Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


[Delphi] GetRetAddress in my hook?
Goto page 1, 2  Next
 
Post new topic   Reply to topic    Cheat Engine Forum Index -> General programming
View previous topic :: View next topic  
Author Message
h4c0r-BG
Master Cheater
Reputation: 0

Joined: 29 Nov 2006
Posts: 449
Location: The yogurt country

PostPosted: Wed Mar 11, 2009 3:34 pm    Post subject: [Delphi] GetRetAddress in my hook? Reply with quote

How can i obtain the address of the "caller" in my hooked function (in Delphi) ?

For example i have hook:

function MY_MessageBoxA(hWnd: HWND; lpText, lpCaption: PAnsiChar; uType: UINT): Integer; stdcall;
var
retaddr:cardinal;
begin
retaddr:=GetRetAddress();
result := NEXT_MessageBoxA(hwnd,lptext,lpcaption,utype);
end;

And in "retaddr" i will know who last called my hooked messagebox.

_________________

Back to top
View user's profile Send private message
smartz993
I post too much
Reputation: 2

Joined: 20 Jun 2006
Posts: 2013
Location: USA

PostPosted: Wed Mar 11, 2009 4:04 pm    Post subject: Reply with quote

Code:
asm
mov retaddress,[ebp+4]
end;


There is much controversy over this topic. As Irwin pointed out, the _ReturnAddress intrinsic is pretty much the best way to do so..

However, Delphi doesn't have this intrinsic, so you must use inline asm.

(If you'd like the calling address, subtract 5, although you will be guessing that it is a normal call (5 bytes) and therefore risking.)
Back to top
View user's profile Send private message
Dark Byte
Site Admin
Reputation: 475

Joined: 09 May 2003
Posts: 25980
Location: The netherlands

PostPosted: Wed Mar 11, 2009 4:15 pm    Post subject: Reply with quote

well, if you find assembler 'icky' you could use this completly legit delphi code without use of any assembler: (only work on call conventions that store the first param on the stack)
Code:

retaddress:=pdword(dword(@firstparameter)-4)^;


honestly, I prefer the assembler line.

_________________
Tools give you results. Knowledge gives you control.

Like my help? Join me on Patreon so i can keep helping
Back to top
View user's profile Send private message MSN Messenger
dnsi0
I post too much
Reputation: 0

Joined: 04 Jan 2007
Posts: 2674

PostPosted: Wed Mar 11, 2009 4:58 pm    Post subject: Reply with quote

nvm...

Last edited by dnsi0 on Wed Mar 11, 2009 6:40 pm; edited 1 time in total
Back to top
View user's profile Send private message
rapion124
Grandmaster Cheater Supreme
Reputation: 0

Joined: 25 Mar 2007
Posts: 1095

PostPosted: Wed Mar 11, 2009 5:25 pm    Post subject: Reply with quote

What I do is I have 1 extra parameter in my hook procedure.

This first hook will be declared with __declspec(naked) and looks like this when compiled:
Code:

push [esp] // return address
push [esp+10]
push [esp+0c]
push [esp+08]
push [esp+..] // push all the parameters of the original function
call realHook
jmp [dwTrampoline]


The real hook is declared with this prototype:
Code:

DWORD WINAPI _HookProc(regularParameters, ..., DWORD dwReturnAddress)


It's more work, but it's guaranteed to work.

The dwReturnAddress will hold the return address.
Back to top
View user's profile Send private message
Slugsnack
Grandmaster Cheater Supreme
Reputation: 71

Joined: 24 Jan 2007
Posts: 1857

PostPosted: Wed Mar 11, 2009 5:46 pm    Post subject: Reply with quote

he doesn't want return address, he wants caller address
Back to top
View user's profile Send private message
smartz993
I post too much
Reputation: 2

Joined: 20 Jun 2006
Posts: 2013
Location: USA

PostPosted: Wed Mar 11, 2009 6:01 pm    Post subject: Reply with quote

Slugsnack wrote:
he doesn't want return address, he wants caller address



so subtract 5, but take a risk :]
Back to top
View user's profile Send private message
&Vage
Grandmaster Cheater Supreme
Reputation: 0

Joined: 25 Jul 2008
Posts: 1053

PostPosted: Wed Mar 11, 2009 6:24 pm    Post subject: Reply with quote

What do you mean subtract 5?
Back to top
View user's profile Send private message
smartz993
I post too much
Reputation: 2

Joined: 20 Jun 2006
Posts: 2013
Location: USA

PostPosted: Wed Mar 11, 2009 6:25 pm    Post subject: Reply with quote

S3NS4 wrote:
What do you mean subtract 5?


Subtract 5 from the return address..?
Back to top
View user's profile Send private message
&Vage
Grandmaster Cheater Supreme
Reputation: 0

Joined: 25 Jul 2008
Posts: 1053

PostPosted: Wed Mar 11, 2009 6:27 pm    Post subject: Reply with quote

mov eax,[ebp+4]
sub [eax],5
mov caller, [eax]

??
Back to top
View user's profile Send private message
Slugsnack
Grandmaster Cheater Supreme
Reputation: 71

Joined: 24 Jan 2007
Posts: 1857

PostPosted: Wed Mar 11, 2009 6:47 pm    Post subject: Reply with quote

sub [eax], 5 ?!?!?!

lern2asm plix
Back to top
View user's profile Send private message
Overload
Master Cheater
Reputation: 0

Joined: 08 Feb 2008
Posts: 293

PostPosted: Wed Mar 11, 2009 6:49 pm    Post subject: Reply with quote

This is kind of a stupid question but how do you know to add an offset of 4 into ebp? How do you know which register to use and move it into which register?

Embarassed

_________________
Blog

Quote:
Rhys says:
you can be my maid
Rhys says:
ill buy you a french maid outfit
Tyler says:
Sounds good
Rhys says:
ill hold you to that
Back to top
View user's profile Send private message MSN Messenger
Dark Byte
Site Admin
Reputation: 475

Joined: 09 May 2003
Posts: 25980
Location: The netherlands

PostPosted: Wed Mar 11, 2009 6:55 pm    Post subject: Reply with quote

Keep in mind that
Code:

push param
mov eax,[ecx+xxx]
call eax

is an often used mechanism in object oriented programming. so it isn't 5 bytes.

I'd say: Add in a disassembler and use that to find out the previous opcode.

BUT, keep in mind, there are some asshole coders that do:
Code:

push [param2]
push [param1]
push lol
jmp routine
...randomgarbage...
lol:
handle result


_________________
Tools give you results. Knowledge gives you control.

Like my help? Join me on Patreon so i can keep helping
Back to top
View user's profile Send private message MSN Messenger
smartz993
I post too much
Reputation: 2

Joined: 20 Jun 2006
Posts: 2013
Location: USA

PostPosted: Wed Mar 11, 2009 6:58 pm    Post subject: Reply with quote

S3NS4 wrote:
mov eax,[ebp+4]
sub [eax],5
mov caller, [eax]

??


looooooooool

you're already storing the value in eax, so doing [eax] (since eax is actually holding the value which is an address) will get the value stored at the address..you want to subtract 5 from eax by itself, not the value stored. (actually, that would change the instruction after the call lmfao)
Back to top
View user's profile Send private message
dnsi0
I post too much
Reputation: 0

Joined: 04 Jan 2007
Posts: 2674

PostPosted: Wed Mar 11, 2009 7:16 pm    Post subject: Reply with quote

S3NS4 wrote:
mov eax,[ebp+4]
sub [eax],5
mov caller, [eax]

??


its actually like this:
Code:
push eax
mov eax,[ebp+4]
sub eax,5
mov caller, eax
pop eax
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> General programming All times are GMT - 6 Hours
Goto page 1, 2  Next
Page 1 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites