| View previous topic :: View next topic |
| Author |
Message |
h4c0r-BG Master Cheater
Reputation: 0
Joined: 29 Nov 2006 Posts: 449 Location: The yogurt country
|
Posted: Wed Mar 11, 2009 3:34 pm Post subject: [Delphi] GetRetAddress in my hook? |
|
|
How can i obtain the address of the "caller" in my hooked function (in Delphi) ?
For example i have hook:
function MY_MessageBoxA(hWnd: HWND; lpText, lpCaption: PAnsiChar; uType: UINT): Integer; stdcall;
var
retaddr:cardinal;
begin
retaddr:=GetRetAddress();
result := NEXT_MessageBoxA(hwnd,lptext,lpcaption,utype);
end;
And in "retaddr" i will know who last called my hooked messagebox. _________________
|
|
| Back to top |
|
 |
smartz993 I post too much
Reputation: 2
Joined: 20 Jun 2006 Posts: 2013 Location: USA
|
Posted: Wed Mar 11, 2009 4:04 pm Post subject: |
|
|
| Code: | asm
mov retaddress,[ebp+4]
end;
|
There is much controversy over this topic. As Irwin pointed out, the _ReturnAddress intrinsic is pretty much the best way to do so..
However, Delphi doesn't have this intrinsic, so you must use inline asm.
(If you'd like the calling address, subtract 5, although you will be guessing that it is a normal call (5 bytes) and therefore risking.) |
|
| Back to top |
|
 |
Dark Byte Site Admin
Reputation: 475
Joined: 09 May 2003 Posts: 25980 Location: The netherlands
|
Posted: Wed Mar 11, 2009 4:15 pm Post subject: |
|
|
well, if you find assembler 'icky' you could use this completly legit delphi code without use of any assembler: (only work on call conventions that store the first param on the stack)
| Code: |
retaddress:=pdword(dword(@firstparameter)-4)^;
|
honestly, I prefer the assembler line. _________________
Tools give you results. Knowledge gives you control.
Like my help? Join me on Patreon so i can keep helping |
|
| Back to top |
|
 |
dnsi0 I post too much
Reputation: 0
Joined: 04 Jan 2007 Posts: 2674
|
Posted: Wed Mar 11, 2009 4:58 pm Post subject: |
|
|
nvm...
Last edited by dnsi0 on Wed Mar 11, 2009 6:40 pm; edited 1 time in total |
|
| Back to top |
|
 |
rapion124 Grandmaster Cheater Supreme
Reputation: 0
Joined: 25 Mar 2007 Posts: 1095
|
Posted: Wed Mar 11, 2009 5:25 pm Post subject: |
|
|
What I do is I have 1 extra parameter in my hook procedure.
This first hook will be declared with __declspec(naked) and looks like this when compiled:
| Code: |
push [esp] // return address
push [esp+10]
push [esp+0c]
push [esp+08]
push [esp+..] // push all the parameters of the original function
call realHook
jmp [dwTrampoline]
|
The real hook is declared with this prototype:
| Code: |
DWORD WINAPI _HookProc(regularParameters, ..., DWORD dwReturnAddress)
|
It's more work, but it's guaranteed to work.
The dwReturnAddress will hold the return address. |
|
| Back to top |
|
 |
Slugsnack Grandmaster Cheater Supreme
Reputation: 71
Joined: 24 Jan 2007 Posts: 1857
|
Posted: Wed Mar 11, 2009 5:46 pm Post subject: |
|
|
| he doesn't want return address, he wants caller address |
|
| Back to top |
|
 |
smartz993 I post too much
Reputation: 2
Joined: 20 Jun 2006 Posts: 2013 Location: USA
|
Posted: Wed Mar 11, 2009 6:01 pm Post subject: |
|
|
| Slugsnack wrote: | | he doesn't want return address, he wants caller address |
so subtract 5, but take a risk :] |
|
| Back to top |
|
 |
&Vage Grandmaster Cheater Supreme
Reputation: 0
Joined: 25 Jul 2008 Posts: 1053
|
Posted: Wed Mar 11, 2009 6:24 pm Post subject: |
|
|
| What do you mean subtract 5? |
|
| Back to top |
|
 |
smartz993 I post too much
Reputation: 2
Joined: 20 Jun 2006 Posts: 2013 Location: USA
|
Posted: Wed Mar 11, 2009 6:25 pm Post subject: |
|
|
| S3NS4 wrote: | | What do you mean subtract 5? |
Subtract 5 from the return address..? |
|
| Back to top |
|
 |
&Vage Grandmaster Cheater Supreme
Reputation: 0
Joined: 25 Jul 2008 Posts: 1053
|
Posted: Wed Mar 11, 2009 6:27 pm Post subject: |
|
|
mov eax,[ebp+4]
sub [eax],5
mov caller, [eax]
?? |
|
| Back to top |
|
 |
Slugsnack Grandmaster Cheater Supreme
Reputation: 71
Joined: 24 Jan 2007 Posts: 1857
|
Posted: Wed Mar 11, 2009 6:47 pm Post subject: |
|
|
sub [eax], 5 ?!?!?!
lern2asm plix |
|
| Back to top |
|
 |
Overload Master Cheater
Reputation: 0
Joined: 08 Feb 2008 Posts: 293
|
Posted: Wed Mar 11, 2009 6:49 pm Post subject: |
|
|
This is kind of a stupid question but how do you know to add an offset of 4 into ebp? How do you know which register to use and move it into which register?
 _________________
Blog
| Quote: | Rhys says:
you can be my maid
Rhys says:
ill buy you a french maid outfit
Tyler says:
Sounds good
Rhys says:
ill hold you to that |
|
|
| Back to top |
|
 |
Dark Byte Site Admin
Reputation: 475
Joined: 09 May 2003 Posts: 25980 Location: The netherlands
|
Posted: Wed Mar 11, 2009 6:55 pm Post subject: |
|
|
Keep in mind that
| Code: |
push param
mov eax,[ecx+xxx]
call eax
|
is an often used mechanism in object oriented programming. so it isn't 5 bytes.
I'd say: Add in a disassembler and use that to find out the previous opcode.
BUT, keep in mind, there are some asshole coders that do:
| Code: |
push [param2]
push [param1]
push lol
jmp routine
...randomgarbage...
lol:
handle result
|
_________________
Tools give you results. Knowledge gives you control.
Like my help? Join me on Patreon so i can keep helping |
|
| Back to top |
|
 |
smartz993 I post too much
Reputation: 2
Joined: 20 Jun 2006 Posts: 2013 Location: USA
|
Posted: Wed Mar 11, 2009 6:58 pm Post subject: |
|
|
| S3NS4 wrote: | mov eax,[ebp+4]
sub [eax],5
mov caller, [eax]
?? |
looooooooool
you're already storing the value in eax, so doing [eax] (since eax is actually holding the value which is an address) will get the value stored at the address..you want to subtract 5 from eax by itself, not the value stored. (actually, that would change the instruction after the call lmfao) |
|
| Back to top |
|
 |
dnsi0 I post too much
Reputation: 0
Joined: 04 Jan 2007 Posts: 2674
|
Posted: Wed Mar 11, 2009 7:16 pm Post subject: |
|
|
| S3NS4 wrote: | mov eax,[ebp+4]
sub [eax],5
mov caller, [eax]
?? |
its actually like this:
| Code: | push eax
mov eax,[ebp+4]
sub eax,5
mov caller, eax
pop eax |
|
|
| Back to top |
|
 |
|