Hook Winsock (?)

Newbie Spellweaver
Joined
Jun 1, 2014
Messages
48
Reaction score
2
Hey dudes!
Im looking for an good Tutorial to Hook the Winsock (send) function.
Its for an unprotected Game (no xtrap, watchdog ect) so i could easy inject a Dll.

But the Problem is i tried it once sadly it didnt worked so im looking for an not too OLD Tutorial.
It dosent matter if its C# or C++.

thanks!
 
Yeah well the Part it fails is at writing my hook i did all right but at the end the Client was frozen seems like something went into an infinite loop
 
Did you write your hook in inline ASM? Normal C(++) functions do a set-up and clean-up at the start and end respectively, and if you JMP to a function rather than CALL, it can **** up your entire app.

You need to mark your hook with __declspec(naked) if you use the method of replacing the first bytes with a JMP. I might be able to tell you what's causing it if I saw your code.
 
Code:
// dllmain.cpp : Definiert den Einstiegspunkt für die DLL-Anwendung.
#include "stdafx.h"
#include <winsock.h>
#include <detours.h>
#include <iostream>
using namespace std;
#pragma comment(lib,"detours")
#pragma comment(lib,"wsock32")


DETOUR_TRAMPOLINE(int WINAPI Real_recv(SOCKET a0, char* a1, int a2, int a3), recv);
int WINAPI custom_recv(SOCKET sock, char FAR* buf, int len, int flags);


BOOL APIENTRY DllMain( HMODULE hModule,
                       DWORD  ul_reason_for_call,
                       LPVOID lpReserved
					 )
{
	switch (ul_reason_for_call)
	{
	case DLL_PROCESS_ATTACH:
		DetourFunctionWithTrampoline((PBYTE)Real_recv, (PBYTE)custom_recv);;
		
	case DLL_THREAD_ATTACH:
	case DLL_THREAD_DETACH:
	case DLL_PROCESS_DETACH:
		DetourRemove((PBYTE)Real_recv, (PBYTE)custom_recv);
		break;
	}
	return TRUE;
}


int WINAPI custom_recv(SOCKET sock, char FAR* buf, int len, int flags)
{
	MessageBoxA(NULL, buf, "xy", MB_OK);
    
	//buf = "4"; //Change data before the program can read it
	return Real_recv(sock, buf, len, flags);
}

Injecting works but nothing happens^^ i didnt get any msgbox
btw its for the game last chaos
 
DllMain doesn't like you doing work inside its body. This is for good reason, because staying in DllMain will **** up the windows loader. My DllMain usually looks like this:

Code:
::BOOL WINAPI DllMain ( __in ::HMODULE hModule, __in ::DWORD dwReason, __in __reserved ::LPVOID lpvReserved )
{
        UNREFERENCED_PARAMETER(lpvReserved);

        if ( dwReason == DLL_PROCESS_ATTACH ) {
                ::DisableThreadLibraryCalls(hModule);
                ::HANDLE hThread = NULL;

                /* Create our initial program thread */
                if ( ( hThread = ::CreateThread(NULL, 0, (::LPTHREAD_START_ROUTINE)DllWork, (::HMODULE)hModule, 0, NULL) ) == NULL ) {
                        return FALSE;
                }
                /* Close our handle to the created thread. Good practice to close thread handles; this doesn't do anything to the thread. */
                 ::CloseHandle(hThread);
        }
        return TRUE;
}

Oh yeah, I write shitty C++. Anyway, try doing something like this with CreateThread and see if you have any luck.
 
Why did you downvote AngraMainyu?
At least he tried to help you, even when it did not in this case.

Tripped me up because his (original) code works for apps that use winsock32.dll or whatever. If they use ws2_32, you need a different header file so Detours can find the right recv function. Programs will crash if DllMain doesn't return before very long, which is what I thought was happening. Sure showed me. :zippy:
 
Back