【问题标题】:64bit ReadProcessMemory access denied64 位 ReadProcessMemory 访问被拒绝
【发布时间】:2016-07-02 12:48:40
【问题描述】:

我试过用Process.EnterDebugMode() 运行它,但它也不起作用。

我想读出Notepad-memory,但不知道如何访问,或者64位系统是否出现问题。

这就是我所做的:

using System;
using System.Diagnostics;
using System.Runtime.InteropServices;
using System.Text;

public class MemoryRead
{

    [DllImport("kernel32.dll")]
    static extern IntPtr OpenProcess(int dwDesiredAccess, bool bInheritHandle, int dwProcessId);

    [DllImport("kernel32.dll")]
    static extern bool ReadProcessMemory(int hProcess, Int64 lpBaseAddress, byte[] buffer, int size, ref int lpNumberOfBytesRead);

    [DllImport("kernel32.dll")]
    static extern bool CloseHandle(IntPtr hObject);

    static void Main(string[] args)
    {
        var pid = 10956; //notepad.exe
        var processHandle = OpenProcess(0x10, false, pid);

        byte[] buffer = new byte[24];
        int bytesRead = 0;
        ReadProcessMemory((int)processHandle, 0x21106B35770, buffer, buffer.Length, ref bytesRead); //0x21106B35770 is the address where "hello world" is written in notepad

        Console.WriteLine(Encoding.Unicode.GetString(buffer) +
           " (" + bytesRead.ToString() + "bytes)");
        Console.ReadLine();
        CloseHandle(processHandle);

        Console.ReadLine();
    }
}

【问题讨论】:

  • 以管理员身份运行您的应用程序
  • 我认为你应该将它作为 x86 运行。我以前做过,不需要管理员权限
  • 您可以在 www.pinvoke.net 中获取方法的 Pinvoke 声明

标签: c# access-denied readprocessmemory


【解决方案1】:

ReadProcessMemory 的 PInvoke 声明不正确(尽管它应该在 32 位系统上工作)。

从这个函数的原生声明可以看出

BOOL WINAPI ReadProcessMemory(
  _In_  HANDLE  hProcess,
  _In_  LPCVOID lpBaseAddress,
  _Out_ LPVOID  lpBuffer,
  _In_  SIZE_T  nSize,
  _Out_ SIZE_T  *lpNumberOfBytesRead
);

它的第一个参数是HANDLE,而it is是PVOID:

指向任何类型的指针。

此类型在 WinNT.h 中声明如下:

typedef void *PVOID;

指向 64 位进程中任何内容的指针是 64 位值 - IntPtr。

size 和 lpNumberOfBytesRead 参数基本相同 - 它们在 64 位进程中也是 64 位。

因此你的声明应该是这样的:

[[DllImport("kernel32.dll", SetLastError = true)]]
[return: MarshalAs(UnmanagedType.Bool)]
static extern Boolean ReadProcessMemory(
  [In]  IntPtr  hProcess,
  [In]  IntPtr lpBaseAddress,
  [Out] Byte[] lpBuffer,
  [In]  UIntPtr  nSize,
  [Out] out UIntPtr lpNumberOfBytesRead
);

P.S.:还有一点无耻的自我推销——如果你不得不经常使用 PInvoke,那么有一个 few good recommendations 我已经学会了一个艰难的方法。

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 2014-08-10
    • 1970-01-01
    • 2021-03-06
    • 2011-05-15
    • 2010-09-06
    • 2014-03-22
    • 2013-08-10
    相关资源
    最近更新 更多