Skip to content

Commit 532afed

Browse files
committed
switched to rewolf-wow64ext
1 parent fb4e58d commit 532afed

23 files changed

+1803
-620
lines changed

contrib/rewolf-wow64ext/.gitignore

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
*.opensdf
2+
*.sdf
3+
*.suo
4+
*.obj
5+
*.ilk
6+
*.db
7+
*.user
8+
*.opendb
9+
*.pdb
10+
src/Release/*
11+
src/Debug/*
12+
sample/*.exe
13+
sample/*.dll
14+
sample/*.lib

contrib/rewolf-wow64ext/.hgignore

Whitespace-only changes.

contrib/rewolf-wow64ext/README.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
# rewolf-wow64ext
2+
WOW64Ext is a helper library for x86 programs that runs under WOW64 layer on x64 versions of Microsoft Windows operating systems. It enables x86 applications to read, write and enumerate memory of a native x64 applications. There is also possibility to call any x64 function from 64-bits version of NTDLL through a special function called X64Call(). As a bonus, wow64ext.h contains definitions of some structures that might be useful for programs that want to access PEB, TEB, TIB etc.
Lines changed: 180 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,180 @@
1+
--------------------------------------------------------------------------------
2+
Name....: WOW64Ext Library
3+
Author..: ReWolf
4+
Rel.Date: 12.I.2012
5+
Update..: 18.I.2017
6+
Version.: 1.0.0.9
7+
8+
9+
10+
www.....: http://blog.rewolf.pl
11+
--------------------------------------------------------------------------------
12+
13+
WOW64Ext is a helper library for x86 programs that runs under WOW64 layer on
14+
x64 versions of Microsoft Windows operating systems. It enables x86 applications
15+
to read, write and enumerate memory of a native x64 applications. There is also
16+
possibility to call any x64 function from 64-bits version of NTDLL through
17+
a special function called X64Call(). As a bonus, wow64ext.h contains definitions
18+
of some structures that might be useful for programs that want to access PEB,
19+
TEB, TIB etc.
20+
21+
Sample application that uses this library can be found in \sample\ directory, it
22+
is simple memory dumper.
23+
24+
--------------------------------------------------------------------------------
25+
26+
Functions:
27+
28+
--------------------------------------------------------------------------------
29+
30+
DWORD64 X64Call(DWORD64 func, int argC, ...);
31+
32+
Low level function that can call any x64 API from NTDLL.
33+
34+
func - address of x64 function, can be obtained by GetProcAddress64()
35+
argC - number of arguments that will be passed to the 'func'
36+
... - rest of arguments for 'func', all values should be casted to DWORD64
37+
38+
--------------------------------------------------------------------------------
39+
40+
DWORD64 GetModuleHandle64(wchar_t* lpModuleName);
41+
42+
Behaviour similar to x86 version of GetModuleHandle, but it looks for the module
43+
name in the list of loaded x64 libraries. Usually x86 processes under WOW64
44+
layer have four x64 libraries: ntdll.dll, wow64.dll, wow64cpu.dll and
45+
wow64win.dll
46+
47+
lpModuleName - unicode string that represents module name
48+
49+
--------------------------------------------------------------------------------
50+
51+
DWORD64 GetProcAddress64(DWORD64 hModule, char* funcName);
52+
53+
Behaviour similar to x86 version of GetProcAddress(), internally it uses x64
54+
version of LdrGetProcedureAddress() from NTDLL.
55+
56+
hModule - base of x64 module
57+
funcName - function name
58+
59+
--------------------------------------------------------------------------------
60+
61+
SIZE_T VirtualQueryEx64(HANDLE hProcess, DWORD64 lpAddress,
62+
MEMORY_BASIC_INFORMATION64* lpBuffer, SIZE_T dwLength)
63+
64+
Behaviour similar to x86 version of VirtualQueryEx(), internally it uses x64
65+
version of NtQueryVirtualMemory() from NTDLL.
66+
67+
hProcess - handle of the process, can be obtained by standard x86 version of
68+
OpenProcess() function
69+
lpAddress - base address of the region of pages to be queried
70+
lpBuffer - a pointer to a MEMORY_BASIC_INFORMATION64 structure, it is defined
71+
in the standard SDK headers
72+
dwLength - size of the buffer pointed to by the lpBuffer parameter
73+
74+
--------------------------------------------------------------------------------
75+
76+
DWORD64 VirtualAllocEx64(HANDLE hProcess, DWORD64 lpAddress, SIZE_T dwSize,
77+
DWORD flAllocationType, DWORD flProtect)
78+
79+
Behaviour similar to x86 version of VirtualAllocEx64(), internally it uses x64
80+
version of NtAllocateVirtualMemory() from NTDLL.
81+
82+
hProcess - handle of the process, can be obtained by standard x86
83+
version of OpenProcess() function
84+
lpAddress - desired base address of the region that will be allocated
85+
dwSize - size of the region that will be allocated
86+
flAllocationType - type of memory allocation
87+
flProtect - memory protection for the region
88+
89+
--------------------------------------------------------------------------------
90+
91+
BOOL VirtualFreeEx64(HANDLE hProcess, DWORD64 lpAddress, SIZE_T dwSize,
92+
DWORD dwFreeType)
93+
94+
Behaviour similar to x86 version of VirtualFreeEx64(), internally it uses x64
95+
version of NtFreeVirtualMemory() from NTDLL.
96+
97+
hProcess - handle of the process, can be obtained by standard x86 version of
98+
OpenProcess() function
99+
lpAddress - base address of the memory region to free
100+
dwSize - size (in bytes) of the memory region to free
101+
dwFreeType - type of free operation (MEM_RELEASE, MEM_DECOMMIT)
102+
103+
--------------------------------------------------------------------------------
104+
105+
BOOL VirtualProtectEx64(HANDLE hProcess, DWORD64 lpAddress, SIZE_T dwSize,
106+
DWORD flNewProtect, DWORD* lpflOldProtect);
107+
108+
Behaviour similar to x86 version of VirtualProtectEx64(), internally it uses
109+
x64 version of NtProtectVirtualMemory() from NTDLL.
110+
111+
hProcess - handle of the process, can be obtained by standard x86
112+
version of OpenProcess() function
113+
lpAddress - base address of the memory region that will have changed
114+
protection
115+
dwSize - size (in bytes) of the memory region that will have changed
116+
protection
117+
flNewProtect - the memory protection option (see MSDN)
118+
lpflOldProtect - pointer to the variable that receives old protection value
119+
120+
--------------------------------------------------------------------------------
121+
122+
BOOL ReadProcessMemory64(HANDLE hProcess, DWORD64 lpBaseAddress,
123+
LPVOID lpBuffer, SIZE_T nSize,
124+
SIZE_T *lpNumberOfBytesRead);
125+
126+
Behaviour similar to x86 version of ReadProcessMemory(), internally it uses x64
127+
version of NtReadVirtualMemory() from NTDLL.
128+
129+
hProcess - handle of the process, can be obtained by standard x86
130+
version of OpenProcess() function
131+
lpBaseAddress - base address of the region that will be read
132+
lpBuffer - output memory buffer for the read data
133+
nSize - number of bytes to be read
134+
lpNumberOfBytesRead - pointer to a variable that receives number of read bytes
135+
136+
--------------------------------------------------------------------------------
137+
138+
BOOL WriteProcessMemory64(HANDLE hProcess, DWORD64 lpBaseAddress,
139+
LPVOID lpBuffer, SIZE_T nSize,
140+
SIZE_T *lpNumberOfBytesWritten);
141+
142+
Behaviour similar to x86 version of WriteProcessMemory(), internally it uses x64
143+
version of NtWriteVirtualMemory() from NTDLL.
144+
145+
hProcess - handle of the process, can be obtained by standard x86
146+
version of OpenProcess() function
147+
lpBaseAddress - base address of the region that will be written
148+
lpBuffer - input memory buffer with the data to write
149+
nSize - number of bytes that will be written
150+
lpNumberOfBytesRead - pointer to variable that receives number of written bytes
151+
152+
--------------------------------------------------------------------------------
153+
154+
BOOL GetThreadContext64(HANDLE hThread, _CONTEXT64* lpContext);
155+
156+
Behaviour similar to x86 version of GetThreadContext(), internally it uses x64
157+
version of NtGetContextThread() from NTDLL. Definition of _CONTEXT64 can be
158+
found in wow64ext.h file.
159+
160+
hThread - handle of the process, can be obtained by standard x86
161+
version of OpenProcess() function
162+
lpContext - A pointer to a _CONTEXT64 structure that will receive
163+
context data from specified thread. Structure will be
164+
filled according to ContextFlags field.
165+
166+
--------------------------------------------------------------------------------
167+
168+
BOOL SetThreadContext64(HANDLE hThread, _CONTEXT64* lpContext);
169+
170+
Behaviour similar to x86 version of SetThreadContext(), internally it uses x64
171+
version of NtSetContextThread() from NTDLL. Definition of _CONTEXT64 can be
172+
found in wow64ext.h file.
173+
174+
hThread - handle of the process, can be obtained by standard x86
175+
version of OpenProcess() function
176+
lpContext - A pointer to a _CONTEXT64 structure that will be used
177+
to fill context data in specified thread. Structure will
178+
use only fields defined by ContextFlags.
179+
180+
--------------------------------------------------------------------------------

contrib/rewolf-wow64ext/lgpl-3.0.txt

Lines changed: 165 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,165 @@
1+
GNU LESSER GENERAL PUBLIC LICENSE
2+
Version 3, 29 June 2007
3+
4+
Copyright (C) 2007 Free Software Foundation, Inc. <http://fsf.org/>
5+
Everyone is permitted to copy and distribute verbatim copies
6+
of this license document, but changing it is not allowed.
7+
8+
9+
This version of the GNU Lesser General Public License incorporates
10+
the terms and conditions of version 3 of the GNU General Public
11+
License, supplemented by the additional permissions listed below.
12+
13+
0. Additional Definitions.
14+
15+
As used herein, "this License" refers to version 3 of the GNU Lesser
16+
General Public License, and the "GNU GPL" refers to version 3 of the GNU
17+
General Public License.
18+
19+
"The Library" refers to a covered work governed by this License,
20+
other than an Application or a Combined Work as defined below.
21+
22+
An "Application" is any work that makes use of an interface provided
23+
by the Library, but which is not otherwise based on the Library.
24+
Defining a subclass of a class defined by the Library is deemed a mode
25+
of using an interface provided by the Library.
26+
27+
A "Combined Work" is a work produced by combining or linking an
28+
Application with the Library. The particular version of the Library
29+
with which the Combined Work was made is also called the "Linked
30+
Version".
31+
32+
The "Minimal Corresponding Source" for a Combined Work means the
33+
Corresponding Source for the Combined Work, excluding any source code
34+
for portions of the Combined Work that, considered in isolation, are
35+
based on the Application, and not on the Linked Version.
36+
37+
The "Corresponding Application Code" for a Combined Work means the
38+
object code and/or source code for the Application, including any data
39+
and utility programs needed for reproducing the Combined Work from the
40+
Application, but excluding the System Libraries of the Combined Work.
41+
42+
1. Exception to Section 3 of the GNU GPL.
43+
44+
You may convey a covered work under sections 3 and 4 of this License
45+
without being bound by section 3 of the GNU GPL.
46+
47+
2. Conveying Modified Versions.
48+
49+
If you modify a copy of the Library, and, in your modifications, a
50+
facility refers to a function or data to be supplied by an Application
51+
that uses the facility (other than as an argument passed when the
52+
facility is invoked), then you may convey a copy of the modified
53+
version:
54+
55+
a) under this License, provided that you make a good faith effort to
56+
ensure that, in the event an Application does not supply the
57+
function or data, the facility still operates, and performs
58+
whatever part of its purpose remains meaningful, or
59+
60+
b) under the GNU GPL, with none of the additional permissions of
61+
this License applicable to that copy.
62+
63+
3. Object Code Incorporating Material from Library Header Files.
64+
65+
The object code form of an Application may incorporate material from
66+
a header file that is part of the Library. You may convey such object
67+
code under terms of your choice, provided that, if the incorporated
68+
material is not limited to numerical parameters, data structure
69+
layouts and accessors, or small macros, inline functions and templates
70+
(ten or fewer lines in length), you do both of the following:
71+
72+
a) Give prominent notice with each copy of the object code that the
73+
Library is used in it and that the Library and its use are
74+
covered by this License.
75+
76+
b) Accompany the object code with a copy of the GNU GPL and this license
77+
document.
78+
79+
4. Combined Works.
80+
81+
You may convey a Combined Work under terms of your choice that,
82+
taken together, effectively do not restrict modification of the
83+
portions of the Library contained in the Combined Work and reverse
84+
engineering for debugging such modifications, if you also do each of
85+
the following:
86+
87+
a) Give prominent notice with each copy of the Combined Work that
88+
the Library is used in it and that the Library and its use are
89+
covered by this License.
90+
91+
b) Accompany the Combined Work with a copy of the GNU GPL and this license
92+
document.
93+
94+
c) For a Combined Work that displays copyright notices during
95+
execution, include the copyright notice for the Library among
96+
these notices, as well as a reference directing the user to the
97+
copies of the GNU GPL and this license document.
98+
99+
d) Do one of the following:
100+
101+
0) Convey the Minimal Corresponding Source under the terms of this
102+
License, and the Corresponding Application Code in a form
103+
suitable for, and under terms that permit, the user to
104+
recombine or relink the Application with a modified version of
105+
the Linked Version to produce a modified Combined Work, in the
106+
manner specified by section 6 of the GNU GPL for conveying
107+
Corresponding Source.
108+
109+
1) Use a suitable shared library mechanism for linking with the
110+
Library. A suitable mechanism is one that (a) uses at run time
111+
a copy of the Library already present on the user's computer
112+
system, and (b) will operate properly with a modified version
113+
of the Library that is interface-compatible with the Linked
114+
Version.
115+
116+
e) Provide Installation Information, but only if you would otherwise
117+
be required to provide such information under section 6 of the
118+
GNU GPL, and only to the extent that such information is
119+
necessary to install and execute a modified version of the
120+
Combined Work produced by recombining or relinking the
121+
Application with a modified version of the Linked Version. (If
122+
you use option 4d0, the Installation Information must accompany
123+
the Minimal Corresponding Source and Corresponding Application
124+
Code. If you use option 4d1, you must provide the Installation
125+
Information in the manner specified by section 6 of the GNU GPL
126+
for conveying Corresponding Source.)
127+
128+
5. Combined Libraries.
129+
130+
You may place library facilities that are a work based on the
131+
Library side by side in a single library together with other library
132+
facilities that are not Applications and are not covered by this
133+
License, and convey such a combined library under terms of your
134+
choice, if you do both of the following:
135+
136+
a) Accompany the combined library with a copy of the same work based
137+
on the Library, uncombined with any other library facilities,
138+
conveyed under the terms of this License.
139+
140+
b) Give prominent notice with the combined library that part of it
141+
is a work based on the Library, and explaining where to find the
142+
accompanying uncombined form of the same work.
143+
144+
6. Revised Versions of the GNU Lesser General Public License.
145+
146+
The Free Software Foundation may publish revised and/or new versions
147+
of the GNU Lesser General Public License from time to time. Such new
148+
versions will be similar in spirit to the present version, but may
149+
differ in detail to address new problems or concerns.
150+
151+
Each version is given a distinguishing version number. If the
152+
Library as you received it specifies that a certain numbered version
153+
of the GNU Lesser General Public License "or any later version"
154+
applies to it, you have the option of following the terms and
155+
conditions either of that published version or of any later version
156+
published by the Free Software Foundation. If the Library as you
157+
received it does not specify a version number of the GNU Lesser
158+
General Public License, you may choose any version of the GNU Lesser
159+
General Public License ever published by the Free Software Foundation.
160+
161+
If the Library as you received it specifies that a proxy can decide
162+
whether future versions of the GNU Lesser General Public License shall
163+
apply, that proxy's public statement of acceptance of any version is
164+
permanent authorization for you to choose that version for the
165+
Library.
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
cl /Zi /D "UNICODE" ../bin/wow64ext.lib main.cpp

0 commit comments

Comments
 (0)