-
Notifications
You must be signed in to change notification settings - Fork 643
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Use functions 'RhCreateStealthRemoteThread' to inject dll failed. #159
Comments
@slivermeteor did you have a chance to test that change? Did it work correctly for 64-bit targets? |
I have tried to use rbx to replace ebx.But it doesn't work correctly same
as using ebx.however, if you use rbx, the target process will trash when it
come back to the old rip not trash in the function 'WaitForSingleObject'.
Maybe, there are my other error code cause the use rbx trash.I will check my code
as fast as possible.I n the other hand, my machine is win10 x64 pro 14393.
2016年12月12日 上午6:44,"Justin Stenning" <notifications@github.com>写道:
… @slivermeteor <https://github.com/slivermeteor> did you have a chance to
test that change? Did it work correctly for 64-bit targets?
—
You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
<#159 (comment)>,
or mute the thread
<https://github.com/notifications/unsubscribe-auth/AT3Vn1j4IiBFJuFIKnGxS_mmj-vkykkkks5rHHzogaJpZM4LJFo3>
.
|
@spazzarama hello,do you still pay attention to this issuse. I have try to use the EasyHook original code to compile the Easyhook64.dll, then try to use it to install a remote hook.At the win7 64-bit to hook 64-bit targets,although the 'NativeInjectionEntryPoint' can be call success, the target will trash when it come back the old rip. At the win10 64-bit, it will tarsh in the 'WaitForSingleObject' at the 'StealthStub_ASM_x64' proc.So I think it is a bug of EasyHook. |
@slivermeteor thanks for posting your update. I'll test out your changes here as well. |
@slivermeteor thanks for you efforts in tracking this one down. I've tested the fix and it seems to work fine here too. Changes are committed to the develop branch. |
@spazzarama It's my pleasure that I can make a little contribution to this project. Since this bug was fixed, I will close this issuse. |
Recent day, I'm studying the EasyHook to installing a remote hook using EasyHook with C++.
![image](https://cloud.githubusercontent.com/assets/20829599/21055622/2ac919f2-be6d-11e6-9e5c-276051eccbc7.png)
But when I complete the function 'RhCreateStealthRemoteThread' and try to use it to install a remote hook, I find it can't work correctly. So I use the Windbg to debug the funtion. In the file 'HookSpecific_x64.asm', I find a bug in the functions 'StealthStub_ASM_x64'.
I think should use rbx to replac ebx.
The text was updated successfully, but these errors were encountered: