Why's my target program crashing when hooking its function?

Viewed 60

This is my target program:

#include <iostream>

int sum(int x, int y) {
    std::cout << "function";
    return x + y;
}

int main()
{
    while (true) {
        std::cin.get();
        std::cout << sum(1, 2);
    }
}

This is how I'm hooking:

// dllmain.cpp : Define o ponto de entrada para o aplicativo DLL.
#include "pch.h"
#include "Windows.h"
#include <iostream>

typedef int(__cdecl* sum) (int x, int y);

sum osum;

int __cdecl hsum(int x, int y) {
    return osum(x, y*5);
}

bool Detour32(void* src, void* dst, int len)
{
    if (len < 5) return false;

    DWORD curProtection;
    VirtualProtect(src, len, PAGE_EXECUTE_READWRITE, &curProtection);

    memset(src, 0x90, len);

    uintptr_t relativeAddress = ((uintptr_t)dst - (uintptr_t)src) - 5;

    *(BYTE*)src = 0xE9;
    *(uintptr_t*)((uintptr_t)src + 1) = relativeAddress;

    DWORD temp;
    VirtualProtect(src, len, curProtection, &temp);

    return true;
}

char* TrampHook32(BYTE* src, BYTE* dst, const intptr_t len)
{
    // Make sure the length is greater than 5
    if (len < 5) return 0;

    // Create the gateway (len + 5 for the overwritten bytes + the jmp)
    BYTE* gateway = (BYTE*)VirtualAlloc(0, len + 5, MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE);

    //Write the stolen bytes into the gateway
    memcpy(gateway, src, len);

    // Get the gateway to destination addy
    intptr_t  gatewayRelativeAddr = ((intptr_t)src - (intptr_t)gateway) - 5;

    // Add the jmp opcode to the end of the gateway
    *(char*)((intptr_t)gateway + len) = 0xE9;

    // Add the address to the jmp
    *(intptr_t*)((intptr_t)gateway + len + 1) = gatewayRelativeAddr;

    // Perform the detour
    Detour32(src, dst, len);

    return (char*)gateway;
}

DWORD WINAPI HackThread(HMODULE hModule) {
    //Create Console
    AllocConsole();
    FILE* f;
    freopen_s(&f, "CONOUT$", "w", stdout);

    uintptr_t moduleBase = (uintptr_t)GetModuleHandle(L"testtt.exe");
    osum = (sum)(moduleBase + 0x123d0);
    osum = (sum)TrampHook32((BYTE*)osum, (BYTE*)hsum, 5);

    fclose(f);
    FreeConsole();
    return 0;
}
BOOL APIENTRY DllMain(HMODULE hModule,
    DWORD  ul_reason_for_call,
    LPVOID lpReserved
)
{
    switch (ul_reason_for_call)
    {
    case DLL_PROCESS_ATTACH:
        CloseHandle(CreateThread(nullptr, 0, (LPTHREAD_START_ROUTINE)HackThread, hModule, 0, nullptr));
    case DLL_THREAD_ATTACH:
    case DLL_THREAD_DETACH:
    case DLL_PROCESS_DETACH:
        break;
    }
    return TRUE;
}

Here's how the function is named: function naming convention

And in Ghidra, the function is displayed as such in the memory/assembly: mem assembly

I'm injecting the dll through a dll injector, the injector is working perfectly, so I decided not to paste it here. I debugged it with cheat engine and the jump did work. Upon arriving at the function that I'm trying to hook, the code jumped to the function I wrote to replace the hooked function and it did execute some of its instructions, however, at a certain point, it crashed. I'll be sincere, I don't know shit about assembly, so even if it did execute some instructions and I've seen where it crashed, I don't know why it did. So, what's happening?

0 Answers
Related