插APC驱动读写

//插APC温柔读内存
BOOLEAN APCReadProcessMemory(ULONG PID, PVOID targetaddress, ULONG length, PVOID retdata)
{
	PEPROCESS pepro;
	KAPC_STATE kapc = { 0 };
	pepro = LookupProcess((HANDLE)PID);
	if (pepro == NULL)
		return FALSE;
	ObDereferenceObject(pepro);
	__try
	{
		KeStackAttachProcess(pepro, &kapc);
		ProbeForRead(targetaddress, length, sizeof(CHAR));
		RtlCopyMemory(retdata, targetaddress, length);
		KeUnstackDetachProcess(&kapc);
	}
	__except (EXCEPTION_EXECUTE_HANDLER)
	{
		KeUnstackDetachProcess(&kapc);
		return FALSE;
	}	
	return TRUE;
}


//插APC温柔写内存
BOOLEAN APCWriteProcessMemory(ULONG PID, PVOID targetaddress, ULONG length, PVOID Indata)
{
	PEPROCESS pepro;
	KAPC_STATE kapc = { 0 };
	pepro = LookupProcess((HANDLE)PID);
	if (pepro == NULL)
		return FALSE;
	ObDereferenceObject(pepro);
	ULONG64 Cr0;
	__try
	{
		KeStackAttachProcess(pepro, &kapc);
		ProbeForWrite(targetaddress, length, sizeof(CHAR));
		_disable();
		Cr0 = __readcr0();
		Cr0 &= 0xfffffffffffeffff;
		__writecr0(Cr0);
		_enable();
		memcpy(targetaddress, Indata, length);
		_disable();
		Cr0 |= 10000;
		__writecr0(Cr0);
		_enable();
		KeUnstackDetachProcess(&kapc);
	}
	__except (EXCEPTION_EXECUTE_HANDLER)
	{
		_disable();
		Cr0 |= 10000;
		__writecr0(Cr0);
		_enable();
		KeUnstackDetachProcess(&kapc);
		return FALSE;
	}
	return TRUE;
}

 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值