ReceiveMessage.cpp 7.6 KB
Newer Older
1 2
#include "pch.h"
#include <vector>
L
ljc545w 已提交
3 4 5 6 7 8 9 10
#include <winsock2.h>
#include <Ws2tcpip.h>

#pragma comment(lib, "ws2_32.lib")

using namespace std;

#define CLTIP "127.0.0.1"
11

L
ljc545w 已提交
12
// 接收消息的HOOK地址偏移
L
ljc545w 已提交
13
#define ReceiveMessageHookOffset 0x78BF0F4C - 0x786A0000
L
ljc545w 已提交
14
// 接收消息HOOK的CALL偏移
L
ljc545w 已提交
15
#define ReceiveMessageNextCallOffset 0x79136350 - 0x786A0000
16

L
ljc545w 已提交
17
// 发送消息的HOOK地址偏移
L
ljc545w 已提交
18
#define SendMessageHookOffset 0x78B88E42 - 0x786A0000
L
ljc545w 已提交
19
// 发送消息HOOK的CALL偏移
L
ljc545w 已提交
20
#define SendMessageNextCallOffset 0x78AA8170 - 0x786A0000
L
ljc545w 已提交
21

L
ljc545w 已提交
22 23 24 25 26 27 28 29 30
static int SRVPORT = 0;

struct ScoketMsgStruct {
	int messagetype;
	BOOL isSendMessage;
	wchar_t sender[80];
	wchar_t wxid[80];
	wchar_t message[0x1000B];
	wchar_t filepath[MAX_PATH];
L
ljc545w 已提交
31
	wchar_t time[30];
L
ljc545w 已提交
32
};
33

L
ljc545w 已提交
34
// 是否开启接收消息HOOK标志
35
BOOL ReceiveMessageHooked = false;
L
ljc545w 已提交
36
// 保存HOOK前的字节码,用于恢复
37
char OldReceiveMessageAsmCode[5] = { 0 };
L
ljc545w 已提交
38
char OldSendMessageAsmCode[5] = { 0 };
L
ljc545w 已提交
39
// 接收消息HOOK地址
40
DWORD ReceiveMessageHookAddress = GetWeChatWinBase() + ReceiveMessageHookOffset;
L
ljc545w 已提交
41
// 接收消息HOOK的CALL地址
42
DWORD ReceiveMessageNextCall = GetWeChatWinBase() + ReceiveMessageNextCallOffset;
L
ljc545w 已提交
43 44 45 46 47 48 49 50
// 接收HOOK的跳转地址
DWORD ReceiveMessageJmpBackAddress = ReceiveMessageHookAddress + 0x5;
// 发送消息HOOK地址
DWORD SendMessageHookAddress = GetWeChatWinBase() + SendMessageHookOffset;
// 发送消息HOOK的CALL地址
DWORD SendMessageNextCall = GetWeChatWinBase() + SendMessageNextCallOffset;
// 发送HOOK的跳转地址
DWORD SendMessageJmpBackAddress = SendMessageHookAddress + 0x5;
51

L
ljc545w 已提交
52 53 54
// 通过socket将消息发送给服务端
BOOL SendSocketMessage(ReceiveMsgStruct* ms)
{
L
ljc545w 已提交
55 56 57 58
	if (SRVPORT == 0) {
		delete ms;
		return false;
	}
L
ljc545w 已提交
59 60 61 62
	SOCKET clientsocket = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);
	if (clientsocket < 0)
	{
#ifdef _DEBUG
L
ljc545w 已提交
63
		cout << "create socket error," << " errno:" << errno << endl;
L
ljc545w 已提交
64 65 66 67 68 69 70 71 72 73 74 75 76
#endif
		return false;
	}
	BOOL status = false;
	sockaddr_in clientAddr;
	memset(&clientAddr, 0, sizeof(clientAddr));
	clientAddr.sin_family = AF_INET;
	clientAddr.sin_port = htons((u_short)SRVPORT);
	InetPtonA(AF_INET,CLTIP,&clientAddr.sin_addr.s_addr);

	if (connect(clientsocket, reinterpret_cast<sockaddr*>(&clientAddr), sizeof(sockaddr)) < 0)
	{
#ifdef _DEBUG
L
ljc545w 已提交
77
		cout << "connect error,"<< " errno:" << errno << endl;
L
ljc545w 已提交
78 79 80 81 82 83 84 85 86 87 88 89 90 91
#endif
		delete ms;
		return false;
	}
	char recvbuf[1024] = { 0 };
	ScoketMsgStruct* sms = new ScoketMsgStruct;
	ZeroMemory(sms, sizeof(ScoketMsgStruct));
	sms->messagetype = ms->messagetype;
	sms->isSendMessage = ms->isSendMessage;
	memcpy(sms->wxid, ms->wxid, ms->l_wxid * 2);
	memcpy(sms->sender, ms->sender, ms->l_sender * 2);
	memcpy(sms->message, ms->message, ms->l_message * 2);
	memcpy(sms->filepath, ms->filepath, ms->l_filepath * 2);
	memcpy(sms->time, ms->time, ms->l_time * 2);
L
ljc545w 已提交
92
	wcout << sms->time << endl;
L
ljc545w 已提交
93 94 95 96
	int ret = send(clientsocket, (char*)sms, sizeof(ScoketMsgStruct), 0);
	if (ret == -1 || ret == 0)
	{
#ifdef _DEBUG
L
ljc545w 已提交
97
		cout << "send fail," << " errno:" << errno << endl;
L
ljc545w 已提交
98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118
#endif
		delete ms;
		delete sms;
		closesocket(clientsocket);
		return false;
	}
	memset(recvbuf, 0, sizeof(recvbuf));
	ret = recv(clientsocket, recvbuf, sizeof(recvbuf), 0);
	delete ms;
	delete sms;
	closesocket(clientsocket);
	if (ret == -1 || ret == 0)
	{
#ifdef _DEBUG
		cout << "the server close" << endl;
#endif
		return false;
	}
	return true;
}

L
ljc545w 已提交
119
// 创建广播消息数组
120 121
#ifndef USE_SOCKET
static SAFEARRAY* CreateMessageArray(ReceiveMsgStruct* ms) {
L
ljc545w 已提交
122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152
	HRESULT hr = S_OK;
	SAFEARRAY* psaValue;
	vector<wstring> MessageInfoKey = {
		L"type",
		L"isSendMessage",
		ms->isSendMessage ? L"sendto" : L"from",
		L"wxid",
		L"message",
		L"filepath",
		L"time"
	};
	SAFEARRAYBOUND rgsaBound[2] = { {MessageInfoKey.size(),0},{2,0} };
	psaValue = SafeArrayCreate(VT_VARIANT, 2, rgsaBound);
	long keyIndex[2] = { 0,0 };
	keyIndex[0] = 0; keyIndex[1] = 0;
	for (unsigned int i = 0; i < MessageInfoKey.size(); i++) {
		keyIndex[0] = i; keyIndex[1] = 0;
		_variant_t key = MessageInfoKey[i].c_str();
		hr = SafeArrayPutElement(psaValue, keyIndex, &key);
		keyIndex[0] = i; keyIndex[1] = 1;
		if (i < 2) {
			_variant_t value = ((DWORD*)ms)[i];
			hr = SafeArrayPutElement(psaValue, keyIndex, &value);
		}
		else {
			_variant_t value = ((wchar_t**)ms)[i * 2 - 2];
			hr = SafeArrayPutElement(psaValue, keyIndex, &value);
		}
	}
	return psaValue;
}
153
#endif
L
ljc545w 已提交
154

L
ljc545w 已提交
155
static void dealMessage(DWORD messageAddr) {
L
ljc545w 已提交
156
	BOOL isSendMessage = *(BOOL*)(messageAddr + 0x3C);
L
ljc545w 已提交
157 158 159
	ReceiveMsgStruct* message = new ReceiveMsgStruct;
	ZeroMemory(message, sizeof(ReceiveMsgStruct));
	message->isSendMessage = isSendMessage;
L
ljc545w 已提交
160
	message->time = GetTimeW(*(DWORD*)(messageAddr + 0x44));
L
ljc545w 已提交
161 162
	message->l_time = wcslen(message->time);
	message->messagetype = *(DWORD*)(messageAddr + 0x38);
L
ljc545w 已提交
163

164
	DWORD length = *(DWORD*)(messageAddr + 0x48 + 0x4);
L
ljc545w 已提交
165 166
	message->sender = new wchar_t[length + 1];
	ZeroMemory(message->sender, (length + 1) * 2);
L
ljc545w 已提交
167
	memcpy(message->sender, (wchar_t*)(*(DWORD*)(messageAddr + 0x48)), length * 2);
L
ljc545w 已提交
168
	message->l_sender = length;
L
ljc545w 已提交
169

170 171
	length = *(DWORD*)(messageAddr + 0x170 + 0x4);
	if (length == 0) {
L
ljc545w 已提交
172 173 174 175
		message->wxid = new wchar_t[message->l_sender + 1];
		ZeroMemory(message->wxid, (message->l_sender + 1) * 2);
		memcpy(message->wxid, (wchar_t*)(*(DWORD*)(messageAddr + 0x48)), message->l_sender * 2);
		message->l_wxid = message->l_sender;
176 177
	}
	else {
L
ljc545w 已提交
178 179 180 181
		message->wxid = new wchar_t[length + 1];
		ZeroMemory(message->wxid, (length + 1) * 2);
		memcpy(message->wxid, (wchar_t*)(*(DWORD*)(messageAddr + 0x170)), length * 2);
		message->l_wxid = length;
182
	}
L
ljc545w 已提交
183

184
	length = *(DWORD*)(messageAddr + 0x70 + 0x4);
L
ljc545w 已提交
185 186 187 188
	message->message = new wchar_t[length + 1];
	ZeroMemory(message->message, (length + 1) * 2);
	memcpy(message->message, (wchar_t*)(*(DWORD*)(messageAddr + 0x70)), length * 2);
	message->l_message = length;
189

L
ljc545w 已提交
190
	length = *(DWORD*)(messageAddr + 0x1AC + 0x4);
L
ljc545w 已提交
191 192 193 194
	message->filepath = new wchar_t[length + 1];
	ZeroMemory(message->filepath, (length + 1) * 2);
	memcpy(message->filepath, (wchar_t*)(*(DWORD*)(messageAddr + 0x1AC)), length * 2);
	message->l_filepath = length;
195
#ifdef USE_COM
L
ljc545w 已提交
196
	// 通过连接点,将消息广播给客户端
L
ljc545w 已提交
197
	SAFEARRAY* psaValue = CreateMessageArray(message);
L
ljc545w 已提交
198 199 200 201
	VARIANT vsaValue;
	vsaValue.vt = VT_ARRAY | VT_VARIANT;
	V_ARRAY(&vsaValue) = psaValue;
	PostComMessage(&vsaValue);
L
ljc545w 已提交
202
#endif
L
ljc545w 已提交
203
	HANDLE hThread = CreateThread(NULL, 0, (LPTHREAD_START_ROUTINE)SendSocketMessage, message, NULL, 0);
L
ljc545w 已提交
204 205 206
	if (hThread) {
		CloseHandle(hThread);
	}
207 208
}

L
ljc545w 已提交
209 210 211 212 213 214 215 216 217 218 219 220 221
/*
* 消息处理函数,根据消息缓冲区组装结构并存入容器
* messageAddr:保存消息的缓冲区地址
* return:void
*/
VOID ReceiveMessage(DWORD messagesAddr) {
	// 此处用于区别是发送的还是接收的消息
	DWORD* messages = (DWORD*)messagesAddr;
	for (DWORD messageAddr = messages[0]; messageAddr < messages[1]; messageAddr += 0x298) {
		dealMessage(messageAddr);
	}
}

222

L
ljc545w 已提交
223 224 225
/*
* HOOK的具体实现,接收到消息后调用处理函数
*/
226 227 228 229
_declspec(naked) void dealReceiveMessage() {
	__asm {
		pushad;
		pushfd;
L
ljc545w 已提交
230 231
		// mov eax, [edi];
		push edi;
232 233 234 235 236
		call ReceiveMessage;
		add esp, 0x4;
		popfd;
		popad;
		call ReceiveMessageNextCall;
L
ljc545w 已提交
237 238 239 240 241 242 243 244 245 246 247 248
		jmp ReceiveMessageJmpBackAddress;
	}
}

/*
* HOOK的具体实现,发送消息后调用处理函数
*/
_declspec(naked) void dealSendMessage() {
	__asm {
		pushad;
		pushfd;
		push edi;
L
ljc545w 已提交
249
		call dealMessage;
L
ljc545w 已提交
250 251 252 253 254
		add esp, 0x4;
		popfd;
		popad;
		call SendMessageNextCall;
		jmp SendMessageJmpBackAddress;
255 256 257
	}
}

L
ljc545w 已提交
258 259 260 261
/*
* 开始接收消息HOOK
* return:void
*/
L
ljc545w 已提交
262 263
VOID HookReceiveMessage(int port) {
	SRVPORT = port;
264 265 266
	if (ReceiveMessageHooked)
		return;
	HookAnyAddress(ReceiveMessageHookAddress,(LPVOID)dealReceiveMessage,OldReceiveMessageAsmCode);
L
ljc545w 已提交
267
	HookAnyAddress(SendMessageHookAddress, (LPVOID)dealSendMessage, OldSendMessageAsmCode);
268 269 270
	ReceiveMessageHooked = TRUE;
}

L
ljc545w 已提交
271 272 273 274
/*
* 停止接收消息HOOK
* return:void
*/
275
VOID UnHookReceiveMessage() {
L
ljc545w 已提交
276
	SRVPORT = 0;
277 278 279
	if (!ReceiveMessageHooked)
		return;
	UnHookAnyAddress(ReceiveMessageHookAddress,OldReceiveMessageAsmCode);
L
ljc545w 已提交
280
	UnHookAnyAddress(SendMessageHookAddress, OldSendMessageAsmCode);
281 282
	ReceiveMessageHooked = FALSE;
}