[Tutorial] Part I: Learning Function Hooking with Detours 08-26-2013, 06:02 PM
#1
Part II of this thread can be found at: http://www.discussionzone.net/showthread.php?tid=8169
Recently, I've been getting into hooking functions with C and C++, and I would like to share some of my knowledge of it.
First of all, what is a hook?
Well a hook is a simple override on something. For instance, when you hook a function, you're making an override on that function and mapping it to your own function. This can be as simple as hooking a math function or hooking a winsock application and overriding connects and sends.
Today, we will be writing a simple application in C to hook a function called "realfunc" and mapping it to a function called "hookedfunc".
This tutorial should take 20-30 minutes depending on how well you are at following instructions

If you don't already have Detours, go get it here:
http://research.microsoft.com/en-us/projects/detours/
The free edition is limited to hooking functions in x86 (32-bit processes) only. You'll also need to compile Detours. To do so, you'll need to open a command prompt that is running with administrative privileges.
Paste the following into a command prompt:
Spoiler:
32-Bit OS (x86):
64-Bit OS (x64):
Code:
"C:\Program Files\Microsoft Visual Studio 10.0\VC\vcvarsall.bat"
cd "C:\Program Files\Microsoft Research\Detours*"
nmake64-Bit OS (x64):
Code:
"C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\vcvarsall.bat"
cd "C:\Program Files (x86)\Microsoft Research\Detours*"
nmakeYou'll then need to copy some files to include them inside of your Visual Studio 2012 project.
Open up the Detours Folder (<ProgramFiles>\Microsoft Research\Detours*) and copy all of the items in the "includes" folder into "<ProgramFiles>\Microsoft Visual Studio 11.0\VC\includes".
You'll also need to copy the libs.X86 folder over (rename it to libs first, and then merge the folder into the VC folder).
Now, time to have some fun.
Open Visual Studio and create a new C++ project.
![[Image: KSjSwBz.png]](http://i.imgur.com/KSjSwBz.png)
A window should open, press next and make sure your project looks like mine:
![[Image: 8lD44Zr.png]](http://i.imgur.com/8lD44Zr.png)
You'll get a nice new project with a .cpp file that looks exactly like this:
![[Image: CwZLIrE.png]](http://i.imgur.com/CwZLIrE.png)
Now, you'll need to create two functions. They'll both return nothing and require an integer as the parameter.
![[Image: 5TXuEMQ.png]](http://i.imgur.com/5TXuEMQ.png)
Let's make those functions have some functionality.
![[Image: Ul9QdTx.png]](http://i.imgur.com/Ul9QdTx.png)
Now we shall initialize our Detours hook!
Code:
#include <Windows.h>
#include <detours.h>Go to Project->Properties->Linker->Input
Press the little arrow under Additional Dependencies and press edit.
Add the following:
![[Image: KY9ulDS.png]](http://i.imgur.com/KY9ulDS.png)
Now, we'll need to get the address of our "RealFunc" function.
Code:
void (*realfunction)(int) = RealFunc;Spoiler:
![[Image: Dak9OBb.png]](http://i.imgur.com/Dak9OBb.png)
Now, we shall start our Detours hook.
![[Image: IN6o7Dw.png]](http://i.imgur.com/IN6o7Dw.png)
Basically, we are attaching Detours to the address of the "RealFunc" function by passing along the pointer of our function in DetourAttach().
It then points to the address of "HookedFunc".
Let's try and run it!
![[Image: 1axgCFm.png]](http://i.imgur.com/1axgCFm.png)
We did it! We called RealFunc() before the hook, and then we called it after the hook! It successfully hooked!
Now, we have to write a method to unhook it just in case we want to restore the original function.
Add this before that last getchar() call:
![[Image: Q19X0Vo.png]](http://i.imgur.com/Q19X0Vo.png)
Let's try to run this again!
![[Image: oA0ywbo.png]](http://i.imgur.com/oA0ywbo.png)
Congratulations! You have successfully hooked a function! You can now apply this to common functions in the Windows API and combining that with DLL injection, you can change the functionality of certain programs.
I hope you enjoyed my tutorial! This took me around 20-minutes to write. Stay tuned for more!
I have included a copy of the project (Source + Binary):
http://www.mediafire.com/download/a8qvnu...ation1.zip
The password is "THR_DZ.NET-DET_TUT".



![[+]](https://sinister.li/images/modern/collapse_collapsed.png)


![[Image: a319ef9581853.560e3236d2b0b.png]](https://mir-s3-cdn-cf.behance.net/project_modules/disp/a319ef9581853.560e3236d2b0b.png)
I'm in the process of writing part II right now.