الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

كيفية استخدام دالتي LoadLibraryA وGetProcAddress

مغلق
بدأه allko في 9 مارس 2006 · 10 رد · 957 مشاهدة · في لغة Assembly لأنظمة 16, 32, 64 بت
مشاركة: واتساب X فيسبوك تيليجرام
#1 صاحب الموضوع

السلام عليكم

اريد ان اعرف كيفية استخدام دالتي

LoadLibraryA & GetProcAddress

لاستدعاء دالة

MassegeBoxA

مع العلم ان LoadLibraryA موجودة عند 4000489E

و GetProcAddress موجودة عند 400048AE

و MassegeBoxA موجودة عند 40006AC0

(اقصد بكلمة "موجودة" اي ان الـ string الخاص باسم الدالة مكتوب عند ذلك العنوان)

على فكرة انا قبل ما احط الموضوع بحثت ولقيت الموضوع هادا

هنـــــــــــا

هوا كويس بس لسا محتاج توضيح اكتر...

وللعلم اكتر ، ما قمت به هو اضافة الدالتين LoadLibraryA و GetProcAddress

الى الـ Import Table الخاص بالبرنامج والان اريد استخدامهما لاستدعاء MassegeBoxA

قبل بدء البرنامج وذلك بوضع الكود في cave ثم تغيير مسار الـ code الى المسج ومن ثم اعادته الى

ما كان عليه. كنت ارغب بجعل المسج مرتبطة بالضغط على زر ااقوم بانشائه لكن واجهتني بعض المشاكل

فقررت تبسيط العملية بجعل المسج غير مرتبطة بزر ما.

btw , MR.moderator , this thread does not belong to the API forum so
DON'T MOVE IT , PlZ !!.

تم تعديل هذه المشاركة بواسطة allko في 9 مارس 2006 في 15:09

#2

هل هو كذا؟

push  (addr of  LoadLibraryA's string)
call   LoadLibraryA
push  (addr of MassegeBoxA's string)
call   GetProcAddress

push  parameter1
push  parameter2
push  parameter3
push  parameter4

call   MassegeBoxA
#3
push  (library name string, kernel32.dll)
call   LoadLibraryA
push  (addr of MassegeBoxA's string)
push  eax                              ; <<<<<<<<<<<<<<< handle of kernel32
call   GetProcAddress

push  parameter1
push  parameter2
push  parameter3
push  parameter4

call   eax              ; <<<<<<<<<<<<<<<< addr of MessageBox

تم تعديل هذه المشاركة بواسطة Xacker في 9 مارس 2006 في 18:22

Do as I say, not as I do

We are Anonymous. We are Legion. We don't forgive. We don't forget

#4

thx , i'll try and then reply

#5

i changed the flow of the code to a cave in which i injected the code,

then i traced the program (with F8) and when it reached the call to my injected

code it just "dissapeared" and i could see this in the buttom of the program:

09dp.jpg

here is my injected code :

17ia1.jpg

so what's going on there?

تم تعديل هذه المشاركة بواسطة allko في 17 مارس 2006 في 01:22

#6

make sure the section characteristics are set to: Executable as code / Readable / Writeable (if your codes tries to save some bytes in that section)

using a hexeditor perhaps like the one and the only :P LordPE :)

Do as I say, not as I do

We are Anonymous. We are Legion. We don't forgive. We don't forget

#7

uh one more thing i can think of ali, you say that your injected code is executed thru a CALL right? well, you must use the RET instruction to exit that CALL so you will have to PUSHAD all the registers values once you hit into the CALL and you should POPAD em so you dont mess the code flow, then you use RET to go back to the main procedure.

one more thing, i can't see the function name in 40320a, and the function name is case sensitive, so watch out, calling EAX without having anything valid to call may lead into a crash, trace into the CALL to see whats going on for real.

peace

Do as I say, not as I do

We are Anonymous. We are Legion. We don't forgive. We don't forget

#8
اقتباس
make sure the section characteristics are set to: Executable as code / Readable / Writeable

كنت اظن ان Writeable تكفي...حسنا لا باس...

اقتباس
you will have to PUSHAD all the registers values once you hit into the CALL and you should POPAD em

كنت قد حفظت قيمة EBP و ESP فقط (وذلك من خلال stack-frame) لكن لا مشكلة ساستخدم pushad , popad لحفظ جميع المسجلات.

ايضا غيرت طريقة تغيير مجرى البرنامج...استخدمت الـ jumps بدلا من call then return اعتقد ان هذا افضل.(عالاقل في هذه الحالة)

اقتباس
i can't see the function name in 40320a

الـ string لاسم الدالة كالتالي :

MassegeBoxA.

اول صفرين هو الـ hint وقيمته صفر. اعتقد ان عنوان RVA لاسم الدالة يبدا من الـ hint وليس من اول حرف (اي حرف M )

عموما لقد غيرته...وظهرت كلمة MassegeBoxA ...

لكن بعد تنفيذ امر GetProcAddress

الاحظ ان eax=00000000 فما الخطا ؟؟؟

17_03_06_01_53_18_1142632398_x.JPG

عموما في المرفقات يوجد نسختين من البرنامج الاولى patched وهي قبل اضافة الـ injected code والاخرى اسمها reversed بعد الاضافة.

(افضل ان تكون الكتابة هنا باللغة العربية ، لا لشيئ ولكن لان المنتدى عربي "الفريق العربي للبرمجة" B) )

0x.rar

#9

الـ hint تستخدمها فقط في الـ IT عند بناء جدول RVAs. عند استخدامها في تعلمة GetProcAddress لازم تشير الى اول حرف وان يكون اسم الوظيفة متل ما قلت متل ما هو لانه حساس بحالة الاحرف.

باي حال, نظرت الى الملفات المرفقة, ثم نظرت الى الصورة.. فانتبهت الى الخطا الذي جعلك تحصل على القيمة 0 بعد تنفيذ GetProcAddress.. انتبه الى الخطا سهوا في كتابة MassegeBoxA بدلا من MessageBoxA !

ايضا, اخطات انا ايضا عندما اكدت على ما كتبته في الكود في مشاركتي الاولى :P

MessageBoxA موجودة في user32.dll وليس في kernel32.dll فلا تواخذني لاني لم انتبه الى ما كتبت.

الان اجر تعديلات لتصبح:

004031FF   > \60                    PUSHAD
00403200   .  68 80484000           PUSH reversed.00404880                             ; /FileName = "USER32.dll"
00403205   .  E8 0353A477           CALL kernel32.LoadLibraryA                         ; \LoadLibraryA
0040320A   .  68 B9504000           PUSH reversed.004050B9                             ; /ProcNameOrOrdinal = "MessageBoxA"
0040320F   .  50                    PUSH EAX                                           ; |hModule = 0012FFE0
00403210   .  E8 E6FBA377           CALL kernel32.GetProcAddress                       ; \GetProcAddress
00403215   .  6A 00                 PUSH 0
00403217   .  68 606A4000           PUSH reversed.00406A60                             ;  ASCII ".:|ReverseengineerinG|:. "
0040321C   .  68 806A4000           PUSH reversed.00406A80                             ;  ASCII "reversed by : allko"
00403221   .  6A 00                 PUSH 0
00403223   .  FFD0                  CALL EAX
00403225   .  61                    POPAD
00403226   .  90                    NOP
00403227   .^ E9 9AFDFFFF           JMP reversed.00402FC6

ولا تنسى ان استخدام Call LoadLibraryA سيؤدي الى استخدام العنوان الذي يزود به نظامك حاليا والخاص بهذه الوظيفة, بمعنى انه سيختلف عندما تقوم بالفرمته او ان استخدمت انا الملف الذي قمت بتعديله لانه سيظهر كبايتات عشوائية فقط.

Do as I say, not as I do

We are Anonymous. We are Legion. We don't forgive. We don't forget

#10

!!! IT WORKS

:D :D :D

لك كل الشكر يا استاذ xacker

الان انتهت المهمة الصغرى...سابدا بمحاولة عمل زر مرتبط مع هذه المسج...

شكرا مرة اخرى

#11

you can do it, goodluck with it, and with your electronics exam ;)

Do as I say, not as I do

We are Anonymous. We are Legion. We don't forgive. We don't forget

هذا الموضوع مغلق.

مواضيع مشابهة