![]() |
|
Dynamic API call / Obfuscation - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Coding (https://sinister.li/Forum-Coding) +--- Forum: C, C++, & Obj-C (https://sinister.li/Forum-C-C-Obj-C) +--- Thread: Dynamic API call / Obfuscation (/Thread-Dynamic-API-call-Obfuscation) |
Dynamic API call / Obfuscation - CPlus - 12-19-2013 Today I will show you guys how to do dynamic function calls in C++ or obfuscation you also may call it.. This is a method witch gets the address to a function in the specified DLL file. Lets Start with some information: A DLL can define two kinds of functions: exported and internal. The exported functions are intended to be called by other modules, as well as from within the DLL where they are defined. Internal functions are typically intended to be called only from within the DLL where they are defined. Although a DLL can export data, its data is generally used only by its functions. However, there is nothing to prevent another module from reading or writing that address. [Reference] So lets get down to it. First we need to decide a function we want to call dynamically, for this example we will use MessageBox() MSDN and Look it up on MSDN. The declaration looks like this. Code: int WINAPI MessageBox(
_In_opt_ HWND hWnd,
_In_opt_ LPCTSTR lpText,
_In_opt_ LPCTSTR lpCaption,
_In_ UINT uType
);So what we need to do is make a new Code: typedefIn a header file or at the top of your .cpp file we add the folowing. Code: #include <Windows.h>
// Defines a new type (A pointer to a WINAPI call aka __stdcall
typedef int (WINAPI *ThisCanBeWhatEver)( HWND hWnd, LPCTSTR lpText, LPCTSTR lpCaption, UINT uType);So with the new definition we can move on. There are two different functions we can use and they work almost the same way. GetModuleHandle(LPCSTR lpName); LoadLibrary(LPCSTR lpname); In my experience LoadLibrary is better for this. Code: HMODULE hDllFile = LoadLibrary("User32.dll");
// HMODULE hDllFile = GetModuleHandle("User32.dll");
if ( hDllFile == NULL )
{
std::cout << "LoadLibrary Error: " << GetLastError() << std::endl;// Retrive error code for GetModuleHandle / LoadLibrary
Sleep(5000);
// exit as safe as possible...
return 0;
}Code: ThisCanBeWhatEver dynamicMessageBox = NULL;
dynamicMessageBox = (ThisCanBeWhatEver)GetProcAddress(hDllFile, "MessageBoxA");
if ( dynamicMessageBox == NULL )
{
std::cout << "GetProcAddress Error: " << GetLastError() << std::endl; // Retrive error code for GetProcAddress
Sleep(5000);
// exit as safe as possible...
FreeLibrary( hDllFile );
return 0;
}Let me explain the above code. GetProcAddress() Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL). Now we call it as you normally would. Code: // Now lets call the function we wanted as we whould normoly.
dynamicMessageBox( NULL, "This was done dynamically.", "We did it now we know something new.", MB_ICONINFORMATION|MB_OK);There we go a dynamic API call or obfuscation.Conclusion: This avoids calling API calls witch AV`s most likly flag. Please let me know if I should post more stuff like this and what I can do better. And a thank you in the thread is also much appreciated. CPlus |