chore: Apply code formatting on entire codebase for consistent style
This commit is contained in:
+93
-65
@@ -30,13 +30,11 @@ static HANDLE debugger_ready_event;
|
||||
|
||||
static PROCESS_INFORMATION pi;
|
||||
|
||||
static PVOID load_nt_header_from_process(HANDLE hProcess,
|
||||
HMODULE hModule,
|
||||
PIMAGE_NT_HEADERS32 pNtHeader);
|
||||
static PVOID load_nt_header_from_process(
|
||||
HANDLE hProcess, HMODULE hModule, PIMAGE_NT_HEADERS32 pNtHeader);
|
||||
|
||||
static HMODULE enumerate_modules_in_process(HANDLE hProcess,
|
||||
HMODULE hModuleLast,
|
||||
PIMAGE_NT_HEADERS32 pNtHeader);
|
||||
static HMODULE enumerate_modules_in_process(
|
||||
HANDLE hProcess, HMODULE hModuleLast, PIMAGE_NT_HEADERS32 pNtHeader);
|
||||
|
||||
// Source:
|
||||
// https://docs.microsoft.com/en-us/windows/win32/memory/obtaining-a-file-name-from-a-file-handle
|
||||
@@ -233,7 +231,8 @@ static bool debugger_create_process(
|
||||
|
||||
if (!ok) {
|
||||
log_warning(
|
||||
"ERROR: Failed to launch hooked EXE: %08x", (unsigned int) GetLastError());
|
||||
"ERROR: Failed to launch hooked EXE: %08x",
|
||||
(unsigned int) GetLastError());
|
||||
|
||||
free(cmd_line);
|
||||
|
||||
@@ -272,7 +271,8 @@ static uint32_t debugger_loop()
|
||||
"EXCEPTION_DEBUG_EVENT(pid %ld, tid %ld): x%s 0x%p",
|
||||
de.dwProcessId,
|
||||
de.dwThreadId,
|
||||
signal_exception_code_to_str(de.u.Exception.ExceptionRecord.ExceptionCode),
|
||||
signal_exception_code_to_str(
|
||||
de.u.Exception.ExceptionRecord.ExceptionCode),
|
||||
de.u.Exception.ExceptionRecord.ExceptionAddress);
|
||||
|
||||
if (de.u.Exception.ExceptionRecord.ExceptionCode ==
|
||||
@@ -518,7 +518,9 @@ bool debugger_inject_dll(const char *path_dll)
|
||||
PAGE_READWRITE);
|
||||
|
||||
if (!remote_addr) {
|
||||
log_warning("ERROR: VirtualAllocEx failed: %08x", (unsigned int) GetLastError());
|
||||
log_warning(
|
||||
"ERROR: VirtualAllocEx failed: %08x",
|
||||
(unsigned int) GetLastError());
|
||||
|
||||
goto alloc_fail;
|
||||
}
|
||||
@@ -528,7 +530,8 @@ bool debugger_inject_dll(const char *path_dll)
|
||||
|
||||
if (!ok) {
|
||||
log_warning(
|
||||
"ERROR: WriteProcessMemory failed: %08x", (unsigned int) GetLastError());
|
||||
"ERROR: WriteProcessMemory failed: %08x",
|
||||
(unsigned int) GetLastError());
|
||||
|
||||
goto write_fail;
|
||||
}
|
||||
@@ -544,7 +547,8 @@ bool debugger_inject_dll(const char *path_dll)
|
||||
|
||||
if (remote_thread == NULL) {
|
||||
log_warning(
|
||||
"ERROR: CreateRemoteThread failed: %08x", (unsigned int) GetLastError());
|
||||
"ERROR: CreateRemoteThread failed: %08x",
|
||||
(unsigned int) GetLastError());
|
||||
|
||||
goto inject_fail;
|
||||
}
|
||||
@@ -556,7 +560,8 @@ bool debugger_inject_dll(const char *path_dll)
|
||||
remote_addr = NULL;
|
||||
|
||||
if (!ok) {
|
||||
log_warning("ERROR: VirtualFreeEx failed: %08x", (unsigned int) GetLastError());
|
||||
log_warning(
|
||||
"ERROR: VirtualFreeEx failed: %08x", (unsigned int) GetLastError());
|
||||
}
|
||||
|
||||
return true;
|
||||
@@ -571,7 +576,8 @@ alloc_fail:
|
||||
return false;
|
||||
}
|
||||
|
||||
HRESULT debugger_pe_patch_remote(HANDLE hProcess, void *dest, const void *src, size_t nbytes)
|
||||
HRESULT debugger_pe_patch_remote(
|
||||
HANDLE hProcess, void *dest, const void *src, size_t nbytes)
|
||||
{
|
||||
DWORD old_protect;
|
||||
BOOL ok;
|
||||
@@ -580,29 +586,19 @@ HRESULT debugger_pe_patch_remote(HANDLE hProcess, void *dest, const void *src, s
|
||||
log_assert(src != NULL);
|
||||
|
||||
ok = VirtualProtectEx(
|
||||
hProcess,
|
||||
dest,
|
||||
nbytes,
|
||||
PAGE_EXECUTE_READWRITE,
|
||||
&old_protect);
|
||||
hProcess, dest, nbytes, PAGE_EXECUTE_READWRITE, &old_protect);
|
||||
|
||||
if (!ok) {
|
||||
return HRESULT_FROM_WIN32(GetLastError());
|
||||
}
|
||||
|
||||
ok = WriteProcessMemory(
|
||||
hProcess, dest, src, nbytes, NULL);
|
||||
ok = WriteProcessMemory(hProcess, dest, src, nbytes, NULL);
|
||||
|
||||
if (!ok) {
|
||||
return HRESULT_FROM_WIN32(GetLastError());
|
||||
}
|
||||
|
||||
ok = VirtualProtectEx(
|
||||
hProcess,
|
||||
dest,
|
||||
nbytes,
|
||||
old_protect,
|
||||
&old_protect);
|
||||
ok = VirtualProtectEx(hProcess, dest, nbytes, old_protect, &old_protect);
|
||||
|
||||
if (!ok) {
|
||||
return HRESULT_FROM_WIN32(GetLastError());
|
||||
@@ -611,7 +607,8 @@ HRESULT debugger_pe_patch_remote(HANDLE hProcess, void *dest, const void *src, s
|
||||
return S_OK;
|
||||
}
|
||||
|
||||
bool debugger_replace_dll_iat(const char *expected_dll, const char *replacement_path_dll)
|
||||
bool debugger_replace_dll_iat(
|
||||
const char *expected_dll, const char *replacement_path_dll)
|
||||
{
|
||||
log_assert(expected_dll);
|
||||
log_assert(replacement_path_dll);
|
||||
@@ -625,7 +622,8 @@ bool debugger_replace_dll_iat(const char *expected_dll, const char *replacement_
|
||||
for (;;) {
|
||||
memset(&inh, 0, sizeof(IMAGE_NT_HEADERS));
|
||||
|
||||
if ((hLast = enumerate_modules_in_process(pi.hProcess, hLast, &inh)) == NULL) {
|
||||
if ((hLast = enumerate_modules_in_process(pi.hProcess, hLast, &inh)) ==
|
||||
NULL) {
|
||||
break;
|
||||
}
|
||||
|
||||
@@ -640,18 +638,23 @@ bool debugger_replace_dll_iat(const char *expected_dll, const char *replacement_
|
||||
goto inject_fail;
|
||||
}
|
||||
|
||||
// Search through import table if it exists and replace the target DLL with our DLL filename
|
||||
PBYTE pbModule = (PBYTE)hModule;
|
||||
PIMAGE_SECTION_HEADER pRemoteSectionHeaders
|
||||
= (PIMAGE_SECTION_HEADER)((PBYTE)pbModule
|
||||
+ sizeof(inh.Signature)
|
||||
+ sizeof(inh.FileHeader)
|
||||
+ inh.FileHeader.SizeOfOptionalHeader);
|
||||
// Search through import table if it exists and replace the target DLL with
|
||||
// our DLL filename
|
||||
PBYTE pbModule = (PBYTE) hModule;
|
||||
PIMAGE_SECTION_HEADER pRemoteSectionHeaders =
|
||||
(PIMAGE_SECTION_HEADER) ((PBYTE) pbModule + sizeof(inh.Signature) +
|
||||
sizeof(inh.FileHeader) +
|
||||
inh.FileHeader.SizeOfOptionalHeader);
|
||||
size_t total_size = inh.OptionalHeader.SizeOfHeaders;
|
||||
|
||||
IMAGE_SECTION_HEADER header;
|
||||
for (DWORD n = 0; n < inh.FileHeader.NumberOfSections; ++n) {
|
||||
if (!ReadProcessMemory(pi.hProcess, pRemoteSectionHeaders + n, &header, sizeof(header), NULL)) {
|
||||
if (!ReadProcessMemory(
|
||||
pi.hProcess,
|
||||
pRemoteSectionHeaders + n,
|
||||
&header,
|
||||
sizeof(header),
|
||||
NULL)) {
|
||||
log_warning("Couldn't read section header: %lu", GetLastError());
|
||||
goto inject_fail;
|
||||
}
|
||||
@@ -671,17 +674,33 @@ bool debugger_replace_dll_iat(const char *expected_dll, const char *replacement_
|
||||
log_assert(remote_addr != NULL);
|
||||
|
||||
debugger_pe_patch_remote(
|
||||
pi.hProcess, remote_addr, replacement_path_dll, strlen(replacement_path_dll));
|
||||
pi.hProcess,
|
||||
remote_addr,
|
||||
replacement_path_dll,
|
||||
strlen(replacement_path_dll));
|
||||
|
||||
if (inh.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT].VirtualAddress != 0) {
|
||||
PIMAGE_IMPORT_DESCRIPTOR pImageImport = (PIMAGE_IMPORT_DESCRIPTOR)(pbModule
|
||||
+ inh.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT].VirtualAddress);
|
||||
if (inh.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT]
|
||||
.VirtualAddress != 0) {
|
||||
PIMAGE_IMPORT_DESCRIPTOR pImageImport =
|
||||
(PIMAGE_IMPORT_DESCRIPTOR) (pbModule +
|
||||
inh.OptionalHeader
|
||||
.DataDirectory
|
||||
[IMAGE_DIRECTORY_ENTRY_IMPORT]
|
||||
.VirtualAddress);
|
||||
|
||||
DWORD size = 0;
|
||||
while (inh.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT].Size == 0
|
||||
|| size < inh.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT].Size) {
|
||||
while (inh.OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT]
|
||||
.Size == 0 ||
|
||||
size < inh.OptionalHeader
|
||||
.DataDirectory[IMAGE_DIRECTORY_ENTRY_IMPORT]
|
||||
.Size) {
|
||||
IMAGE_IMPORT_DESCRIPTOR ImageImport;
|
||||
if (!ReadProcessMemory(pi.hProcess, pImageImport, &ImageImport, sizeof(ImageImport), NULL)) {
|
||||
if (!ReadProcessMemory(
|
||||
pi.hProcess,
|
||||
pImageImport,
|
||||
&ImageImport,
|
||||
sizeof(ImageImport),
|
||||
NULL)) {
|
||||
log_warning("Couldn't read import: %lu", GetLastError());
|
||||
goto inject_fail;
|
||||
}
|
||||
@@ -691,13 +710,19 @@ bool debugger_replace_dll_iat(const char *expected_dll, const char *replacement_
|
||||
}
|
||||
|
||||
char name[MAX_PATH] = {0};
|
||||
if (ReadProcessMemory(pi.hProcess, pbModule + ImageImport.Name, name, sizeof(name), NULL)) {
|
||||
if (ReadProcessMemory(
|
||||
pi.hProcess,
|
||||
pbModule + ImageImport.Name,
|
||||
name,
|
||||
sizeof(name),
|
||||
NULL)) {
|
||||
// log_misc("\tImport DLL: %ld %s", ImageImport.Name, name);
|
||||
|
||||
if (strcmp(name, expected_dll) == 0) {
|
||||
//log_misc("Replacing %s with %s", name, replacement_path_dll, (void*)pImageImport);
|
||||
// log_misc("Replacing %s with %s", name,
|
||||
// replacement_path_dll, (void*)pImageImport);
|
||||
|
||||
ImageImport.Name = (DWORD)((PBYTE)remote_addr - pbModule);
|
||||
ImageImport.Name = (DWORD) ((PBYTE) remote_addr - pbModule);
|
||||
|
||||
debugger_pe_patch_remote(
|
||||
pi.hProcess,
|
||||
@@ -768,11 +793,10 @@ void debugger_finit(bool failure)
|
||||
}
|
||||
|
||||
// Helper functions based on Microsoft Detours
|
||||
static PVOID load_nt_header_from_process(HANDLE hProcess,
|
||||
HMODULE hModule,
|
||||
PIMAGE_NT_HEADERS32 pNtHeader)
|
||||
static PVOID load_nt_header_from_process(
|
||||
HANDLE hProcess, HMODULE hModule, PIMAGE_NT_HEADERS32 pNtHeader)
|
||||
{
|
||||
PBYTE pbModule = (PBYTE)hModule;
|
||||
PBYTE pbModule = (PBYTE) hModule;
|
||||
|
||||
memset(pNtHeader, 0, sizeof(*pNtHeader));
|
||||
|
||||
@@ -795,13 +819,17 @@ static PVOID load_nt_header_from_process(HANDLE hProcess,
|
||||
}
|
||||
|
||||
if (idh.e_magic != IMAGE_DOS_SIGNATURE ||
|
||||
(DWORD)idh.e_lfanew > mbi.RegionSize ||
|
||||
(DWORD)idh.e_lfanew < sizeof(idh)) {
|
||||
(DWORD) idh.e_lfanew > mbi.RegionSize ||
|
||||
(DWORD) idh.e_lfanew < sizeof(idh)) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
if (!ReadProcessMemory(hProcess, pbModule + idh.e_lfanew,
|
||||
pNtHeader, sizeof(*pNtHeader), NULL)) {
|
||||
if (!ReadProcessMemory(
|
||||
hProcess,
|
||||
pbModule + idh.e_lfanew,
|
||||
pNtHeader,
|
||||
sizeof(*pNtHeader),
|
||||
NULL)) {
|
||||
log_warning("Could not read NT header: %lu", GetLastError());
|
||||
return NULL;
|
||||
}
|
||||
@@ -813,11 +841,10 @@ static PVOID load_nt_header_from_process(HANDLE hProcess,
|
||||
return pbModule + idh.e_lfanew;
|
||||
}
|
||||
|
||||
static HMODULE enumerate_modules_in_process(HANDLE hProcess,
|
||||
HMODULE hModuleLast,
|
||||
PIMAGE_NT_HEADERS32 pNtHeader)
|
||||
static HMODULE enumerate_modules_in_process(
|
||||
HANDLE hProcess, HMODULE hModuleLast, PIMAGE_NT_HEADERS32 pNtHeader)
|
||||
{
|
||||
PBYTE pbLast = (PBYTE)hModuleLast + MM_ALLOCATION_GRANULARITY;
|
||||
PBYTE pbLast = (PBYTE) hModuleLast + MM_ALLOCATION_GRANULARITY;
|
||||
|
||||
memset(pNtHeader, 0, sizeof(*pNtHeader));
|
||||
|
||||
@@ -825,17 +852,17 @@ static HMODULE enumerate_modules_in_process(HANDLE hProcess,
|
||||
memset(&mbi, 0, sizeof(mbi));
|
||||
|
||||
// Find the next memory region that contains a mapped PE image.
|
||||
for (;; pbLast = (PBYTE)mbi.BaseAddress + mbi.RegionSize) {
|
||||
if (VirtualQueryEx(hProcess, (PVOID)pbLast, &mbi, sizeof(mbi)) == 0) {
|
||||
for (;; pbLast = (PBYTE) mbi.BaseAddress + mbi.RegionSize) {
|
||||
if (VirtualQueryEx(hProcess, (PVOID) pbLast, &mbi, sizeof(mbi)) == 0) {
|
||||
break;
|
||||
}
|
||||
|
||||
// Usermode address space has such an unaligned region size always at the
|
||||
// end and only at the end.
|
||||
// Usermode address space has such an unaligned region size always at
|
||||
// the end and only at the end.
|
||||
if ((mbi.RegionSize & 0xfff) == 0xfff) {
|
||||
break;
|
||||
}
|
||||
if (((PBYTE)mbi.BaseAddress + mbi.RegionSize) < pbLast) {
|
||||
if (((PBYTE) mbi.BaseAddress + mbi.RegionSize) < pbLast) {
|
||||
break;
|
||||
}
|
||||
|
||||
@@ -846,8 +873,9 @@ static HMODULE enumerate_modules_in_process(HANDLE hProcess,
|
||||
continue;
|
||||
}
|
||||
|
||||
if (load_nt_header_from_process(hProcess, (HMODULE)pbLast, pNtHeader)) {
|
||||
return (HMODULE)pbLast;
|
||||
if (load_nt_header_from_process(
|
||||
hProcess, (HMODULE) pbLast, pNtHeader)) {
|
||||
return (HMODULE) pbLast;
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -2,7 +2,6 @@
|
||||
|
||||
#include <stdbool.h>
|
||||
|
||||
|
||||
/**
|
||||
* Initialize inject's logger backend.
|
||||
*
|
||||
@@ -14,7 +13,6 @@
|
||||
* disable.
|
||||
*/
|
||||
|
||||
|
||||
/**
|
||||
* Initialize the debugger.
|
||||
*
|
||||
@@ -58,7 +56,8 @@ bool debugger_inject_dll(const char *path_dll);
|
||||
* @param replacement_path_dll Name of dll to inject.
|
||||
* @return true if sucessful, false on error.
|
||||
*/
|
||||
bool debugger_replace_dll_iat(const char *expected_dll, const char *replacement_path_dll);
|
||||
bool debugger_replace_dll_iat(
|
||||
const char *expected_dll, const char *replacement_path_dll);
|
||||
|
||||
/**
|
||||
* Wait/block for a remote debugger to attach to the remote process.
|
||||
|
||||
@@ -15,11 +15,11 @@
|
||||
static FILE *log_file;
|
||||
static HANDLE log_mutex;
|
||||
|
||||
static const char* logger_get_formatted_timestamp(void)
|
||||
static const char *logger_get_formatted_timestamp(void)
|
||||
{
|
||||
static char buffer[64];
|
||||
time_t cur = 0;
|
||||
struct tm* tm = NULL;
|
||||
struct tm *tm = NULL;
|
||||
|
||||
cur = time(NULL);
|
||||
tm = localtime(&cur);
|
||||
@@ -94,7 +94,8 @@ static size_t logger_msg_coloring_len(const char *str)
|
||||
return 0;
|
||||
}
|
||||
|
||||
static void logger_console(void *ctx, const char *chars, size_t nchars, const char* timestamp_str)
|
||||
static void logger_console(
|
||||
void *ctx, const char *chars, size_t nchars, const char *timestamp_str)
|
||||
{
|
||||
char color;
|
||||
size_t color_len;
|
||||
@@ -128,10 +129,11 @@ static void logger_console(void *ctx, const char *chars, size_t nchars, const ch
|
||||
}
|
||||
}
|
||||
|
||||
static void logger_file(void *ctx, const char *chars, size_t nchars, const char* timestamp_str)
|
||||
static void logger_file(
|
||||
void *ctx, const char *chars, size_t nchars, const char *timestamp_str)
|
||||
{
|
||||
if (ctx) {
|
||||
fwrite(timestamp_str, 1, strlen(timestamp_str), (FILE*) ctx);
|
||||
fwrite(timestamp_str, 1, strlen(timestamp_str), (FILE *) ctx);
|
||||
fwrite(chars, 1, nchars, (FILE *) ctx);
|
||||
fflush((FILE *) ctx);
|
||||
}
|
||||
@@ -139,7 +141,7 @@ static void logger_file(void *ctx, const char *chars, size_t nchars, const char*
|
||||
|
||||
static void logger_writer(void *ctx, const char *chars, size_t nchars)
|
||||
{
|
||||
const char* timestamp_str;
|
||||
const char *timestamp_str;
|
||||
|
||||
// Different threads logging the same destination, e.g. debugger thread,
|
||||
// main thread
|
||||
|
||||
@@ -2,11 +2,11 @@
|
||||
|
||||
/**
|
||||
* Initialize inject's logger backend.
|
||||
*
|
||||
*
|
||||
* This takes care of hooking and merging the different log
|
||||
* streams, e.g. inject's local logging and inject's debugger
|
||||
* receiving remote logging events.
|
||||
*
|
||||
*
|
||||
* @param log_file_path Path to the file to log to or NULL to
|
||||
* disable.
|
||||
*/
|
||||
@@ -14,10 +14,10 @@ bool logger_init(const char *log_file_path);
|
||||
|
||||
/**
|
||||
* Write a message to the logging backend.
|
||||
*
|
||||
*
|
||||
* This is used by inject's debugger to redirect log messages
|
||||
* recevied from the remote process.
|
||||
*
|
||||
*
|
||||
* @param str String to log
|
||||
*/
|
||||
void logger_log(const char *str);
|
||||
|
||||
@@ -92,7 +92,8 @@ verify_hook_dlls_exist(int argc, char **argv, uint32_t hook_dll_count)
|
||||
|
||||
if (dll_path_length == 0) {
|
||||
log_warning(
|
||||
"ERROR: Hook DLL not found: %08x", (unsigned int) GetLastError());
|
||||
"ERROR: Hook DLL not found: %08x",
|
||||
(unsigned int) GetLastError());
|
||||
|
||||
return false;
|
||||
}
|
||||
@@ -114,7 +115,7 @@ static bool inject_iat_hook_dlls(uint32_t hooks, char **argv)
|
||||
continue;
|
||||
|
||||
*iat_hook = '\0';
|
||||
debugger_replace_dll_iat(argv[i + 1], iat_hook+1);
|
||||
debugger_replace_dll_iat(argv[i + 1], iat_hook + 1);
|
||||
*iat_hook = '=';
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user