[Tutorial] Part II: Hooking Functions in Remote Processes 08-31-2013, 02:12 AM
#1
This is a continuation of the thread located at:
http://www.discussionzone.net/showthread.php?tid=8036
As a continuation from the other thread, I would like to start out with a small explanation.
Let's try a small scenario. You're trying to create a program that proxies other programs through a Socks5 proxy. You'd want to use what I'm about to show you so you can override the Winsock connect method and point it to your own connection method. Using hooking in remote processes, you can achieve something like this.
First of all, you'll want to create a new Win32 project.
![[Image: 21PrlaQ.png]](http://i.imgur.com/21PrlaQ.png)
After you've created it, you'll want to match your settings with this image:
![[Image: OtAtYWu.png]](http://i.imgur.com/OtAtYWu.png)
Afterwards, press finish. You're going to want to click on dllmain.cpp located in the source explorer.
Now, the source file is going to look exactly like this.
![[Image: XfPLpnz.png]](http://i.imgur.com/XfPLpnz.png)
You're going to want to follow the other tutorial for including Detours in your project.
First, we'll need to include the Windows API functions in our project.
Next, we'll create a pointer that will point to the address of the Windows API function "MessageBox" in the remote process.
![[Image: CZaDTji.png]](http://i.imgur.com/CZaDTji.png)
Right below our pointer, we'll want to create our function that we will use to override the messagebox function.
![[Image: QCeNDuk.png]](http://i.imgur.com/QCeNDuk.png)
This is calling the default MessageBox function, but replacing the title with "Hooked!" so we can see if we have successfully hooked the function.
Next, we're going to want to write our hooking code.
![[Image: hhz6Dh2.png]](http://i.imgur.com/hhz6Dh2.png)
Next, we're going to want to make some code that detaches our hook after the DLL gets unloaded, so there are no memory leaks if the DLL is unloaded before the process exits.
![[Image: hL9mDhS.png]](http://i.imgur.com/hL9mDhS.png)
Last but not least, think of this, what if MessageBox gets called, and gets pointed to our MessageBoxNew function, which in turn calls MessageBox again, won't that loop continuously? The answer is yes. This is very important to understand that you don't want the program to crash. So let's fix that.
Here's our old code from MessageBoxNew:
![[Image: iHHmKpk.png]](http://i.imgur.com/iHHmKpk.png)
We're going to want to unhook the function temporarily until the function is finished executing.
![[Image: ETchAd6.png]](http://i.imgur.com/ETchAd6.png)
This basically unhooks and then calls MessageBox and then hooks again. Quite simple really.
Next step is to test this out!
First, compile it and find the DLL located in the Debug folder under the main project folder.
You'll want to create a new project to test this one out. This project will be a regular Win32 project compiled as a Console Application. It should look like this:
![[Image: TbqlaPP.png]](http://i.imgur.com/TbqlaPP.png)
All we are doing is pausing to give us time to inject the DLL, and then we inject the DLL and hook the function, and our MessageBox function will be called.
If you run the console application, it should look like this:
![[Image: KEKt3GV.png]](http://i.imgur.com/KEKt3GV.png)
The DLL injector I am using is called Extreme Injector v2.
![[Image: zFzPv8a.png]](http://i.imgur.com/zFzPv8a.png)
You'll basically want to go to your project settings under the Debug tab, and find the location of ConsoleApplication.exe and place that path under the Command, and Attach To Process should be set to No.
As soon as you press the Play button in VS, you'll have a few seconds to press the inject button on your Injector.
You should get the prompt popping up that says "Inject your DLL now...", once you see that, press inject.
![[Image: nJNFVIz.png]](http://i.imgur.com/nJNFVIz.png)
Congratulations! You have successfully injected a DLL into a remote process and hooked a function! All of these files can be found at http://www.mediafire.com/download/q9kvgu...cesses.zip
Stay tuned for part III where you'll learn how to hook an exported function instead of just a regular Windows API function!
http://www.discussionzone.net/showthread.php?tid=8036
PART II: HOOKING FUNCTIONS IN REMOTE PROCESSES
As a continuation from the other thread, I would like to start out with a small explanation.
Let's try a small scenario. You're trying to create a program that proxies other programs through a Socks5 proxy. You'd want to use what I'm about to show you so you can override the Winsock connect method and point it to your own connection method. Using hooking in remote processes, you can achieve something like this.
First of all, you'll want to create a new Win32 project.
![[Image: 21PrlaQ.png]](http://i.imgur.com/21PrlaQ.png)
After you've created it, you'll want to match your settings with this image:
![[Image: OtAtYWu.png]](http://i.imgur.com/OtAtYWu.png)
Afterwards, press finish. You're going to want to click on dllmain.cpp located in the source explorer.
Now, the source file is going to look exactly like this.
![[Image: XfPLpnz.png]](http://i.imgur.com/XfPLpnz.png)
You're going to want to follow the other tutorial for including Detours in your project.
First, we'll need to include the Windows API functions in our project.
Code:
#include <Windows.h>Next, we'll create a pointer that will point to the address of the Windows API function "MessageBox" in the remote process.
![[Image: CZaDTji.png]](http://i.imgur.com/CZaDTji.png)
Right below our pointer, we'll want to create our function that we will use to override the messagebox function.
![[Image: QCeNDuk.png]](http://i.imgur.com/QCeNDuk.png)
This is calling the default MessageBox function, but replacing the title with "Hooked!" so we can see if we have successfully hooked the function.
Next, we're going to want to write our hooking code.
![[Image: hhz6Dh2.png]](http://i.imgur.com/hhz6Dh2.png)
Next, we're going to want to make some code that detaches our hook after the DLL gets unloaded, so there are no memory leaks if the DLL is unloaded before the process exits.
![[Image: hL9mDhS.png]](http://i.imgur.com/hL9mDhS.png)
Last but not least, think of this, what if MessageBox gets called, and gets pointed to our MessageBoxNew function, which in turn calls MessageBox again, won't that loop continuously? The answer is yes. This is very important to understand that you don't want the program to crash. So let's fix that.
Here's our old code from MessageBoxNew:
![[Image: iHHmKpk.png]](http://i.imgur.com/iHHmKpk.png)
We're going to want to unhook the function temporarily until the function is finished executing.
![[Image: ETchAd6.png]](http://i.imgur.com/ETchAd6.png)
This basically unhooks and then calls MessageBox and then hooks again. Quite simple really.
Next step is to test this out!
First, compile it and find the DLL located in the Debug folder under the main project folder.
You'll want to create a new project to test this one out. This project will be a regular Win32 project compiled as a Console Application. It should look like this:
![[Image: TbqlaPP.png]](http://i.imgur.com/TbqlaPP.png)
All we are doing is pausing to give us time to inject the DLL, and then we inject the DLL and hook the function, and our MessageBox function will be called.
If you run the console application, it should look like this:
![[Image: KEKt3GV.png]](http://i.imgur.com/KEKt3GV.png)
The DLL injector I am using is called Extreme Injector v2.
![[Image: zFzPv8a.png]](http://i.imgur.com/zFzPv8a.png)
You'll basically want to go to your project settings under the Debug tab, and find the location of ConsoleApplication.exe and place that path under the Command, and Attach To Process should be set to No.
As soon as you press the Play button in VS, you'll have a few seconds to press the inject button on your Injector.
You should get the prompt popping up that says "Inject your DLL now...", once you see that, press inject.
![[Image: nJNFVIz.png]](http://i.imgur.com/nJNFVIz.png)
Congratulations! You have successfully injected a DLL into a remote process and hooked a function! All of these files can be found at http://www.mediafire.com/download/q9kvgu...cesses.zip
Stay tuned for part III where you'll learn how to hook an exported function instead of just a regular Windows API function!



![[+]](https://sinister.li/images/modern/collapse_collapsed.png)



It helps knowing that at least someone likes my tutorials