|
|
dd89bb |
/********************************************************/
|
|
|
dd89bb |
/* ntapi: Native API core library */
|
|
|
dd89bb |
/* Copyright (C) 2013,2014,2015 Z. Gilboa */
|
|
|
dd89bb |
/* Released under GPLv2 and GPLv3; see COPYING.NTAPI. */
|
|
|
dd89bb |
/********************************************************/
|
|
|
dd89bb |
|
|
|
dd89bb |
#include <psxtypes/psxtypes.h>
|
|
|
dd89bb |
#include <ntapi/nt_memory.h>
|
|
|
dd89bb |
#include <ntapi/nt_process.h>
|
|
|
dd89bb |
#include <ntapi/ntapi.h>
|
|
|
dd89bb |
#include "ntapi_impl.h"
|
|
|
dd89bb |
|
|
|
dd89bb |
typedef struct _nt_process_basic_information nt_pbi;
|
|
|
dd89bb |
|
|
|
dd89bb |
int32_t __stdcall __ntapi_tt_create_remote_runtime_data(
|
|
|
dd89bb |
__in void * hprocess,
|
|
|
dd89bb |
__in_out nt_runtime_data_block * rtblock)
|
|
|
dd89bb |
{
|
|
|
dd89bb |
int32_t status;
|
|
|
dd89bb |
|
|
|
dd89bb |
size_t bytes_written;
|
|
|
dd89bb |
nt_pbi rpbi;
|
|
|
dd89bb |
nt_process_parameters * rprocess_params;
|
|
|
dd89bb |
nt_unicode_string rcmd_line;
|
|
|
dd89bb |
uint32_t runtime_arg_hash;
|
|
|
dd89bb |
nt_runtime_data * rtdata;
|
|
|
dd89bb |
void * srv_ready;
|
|
|
dd89bb |
|
|
|
dd89bb |
#if defined (__NT32)
|
|
|
dd89bb |
wchar16_t runtime_arg[8] = {
|
|
|
dd89bb |
'i','n','t','e','g','r','a','l'};
|
|
|
dd89bb |
#elif defined (__NT64)
|
|
|
dd89bb |
wchar16_t runtime_arg[16] = {
|
|
|
dd89bb |
'i','n','t','e','g','r','a','l',
|
|
|
dd89bb |
'-','r','u','n','t','i','m','e'};
|
|
|
dd89bb |
#endif
|
|
|
dd89bb |
|
|
|
dd89bb |
/* validation */
|
|
|
dd89bb |
if (!hprocess)
|
|
|
dd89bb |
return NT_STATUS_INVALID_PARAMETER_1;
|
|
|
dd89bb |
else if (!rtblock)
|
|
|
dd89bb |
return NT_STATUS_INVALID_PARAMETER_2;
|
|
|
dd89bb |
else if (!rtblock->addr)
|
|
|
dd89bb |
return NT_STATUS_INVALID_PARAMETER_2;
|
|
|
dd89bb |
else if (!rtblock->size)
|
|
|
dd89bb |
return NT_STATUS_INVALID_PARAMETER_2;
|
|
|
dd89bb |
|
|
|
dd89bb |
runtime_arg_hash = __ntapi->tt_buffer_crc32(
|
|
|
dd89bb |
0,
|
|
|
dd89bb |
(char *)runtime_arg,
|
|
|
dd89bb |
sizeof(runtime_arg));
|
|
|
dd89bb |
|
|
|
dd89bb |
/* obtain process information */
|
|
|
dd89bb |
status = __ntapi->zw_query_information_process(
|
|
|
dd89bb |
hprocess,
|
|
|
dd89bb |
NT_PROCESS_BASIC_INFORMATION,
|
|
|
dd89bb |
(void *)&rpbi,
|
|
|
dd89bb |
sizeof(nt_process_basic_information),
|
|
|
dd89bb |
0);
|
|
|
dd89bb |
|
|
|
dd89bb |
if (status != NT_STATUS_SUCCESS)
|
|
|
dd89bb |
return status;
|
|
|
dd89bb |
|
|
|
dd89bb |
status = __ntapi->zw_read_virtual_memory(
|
|
|
dd89bb |
hprocess,
|
|
|
dd89bb |
pe_va_from_rva(
|
|
|
dd89bb |
rpbi.peb_base_address,
|
|
|
dd89bb |
(uintptr_t)&(((nt_peb *)0)->process_params)),
|
|
|
dd89bb |
(char *)&rprocess_params,
|
|
|
dd89bb |
sizeof(uintptr_t),
|
|
|
dd89bb |
&bytes_written);
|
|
|
dd89bb |
|
|
|
dd89bb |
if (status != NT_STATUS_SUCCESS)
|
|
|
dd89bb |
return status;
|
|
|
dd89bb |
|
|
|
dd89bb |
status = __ntapi->zw_read_virtual_memory(
|
|
|
dd89bb |
hprocess,
|
|
|
dd89bb |
&rprocess_params->command_line,
|
|
|
dd89bb |
(char *)&rcmd_line,
|
|
|
dd89bb |
sizeof(nt_unicode_string),
|
|
|
dd89bb |
&bytes_written);
|
|
|
dd89bb |
|
|
|
dd89bb |
if (status != NT_STATUS_SUCCESS)
|
|
|
dd89bb |
return status;
|
|
|
dd89bb |
|
|
|
dd89bb |
if (rcmd_line.buffer == 0)
|
|
|
dd89bb |
return NT_STATUS_BUFFER_TOO_SMALL;
|
|
|
dd89bb |
else if (rcmd_line.strlen < sizeof(runtime_arg) + 4*sizeof(wchar16_t))
|
|
|
dd89bb |
return NT_STATUS_INVALID_USER_BUFFER;
|
|
|
dd89bb |
|
|
|
dd89bb |
status = __ntapi->zw_read_virtual_memory(
|
|
|
dd89bb |
hprocess,
|
|
|
dd89bb |
pe_va_from_rva(
|
|
|
dd89bb |
rcmd_line.buffer,
|
|
|
dd89bb |
rcmd_line.strlen - sizeof(runtime_arg)),
|
|
|
dd89bb |
(char *)&runtime_arg,
|
|
|
dd89bb |
sizeof(runtime_arg),
|
|
|
dd89bb |
&bytes_written);
|
|
|
dd89bb |
|
|
|
dd89bb |
if (status != NT_STATUS_SUCCESS)
|
|
|
dd89bb |
return status;
|
|
|
dd89bb |
|
|
|
dd89bb |
/* verify remote process compatibility */
|
|
|
dd89bb |
runtime_arg_hash ^= __ntapi->tt_buffer_crc32(
|
|
|
dd89bb |
0,
|
|
|
dd89bb |
(char *)runtime_arg,
|
|
|
dd89bb |
sizeof(runtime_arg));
|
|
|
dd89bb |
|
|
|
dd89bb |
if (runtime_arg_hash)
|
|
|
dd89bb |
return NT_STATUS_INVALID_SIGNATURE;
|
|
|
dd89bb |
|
|
|
dd89bb |
/* remote block */
|
|
|
dd89bb |
rtblock->remote_size = rtblock->size;
|
|
|
dd89bb |
status = __ntapi->zw_allocate_virtual_memory(
|
|
|
dd89bb |
hprocess,
|
|
|
dd89bb |
&rtblock->remote_addr,
|
|
|
dd89bb |
0,
|
|
|
dd89bb |
&rtblock->remote_size,
|
|
|
dd89bb |
NT_MEM_RESERVE | NT_MEM_COMMIT,
|
|
|
dd89bb |
NT_PAGE_READWRITE);
|
|
|
dd89bb |
|
|
|
dd89bb |
if (status != NT_STATUS_SUCCESS)
|
|
|
dd89bb |
return status;
|
|
|
dd89bb |
|
|
|
dd89bb |
/* session handles */
|
|
|
dd89bb |
if (rtblock->flags & NT_RUNTIME_DATA_DUPLICATE_SESSION_HANDLES) {
|
|
|
dd89bb |
rtdata = (nt_runtime_data *)rtblock->addr;
|
|
|
dd89bb |
srv_ready = rtdata->srv_ready;
|
|
|
dd89bb |
|
|
|
dd89bb |
status = __ntapi->zw_duplicate_object(
|
|
|
dd89bb |
NT_CURRENT_PROCESS_HANDLE,
|
|
|
dd89bb |
srv_ready,
|
|
|
dd89bb |
hprocess,
|
|
|
dd89bb |
&rtdata->srv_ready,
|
|
|
dd89bb |
0,0,NT_DUPLICATE_SAME_ATTRIBUTES | NT_DUPLICATE_SAME_ACCESS);
|
|
|
dd89bb |
if (status) return status;
|
|
|
dd89bb |
} else
|
|
|
dd89bb |
srv_ready = 0;
|
|
|
dd89bb |
|
|
|
dd89bb |
/* copy local block to remote process */
|
|
|
dd89bb |
status = __ntapi->zw_write_virtual_memory(
|
|
|
dd89bb |
hprocess,
|
|
|
dd89bb |
rtblock->remote_addr,
|
|
|
dd89bb |
(char *)rtblock->addr,
|
|
|
dd89bb |
rtblock->size,
|
|
|
dd89bb |
&bytes_written);
|
|
|
dd89bb |
|
|
|
dd89bb |
/* restore rtdata */
|
|
|
dd89bb |
if (srv_ready)
|
|
|
dd89bb |
rtdata->srv_ready = srv_ready;
|
|
|
dd89bb |
|
|
|
dd89bb |
if (status != NT_STATUS_SUCCESS)
|
|
|
dd89bb |
return status;
|
|
|
dd89bb |
|
|
|
dd89bb |
/* runtime_arg */
|
|
|
dd89bb |
__ntapi->tt_uintptr_to_hex_utf16(
|
|
|
dd89bb |
(uintptr_t)rtblock->remote_addr,
|
|
|
dd89bb |
runtime_arg);
|
|
|
dd89bb |
|
|
|
dd89bb |
/* update remote runtime arg */
|
|
|
dd89bb |
status = __ntapi->zw_write_virtual_memory(
|
|
|
dd89bb |
hprocess,
|
|
|
dd89bb |
pe_va_from_rva(
|
|
|
dd89bb |
rcmd_line.buffer,
|
|
|
dd89bb |
rcmd_line.strlen - sizeof(runtime_arg)),
|
|
|
dd89bb |
(char *)&runtime_arg,
|
|
|
dd89bb |
sizeof(runtime_arg),
|
|
|
dd89bb |
&bytes_written);
|
|
|
dd89bb |
|
|
|
dd89bb |
if (status)
|
|
|
dd89bb |
__ntapi->zw_free_virtual_memory(
|
|
|
dd89bb |
hprocess,
|
|
|
dd89bb |
&rtblock->remote_addr,
|
|
|
dd89bb |
&rtblock->remote_size,
|
|
|
dd89bb |
NT_MEM_RELEASE);
|
|
|
dd89bb |
|
|
|
dd89bb |
return status;
|
|
|
dd89bb |
}
|