ICode9

精准搜索请尝试: 精确搜索
首页 > 系统相关> 文章详细

32位程序读取64位进程内存

2021-10-09 20:58:36  阅读:173  来源: 互联网

标签:__ LPFN 32 NtWow64ReadVirtualMemory64 bbb 64 内存 sizeof hProcess


//第一步://定義函數參數結構
typedef NTSTATUS(NTAPI *LPFN_NTWOW64READVIRTUALMEMORY64)(
IN HANDLE ProcessHandle,
IN ULONG64 BaseAddress,
OUT PVOID BufferData,
IN ULONG64 BufferLength,
OUT PULONG64 ReturnLength OPTIONAL);

typedef NTSTATUS(NTAPI *LPFN_NTWOW64WRITEVIRTUALMEMORY64)(
IN HANDLE ProcessHandle,
IN ULONG64 BaseAddress,
OUT PVOID BufferData,
IN ULONG64 BufferLength,
OUT PULONG64 ReturnLength OPTIONAL);
//第二步
//LPFN_NTWOW64QUERYINFORMATIONPROCESS64
HMODULE NtdllModuleBase;
LPFN_NTWOW64READVIRTUALMEMORY64 __NtWow64ReadVirtualMemory64;
//LPFN_NTWOW64WRITEVIRTUALMEMORY64 __NtWow64WriteVirtualMemory64;

//第三步:
__NtWow64ReadVirtualMemory64 = (LPFN_NTWOW64READVIRTUALMEMORY64)GetProcAddress(NtdllModuleBase,
“NtWow64ReadVirtualMemory64”);

__NtWow64WriteVirtualMemory64 = (LPFN_NTWOW64WRITEVIRTUALMEMORY64)GetProcAddress(NtdllModuleBase,
    "NtWow64WriteVirtualMemory64");

//例子: 和ReadProcessMemory用法差不多
讀取矩陣地址
// __NtWow64ReadVirtualMemory64(hProcess, module_address + 0x19386D8, &aaa, sizeof(DWORD64), 0);
// __NtWow64ReadVirtualMemory64(hProcess, aaa + 0x1FC, &bbb, sizeof(DWORD64), 0);
// __NtWow64ReadVirtualMemory64(hProcess, bbb + 0xA4, &aaa, sizeof(DWORD64), 0);
// __NtWow64ReadVirtualMemory64(hProcess, aaa + 0x20, &bbb, sizeof(DWORD64), 0);
// __NtWow64ReadVirtualMemory64(hProcess, bbb + 0x1F8, &aaa, sizeof(DWORD64), 0);
// __NtWow64ReadVirtualMemory64(hProcess, aaa + 0x30, &bbb, sizeof(DWORD64), 0);
// __NtWow64ReadVirtualMemory64(hProcess, bbb+0x1BE0, location2, sizeof(location2), 0);

标签:__,LPFN,32,NtWow64ReadVirtualMemory64,bbb,64,内存,sizeof,hProcess
来源: https://blog.csdn.net/htpidk/article/details/120678990

本站声明: 1. iCode9 技术分享网(下文简称本站)提供的所有内容,仅供技术学习、探讨和分享;
2. 关于本站的所有留言、评论、转载及引用,纯属内容发起人的个人观点,与本站观点和立场无关;
3. 关于本站的所有言论和文字,纯属内容发起人的个人观点,与本站观点和立场无关;
4. 本站文章均是网友提供,不完全保证技术分享内容的完整性、准确性、时效性、风险性和版权归属;如您发现该文章侵犯了您的权益,可联系我们第一时间进行删除;
5. 本站为非盈利性的个人网站,所有内容不会用来进行牟利,也不会利用任何形式的广告来间接获益,纯粹是为了广大技术爱好者提供技术内容和技术思想的分享性交流网站。

专注分享技术,共同学习,共同进步。侵权联系[81616952@qq.com]

Copyright (C)ICode9.com, All Rights Reserved.

ICode9版权所有