-
Notifications
You must be signed in to change notification settings - Fork 5
Expand file tree
/
Copy pathveh.cpp
More file actions
128 lines (107 loc) · 2.73 KB
/
veh.cpp
File metadata and controls
128 lines (107 loc) · 2.73 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
#include "pch.h"
#include "veh.h"
namespace VEH
{
//Authors: kemo#1337, AsrielD#6969
bool IsSamePage(void* A, void* B)
{
MEMORY_BASIC_INFORMATION InfoA;
if (!VirtualQuery(A, &InfoA, sizeof(InfoA)))
{
return true;
}
MEMORY_BASIC_INFORMATION InfoB;
if (!VirtualQuery(B, &InfoB, sizeof(InfoB)))
{
return true;
}
return InfoA.BaseAddress == InfoB.BaseAddress;
}
struct HOOK_INFO
{
void* Original;
void* Detour;
HOOK_INFO(void* Original, void* Detour) :
Original(Original),
Detour(Detour)
{
}
};
std::vector<HOOK_INFO> Hooks;
std::vector<DWORD> HookProtections;
HANDLE ExceptionHandler;
LONG WINAPI Handler(EXCEPTION_POINTERS* Exception)
{
//thread_local void* OriginalHook = nullptr;
if (Exception->ExceptionRecord->ExceptionCode == STATUS_GUARD_PAGE_VIOLATION)
{
auto Itr = std::find_if(Hooks.begin(), Hooks.end(),
[Rip = Exception->ContextRecord->Rip](const HOOK_INFO& Hook)
{
return Hook.Original == (void*)Rip;
});
if (Itr != Hooks.end())
{
//OriginalHook = Itr->Original;
Exception->ContextRecord->Rip = (uintptr_t)Itr->Detour;
}
Exception->ContextRecord->EFlags |= 0x100; // SINGLE_STEP_FLAG
return EXCEPTION_CONTINUE_EXECUTION;
}
else if (Exception->ExceptionRecord->ExceptionCode == STATUS_SINGLE_STEP)
{
//TODO: find a way to only vp the function that about to get executed
for (auto& Hook : Hooks)
{
DWORD dwOldProtect;
VirtualProtect(Hook.Original, 1, PAGE_EXECUTE_READ | PAGE_GUARD,
&dwOldProtect);
}
return EXCEPTION_CONTINUE_EXECUTION;
}
return EXCEPTION_CONTINUE_SEARCH;
}
bool Init()
{
if (ExceptionHandler == nullptr)
{
ExceptionHandler = AddVectoredExceptionHandler(true, (PVECTORED_EXCEPTION_HANDLER)Handler);
}
return ExceptionHandler != nullptr;
}
bool AddHook(void* Target, void* Detour)
{
if (ExceptionHandler == nullptr)
{
return false;
}
if (IsSamePage(Target, Detour))
{
return false;
}
if (!VirtualProtect(Target, 1, PAGE_EXECUTE_READ | PAGE_GUARD, &HookProtections.emplace_back()))
{
HookProtections.pop_back();
return false;
}
Hooks.emplace_back(Target, Detour);
return true;
}
bool RemoveHook(void* Original)
{
auto Itr = std::find_if(Hooks.begin(), Hooks.end(), [Original](const HOOK_INFO& Hook)
{
return Hook.Original == Original;
});
if (Itr == Hooks.end())
{
return false;
}
const auto ProtItr = HookProtections.begin() + std::distance(Hooks.begin(), Itr);
Hooks.erase(Itr);
DWORD dwOldProtect;
bool Ret = VirtualProtect(Original, 1, *ProtItr, &dwOldProtect);
HookProtections.erase(ProtItr);
return false;
}
}