Login Register






[Tutorial] Part I: Learning Function Hooking with Detours filter_list
Author
Message
[Tutorial] Part I: Learning Function Hooking with Detours #1

Part II of this thread can be found at: http://www.discussionzone.net/showthread.php?tid=8169

Recently, I've been getting into hooking functions with C and C++, and I would like to share some of my knowledge of it.

First of all, what is a hook?
Well a hook is a simple override on something. For instance, when you hook a function, you're making an override on that function and mapping it to your own function. This can be as simple as hooking a math function or hooking a winsock application and overriding connects and sends.

Today, we will be writing a simple application in C to hook a function called "realfunc" and mapping it to a function called "hookedfunc".

This tutorial should take 20-30 minutes depending on how well you are at following instructions Wink

If you don't already have Detours, go get it here:
http://research.microsoft.com/en-us/projects/detours/

The free edition is limited to hooking functions in x86 (32-bit processes) only. You'll also need to compile Detours. To do so, you'll need to open a command prompt that is running with administrative privileges.

Paste the following into a command prompt:

Spoiler:
32-Bit OS (x86):
Code:
"C:\Program Files\Microsoft Visual Studio 10.0\VC\vcvarsall.bat" cd "C:\Program Files\Microsoft Research\Detours*" nmake

64-Bit OS (x64):
Code:
"C:\Program Files (x86)\Microsoft Visual Studio 10.0\VC\vcvarsall.bat" cd "C:\Program Files (x86)\Microsoft Research\Detours*" nmake


You'll then need to copy some files to include them inside of your Visual Studio 2012 project.

Open up the Detours Folder (<ProgramFiles>\Microsoft Research\Detours*) and copy all of the items in the "includes" folder into "<ProgramFiles>\Microsoft Visual Studio 11.0\VC\includes".
You'll also need to copy the libs.X86 folder over (rename it to libs first, and then merge the folder into the VC folder).

Now, time to have some fun.

Open Visual Studio and create a new C++ project.

[Image: KSjSwBz.png]

A window should open, press next and make sure your project looks like mine:

[Image: 8lD44Zr.png]

You'll get a nice new project with a .cpp file that looks exactly like this:

[Image: CwZLIrE.png]

Now, you'll need to create two functions. They'll both return nothing and require an integer as the parameter.

[Image: 5TXuEMQ.png]

Let's make those functions have some functionality.

[Image: Ul9QdTx.png]

Now we shall initialize our Detours hook!

Code:
#include <Windows.h> #include <detours.h>

Go to Project->Properties->Linker->Input
Press the little arrow under Additional Dependencies and press edit.
Add the following:

[Image: KY9ulDS.png]

Now, we'll need to get the address of our "RealFunc" function.

Code:
void (*realfunction)(int) = RealFunc;

Spoiler:
[Image: Dak9OBb.png]


Now, we shall start our Detours hook.

[Image: IN6o7Dw.png]

Basically, we are attaching Detours to the address of the "RealFunc" function by passing along the pointer of our function in DetourAttach().
It then points to the address of "HookedFunc".

Let's try and run it!

[Image: 1axgCFm.png]

We did it! We called RealFunc() before the hook, and then we called it after the hook! It successfully hooked!

Now, we have to write a method to unhook it just in case we want to restore the original function.

Add this before that last getchar() call:

[Image: Q19X0Vo.png]

Let's try to run this again!

[Image: oA0ywbo.png]

Congratulations! You have successfully hooked a function! You can now apply this to common functions in the Windows API and combining that with DLL injection, you can change the functionality of certain programs.

I hope you enjoyed my tutorial! This took me around 20-minutes to write. Stay tuned for more!

I have included a copy of the project (Source + Binary):
http://www.mediafire.com/download/a8qvnu...ation1.zip
The password is "THR_DZ.NET-DET_TUT".

Reply

RE: [Tutorial] Part I: Learning Function Hooking with Detours #2
This is just amazing. I learned so much from reading this. Thanks bro.
[Image: nwpTO2D.gif]

Reply

RE: [Tutorial] Part I: Learning Function Hooking with Detours #3
(08-26-2013, 06:24 PM)0x4b33 Wrote: This is just amazing. I learned so much from reading this. Thanks bro.

I'm glad I could help Smile
Part II will be posted later today or tomorrow. It will be about DLL injection and hooking functions in injected processes.

Reply

RE: [Tutorial] Part I: Learning Function Hooking with Detours #4
Holy fuck balls. Good work, Thr. I'm really impressed.
[Image: a319ef9581853.560e3236d2b0b.png]

Reply

RE: [Tutorial] Part I: Learning Function Hooking with Detours #5
(08-27-2013, 06:38 PM)Exiled Wrote: Holy fuck balls. Good work, Thr. I'm really impressed.

Thanks :3

It was a lot of fun writing that Wink

Reply

RE: [Tutorial] Part I: Learning Function Hooking with Detours #6
(08-27-2013, 07:30 PM)Thr Wrote:
(08-27-2013, 06:38 PM)Exiled Wrote: Holy fuck balls. Good work, Thr. I'm really impressed.

Thanks :3

It was a lot of fun writing that Wink

I'm sure you did, looks very neat and sleek.
[Image: a319ef9581853.560e3236d2b0b.png]

Reply

RE: [Tutorial] Part I: Learning Function Hooking with Detours #7
(08-30-2013, 07:02 PM)Exiled Wrote:
(08-27-2013, 07:30 PM)Thr Wrote:
(08-27-2013, 06:38 PM)Exiled Wrote: Holy fuck balls. Good work, Thr. I'm really impressed.

Thanks :3

It was a lot of fun writing that Wink

I'm sure you did, looks very neat and sleek.

Haha thanks Tongue I'm in the process of writing part II right now.

Reply

RE: [Tutorial] Part I: Learning Function Hooking with Detours #8
(08-30-2013, 11:26 PM)Thr Wrote:
(08-30-2013, 07:02 PM)Exiled Wrote:
(08-27-2013, 07:30 PM)Thr Wrote: Thanks :3

It was a lot of fun writing that Wink

I'm sure you did, looks very neat and sleek.

Haha thanks Tongue I'm in the process of writing part II right now.

Can't wait to see it! Best of luck creating it.
[Image: a319ef9581853.560e3236d2b0b.png]

Reply