c++ - Failing dll injection -
i'm in process of making security program network. 1 of it's instances check , monitor api's , libraries called. dll , program go along finished. there problem cant seem fix.
when trying inject dll system processes (such explorer.exe, main test system process) ntcreatethreadex return value: c0000022, means along lines of: status_access_denied (it returns in ntstatus, dword do)
i have no idea do, i'm running administrator, raised privileges, , used proper functions, still c0000022
here's code i'm using inject ( couldn't post formated code here, because toolbar wouldn't appear)
#include "main.h" typedef dword ntstatus; struct ntcreatethreadexbuffer{ ulong size; ulong unknown1; ulong unknown2; pulong unknown3; ulong unknown4; ulong unknown5; ulong unknown6; pulong unknown7; ulong unknown8; }; typedef ntstatus (winapi *lpfun_ntcreatethreadex) ( out phandle hthread, in access_mask desiredaccess, in lpvoid objectattributes, in handle processhandle, in lpthread_start_routine lpstartaddress, in lpvoid lpparameter, in bool createsuspended, in ulong stackzerobits, in ulong sizeofstackcommit, in ulong sizeofstackreserve, out lpvoid lpbytesbuffer ); using namespace std; //#define create_thread_access (process_create_thread | process_query_information | process_vm_operation | process_vm_write | process_vm_read) #define create_thread_access ( process_all_access ) bool loaddll(char *procname, char *dllname); bool injectdll(dword dwprocessid, char *dllname); bool loaddll(char *dllname, dword dwprocid){ printf("process id inject: %d",dwprocid); if(!dwprocid){ printf("no vailid pid\n"); return false; } file* filecheck = fopen(dllname, "r"); if(filecheck==null){ printf("\nunable inject %s", dllname); return false; } fclose(filecheck); if(!injectdll(dwprocid, dllname)){ printf("injection failed\n"); return false; } else { return true; } } bool injectdll(dword dwprocessid, char *dllname){ handle hproc; handle htoken; char buf[50]={0}; lpvoid remotestring, loadlibaddy; if(!dwprocessid)return false; handle hcurrentproc = getcurrentprocess(); if (!openprocesstoken(hcurrentproc,token_query | token_adjust_privileges,&htoken)){ printf("openprocesstoken error:%d\n", getlasterror()); } else { if (!raiseprivleges(htoken, (char*)se_debug_name)){ printf("setprivleges se_debug_name error:%d\n", getlasterror()); } } if (htoken)closehandle(htoken); hproc = openprocess(create_thread_access, false, dwprocessid); printf("\nhandle process: %x\n", hproc); if(!hproc){ printf("openprocess() failed: %d", getlasterror()); return false; } loadlibaddy = (lpvoid)getprocaddress(getmodulehandle("kernel32.dll"), "loadlibrarya"); if(!loadlibaddy){ printf("getprocaddress() failed: %d", getlasterror()); return false; } remotestring = (lpvoid)virtualallocex(hproc, null, strlen(dllname), mem_reserve|mem_commit, page_readwrite); if(remotestring == null){ printf("virtualallocex() failed: %d", getlasterror()); return false; } printf("\nremote address: %x\n", remotestring); if(writeprocessmemory(hproc, (lpvoid)remotestring, dllname, strlen(dllname), null) == null){ printf("writeprocessmemory() failed: %d", getlasterror()); return false; } /* if(!createremotethread(hproc, null, null, (lpthread_start_routine)loadlibaddy, (lpvoid)remotestring, null, null)){ printf("createremotethread() failed: %d", getlasterror()); return false; } */ hmodule modntdll = getmodulehandle("ntdll.dll"); if( !modntdll ) { printf("n failed module handle ntdll.dll, error=0x%.8x", getlasterror()); return 0; } lpfun_ntcreatethreadex funntcreatethreadex = (lpfun_ntcreatethreadex) getprocaddress(modntdll, "ntcreatethreadex"); if( !funntcreatethreadex ) { printf("n failed function (ntcreatethreadex) address ntdll.dll, error=0x%.8x\ntrying createremotethread api\n", getlasterror()); if(!createremotethread(hproc, null, null, (lpthread_start_routine)loadlibaddy, (lpvoid)remotestring, null, null)){ printf("createremotethread() failed: %d", getlasterror()); return false; } else { printf("createremotethread success!\n"); return true; } return 0; } ntcreatethreadexbuffer ntbuffer; memset (&ntbuffer,0,sizeof(ntcreatethreadexbuffer)); dword temp1 = 0; dword temp2 = 0; handle premotethread = null; ntbuffer.size = sizeof(ntcreatethreadexbuffer); ntbuffer.unknown1 = 0x10003; ntbuffer.unknown2 = 0x8; ntbuffer.unknown3 = &temp2; ntbuffer.unknown4 = 0; ntbuffer.unknown5 = 0x10004; ntbuffer.unknown6 = 4; ntbuffer.unknown7 = &temp1; ntbuffer.unknown8 = 0; ntstatus status = funntcreatethreadex( &premotethread, 0x1fffff, null, hproc, (lpthread_start_routine) loadlibaddy, (lpvoid)remotestring, false, //start instantly null, null, null, &ntbuffer ); printf("ntcreatethreadex return: %x\n", status); // resume thread execution waitforsingleobject(premotethread, infinite); //check return code remote thread function dword dwexitcode; if( getexitcodethread(premotethread, (dword*) &dwexitcode) ) { printf("\n remote thread returned status = %d\n", dwexitcode); } closehandle(premotethread); closehandle(hproc); return true; } bool raiseprivleges( handle htoken, char *ppriv ){ token_privileges tkp; tkp.privilegecount = 1; tkp.privileges[0].attributes = se_privilege_enabled; tkp.privileges[0].luid.highpart = 0; tkp.privileges[0].luid.lowpart = 0; if (!lookupprivilegevalue(null, ppriv, &tkp.privileges[0].luid)){ printf("lookupprivilegevalue error:%d\n", getlasterror()); return false; } int iret = adjusttokenprivileges(htoken, false, &tkp, 0x10, (ptoken_privileges)null, 0); if (iret == null){ printf( "adjusttokenprivileges error:%d\n", getlasterror()); return true; } else { iret = getlasterror(); switch (iret){ case error_not_all_assigned:{ printf("adjusttokenprivileges error_not_all_assigned\n" ); return false; } case error_success:{ return true; } default:{ printf("adjusttokenprivileges unknow error:%d\n", iret); return false; } } } }
1) if you're running on vista or later you're possibly trying inject 'protected process' 'non protected process'. see process security , access rights in msdn. non protected processes can't create threads in protected processes; though must admit i'd expect call open process fail when request inappropriate access rights rather subsequent create thread call fail.
2) why using ntcreatethreadex() rather calling createremotethread()?
3) isn't cause of problem, but... you're failing allocate memory null terminator in string, should allocating strlen(dllname) + 1.
4) assume process doing injecting , process you're injecting both same architecture, you're not running x86 exe on x64 , expecting inject x64 exe?
Comments
Post a Comment