【发布时间】:2020-04-20 10:31:34
【问题描述】:
我正在使用 CreateRemoteThread 将 dll 注入到目标进程中,它运行良好,目前它需要参数:
inject(string procName, string dllPath);
并读取 dllPath 到字节数组:
byte[] bytes = Encoding.ASCII.GetBytes(dllPath);
我想跳过这个过程,直接给它一个字节数组,因为我从我的服务器上下载了加密的字节。请注意,我的目标平台是 x64,这就是我不使用 jLibrary 的原因。
如果我去: byte[] bytes = File.ReadAllBytes(someFile) 来测试它,注入失败所以我尝试将 byte[] 从我现有的文件转换为 char[] 然后将其编码为 ascii 但它也失败了。我该怎么做呢?
班级是:
bool injectionDLL(uint processToInject, string dllPath) {
IntPtr processHandle = OpenProcess(desiredAccess, 1, processToInject);
if (processHandle == INTPTR_ZERO) return false;
IntPtr loadLibraryAddress = GetProcAddress(GetModuleHandle("kernel32.dll"), "LoadLibraryA");
if (loadLibraryAddress == INTPTR_ZERO) return false;
IntPtr argAddress = VirtualAllocEx(processHandle, (IntPtr)null, (IntPtr)dllPath.Length, (0x1000 | 0x2000), 0X40);
if (argAddress == INTPTR_ZERO) return false;
byte[] bytes = Encoding.ASCII.GetBytes(dllPath);
if (WriteProcessMemory(processHandle, argAddress, bytes, (uint)bytes.Length, 0) == 0)
return false;
if (CreateRemoteThread(processHandle, (IntPtr)null, INTPTR_ZERO, loadLibraryAddress, argAddress, 0, (IntPtr)null) == INTPTR_ZERO)
{
return false;
}
CloseHandle(processHandle);
return true;
}
【问题讨论】:
-
哪里出错了?您是否在任一过程中都遇到错误?你在这些 if 分支中返回 false 吗?
-
@Glubus 我没有收到任何错误,注入“成功”但是 dll 没有正确映射到进程上。该 DLL 旨在在目标进程中显示文本,但它没有这样做
-
不确定这是否是问题,但 Windows API 中的路径是 Unicode。真正的 Windows API 是以 W 结尾的函数; A 是 Windows 95 的拐杖。因此,如果您需要字节而不是字符串中的文本,我建议您切换到 W 函数并使用 Encoding.Unicode (UTF-16)。
标签: c#