
@@ -233,7 +231,8 @@ static bool debugger_create_process(
if (!ok) {
log_warning(
"ERROR: Failed to launch hooked EXE: %08x", (unsigned int) GetLastError());
"ERROR: Failed to launch hooked EXE: %08x",
(unsigned int) GetLastError());
free(cmd_line);
@@ -272,7 +271,8 @@ static uint32_t debugger_loop()
"EXCEPTION_DEBUG_EVENT(pid %ld, tid %ld): x%s 0x%p",
de.dwProcessId,
de.dwThreadId,
signal_exception_code_to_str(de.u.Exception.ExceptionRecord.ExceptionCode),
signal_exception_code_to_str(
de.u.Exception.ExceptionRecord.ExceptionCode),
de.u.Exception.ExceptionRecord.ExceptionAddress);
if (de.u.Exception.ExceptionRecord.ExceptionCode ==
@@ -518,7 +518,9 @@ bool debugger_inject_dll(const char *path_dll)
PAGE_READWRITE);
if (!remote_addr) {
log_warning("ERROR: VirtualAllocEx failed: %08x", (unsigned int) GetLastError());
log_warning(
"ERROR: VirtualAllocEx failed: %08x",
(unsigned int) GetLastError());
goto alloc_fail;
}
@@ -528,7 +530,8 @@ bool debugger_inject_dll(const char *path_dll)
if (!ok) {
log_warning(
"ERROR: WriteProcessMemory failed: %08x", (unsigned int) GetLastError());
"ERROR: WriteProcessMemory failed: %08x",
(unsigned int) GetLastError());
goto write_fail;
}
@@ -544,7 +547,8 @@ bool debugger_inject_dll(const char *path_dll)
if (remote_thread == NULL) {
log_warning(
"ERROR: CreateRemoteThread failed: %08x", (unsigned int) GetLastError());
"ERROR: CreateRemoteThread failed: %08x",
(unsigned int) GetLastError());
goto inject_fail;
}
@@ -556,7 +560,8 @@ bool debugger_inject_dll(const char *path_dll)
remote_addr = NULL;
if (!ok) {
log_warning("ERROR: VirtualFreeEx failed: %08x", (unsigned int) GetLastError());
log_warning(
"ERROR: VirtualFreeEx failed: %08x", (unsigned int) GetLastError());
}
return true;
@@ -571,7 +576,8 @@ alloc_fail:
return false;
}
HRESULT debugger_pe_patch_remote(HANDLE hProcess, void *dest, const void *src, size_t nbytes)
HRESULT debugger_pe_patch_remote(
HANDLE hProcess, void *dest, const void *src, size_t nbytes)
{
DWORD old_protect;
BOOL ok;
@@ -580,29 +586,19 @@ HRESULT debugger_pe_patch_remote(HANDLE hProcess, void *dest, const void *src, s
log_assert(src != NULL);
ok = VirtualProtectEx(
hProcess,
dest,
nbytes,
PAGE_EXECUTE_READWRITE,
&old_protect);
hProcess, dest, nbytes, PAGE_EXECUTE_READWRITE, &old_protect);
if (!ok) {
return HRESULT_FROM_WIN32(GetLastError());
}
ok = WriteProcessMemory(
hProcess, dest, src, nbytes, NULL);
ok = WriteProcessMemory(hProcess, dest, src, nbytes, NULL);
if (!ok) {
return HRESULT_FROM_WIN32(GetLastError());
}
ok = VirtualProtectEx(
hProcess,
dest,
nbytes,
old_protect,
&old_protect);
ok = VirtualProtectEx(hProcess, dest, nbytes, old_protect, &old_protect);
if (!ok) {
return HRESULT_FROM_WIN32(GetLastError());
@@ -611,7 +607,8 @@ HRESULT debugger_pe_patch_remote(HANDLE hProcess, void *dest, const void *src, s
return S_OK;
}
bool debugger_replace_dll_iat(const char *expected_dll, const char *replacement_path_dll)
bool debugger_replace_dll_iat(
const char *expected_dll, const char *replacement_path_dll)
{
log_assert(expected_dll);
log_assert(replacement_path_dll);
@@ -625,7 +622,8 @@ bool debugger_replace_dll_iat(const char *expected_dll, const char *replacement_
for (;;) {
memset(&inh, 0, sizeof(IMAGE_NT_HEADERS));
if ((hLast = enumerate_modules_in_process(pi.hProcess, hLast, &inh)) == NULL) {
if ((hLast = enumerate_modules_in_process(pi.hProcess, hLast, &inh)) ==
NULL) {
break;
}
@@ -640,18 +638,23 @@ bool debugger_replace_dll_iat(const char *expected_dll, const char *replacement_
goto inject_fail;
}
// Search through import table if it exists and replace the target DLL with our DLL filename
PBYTE pbModule = (PBYTE)hModule;
PIMAGE_SECTION_HEADER pRemoteSectionHeaders
= (PIMAGE_SECTION_HEADER)((PBYTE)pbModule
+ sizeof(inh.Signature)
+ sizeof(inh.FileHeader)
+ inh.FileHeader.SizeOfOptionalHeader);
// Search through import table if it exists and replace the target DLL with
// our DLL filename
PBYTE pbModule = (PBYTE) hModule;
PIMAGE_SECTION_HEADER pRemoteSectionHeaders =
(PIMAGE_SECTION_HEADER) ((PBYTE) pbModule + sizeof(inh.Signature) +
sizeof(inh.FileHeader) +
inh.FileHeader.SizeOfOptionalHeader);
size_t total_size = inh.OptionalHeader.SizeOfHeaders;
IMAGE_SECTION_HEADER header;
for (DWORD n = 0; n < inh.FileHeader.NumberOfSections; ++n) {
if (!ReadProcessMemory(pi.hProcess, pRemoteSectionHeaders + n, &header, sizeof(header), NULL)) {
if (!ReadProcessMemory(
pi.hProcess,
pRemoteSectionHeaders + n,
&header,
sizeof(header),
NULL)) {
log_warning("Couldn't read section header: %lu", GetLastError());
goto inject_fail;
}
@@ -671,17 +674,33 @@ bool debugger_replace_dll_iat(const char *expected_dll, const char *replacement_
log_assert(remote_addr != NULL);
debugger_pe_patch_remote(
pi.hProcess, remote_addr, replacement_path_dll, strlen(replacement_path_dll));
pi.hProcess,
remote_addr,
replacement_path_dll,
strlen(replacement_path_dll));
if (inh.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT].VirtualAddress != 0) {
PIMAGE_IMPORT_DESCRIPTOR pImageImport = (PIMAGE_IMPORT_DESCRIPTOR)(pbModule
+ inh.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT].VirtualAddress);
if (inh.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT]
.VirtualAddress != 0) {
PIMAGE_IMPORT_DESCRIPTOR pImageImport =
(PIMAGE_IMPORT_DESCRIPTOR) (pbModule +
inh.OptionalHeader
.DataDirectory
[IMAGE_DIRECTORY_ENTRY_IMPORT]
.VirtualAddress);
DWORD size = 0;
while (inh.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT].Size == 0
|| size < inh.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT].Size) {
while (inh.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT]
.Size == 0 ||
size < inh.OptionalHeader
.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT]
.Size) {
IMAGE_IMPORT_DESCRIPTOR ImageImport;
if (!ReadProcessMemory(pi.hProcess, pImageImport, &ImageImport, sizeof(ImageImport), NULL)) {
if (!ReadProcessMemory(
pi.hProcess,
pImageImport,
&ImageImport,
sizeof(ImageImport),
NULL)) {
log_warning("Couldn't read import: %lu", GetLastError());
goto inject_fail;
}
@@ -691,13 +710,19 @@ bool debugger_replace_dll_iat(const char *expected_dll, const char *replacement_
}
char name[MAX_PATH] = {0};
if (ReadProcessMemory(pi.hProcess, pbModule + ImageImport.Name, name, sizeof(name), NULL)) {
if (ReadProcessMemory(
pi.hProcess,
pbModule + ImageImport.Name,
name,
sizeof(name),
NULL)) {
// log_misc("\tImport DLL: %ld %s", ImageImport.Name, name);
if (strcmp(name, expected_dll) == 0) {
//log_misc("Replacing %s with %s", name, replacement_path_dll, (void*)pImageImport);
// log_misc("Replacing %s with %s", name,
// replacement_path_dll, (void*)pImageImport);
ImageImport.Name = (DWORD)((PBYTE)remote_addr - pbModule);
ImageImport.Name = (DWORD) ((PBYTE) remote_addr - pbModule);
debugger_pe_patch_remote(
pi.hProcess,
@@ -768,11 +793,10 @@ void debugger_finit(bool failure)
}
// Helper functions based on Microsoft Detours
static PVOID load_nt_header_from_process(HANDLE hProcess,
HMODULE hModule,
PIMAGE_NT_HEADERS32 pNtHeader)
static PVOID load_nt_header_from_process(
HANDLE hProcess, HMODULE hModule, PIMAGE_NT_HEADERS32 pNtHeader)
{
PBYTE pbModule = (PBYTE)hModule;
PBYTE pbModule = (PBYTE) hModule;
memset(pNtHeader, 0, sizeof(*pNtHeader));
@@ -795,13 +819,17 @@ static PVOID load_nt_header_from_process(HANDLE hProcess,
}
if (idh.e_magic != IMAGE_DOS_SIGNATURE ||
(DWORD)idh.e_lfanew > mbi.RegionSize ||
(DWORD)idh.e_lfanew < sizeof(idh)) {
(DWORD) idh.e_lfanew > mbi.RegionSize ||
(DWORD) idh.e_lfanew < sizeof(idh)) {
return NULL;
}
if (!ReadProcessMemory(hProcess, pbModule + idh.e_lfanew,
pNtHeader, sizeof(*pNtHeader), NULL)) {
if (!ReadProcessMemory(
hProcess,
pbModule + idh.e_lfanew,
pNtHeader,
sizeof(*pNtHeader),
NULL)) {
log_warning("Could not read NT header: %lu", GetLastError());
return NULL;
}
@@ -813,11 +841,10 @@ static PVOID load_nt_header_from_process(HANDLE hProcess,
return pbModule + idh.e_lfanew;
}
static HMODULE enumerate_modules_in_process(HANDLE hProcess,
HMODULE hModuleLast,
PIMAGE_NT_HEADERS32 pNtHeader)
static HMODULE enumerate_modules_in_process(
HANDLE hProcess, HMODULE hModuleLast, PIMAGE_NT_HEADERS32 pNtHeader)
{
PBYTE pbLast = (PBYTE)hModuleLast + MM_ALLOCATION_GRANULARITY;
PBYTE pbLast = (PBYTE) hModuleLast + MM_ALLOCATION_GRANULARITY;
memset(pNtHeader, 0, sizeof(*pNtHeader));
@@ -825,17 +852,17 @@ static HMODULE enumerate_modules_in_process(HANDLE hProcess,
memset(&mbi, 0, sizeof(mbi));
// Find the next memory region that contains a mapped PE image.
for (;; pbLast = (PBYTE)mbi.BaseAddress + mbi.RegionSize) {
if (VirtualQueryEx(hProcess, (PVOID)pbLast, &mbi, sizeof(mbi)) == 0) {
for (;; pbLast = (PBYTE) mbi.BaseAddress + mbi.RegionSize) {
if (VirtualQueryEx(hProcess, (PVOID) pbLast, &mbi, sizeof(mbi)) == 0) {
break;
}
// Usermode address space has such an unaligned region size always at the
// end and only at the end.
// Usermode address space has such an unaligned region size always at
// the end and only at the end.
if ((mbi.RegionSize & 0xfff) == 0xfff) {
break;
}
if (((PBYTE)mbi.BaseAddress + mbi.RegionSize) < pbLast) {
if (((PBYTE) mbi.BaseAddress + mbi.RegionSize) < pbLast) {
break;
}
@@ -846,8 +873,9 @@ static HMODULE enumerate_modules_in_process(HANDLE hProcess,
continue;
}
if (load_nt_header_from_process(hProcess, (HMODULE)pbLast, pNtHeader)) {
return (HMODULE)pbLast;
if (load_nt_header_from_process(
hProcess, (HMODULE) pbLast, pNtHeader)) {
return (HMODULE) pbLast;
}
}
+2 -3
View File
@@ -2,7 +2,6 @@
#include <stdbool.h>
/**
* Initialize inject's logger backend.
*
@@ -14,7 +13,6 @@
* disable.
*/
/**
* Initialize the debugger.
*
@@ -58,7 +56,8 @@ bool debugger_inject_dll(const char *path_dll);
* @param replacement_path_dll Name of dll to inject.
* @return true if sucessful, false on error.
*/
bool debugger_replace_dll_iat(const char *expected_dll, const char *replacement_path_dll);
bool debugger_replace_dll_iat(
const char *expected_dll, const char *replacement_path_dll);
/**
* Wait/block for a remote debugger to attach to the remote process.
+8 -6
View File
@@ -15,11 +15,11 @@
static FILE *log_file;
static HANDLE log_mutex;
static const char* logger_get_formatted_timestamp(void)
static const char *logger_get_formatted_timestamp(void)
{
static char buffer[64];
time_t cur = 0;
struct tm* tm = NULL;
struct tm *tm = NULL;
cur = time(NULL);
tm = localtime(&cur);
@@ -94,7 +94,8 @@ static size_t logger_msg_coloring_len(const char *str)
return 0;
}
static void logger_console(void *ctx, const char *chars, size_t nchars, const char* timestamp_str)
static void logger_console(
void *ctx, const char *chars, size_t nchars, const char *timestamp_str)
{
char color;
size_t color_len;
@@ -128,10 +129,11 @@ static void logger_console(void *ctx, const char *chars, size_t nchars, const ch
}
}
static void logger_file(void *ctx, const char *chars, size_t nchars, const char* timestamp_str)
static void logger_file(
void *ctx, const char *chars, size_t nchars, const char *timestamp_str)
{
if (ctx) {
fwrite(timestamp_str, 1, strlen(timestamp_str), (FILE*) ctx);
fwrite(timestamp_str, 1, strlen(timestamp_str), (FILE *) ctx);
fwrite(chars, 1, nchars, (FILE *) ctx);
fflush((FILE *) ctx);
}
@@ -139,7 +141,7 @@ static void logger_file(void *ctx, const char *chars, size_t nchars, const char*
static void logger_writer(void *ctx, const char *chars, size_t nchars)
{
const char* timestamp_str;
const char *timestamp_str;
// Different threads logging the same destination, e.g. debugger thread,
// main thread
+4 -4
View File
@@ -2,11 +2,11 @@
/**
* Initialize inject's logger backend.
*
*
* This takes care of hooking and merging the different log
* streams, e.g. inject's local logging and inject's debugger
* receiving remote logging events.
*
*
* @param log_file_path Path to the file to log to or NULL to
* disable.
*/
@@ -14,10 +14,10 @@ bool logger_init(const char *log_file_path);
/**
* Write a message to the logging backend.
*
*
* This is used by inject's debugger to redirect log messages
* recevied from the remote process.
*
*
* @param str String to log
*/
void logger_log(const char *str);
+3 -2
View File
@@ -92,7 +92,8 @@ verify_hook_dlls_exist(int argc, char **argv, uint32_t hook_dll_count)
if (dll_path_length == 0) {
log_warning(
"ERROR: Hook DLL not found: %08x", (unsigned int) GetLastError());
"ERROR: Hook DLL not found: %08x",
(unsigned int) GetLastError());
return false;
}
@@ -114,7 +115,7 @@ static bool inject_iat_hook_dlls(uint32_t hooks, char **argv)
continue;
*iat_hook = '\0';
debugger_replace_dll_iat(argv[i + 1], iat_hook+1);
debugger_replace_dll_iat(argv[i + 1], iat_hook + 1);
*iat_hook = '=';
}