• Welcome to Valhalla Legends Archive.
 

Calling or injecting code into another process

Started by Banana fanna fo fanna, January 15, 2003, 12:36 PM

Previous topic - Next topic

Banana fanna fo fanna

Hey guys,

Let's say I know the offset of a function I want to call in a running program. Is there any way for me to call into another totally seperate process?

If not, could I dynamically inject code in-memory? I'm thinking OpenProcess might help...?

Thanks for your help.

iago

#1
No, and yes.

I suggest using CreateRemoteThread(), and yes, OpenProcess is necessary :D
This'll make an interesting test for broken AV:
QuoteX5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*


Banana fanna fo fanna

#2
I found the answer in an e-book Grok sent me a looong time ago ;)

Etheran

#3
Share the answer, I'd like to know.  I'm currently learning how to inject code.  I'm using starcraft without any help from tutorials (I wanted to do something on my own).

iago

#4
I can send you an ebook about the win32 api.. it'll tell you how to inject code, but it won't do it for you, it's designed as an educational book with everything from threading to dlls to injection.  Actually, Grok is the one who suggested I buy it originally :D
This'll make an interesting test for broken AV:
QuoteX5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*


Zakath

#5
iago, send me that book, will you?

You know how to find me. :P
Quote from: iago on February 02, 2005, 03:07 PM
Yes, you can't have everybody...contributing to the main source repository.  That would be stupid and create chaos.

Opensource projects...would be dumb.

Etheran

#6
yes!! plz kthx leet h4x0r time.  lol :P

Yoni

#7
That's where it should have gone.

A year (exactly) old but it should still work:
http://www.valhallalegends.com/yoni/SampleHDL.zip

iago

#8
You can get it here:
ftp://Guest:[email protected]:665/windows.chm

If it doesn't work, it means I turned off my computer, try again later :D
This'll make an interesting test for broken AV:
QuoteX5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*


Etheran

#9
nice one, thanks iago and Grok! :)

iago

#10
QuoteYou can get it here:
ftp://Guest:[email protected]:665/windows.chm

If it doesn't work, it means I turned off my computer, try again later :D

Wow, 8 downloads in 12 hours.. it's at #1 on my ftp at.. 8 downloads :-)
This'll make an interesting test for broken AV:
QuoteX5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*


Grok

#11
Someone probably wanted extra copies for their friends.

=P

iago

That doesn't even make sense, and you know it! :-P

Besides, it's unique ip's.

But on that note, if when you're done with the file, please put it back so other people can use it (I only have so many copies)!
This'll make an interesting test for broken AV:
QuoteX5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*


l)ragon

#13
/me looks around
Is that what that book is ^^
Sopose i'll have to read latteron. 8p
*^~·.,¸¸,.·´¯`·.,¸¸,.-·~^*ˆ¨¯¯¨ˆ*^~·.,l)ragon,.-·~^*ˆ¨¯¯¨ˆ*^~·.,¸¸,.·´¯`·.,¸¸,.-·~^*

Etheran

I wish I could find an ebook library; that'd be sweet. :)