UserInfo.cpp 5.2 KB
Newer Older
L
ljc545w 已提交
1 2 3 4 5
#include "pch.h"
#include <typeinfo>
#include <string>
#include <vector>

L
ljc545w 已提交
6
// 获取好友信息CALL0偏移
L
ljc545w 已提交
7
#define GetUserInfoCall0Offset 0x6740A000 - 0x67370000
L
ljc545w 已提交
8
// 获取好友信息CALL1偏移
L
ljc545w 已提交
9
#define GetUserInfoCall1Offset 0x679C9840 - 0x67370000
L
ljc545w 已提交
10
// 获取好友信息CALL2偏移
L
ljc545w 已提交
11
#define GetUserInfoCall2Offset 0x67A71DC0 - 0x67370000
L
ljc545w 已提交
12
// 获取好友信息CALL3偏移
L
ljc545w 已提交
13 14
#define GetUserInfoCall3Offset 0x677724A0 - 0x67370000

L
ljc545w 已提交
15
// 清空缓存CALL1偏移
L
ljc545w 已提交
16
#define DeleteUserInfoCacheCall1Offset 0x67775990 - 0x67370000
L
ljc545w 已提交
17
// 清空缓存CALL2偏移
L
ljc545w 已提交
18 19
#define DeleteUserInfoCacheCall2Offset 0x679CA340 - 0x67370000

L
ljc545w 已提交
20 21 22 23 24
/*
* 外部调用时的返回类型
* message:wUserInfo.c_str()
* length:wUserInfo字符串长度
*/
L
ljc545w 已提交
25 26 27 28 29
struct GetUserInfoStruct {
	DWORD message;
	DWORD length;
};

L
ljc545w 已提交
30
// 保存好友信息的字符串
L
ljc545w 已提交
31
wstring wUserInfo = L"";
L
ljc545w 已提交
32
// 外部调用时的具体返回对象
L
ljc545w 已提交
33 34
GetUserInfoStruct ret = { 0 };

L
ljc545w 已提交
35 36 37 38 39
/*
* 根据缓冲区内容拼接好友信息
* address:缓冲区地址
* return:void
*/
L
ljc545w 已提交
40 41 42 43 44
VOID WxUserInfo(DWORD address) {
	vector<DWORD> InfoType{
		address + 0x10,
		address + 0x24,
		address + 0x38,
L
ljc545w 已提交
45
		address + 0x58,
L
ljc545w 已提交
46 47 48 49 50 51 52 53 54 55 56 57 58
		address + 0x6C,
		address + 0xFC,
		address + 0x110,
		address + 0x19C,
		address + 0x1B0,
		address + 0x1C4,
		address + 0x1D8,
		address + 0x27C
	};
	vector<wchar_t*> InfoTypeName{
		(WCHAR*)L"\"wxId\"",
		(WCHAR*)L"\"wxNumber\"",
		(WCHAR*)L"\"wxV3\"",
L
ljc545w 已提交
59
		(WCHAR*)L"\"wxRemark\"",
L
ljc545w 已提交
60 61 62 63 64 65 66 67 68 69 70 71
		(WCHAR*)L"\"wxNickName\"",
		(WCHAR*)L"\"wxBigAvatar\"",
		(WCHAR*)L"\"wxSmallAvatar\"",
		(WCHAR*)L"\"wxSignature\"",
		(WCHAR*)L"\"wxNation\"",
		(WCHAR*)L"\"wxProvince\"",
		(WCHAR*)L"\"wxCity\"",
		(WCHAR*)L"\"wxBackground\"",
	};
	wUserInfo += L"{";
	for (unsigned int i = 0; i < InfoType.size(); i++) {
		wchar_t* wstemp = ((*((DWORD*)InfoType[i])) != 0) ? (WCHAR*)(*((LPVOID*)InfoType[i])) : (WCHAR*)L"null";
L
ljc545w 已提交
72 73
		wstring wsrtemp = wreplace(wstemp,L'\"',L"\\\"");
		wUserInfo = wUserInfo + InfoTypeName[i] + L":\"" + wsrtemp + L"\"";
L
ljc545w 已提交
74 75 76 77 78 79 80 81 82 83 84
		if (i != InfoType.size() - 1) {
			wUserInfo += L",";
		}
	}
	wUserInfo += L"}";
#ifdef _DEBUG
	wcout.imbue(locale("chs"));
	wcout << wUserInfo.c_str() << endl;
#endif
}

L
ljc545w 已提交
85 86 87 88 89
/*
* 供外部调用的获取好友信息接口
* lparamter:保存好友wxid的地址
* return:DWORD,`ret`的首地址
*/
L
ljc545w 已提交
90 91 92 93 94 95 96 97 98 99 100
DWORD GetWxUserInfoRemote(LPVOID lparamter) {
	wchar_t* userwxid = (wchar_t*)lparamter;
	
	if (!GetUserInfoByWxId(userwxid)) {
		return 0;
	}
	ret.message = (DWORD)wUserInfo.c_str();
	ret.length = (DWORD)wUserInfo.length();
	return (DWORD)&ret;
}

L
ljc545w 已提交
101 102 103 104
/*
* 供外部调用的清空好友信息缓存的接口
* return:void
*/
L
ljc545w 已提交
105 106 107 108 109 110 111 112
VOID DeleteUserInfoCacheRemote() {
	if (ret.length) {
		ZeroMemory((wchar_t*)ret.message, ret.length * 2 + 2);
		ret.length = 0;
		wUserInfo = L"";
	}
}

L
ljc545w 已提交
113 114 115 116 117
/*
* 根据wxid获取好友信息的具体实现
* wxid:好友wxid
* return:BOOL,成功返回`1`,失败返回`0`
*/
L
ljc545w 已提交
118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162
BOOL __stdcall GetUserInfoByWxId(wchar_t* wxid) {
	DWORD WeChatWinBase = GetWeChatWinBase();
	DWORD WxGetUserInfoCall0 = WeChatWinBase + GetUserInfoCall0Offset;
	DWORD WxGetUserInfoCall1 = WeChatWinBase + GetUserInfoCall1Offset;
	DWORD WxGetUserInfoCall2 = WeChatWinBase + GetUserInfoCall2Offset;
	DWORD WxGetUserInfoCall3 = WeChatWinBase + GetUserInfoCall3Offset;
	DWORD DeleteUserInofCacheCall1 = WeChatWinBase + DeleteUserInfoCacheCall1Offset;
	DWORD DeleteUserInofCacheCall2 = WeChatWinBase + DeleteUserInfoCacheCall2Offset;
	char buffer[0x3FC] = { 0 };
	WxBaseStruct pWxid(wxid);
	DWORD address = 0;
	DWORD isSuccess = 0;
	__asm
	{
		pushad;
		call WxGetUserInfoCall0;
		mov edi, eax;
		lea ecx, buffer;
		call WxGetUserInfoCall1;
		lea eax, buffer;
		mov address, eax;
		push eax;
		sub esp, 0x14;
		mov ecx, esp;
		lea esi, pWxid;
		push esi;
		call WxGetUserInfoCall2;
		mov ecx, edi;
		call WxGetUserInfoCall3;
		mov isSuccess, eax;
		popad;
	}
	if(isSuccess)
		WxUserInfo(address);
	__asm {
		pushad;
		lea eax, buffer;
		push eax;
		call DeleteUserInofCacheCall1;
		lea ecx, buffer;
		mov esi, eax;
		call DeleteUserInofCacheCall2;
		popad;
	}
	return isSuccess;
L
ljc545w 已提交
163 164
}

L
ljc545w 已提交
165 166 167 168 169
/*
* 根据wxid获取联系人昵称,主要用于发送艾特消息接口
* wxid:联系人wxid
* return:wchar_t*,获取到的wxid
*/
L
ljc545w 已提交
170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219
wchar_t* __stdcall GetUserNickNameByWxId(wchar_t* wxid) {
	DWORD WeChatWinBase = GetWeChatWinBase();
	DWORD WxGetUserInfoCall0 = WeChatWinBase + GetUserInfoCall0Offset;
	DWORD WxGetUserInfoCall1 = WeChatWinBase + GetUserInfoCall1Offset;
	DWORD WxGetUserInfoCall2 = WeChatWinBase + GetUserInfoCall2Offset;
	DWORD WxGetUserInfoCall3 = WeChatWinBase + GetUserInfoCall3Offset;
	DWORD DeleteUserInofCacheCall1 = WeChatWinBase + DeleteUserInfoCacheCall1Offset;
	DWORD DeleteUserInofCacheCall2 = WeChatWinBase + DeleteUserInfoCacheCall2Offset;
	char buffer[0x3FC] = { 0 };
	WxBaseStruct pWxid(wxid);
	DWORD address = 0;
	DWORD isSuccess = 0;
	__asm
	{
		pushad;
		call WxGetUserInfoCall0;
		mov edi, eax;
		lea ecx, buffer;
		call WxGetUserInfoCall1;
		lea eax, buffer;
		mov address, eax;
		push eax;
		sub esp, 0x14;
		mov ecx, esp;
		lea esi, pWxid;
		push esi;
		call WxGetUserInfoCall2;
		mov ecx, edi;
		call WxGetUserInfoCall3;
		mov isSuccess, eax;
		popad;
	}
	wchar_t* NickName = NULL;
	if (isSuccess) {
		DWORD length = *(DWORD*)(address + 0x6C + 0x4);
		NickName = new wchar_t[length + 1];
		ZeroMemory(NickName, (length + 1) * 2);
		memcpy(NickName, (wchar_t*)(*(DWORD*)(address + 0x6C)), length * 2);
	}
	__asm {
		pushad;
		lea eax, buffer;
		push eax;
		call DeleteUserInofCacheCall1;
		lea ecx, buffer;
		mov esi, eax;
		call DeleteUserInofCacheCall2;
		popad;
	}
	return NickName;
L
ljc545w 已提交
220
}