Witam,
chciałbym zrobic hooka (tak to sie chyba nazywa) na funkcje
konkrety, chodzi o tibie 8.50
[code]Tibia 8.50
Found intermodular calls, item 797
Address=00576147
Disassembly=CALL DWORD PTR DS:[<&WS2_32.#16>]
Destination=WS2_32.recv[/code]
nie wiem czy to sie komukolwiek przyda, ale jesli juz pisac temat, to sadze, ze powinno dawac sie wszystkie potrzebne linki,
client gry: http://download.tibia.com/tibia850.exe
ollydbg http://www.ollydbg.de/odbg110.zip <font size="1">[link na stronie http://www.ollydbg.de/download.htm]</span>
przy pomocy olledbg znalazlem adres wskaznika na funkcje recv
ale teraz nie mam pojecia co zrobic dalej
mam taki source programu
#include <windows.h>
#include <iostream>
//#include "inject.h"
typedef int (WINAPI *SENDPACKET)(DWORD, char*, BOOL, BOOL);
class client
{
public:
HWND handle;
DWORD pid;
HINSTANCE hLib;
SENDPACKET SendPacket;
client()
{
SendPacket = NULL;
handle=FindWindow("TibiaClient", 0);
GetWindowThreadProcessId(handle, &pid);
hLib = LoadLibrary("packet850.dll");
SendPacket = (SENDPACKET)GetProcAddress(hLib, "SendPacket");
}
void client::sendpacket()
{
char Packet[3];
Packet[0]=0x01;
Packet[1]=0x00;
Packet[2]=0x65;
SendPacket(pid, Packet, 1, 0);
}
client::~client()
{
if(hLib)
FreeLibrary(hLib);
}
};
/* Declare Windows procedure */
LRESULT CALLBACK WindowProcedure (HWND, UINT, WPARAM, LPARAM);
/* Make the class name into a global variable */
char szClassName[ ] = "WindowsApp";
client *cln;
int WINAPI WinMain (HINSTANCE hThisInstance,
HINSTANCE hPrevInstance,
LPSTR lpszArgument,
int nFunsterStil)
{
HWND hwnd; /* This is the handle for our window */
MSG messages; /* Here messages to the application are saved */
WNDCLASSEX wincl; /* Data structure for the windowclass */
/* The Window structure */
wincl.hInstance = hThisInstance;
wincl.lpszClassName = szClassName;
wincl.lpfnWndProc = WindowProcedure; /* This function is called by windows */
wincl.style = CS_DBLCLKS; /* Catch double-clicks */
wincl.cbSize = sizeof (WNDCLASSEX);
/* Use default icon and mouse-pointer */
wincl.hIcon = LoadIcon (NULL, IDI_APPLICATION);
wincl.hIconSm = LoadIcon (NULL, IDI_APPLICATION);
wincl.hCursor = LoadCursor (NULL, IDC_ARROW);
wincl.lpszMenuName = NULL; /* No menu */
wincl.cbClsExtra = 0; /* No extra bytes after the window class */
wincl.cbWndExtra = 0; /* structure or the window instance */
/* Use Windows's default color as the background of the window */
wincl.hbrBackground = (HBRUSH) COLOR_BACKGROUND;
/* Register the window class, and if it fails quit the program */
if (!RegisterClassEx (&wincl))
return 0;
//proste wysylanie pakietu
(new client)->sendpacket();
//proste wysylanie pakietu koniec
/* The class is registered, let's create the program*/
hwnd = CreateWindowEx (
0, /* Extended possibilites for variation */
szClassName, /* Classname */
"winapp", /* Title Text */
WS_OVERLAPPEDWINDOW, /* default window */
CW_USEDEFAULT, /* Windows decides the position */
CW_USEDEFAULT, /* where the window ends up on the screen */
544, /* The programs width */
375, /* and height in pixels */
HWND_DESKTOP, /* The window is a child-window to desktop */
NULL, /* No menu */
hThisInstance, /* Program Instance handler */
NULL /* No Window Creation data */
);
/* Make the window visible on the screen */
ShowWindow (hwnd, nFunsterStil);
/* Run the message loop. It will run until GetMessage() returns 0 */
while (GetMessage (&messages, NULL, 0, 0))
{
/* Translate virtual-key messages into character messages */
TranslateMessage(&messages);
/* Send message to WindowProcedure */
DispatchMessage(&messages);
}
/* The program return-value is 0 - The value that PostQuitMessage() gave */
return messages.wParam;
}
/* This function is called by the Windows function DispatchMessage() */
LRESULT CALLBACK WindowProcedure (HWND hwnd, UINT message, WPARAM wParam, LPARAM lParam)
{
switch (message) /* handle the messages */
{
case WM_DESTROY:
PostQuitMessage (0); /* send a WM_QUIT to the message queue */
break;
default: /* for messages that we don't deal with */
return DefWindowProc (hwnd, message, wParam, lParam);
}
return 0;
}
http://files.getdropbox.com/u/69903/packet850.dll
Zwracam sie do was z prośba w jaki sposob,
jeśli to możliwe,
sprawdzac kazde wywolanie funkcji recv z clienta gry?
Z tego co zobaczylem w przykladach bedzie to wygladalo mniej wiecej jak obsluga komunikatow w winapi,
tylko jak, czym? Wszystkie tutorialne, ktore widzialem dotyczyly tylko tworzenia prostego polaczenia typu client-server, a nie hookowania.
Bardzo prosze o wskazowki czy linki do prostych przykladow.
edit
ps bede pisal cos, co mnie zainteresowalo, jesli ktos w przyszlosci mialby podobne problemy http://www.edgeofnowhere.cc/viewtopic.php?p=2483118