This is my target program:
#include <iostream>
int sum(int x, int y) {
std::cout << "function";
return x + y;
}
int main()
{
while (true) {
std::cin.get();
std::cout << sum(1, 2);
}
}
This is how I'm hooking:
// dllmain.cpp : Define o ponto de entrada para o aplicativo DLL.
#include "pch.h"
#include "Windows.h"
#include <iostream>
typedef int(__cdecl* sum) (int x, int y);
sum osum;
int __cdecl hsum(int x, int y) {
return osum(x, y*5);
}
bool Detour32(void* src, void* dst, int len)
{
if (len < 5) return false;
DWORD curProtection;
VirtualProtect(src, len, PAGE_EXECUTE_READWRITE, &curProtection);
memset(src, 0x90, len);
uintptr_t relativeAddress = ((uintptr_t)dst - (uintptr_t)src) - 5;
*(BYTE*)src = 0xE9;
*(uintptr_t*)((uintptr_t)src + 1) = relativeAddress;
DWORD temp;
VirtualProtect(src, len, curProtection, &temp);
return true;
}
char* TrampHook32(BYTE* src, BYTE* dst, const intptr_t len)
{
// Make sure the length is greater than 5
if (len < 5) return 0;
// Create the gateway (len + 5 for the overwritten bytes + the jmp)
BYTE* gateway = (BYTE*)VirtualAlloc(0, len + 5, MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE);
//Write the stolen bytes into the gateway
memcpy(gateway, src, len);
// Get the gateway to destination addy
intptr_t gatewayRelativeAddr = ((intptr_t)src - (intptr_t)gateway) - 5;
// Add the jmp opcode to the end of the gateway
*(char*)((intptr_t)gateway + len) = 0xE9;
// Add the address to the jmp
*(intptr_t*)((intptr_t)gateway + len + 1) = gatewayRelativeAddr;
// Perform the detour
Detour32(src, dst, len);
return (char*)gateway;
}
DWORD WINAPI HackThread(HMODULE hModule) {
//Create Console
AllocConsole();
FILE* f;
freopen_s(&f, "CONOUT$", "w", stdout);
uintptr_t moduleBase = (uintptr_t)GetModuleHandle(L"testtt.exe");
osum = (sum)(moduleBase + 0x123d0);
osum = (sum)TrampHook32((BYTE*)osum, (BYTE*)hsum, 5);
fclose(f);
FreeConsole();
return 0;
}
BOOL APIENTRY DllMain(HMODULE hModule,
DWORD ul_reason_for_call,
LPVOID lpReserved
)
{
switch (ul_reason_for_call)
{
case DLL_PROCESS_ATTACH:
CloseHandle(CreateThread(nullptr, 0, (LPTHREAD_START_ROUTINE)HackThread, hModule, 0, nullptr));
case DLL_THREAD_ATTACH:
case DLL_THREAD_DETACH:
case DLL_PROCESS_DETACH:
break;
}
return TRUE;
}
Here's how the function is named: 
And in Ghidra, the function is displayed as such in the memory/assembly:

I'm injecting the dll through a dll injector, the injector is working perfectly, so I decided not to paste it here. I debugged it with cheat engine and the jump did work. Upon arriving at the function that I'm trying to hook, the code jumped to the function I wrote to replace the hooked function and it did execute some of its instructions, however, at a certain point, it crashed. I'll be sincere, I don't know shit about assembly, so even if it did execute some instructions and I've seen where it crashed, I don't know why it did. So, what's happening?