【问题标题】:Using ReadProcessMemory with process module base address and offsets使用带有进程模块基地址和偏移量的 ReadProcessMemory
【发布时间】:2017-05-19 07:44:45
【问题描述】:

如何使用进程模块的基地址和偏移量来读取内存?我已经使用以下内容获取了所需模块的基地址:

        Process process = Process.GetProcessesByName("process")[0];
        ProcessModule bClient;
        ProcessModuleCollection bModules = process.Modules;
        IntPtr processHandle = OpenProcess(0x10, false, process.Id);
        int firstOffset = 0xA4C58C;
        int anotherOffset = 0xFC;

        for (int i = 0; i < bModules.Count; i++)
        {
            bClient = bModules[i];
            if (bClient.ModuleName == "module.dll")
            {
                IntPtr baseAddress = bClient.BaseAddress;
                Console.WriteLine("Base address: " + baseAddress);
            }
        }

之后我将第一个偏移量添加到基地址:

IntPtr firstPointer = IntPtr.Add(baseAddress, (int)firstOffset);

这给了我一个指针;在这种情况下为 440911244。

例如,我可以在作弊引擎中使用此指针来浏览其内存区域并找到anotherPointer 指向的值,但我找不到将偏移量添加到firstPointer 的正确方法,但是。

我的问题是,在将最终的anotherOffset 添加到指针之前,我是否必须使用 ReadProcessMemory?如果是这样,在这种情况下使用它的正确方法是什么?

[DllImport("kernel32.dll", SetLastError = true)]
static extern bool ReadProcessMemory(
IntPtr hProcess, 
IntPtr lpBaseAddress,
IntPtr lpBuffer, 
int dwSize, 
out IntPtr lpNumberOfBytesRead);

【问题讨论】:

  • 什么是“anotherOffset”?你希望从进程的内存中读取什么?
  • @KrzysztofBracha firstOffset 指向特定的内存区域,并且在其中 anotherOffset 指向我需要读取的“浮点数”。

标签: c# pointers memory process memory-address


【解决方案1】:

将 ReadProcessMemory lpBuffer 参数更改为:

byte[] lpBuffer,

然后

byte[] buffer = new byte[sizeof(float)];
IntPtr bytesRead = IntPtr.Zero;

IntPtr readAddress = IntPtr.Add(baseAddress, firstOffset);
readAddress = IntPtr.Add(readAddress, anotherOffset)

ReadProcessMemory(processHandle, readAddress, buffer, buffer.Length, out bytesRead);

float value = BitConverter.ToSingle(buffer, 0);

【讨论】:

  • 感谢您的回答。我认为它不起作用。只是将偏移量添加到基地址似乎指向错误的位置。是否可以将 int 类型的偏移量(十六进制)添加到基地址?编辑:似乎只向基数添加一个偏移量(firstOffset)并读取内存会给出正确的“临时地址”。从那里我需要进一步去 0xFC 找到最终的浮动。
  • 我已经更新了答案,为错误道歉。
猜你喜欢
  • 1970-01-01
  • 2020-02-24
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多