-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathinjection.cpp
More file actions
151 lines (119 loc) · 4.01 KB
/
injection.cpp
File metadata and controls
151 lines (119 loc) · 4.01 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
// injection.cpp : 定义应用程序的入口点。
//
#include "framework.h"
#include "injection.h"
#include "shlobj_core.h"
#include <stdlib.h>
INT_PTR CALLBACK Injection(HWND hDlg, UINT message, WPARAM wParam, LPARAM lParam);
BOOL GetFileFullPath(HWND hDlg);
BOOL InjectionDll(DWORD ProcessId, CONST CHAR DllAddressStr[MAX_PATH]);
int APIENTRY wWinMain(_In_ HINSTANCE hInstance,
_In_opt_ HINSTANCE hPrevInstance,
_In_ LPWSTR lpCmdLine,
_In_ int nCmdShow)
{
DialogBox(hInstance, MAKEINTRESOURCE(IDD_MAIN), NULL, Injection);
return TRUE;
}
INT_PTR CALLBACK Injection(HWND hDlg, UINT message, WPARAM wParam, LPARAM lParam)
{
switch (message)
{
case WM_INITDIALOG:
SetDlgItemTextA(hDlg, IDC_EDIT_FILEPATH, "path");
SetDlgItemTextA(hDlg, IDC_EDIT_PID, "pid");
return (INT_PTR)TRUE;
case WM_COMMAND:
if (LOWORD(wParam) == IDOK || LOWORD(wParam) == IDCANCEL)
{
EndDialog(hDlg, LOWORD(wParam));
return (INT_PTR)TRUE;
}
// IDC_BUTTON_SELECT 打开文件_按钮
if (LOWORD(wParam) == IDC_BUTTON_SELECT)
{
if (GetFileFullPath(hDlg))
{
return (INT_PTR)TRUE;
}
}
// IDC_BUTTON_INJECTION 注入_按钮
if (LOWORD(wParam) == IDC_BUTTON_INJECTION)
{
CHAR FilePath[MAX_PATH] = { NULL };
// DWORD 4字节
CHAR ProcessIdStr[0x10] = { NULL };
GetDlgItemTextA(hDlg, IDC_EDIT_FILEPATH, FilePath, MAX_PATH);
GetDlgItemTextA(hDlg, IDC_EDIT_PID, (LPSTR)ProcessIdStr, sizeof(ProcessIdStr));
// 字符串转DWORD
DWORD ProcessId = atol(ProcessIdStr);
// 注入
if (!InjectionDll(ProcessId, FilePath))
{
MessageBoxA(hDlg, "注入失败!", "注入失败!", MB_OK);
break;
}
MessageBoxA(hDlg, "注入成功!", "注入成功!", MB_OK);
return (INT_PTR)TRUE;
}
break;
}
return (INT_PTR)FALSE;
}
BOOL InjectionDll(DWORD ProcessId, CONST CHAR DllAddressStr[MAX_PATH])
{
// 打开句柄
HANDLE hProcess = OpenProcess(PROCESS_ALL_ACCESS, FALSE, ProcessId);
// 申请虚拟内存存放DLL地址
/*CHAR DllAddressStr[MAX_PATH] = { "E://code//cpp//Visual Studio//EntryDll//x64//Debug//EntryDll.dll" };*/
LPVOID dllAddress = VirtualAllocEx(hProcess, NULL, strlen(DllAddressStr), MEM_COMMIT, PAGE_READWRITE);
if (!dllAddress)
{
return FALSE;
}
// DLL写入目标进程内存
if (!WriteProcessMemory(hProcess, dllAddress, DllAddressStr, strlen(DllAddressStr), NULL))
{
return FALSE;
}
// 创建远程线程执行dll
// 每个程序都会包含Kernel32.dll,所以使用Kernel32.dll执行LoadLibraryA函数加载目标DLL
HMODULE hKernel32 = GetModuleHandle(L"Kernel32.dll");
if (!hKernel32)
{
return FALSE;
}
LPCVOID kernalAddress = GetProcAddress(hKernel32, "LoadLibraryA");
if (!kernalAddress)
{
return FALSE;
}
// 创建远程线程加载DLL
if (CreateRemoteThread(hProcess, NULL, 0, (LPTHREAD_START_ROUTINE)kernalAddress, dllAddress, 0, NULL))
{
return TRUE;
}
return FALSE;
}
/*
使用SHBrowseForFolderA查询文件
*/
BOOL GetFileFullPath(HWND hDlg)
{
TCHAR szTitle[MAX_PATH] = { 0 };
TCHAR szPath[MAX_PATH] = { 0 };
TCHAR szDisplay[MAX_PATH] = { 0 };
BROWSEINFOA lpbi;
lpbi.hwndOwner = NULL;
lpbi.pidlRoot = NULL;
lpbi.pszDisplayName = (LPSTR)szDisplay;
lpbi.lpszTitle = (LPSTR)szTitle;
lpbi.ulFlags = BIF_BROWSEINCLUDEFILES;
lpbi.iImage = IDR_MAINFRAME;
lpbi.lpfn = NULL;
lpbi.lParam = 0;
LPITEMIDLIST Lpi = SHBrowseForFolderA(&lpbi);
SHGetPathFromIDListA(Lpi, (LPSTR)szPath);
SetDlgItemTextA(hDlg, IDC_EDIT_FILEPATH, (LPCSTR)szPath);;
return TRUE;
}