地址的奇怪错误

Weird bug with addresses

本文关键字:错误 地址      更新时间:2023-10-16

我有几个问题要解决,请帮忙!

我的第一个问题是表达式必须是指向完整对象类型的指针,但是我已经通过在变量之前添加解决了这个问题,我做得对吗?

下面的代码片段。


LPVOID dll;
PIMAGE_DOS_HEADER dos;
dll = LoadLibraryA(a[1]);
dos = (PIMAGE_DOS_HEADER)dll;
nt = (PIMAGE_NT_HEADERS)(&dll+dos->e_lfanew);

下一个问题是我的程序输出总是不同的,为什么? 我的程序应该显示所有地址和函数名称,下面的代码。

#include<stdio.h>
#include<windows.h>
#include<winternl.h>

int main(int i, char* a[]) {
LPVOID dll, faddr;
PIMAGE_DOS_HEADER dos;
PIMAGE_NT_HEADERS nt;
PIMAGE_EXPORT_DIRECTORY exp;
PWORD f_addr_list, f_name_list;
PWORD f_ord_list;
DWORD rva;
LPSTR fname;

if (i != 2) {
printf("error");
return 0;
}
dll = LoadLibraryA(a[1]);
if (dll == NULL) {
printf("failed to load");
return 0;
}
dos = (PIMAGE_DOS_HEADER)dll;
nt = (PIMAGE_NT_HEADERS)(dll+dos->e_lfanew);
exp = (PIMAGE_EXPORT_DIRECTORY)(&dll + nt->OptionalHeader.DataDirectory[0].VirtualAddress);
f_addr_list = (PDWORD)(&dll + exp->AddressOfFunctions);
f_name_list = (PDWORD)(&dll + exp->AddressOfNames);
f_ord_list = (PWORD)(&dll + exp->AddressOfNameOrdinals);

printf("Total function names: %ldnTotal Function: %ldn", exp->NumberOfNames, exp->NumberOfFunctions);
printf("AddressttttFunction Namen");
printf("-------ttttt----------n");
for (i = 0; i < exp->NumberOfNames; i++)
{
fname = (LPSTR)dll + f_name_list[i];
rva = f_ord_list[i];
faddr = &dll + f_addr_list[rva];
printf("%ptttt%sn", faddr, fname);

}
FreeLibrary(dll);
return 0;
}

示例输出:

C:UsersuserProject2Debug>Project2.exe user32.dll
Total function names: 2
Total Function: 11914128
Address                         Function Name
-------                                 ----------
C:UsersuserProject2Debug>Project2.exe user32.dll
Total function names: 2
Total Function: 11914128
Address                         Function Name
-------                                 ----------
C:UsersuserProject2Debug>Project2.exe user32.dll
Total function names: 22826784
Total Function: 2
Address                         Function Name
-------                                 ----------

里面有什么问题?

在 WIN OS 下,模块句柄是加载到内存中的库的基址

在地址之前添加&并不能解决问题,但会创建一个更大的地址,添加导致内存冲突的间接寻址(现在您使用变量dll的地址作为模块基址(。

您不能对空指针进行数学运算,因为void没有阻止正确位移计算的大小。将基指针设置为BYTE指针,而不是将基数大小设为 1。

您尝试执行的操作的工作代码是:

#include<stdio.h>
#include<windows.h>
#include<winternl.h>
int main(int i, char *a[])
{
LPVOID faddr;
BYTE *dll;
PIMAGE_DOS_HEADER dos;
PIMAGE_NT_HEADERS nt;
PIMAGE_EXPORT_DIRECTORY exp;
PDWORD f_addr_list, f_name_list;
PWORD f_ord_list;
DWORD rva;
LPSTR fname;
if (i != 2)
{
printf("errorn");
return 0;
}
dll = (BYTE *)LoadLibraryA(a[1]);
if (dll == NULL)
{
printf("failed to loadn");
return 0;
}
dos = (PIMAGE_DOS_HEADER)dll;
nt  = (PIMAGE_NT_HEADERS) (dll + dos->e_lfanew);
exp = (PIMAGE_EXPORT_DIRECTORY) (dll + nt->OptionalHeader.DataDirectory[0].VirtualAddress);
f_addr_list = (PDWORD) (dll + exp->AddressOfFunctions);
f_name_list = (PDWORD) (dll + exp->AddressOfNames);
f_ord_list  = (PWORD) (dll + exp->AddressOfNameOrdinals);
printf("Total function names: %ldnTotal Function: %ldn", exp->NumberOfNames, exp->NumberOfFunctions);
printf("AddressttttFunction Namen");
printf("-------ttttt----------n");
for (i = 0; i < exp->NumberOfNames; i++)
{
fname = (LPSTR)(dll + f_name_list[i]);
rva   = f_ord_list[i];
faddr = dll + f_addr_list[rva];
printf("%ptttt%sn", faddr, fname);
}
FreeLibrary((LPVOID)dll);
return 0;
}
相关文章: