gpt4 book ai didi

c++ - VirtualProtect 和 kernel32.dll - 尝试访问无效地址

转载 作者:可可西里 更新时间:2023-11-01 12:43:44 27 4
gpt4 key购买 nike

我正在分析进程加载的各种模块。不幸的是,我无法创建 kernel32.dll 内存快照,尽管该函数可以与其他模块(例如 ntddl.dll)一起正常工作。问题在于以下代码:

/* Copy code from memory  */
if (VirtualProtect((BYTE*)virtualAddress, sizeOfCode, PAGE_EXECUTE_READWRITE, &flags) == 0) {
std::cout << "VirtualProtect failed!" << std::endl;
std::cout << "Virtual address: " << virtualAddress << std::endl;
std::cout << "Size of code: " << sizeOfCode << std::endl;
std::cout << "Error code: " << GetLastError() << std::endl;
}

kernel32.dll 调用这段代码的结果是:

Virtual address: 747d0000
Size of code: 6a000
Error code: 0x1e7

错误描述是这样说的:

ERROR_INVALID_ADDRESS
487 (0x1E7)
Attempt to access invalid address.

我检查了进程的内存映射和 kernel32.dll 地址是正确的。这是什么原因?

最佳答案

很难验证您的地址是否正确,它异常低。我刚刚写了另一个程序来测试这个。它枚举 kernel32.dll 中的区域并对它们调用 VirtualProtect():

#include <Windows.h>
#include <assert.h>
#include <iostream>


int main()
{
HMODULE hmod = GetModuleHandle(L"kernel32.dll");
MEMORY_BASIC_INFORMATION info;
// Start at PE32 header
SIZE_T len = VirtualQuery(hmod, &info, sizeof(info));
assert(len > 0);
BYTE* dllBase = (BYTE*)info.AllocationBase;
BYTE* address = dllBase;
for (;;) {
len = VirtualQuery(address, &info, sizeof(info));
assert(len > 0);
if (info.AllocationBase != dllBase) break;
std::cout << "Address: " << std::hex << info.BaseAddress;
std::cout << " (" << std::hex << info.RegionSize << ") ";
std::cout << " protect = " << std::hex << info.Protect;
DWORD oldprotect;
if (info.Protect == 0) std::cout << ", VirtualProtect skipped" << std::endl;
else {
BOOL ok = VirtualProtect(info.BaseAddress, info.RegionSize, PAGE_EXECUTE_READWRITE, &oldprotect);
std::cout << ", VirtualProtect = " << (ok ? "okay" : "Failed!") << std::endl;
}
address = (BYTE*)info.BaseAddress + info.RegionSize;
}
return 0;
}

此程序在我的机器上的输出,运行 Windows 8.1 x64:

Address: 77470000 (1000)  protect = 2, VirtualProtect = okay
Address: 77471000 (f000) protect = 0, VirtualProtect skipped
Address: 77480000 (62000) protect = 20, VirtualProtect = okay
Address: 774E2000 (e000) protect = 0, VirtualProtect skipped
Address: 774F0000 (7e000) protect = 2, VirtualProtect = okay
Address: 7756E000 (2000) protect = 0, VirtualProtect skipped
Address: 77570000 (1000) protect = 4, VirtualProtect = okay
Address: 77571000 (f000) protect = 0, VirtualProtect skipped
Address: 77580000 (1000) protect = 2, VirtualProtect = okay
Address: 77581000 (f000) protect = 0, VirtualProtect skipped
Address: 77590000 (1a000) protect = 2, VirtualProtect = okay
Address: 775AA000 (6000) protect = 0, VirtualProtect skipped

在 64 位模式下运行:

Address: 00007FFC4F870000 (1000)  protect = 2, VirtualProtect = okay
Address: 00007FFC4F871000 (112000) protect = 20, VirtualProtect = okay
Address: 00007FFC4F983000 (1000) protect = 4, VirtualProtect = okay
Address: 00007FFC4F984000 (1000) protect = 8, VirtualProtect = okay
Address: 00007FFC4F985000 (24000) protect = 2, VirtualProtect = okay

很明显,您的 Windows 版本不同,因此请务必在您的计算机上运行该程序以获得可比较的结果。

我得出的结论是,这种代码失败没有根本原因。如果它在您的机器上发生,那很可能是环境问题。有一个非常明显的候选者是您的反恶意软件,这当然在防止代码与 kernel32.dll 混淆方面有很大的利害关系。我在我的机器上运行最低限度的保护。

关于c++ - VirtualProtect 和 kernel32.dll - 尝试访问无效地址,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/20303380/

27 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com