【问题标题】:C# Using byte[] directly in CreateRemoteThread and LoadLibrary injectionC# 在 CreateRemoteThread 和 LoadLibrary 注入中直接使用 byte[]
【发布时间】:2020-04-20 10:31:34
【问题描述】:

我正在使用 CreateRemoteThread 将 dll 注入到目标进程中,它运行良好,目前它需要参数:

inject(string procName, string dllPath);

并读取 dllPath 到字节数组:

byte[] bytes = Encoding.ASCII.GetBytes(dllPath);

我想跳过这个过程,直接给它一个字节数组,因为我从我的服务器上下载了加密的字节。请注意,我的目标平台是 x64,这就是我不使用 jLibrary 的原因。

如果我去: byte[] bytes = File.ReadAllBytes(someFile) 来测试它,注入失败所以我尝试将 byte[] 从我现有的文件转换为 char[] 然后将其编码为 ascii 但它也失败了。我该怎么做呢?

班级是:

bool injectionDLL(uint processToInject, string dllPath) {

        IntPtr processHandle = OpenProcess(desiredAccess, 1, processToInject);

        if (processHandle == INTPTR_ZERO) return false;

        IntPtr loadLibraryAddress = GetProcAddress(GetModuleHandle("kernel32.dll"), "LoadLibraryA");

        if (loadLibraryAddress == INTPTR_ZERO) return false;

        IntPtr argAddress = VirtualAllocEx(processHandle, (IntPtr)null, (IntPtr)dllPath.Length, (0x1000 | 0x2000), 0X40);

        if (argAddress == INTPTR_ZERO) return false;

        byte[] bytes = Encoding.ASCII.GetBytes(dllPath);

        if (WriteProcessMemory(processHandle, argAddress, bytes, (uint)bytes.Length, 0) == 0)
            return false;

        if (CreateRemoteThread(processHandle, (IntPtr)null, INTPTR_ZERO, loadLibraryAddress, argAddress, 0, (IntPtr)null) == INTPTR_ZERO)
        {
            return false;
        }

        CloseHandle(processHandle);
        return true;
    }

【问题讨论】:

  • 哪里出错了?您是否在任一过程中都遇到错误?你在这些 if 分支中返回 false 吗?
  • @Glubus 我没有收到任何错误,注入“成功”但是 dll 没有正确映射到进程上。该 DLL 旨在在目标进程中显示文本,但它没有这样做
  • 不确定这是否是问题,但 Windows API 中的路径是 Unicode。真正的 Windows API 是以 W 结尾的函数; A 是 Windows 95 的拐杖。因此,如果您需要字节而不是字符串中的文本,我建议您切换到 W 函数并使用 Encoding.Unicode (UTF-16)。

标签: c#


【解决方案1】:

不必将字符串转换为字节数组。

只需使用 string::ToCharArray()

IntPtr bytesRead = IntPtr.Zero;
WriteProcessMemory(proc.Handle, loc, dllpath.ToCharArray(), dllpath.Length, out bytesRead);

【讨论】:

    猜你喜欢
    • 2014-05-10
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2011-09-28
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多