📄 callback.xs
字号:
&& *(cursor+2) == 0xDE
&& *(cursor+3) == 0xC0
) {
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate.Study: checkpoint_END=%d\n", distance);
#endif
checkpoint_END = distance - 3;
}
#ifdef WIN32_API_DEBUG
if(checkpoint_END > 0) {
printf("(C)CallbackCreate.Study: after END got 0x%02X at %d\n", *cursor, distance);
}
#endif
if(*(cursor+0) == 0xC9 // leave
&& *(cursor+1) == 0xC3 // ret
) {
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate.Study: checkpoint_DONE=%d\n", distance);
#endif
checkpoint_DONE = distance + 2;
done = TRUE;
}
if(cursor >= (unsigned char *) PerformCallback) {
checkpoint_DONE = distance;
done = TRUE;
}
// TODO: add fallback (eg. if cursor >= CallbackCreate then done)
cursor++;
distance++;
}
section_START = checkpoint_PUSHI;
section_PUSHI = checkpoint_PUSHL - checkpoint_PUSHI;
section_PUSHL = checkpoint_PUSHP - checkpoint_PUSHL;
section_PUSHP = checkpoint_PUSHS - checkpoint_PUSHP;
section_PUSHS = checkpoint_END - checkpoint_PUSHS;
section_END = checkpoint_DONE - checkpoint_END;
toalloc = section_START;
toalloc += section_END;
toalloc += 3; // we'll need 3 extra bytes for the callback epilogue
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: toalloc=%d\n", toalloc);
#endif
for(i=0; i<nparams; i++) {
if(params[i].t == T_NUMBER) {
toalloc += section_PUSHI;
}
if(params[i].t == T_POINTER) {
toalloc += section_PUSHP;
}
if(params[i].t == T_STRUCTURE) {
toalloc += section_PUSHS;
}
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: summing param[%d] (%d), toalloc=%d\n", i, params[i].t, toalloc);
#endif
}
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: fakeint is at: 0x%08X\n", &fakeint);
printf("(C)CallbackCreate: fakepointer is at: 0x%08X\n", &fakepointer);
printf("(C)CallbackCreate: fakesv is at: 0x%08X\n", &fakesv);
printf("(C)CallbackCreate: CallbackTemplate is at: 0x%08X\n", CallbackTemplate);
printf("(C)CallbackCreate: allocating %d bytes\n", toalloc);
#endif
code = (unsigned char *) malloc(toalloc);
if(code == NULL) {
printf("can't allocate callback code, aborting!\n");
return 0;
}
cursor = code;
displacement = code - source;
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: source = 0x%x\n", source);
printf("(C)CallbackCreate: code = 0x%x\n", code);
#endif
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: COPYING SECTION section_START (%d bytes)\n", section_START);
#endif
memcpy( (void *) cursor, source, section_START);
for(i=0; i < section_START; i++) {
r = RelocateCode(cursor, displacement);
if(r == 7
&& *(cursor+3) == 0xDE
&& *(cursor+4) == 0xC0
&& *(cursor+5) == 0xFF
&& *(cursor+6) == 0xFF) {
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: FOUND CODE at 0x%x...\n", cursor+3);
printf("(C)CallbackCreate: callback = 0x%x\n", callback);
#endif
*((int*)(cursor+3)) = (int) callback;
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: CODE now is = 0x%x\n", *((int*)(cursor+3)));
#endif
}
if(r == 7
&& *(cursor+3) == 0x01
&& *(cursor+4) == 0x00
&& *(cursor+5) == 0xDE
&& *(cursor+6) == 0xC0) {
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: FOUND SELF at 0x%08x...\n", cursor+3);
printf("(C)CallbackCreate: self = 0x%08x\n", self);
#endif
hv_store((HV*) SvRV(self), "selfpos", 7, newSViv((long) cursor+3), 0);
*((int*)(cursor+3)) = (int) self;
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: SELF now is = 0x%08x\n", *((int*)(cursor+3)));
#endif
}
if(r == 7
&& *(cursor+3) == 0x02
&& *(cursor+4) == 0x00
&& *(cursor+5) == 0xDE
&& *(cursor+6) == 0xC0) {
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: FOUND NPARAMS 0x%08x...\n", cursor+3);
printf("(C)CallbackCreate: NPARAMS = 0x%08x\n", nparams);
#endif
*((int*)(cursor+3)) = nparams;
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: NPARAMS now = 0x%08x\n", *((int*)(cursor+3)));
#endif
}
cursor += r;
if(r > 1) i += (r-1);
}
for(j=0; j<nparams; j++) {
if(params[j].t == T_STRUCTURE) {
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: COPYING SECTION section_PUSHS (%d bytes)\n", section_PUSHS);
#endif
memcpy( (void *) cursor, source + checkpoint_PUSHS, section_PUSHS );
displacement = cursor - (source + checkpoint_PUSHS);
for(i=0; i < section_PUSHS; i++) {
if(*(cursor+0) == 0x8B
&& *(cursor+1) == 0x15
&& *((int*)(cursor+2)) == (int) &fakeint
) {
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: FOUND THE SVPV at 0x%x\n", cursor);
printf("(C)CallbackCreate: writing EBP+%02Xh\n", ebpcounter);
#endif
*(cursor+0) = 0x8B;
*(cursor+1) = 0x55;
*(cursor+2) = ebpcounter;
*(cursor+3) = 0x90; // nop
*(cursor+4) = 0x90; // nop
*(cursor+5) = 0x90; // nop
cursor += 5;
i += 4;
} else
if(*(cursor+0) == 0xC7
&& *(cursor+1) == 0x45
&& *(cursor+2) == 0xEC
&& *((int*)(cursor+3)) == 0xC0DE0003
) {
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: FOUND NPARAM at 0x%x\n", cursor);
printf("(C)CallbackCreate: writing = 0x%08X\n", j);
#endif
*((int*)(cursor+3)) = j;
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: NPARAM now is = 0x%08X\n", *((int*)(cursor+3)));
#endif
cursor += 6;
i += 5;
} else {
r = RelocateCode(cursor, displacement);
cursor += r;
if(r > 1) i += (r-1);
}
}
}
if(params[j].t == T_NUMBER) {
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: COPYING SECTION section_PUSHI (%d bytes)\n", section_PUSHI);
#endif
memcpy( (void *) cursor, source + checkpoint_PUSHI, section_PUSHI );
displacement = cursor - (source + checkpoint_PUSHI);
for(i=0; i < section_PUSHI; i++) {
if(*(cursor+0) == 0x8B
&& *(cursor+1) == 0x15
&& *((int*)(cursor+2)) == (int) &fakeint
) {
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: FOUND THE SVIV at 0x%x\n", cursor);
printf("(C)CallbackCreate: writing EBP+%02Xh\n", ebpcounter);
#endif
*(cursor+0) = 0x8B;
*(cursor+1) = 0x55;
*(cursor+2) = ebpcounter;
*(cursor+3) = 0x90; // push ecx
*(cursor+4) = 0x90; // push esi
*(cursor+5) = 0x90; // pop esi
cursor += 5;
i += 4;
} else
if(*(cursor+0) == 0xC7
&& *(cursor+1) == 0x45
&& *(cursor+2) == 0xEC
&& *((int*)(cursor+3)) == 0xC0DE0003
) {
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: FOUND NPARAM at 0x%x\n", cursor);
printf("(C)CallbackCreate: writing = 0x%08X\n", j);
#endif
*((int*)(cursor+3)) = j;
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: NPARAM now is = 0x%08X\n", *((int*)(cursor+3)));
#endif
cursor += 6;
i += 5;
} else {
r = RelocateCode(cursor, displacement);
cursor += r;
if(r > 1) i += (r-1);
}
}
}
if(params[j].t == T_POINTER) {
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: COPYING SECTION section_PUSHP (%d bytes)\n", section_PUSHP);
#endif
memcpy( (void *) cursor, source + checkpoint_PUSHP, section_PUSHP );
displacement = cursor - (source + checkpoint_PUSHP);
for(i=0; i < section_PUSHP; i++) {
if(*(cursor+0) == 0x8B
&& *(cursor+1) == 0x15
&& *((int*)(cursor+2)) == (int) &fakeint
) {
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: FOUND THE SVPV at 0x%x\n", cursor);
printf("(C)CallbackCreate: writing EBP+%02Xh\n", ebpcounter);
#endif
*(cursor+0) = 0x8B;
*(cursor+1) = 0x55;
*(cursor+2) = ebpcounter;
*(cursor+3) = 0x90; // nop
*(cursor+4) = 0x90; // nop
*(cursor+5) = 0x90; // nop
cursor += 5;
i += 4;
} else
if(*(cursor+0) == 0xC7
&& *(cursor+1) == 0x45
&& *(cursor+2) == 0xEC
&& *((int*)(cursor+3)) == 0xC0DE0003
) {
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: FOUND NPARAM at 0x%x\n", cursor);
printf("(C)CallbackCreate: writing = 0x%08X\n", j);
#endif
*((int*)(cursor+3)) = j;
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: NPARAM now is = 0x%08X\n", *((int*)(cursor+3)));
#endif
cursor += 6;
i += 5;
} else {
r = RelocateCode(cursor, displacement);
cursor += r;
if(r > 1) i += (r-1);
}
}
}
ebpcounter += 4;
}
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: COPYING SECTION section_END (%d bytes) at 0x%08x\n", section_END, cursor);
#endif
memcpy( (void *) cursor, source + checkpoint_END, section_END );
displacement = cursor - (source + checkpoint_END);
for(i=0; i < section_END; i++) {
r = RelocateCode(cursor, displacement);
cursor += r;
if(r > 1) i += (r-1);
}
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: adjusting callback epilogue...\n");
#endif
// #### back up two bytes (leave/ret)
cursor -= 2;
// #### insert the callback epilogue
*(cursor+0) = 0x8B; // mov esp,ebp
*(cursor+1) = 0xE5;
*(cursor+2) = 0x5D; // pop ebp
*(cursor+3) = 0xC2; // ret + 2 bytes
*(cursor+4) = ebpcounter - 8;
*(cursor+5) = 0x00;
#ifdef WIN32_API_DEBUG
printf("(C)CallbackCreate: DONE!\n");
#endif
return code;
}
MODULE = Win32::API::Callback PACKAGE = Win32::API::Callback
PROTOTYPES: DISABLE
unsigned int
CallbackCreate(self)
SV* self
PREINIT:
APIPARAM *params;
int iParam;
long lParam;
float fParam;
double dParam;
char cParam;
char *pParam;
LPBYTE ppParam;
HV* obj;
SV** obj_sub;
SV* sub;
SV** obj_proto;
SV** obj_in;
SV** obj_out;
SV** obj_intypes;
SV** in_type;
AV* inlist;
AV* intypes;
int nin, tout, i;
CODE:
#ifdef WIN32_API_DEBUG
printf("(XS)CallbackCreate: got self='%s'\n", SvPV_nolen(self));
printf("(XS)CallbackCreate: self dump:\n");
sv_dump(self);
if(SvROK(self)) sv_dump(SvRV(self));
#endif
obj = (HV*) SvRV(self);
obj_in = hv_fetch(obj, "in", 2, FALSE);
obj_out = hv_fetch(obj, "out", 3, FALSE);
inlist = (AV*) SvRV(*obj_in);
nin = av_len(inlist);
#ifdef WIN32_API_DEBUG
printf("(XS)CallbackCreate: nin=%d\n", nin);
#endif
tout = SvIV(*obj_out);
#ifdef WIN32_API_DEBUG
printf("(XS)CallbackCreate: tout=%d\n", tout);
#endif
obj_sub = hv_fetch(obj, "sub", 3, FALSE);
sub = *obj_sub;
#ifdef WIN32_API_DEBUG
printf("(XS)CallbackCreate: self.sub='%s'\n", SvPV_nolen(sub));
printf("(XS)CallbackCreate: self.sub dump:\n");
sv_dump(sub);
if(SvROK(sub)) sv_dump(SvRV(sub));
#endif
EXTEND(SP, 1);
if(nin >= 0) {
params = (APIPARAM *) safemalloc((nin+1) * sizeof(APIPARAM));
for(i = 0; i <= nin; i++) {
in_type = av_fetch(inlist, i, 0);
params[i].t = SvIV(*in_type);
// params[i].t = T_NUMBER;
}
}
RETVAL = (unsigned int) CallbackCreate(nin+1, params, self, sub);
#ifdef WIN32_API_DEBUG
printf("(XS)CallbackCreate: got RETVAL=0x%08x\n", RETVAL);
#endif
if(nin > 0) safefree(params);
#ifdef WIN32_API_DEBUG
printf("(XS)CallbackCreate: returning to caller\n");
#endif
OUTPUT:
RETVAL
void
PushSelf(self)
SV* self
PREINIT:
HV* obj;
SV** obj_selfpos;
unsigned char *selfpos;
CODE:
#ifdef WIN32_API_DEBUG
printf("(XS)PushSelf: got self='%s' (SV=0x%08x)\n", SvPV_nolen(self), self);
#endif
obj = (HV*) SvRV(self);
obj_selfpos = hv_fetch(obj, "selfpos", 7, FALSE);
if(obj_selfpos != NULL) {
#ifdef WIN32_API_DEBUG
printf("(XS)PushSelf: obj_selfpos=0x%08x\n", SvIV(*obj_selfpos));
#endif
*((int*)SvIV(*obj_selfpos)) = (int) self;
}
void
DESTROY(self)
SV* self
PREINIT:
HV* obj;
SV** obj_code;
CODE:
obj = (HV*) SvRV(self);
obj_code = hv_fetch(obj, "code", 4, FALSE);
if(obj_code != NULL) free((unsigned char *) SvIV(*obj_code));
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -