Вы не можете выбрать более 25 тем Темы должны начинаться с буквы или цифры, могут содержать дефисы(-) и должны содержать не более 35 символов.

410 lines
9.3KB

  1. /**
  2. *
  3. * WOW64Ext Library
  4. *
  5. * Copyright (c) 2014 ReWolf
  6. * http://blog.rewolf.pl/
  7. *
  8. * This program is free software: you can redistribute it and/or modify
  9. * it under the terms of the GNU Lesser General Public License as published
  10. * by the Free Software Foundation, either version 3 of the License, or
  11. * (at your option) any later version.
  12. *
  13. * This program is distributed in the hope that it will be useful,
  14. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  15. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  16. * GNU Lesser General Public License for more details.
  17. *
  18. * You should have received a copy of the GNU Lesser General Public License
  19. * along with this program. If not, see <http://www.gnu.org/licenses/>.
  20. *
  21. */
  22. #pragma once
  23. #ifndef STATUS_SUCCESS
  24. # define STATUS_SUCCESS 0
  25. #endif
  26. #pragma pack(push)
  27. #pragma pack(1)
  28. template <class T>
  29. struct _LIST_ENTRY_T
  30. {
  31. T Flink;
  32. T Blink;
  33. };
  34. template <class T>
  35. struct _UNICODE_STRING_T
  36. {
  37. union
  38. {
  39. struct
  40. {
  41. WORD Length;
  42. WORD MaximumLength;
  43. };
  44. T dummy;
  45. };
  46. T Buffer;
  47. };
  48. template <class T>
  49. struct _NT_TIB_T
  50. {
  51. T ExceptionList;
  52. T StackBase;
  53. T StackLimit;
  54. T SubSystemTib;
  55. T FiberData;
  56. T ArbitraryUserPointer;
  57. T Self;
  58. };
  59. template <class T>
  60. struct _CLIENT_ID_T
  61. {
  62. T UniqueProcess;
  63. T UniqueThread;
  64. };
  65. template <class T>
  66. struct _TEB_T_
  67. {
  68. _NT_TIB_T<T> NtTib;
  69. T EnvironmentPointer;
  70. _CLIENT_ID_T<T> ClientId;
  71. T ActiveRpcHandle;
  72. T ThreadLocalStoragePointer;
  73. T ProcessEnvironmentBlock;
  74. DWORD LastErrorValue;
  75. DWORD CountOfOwnedCriticalSections;
  76. T CsrClientThread;
  77. T Win32ThreadInfo;
  78. DWORD User32Reserved[26];
  79. //rest of the structure is not defined for now, as it is not needed
  80. };
  81. template <class T>
  82. struct _LDR_DATA_TABLE_ENTRY_T
  83. {
  84. _LIST_ENTRY_T<T> InLoadOrderLinks;
  85. _LIST_ENTRY_T<T> InMemoryOrderLinks;
  86. _LIST_ENTRY_T<T> InInitializationOrderLinks;
  87. T DllBase;
  88. T EntryPoint;
  89. union
  90. {
  91. DWORD SizeOfImage;
  92. T dummy01;
  93. };
  94. _UNICODE_STRING_T<T> FullDllName;
  95. _UNICODE_STRING_T<T> BaseDllName;
  96. DWORD Flags;
  97. WORD LoadCount;
  98. WORD TlsIndex;
  99. union
  100. {
  101. _LIST_ENTRY_T<T> HashLinks;
  102. struct
  103. {
  104. T SectionPointer;
  105. T CheckSum;
  106. };
  107. };
  108. union
  109. {
  110. T LoadedImports;
  111. DWORD TimeDateStamp;
  112. };
  113. T EntryPointActivationContext;
  114. T PatchInformation;
  115. _LIST_ENTRY_T<T> ForwarderLinks;
  116. _LIST_ENTRY_T<T> ServiceTagLinks;
  117. _LIST_ENTRY_T<T> StaticLinks;
  118. T ContextInformation;
  119. T OriginalBase;
  120. _LARGE_INTEGER LoadTime;
  121. };
  122. template <class T>
  123. struct _PEB_LDR_DATA_T
  124. {
  125. DWORD Length;
  126. DWORD Initialized;
  127. T SsHandle;
  128. _LIST_ENTRY_T<T> InLoadOrderModuleList;
  129. _LIST_ENTRY_T<T> InMemoryOrderModuleList;
  130. _LIST_ENTRY_T<T> InInitializationOrderModuleList;
  131. T EntryInProgress;
  132. DWORD ShutdownInProgress;
  133. T ShutdownThreadId;
  134. };
  135. template <class T, class NGF, int A>
  136. struct _PEB_T
  137. {
  138. union
  139. {
  140. struct
  141. {
  142. BYTE InheritedAddressSpace;
  143. BYTE ReadImageFileExecOptions;
  144. BYTE BeingDebugged;
  145. BYTE BitField;
  146. };
  147. T dummy01;
  148. };
  149. T Mutant;
  150. T ImageBaseAddress;
  151. T Ldr;
  152. T ProcessParameters;
  153. T SubSystemData;
  154. T ProcessHeap;
  155. T FastPebLock;
  156. T AtlThunkSListPtr;
  157. T IFEOKey;
  158. T CrossProcessFlags;
  159. T UserSharedInfoPtr;
  160. DWORD SystemReserved;
  161. DWORD AtlThunkSListPtr32;
  162. T ApiSetMap;
  163. T TlsExpansionCounter;
  164. T TlsBitmap;
  165. DWORD TlsBitmapBits[2];
  166. T ReadOnlySharedMemoryBase;
  167. T HotpatchInformation;
  168. T ReadOnlyStaticServerData;
  169. T AnsiCodePageData;
  170. T OemCodePageData;
  171. T UnicodeCaseTableData;
  172. DWORD NumberOfProcessors;
  173. union
  174. {
  175. DWORD NtGlobalFlag;
  176. NGF dummy02;
  177. };
  178. LARGE_INTEGER CriticalSectionTimeout;
  179. T HeapSegmentReserve;
  180. T HeapSegmentCommit;
  181. T HeapDeCommitTotalFreeThreshold;
  182. T HeapDeCommitFreeBlockThreshold;
  183. DWORD NumberOfHeaps;
  184. DWORD MaximumNumberOfHeaps;
  185. T ProcessHeaps;
  186. T GdiSharedHandleTable;
  187. T ProcessStarterHelper;
  188. T GdiDCAttributeList;
  189. T LoaderLock;
  190. DWORD OSMajorVersion;
  191. DWORD OSMinorVersion;
  192. WORD OSBuildNumber;
  193. WORD OSCSDVersion;
  194. DWORD OSPlatformId;
  195. DWORD ImageSubsystem;
  196. DWORD ImageSubsystemMajorVersion;
  197. T ImageSubsystemMinorVersion;
  198. T ActiveProcessAffinityMask;
  199. T GdiHandleBuffer[A];
  200. T PostProcessInitRoutine;
  201. T TlsExpansionBitmap;
  202. DWORD TlsExpansionBitmapBits[32];
  203. T SessionId;
  204. ULARGE_INTEGER AppCompatFlags;
  205. ULARGE_INTEGER AppCompatFlagsUser;
  206. T pShimData;
  207. T AppCompatInfo;
  208. _UNICODE_STRING_T<T> CSDVersion;
  209. T ActivationContextData;
  210. T ProcessAssemblyStorageMap;
  211. T SystemDefaultActivationContextData;
  212. T SystemAssemblyStorageMap;
  213. T MinimumStackCommit;
  214. T FlsCallback;
  215. _LIST_ENTRY_T<T> FlsListHead;
  216. T FlsBitmap;
  217. DWORD FlsBitmapBits[4];
  218. T FlsHighIndex;
  219. T WerRegistrationData;
  220. T WerShipAssertPtr;
  221. T pContextData;
  222. T pImageHeaderHash;
  223. T TracingFlags;
  224. };
  225. typedef _LDR_DATA_TABLE_ENTRY_T<DWORD> LDR_DATA_TABLE_ENTRY32;
  226. typedef _LDR_DATA_TABLE_ENTRY_T<DWORD64> LDR_DATA_TABLE_ENTRY64;
  227. typedef _TEB_T_<DWORD> TEB32;
  228. typedef _TEB_T_<DWORD64> TEB64;
  229. typedef _PEB_LDR_DATA_T<DWORD> PEB_LDR_DATA32;
  230. typedef _PEB_LDR_DATA_T<DWORD64> PEB_LDR_DATA64;
  231. typedef _PEB_T<DWORD, DWORD64, 34> PEB32;
  232. //typedef _PEB_T<DWORD64, DWORD, 30> PEB64;
  233. struct _XSAVE_FORMAT64
  234. {
  235. WORD ControlWord;
  236. WORD StatusWord;
  237. BYTE TagWord;
  238. BYTE Reserved1;
  239. WORD ErrorOpcode;
  240. DWORD ErrorOffset;
  241. WORD ErrorSelector;
  242. WORD Reserved2;
  243. DWORD DataOffset;
  244. WORD DataSelector;
  245. WORD Reserved3;
  246. DWORD MxCsr;
  247. DWORD MxCsr_Mask;
  248. _M128A FloatRegisters[8];
  249. _M128A XmmRegisters[16];
  250. BYTE Reserved4[96];
  251. };
  252. struct _CONTEXT64
  253. {
  254. DWORD64 P1Home;
  255. DWORD64 P2Home;
  256. DWORD64 P3Home;
  257. DWORD64 P4Home;
  258. DWORD64 P5Home;
  259. DWORD64 P6Home;
  260. DWORD ContextFlags;
  261. DWORD MxCsr;
  262. WORD SegCs;
  263. WORD SegDs;
  264. WORD SegEs;
  265. WORD SegFs;
  266. WORD SegGs;
  267. WORD SegSs;
  268. DWORD EFlags;
  269. DWORD64 Dr0;
  270. DWORD64 Dr1;
  271. DWORD64 Dr2;
  272. DWORD64 Dr3;
  273. DWORD64 Dr6;
  274. DWORD64 Dr7;
  275. DWORD64 Rax;
  276. DWORD64 Rcx;
  277. DWORD64 Rdx;
  278. DWORD64 Rbx;
  279. DWORD64 Rsp;
  280. DWORD64 Rbp;
  281. DWORD64 Rsi;
  282. DWORD64 Rdi;
  283. DWORD64 R8;
  284. DWORD64 R9;
  285. DWORD64 R10;
  286. DWORD64 R11;
  287. DWORD64 R12;
  288. DWORD64 R13;
  289. DWORD64 R14;
  290. DWORD64 R15;
  291. DWORD64 Rip;
  292. _XSAVE_FORMAT64 FltSave;
  293. _M128A Header[2];
  294. _M128A Legacy[8];
  295. _M128A Xmm0;
  296. _M128A Xmm1;
  297. _M128A Xmm2;
  298. _M128A Xmm3;
  299. _M128A Xmm4;
  300. _M128A Xmm5;
  301. _M128A Xmm6;
  302. _M128A Xmm7;
  303. _M128A Xmm8;
  304. _M128A Xmm9;
  305. _M128A Xmm10;
  306. _M128A Xmm11;
  307. _M128A Xmm12;
  308. _M128A Xmm13;
  309. _M128A Xmm14;
  310. _M128A Xmm15;
  311. _M128A VectorRegister[26];
  312. DWORD64 VectorControl;
  313. DWORD64 DebugControl;
  314. DWORD64 LastBranchToRip;
  315. DWORD64 LastBranchFromRip;
  316. DWORD64 LastExceptionToRip;
  317. DWORD64 LastExceptionFromRip;
  318. };
  319. // Below defines for .ContextFlags field are taken from WinNT.h
  320. #ifndef CONTEXT_AMD64
  321. #define CONTEXT_AMD64 0x100000
  322. #endif
  323. #define CONTEXT64_CONTROL (CONTEXT_AMD64 | 0x1L)
  324. #define CONTEXT64_INTEGER (CONTEXT_AMD64 | 0x2L)
  325. #define CONTEXT64_SEGMENTS (CONTEXT_AMD64 | 0x4L)
  326. #define CONTEXT64_FLOATING_POINT (CONTEXT_AMD64 | 0x8L)
  327. #define CONTEXT64_DEBUG_REGISTERS (CONTEXT_AMD64 | 0x10L)
  328. #define CONTEXT64_FULL (CONTEXT64_CONTROL | CONTEXT64_INTEGER | CONTEXT64_FLOATING_POINT)
  329. #define CONTEXT64_ALL (CONTEXT64_CONTROL | CONTEXT64_INTEGER | CONTEXT64_SEGMENTS | CONTEXT64_FLOATING_POINT | CONTEXT64_DEBUG_REGISTERS)
  330. #define CONTEXT64_XSTATE (CONTEXT_AMD64 | 0x20L)
  331. // My changes
  332. template <class T>
  333. struct _OBJECT_ATTRIBUTES_T
  334. {
  335. union
  336. {
  337. ULONG uLength;
  338. T dummy;
  339. };
  340. T hRootDirectory;
  341. T pObjectName;
  342. union
  343. {
  344. ULONG uAttributes;
  345. T dummy2;
  346. };
  347. T pSecurityDescriptor;
  348. T pSecurityQualityOfService;
  349. };
  350. template <class T>
  351. struct _HANDLE_T
  352. {
  353. T h;
  354. };
  355. /* Extremly weird. sizeof(IO_STATUS_BLOCK) == 8 on x86 & x64.
  356. However NtCreateFile doesn't seem to agree
  357. UNICODE_STRING filename = {0};
  358. RtlInitUnicodeString(&filename, L"\\??\\D:\\abc.txt");
  359. OBJECT_ATTRIBUTES obja = {0};
  360. IO_STATUS_BLOCK iostatusblock = {0};
  361. InitializeObjectAttributes(&obja, &filename, OBJ_CASE_INSENSITIVE, NULL, NULL);
  362. HANDLE h = INVALID_HANDLE_VALUE;
  363. NTSTATUS stat = NtCreateFile(&h, FILE_READ_DATA | FILE_WRITE_DATA | SYNCHRONIZE,
  364. &obja, &iostatusblock,
  365. NULL, FILE_ATTRIBUTE_NORMAL, FILE_SHARE_READ, FILE_OVERWRITE_IF,
  366. FILE_NON_DIRECTORY_FILE | FILE_SYNCHRONOUS_IO_NONALERT, NULL, 0);
  367. Run in Debug mode and see Run-Time Check Failure #2 - Stack around the variable 'iostatusblock' was corrupted.
  368. */
  369. template <class T>
  370. struct _IO_STATUS_BLOCK_T
  371. {
  372. union
  373. {
  374. NTSTATUS Status;
  375. T dummy;
  376. };
  377. union
  378. {
  379. ULONG uInformation;
  380. T dummy;
  381. };
  382. };
  383. #pragma pack(pop)