以前通常用修改hosts文件的方法,实现验证地址修改,但直接使用ip或dns查询代码的软件,修改hosts是无效的。
通过调试,发现某个软件请求验证前调用了inet_addr转换ip地址,通过hook inet_addr函数,实现了ip替换,网络验证转为本地验证。
unit APIHook;
interface
uses
SysUtils,
Windows, WinSock;
type
TSockProc =function (cp: PChar): DWord; stdcall;
PJmpCode = ^TJmpCode;
TJmpCode = packed record
JmpCode: BYTE;
Address: TSockProc;
MovEAX: Array [0..2] of BYTE;
end;
procedure HookAPI;
procedure UnHookAPI;
var
Oldinet_addr: TSockProc;
JmpCode: TJmpCode;
OldProc: array [0..1] of TJmpCode;
Addinet_addr: pointer; //API地址
TmpJmp: TJmpCode;
ProcessHandle: THandle;
implementation
{---------------------------------------}
{函数功能:inet_addr函数的HOOK
{函数参数:同inet_addr
{函数返回值:DWord
{---------------------------------------}
function Myinet_addr(cp: PChar): DWord; stdcall;
begin
if cp= '121.14.34.50' then //原验证地址
begin
cp:=pchar('127.0.0.1'); //替换ip
end;
WriteProcessMemory(ProcessHandle, Addinet_addr, @OldProc[0], 8, dwSize);
Result := Oldinet_addr(cp);
JmpCode.Address := @Myinet_addr;
WriteProcessMemory(ProcessHandle, Addinet_addr, @JmpCode, 8, dwSize);
end;
{------------------------------------}
{过程功能:HookAPI
{过程参数:无
{------------------------------------}
procedure HookAPI;
var
DLLModule: THandle;
dwSize: cardinal;
begin
ProcessHandle := GetCurrentProcess;
DLLModule := LoadLibrary('ws2_32.dll');
Addinet_addr := GetProcAddress(DLLModule, 'inet_addr'); //取得API地址
JmpCode.JmpCode := $B8;
JmpCode.MovEAX[0] := $FF;
JmpCode.MovEAX[1] := $E0;
JmpCode.MovEAX[2] := 0;
ReadProcessMemory(ProcessHandle, Addinet_addr, @OldProc[0], 8, dwSize);
JmpCode.Address := @Myinet_addr;
WriteProcessMemory(ProcessHandle, Addinet_addr, @JmpCode, 8, dwSize); //修改inet_addr入口
Oldinet_addr := Addinet_addr;
end;
{------------------------------------}
{过程功能:取消HOOKAPI
{过程参数:无
{------------------------------------}
procedure UnHookAPI;
var
dwSize: Cardinal;
begin
WriteProcessMemory(ProcessHandle, Addinet_addr, @OldProc[0], 8, dwSize);
end;
end.
调用
procedure TForm1.Button1Click(Sender: TObject);
var
ModuleHandle: THandle;
TmpWndHandle: THandle;
begin
TmpWndHandle := FindWindow(pchar('WindowsForms10.Window.8.app.0.378734a'), nil); //目标程序窗口
if not isWindow(TmpWndHandle) then
begin
MessageBox(self.Handle, '没有找到窗口', '!!!', MB_OK);
exit;
end;
ModuleHandle := LoadLibrary('Hook.dll');
@InstallHook := GetProcAddress(ModuleHandle, 'InstallHook');
@UnHook := GetProcAddress(ModuleHandle, 'UnHook');
if InstallHook(TmpWndHandle) then
ShowMessage('Hook OK');
end;
也可以hook connect函数实现ip转向
function MyConnect(s:TSocket;var sa:TSockAddr;len:integer):integer;stdcall;
var dwSize: cardinal;
begin
if sa.sin_port=htons(6666) then //符合条件,处理
begin
sa.sin_addr.S_addr:=Inet_addr('127.0.0.1'); //这儿连接转向
end;
WriteProcessMemory(ProcessHandle, NewConn, @OldConnProc, 8, dwSize);
Result:=OldConn(s,sa,len);
JmpConnCode.Address:=@MyConnect;
WriteProcessMemory(ProcessHandle, NewConn, @JmpConnCode, 8, dwSize);
end;