1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
|
#pragma once
#include "KInterface.h"
#include <winsock.h>
#include <vector>
#define CE_PORT "52736"
#define MSG_WAITALL 0x8
#pragma warning(push)
#pragma warning(disable : 26812)
typedef enum ce_command {
CMD_GETVERSION = 0,
CMD_CLOSECONNECTION,
CMD_TERMINATESERVER,
CMD_OPENPROCESS,
CMD_CREATETOOLHELP32SNAPSHOT,
CMD_PROCESS32FIRST,
CMD_PROCESS32NEXT,
CMD_CLOSEHANDLE,
CMD_VIRTUALQUERYEX,
CMD_READPROCESSMEMORY,
CMD_WRITEPROCESSMEMORY,
CMD_STARTDEBUG,
CMD_STOPDEBUG,
CMD_WAITFORDEBUGEVENT,
CMD_CONTINUEFROMDEBUGEVENT,
CMD_SETBREAKPOINT,
CMD_REMOVEBREAKPOINT,
CMD_SUSPENDTHREAD,
CMD_RESUMETHREAD,
CMD_GETTHREADCONTEXT,
CMD_SETTHREADCONTEXT,
CMD_GETARCHITECTURE,
CMD_MODULE32FIRST,
CMD_MODULE32NEXT,
CMD_GETSYMBOLLISTFROMFILE,
CMD_LOADEXTENSION,
CMD_ALLOC,
CMD_FREE,
CMD_CREATETHREAD,
CMD_LOADMODULE,
CMD_SPEEDHACK_SETSPEED,
CMD_VIRTUALQUERYEXFULL,
CMD_GETREGIONINFO,
CMD_AOBSCAN = 200,
CMD_COMMANDLIST2 = 255,
CMD_MAX
} ce_command;
static inline char const* ce_command_to_string(enum ce_command cmd)
{
static char const* const cmd_map[] = {
"CMD_GETVERSION", "CMD_CLOSECONNECTION", "CMD_TERMINATESERVER", "CMD_OPENPROCESS",
"CMD_CREATETOOLHELP32SNAPSHOT", "CMD_PROCESS32FIRST", "CMD_PROCESS32NEXT", "CMD_CLOSEHANDLE",
"CMD_VIRTUALQUERYEX", "CMD_READPROCESSMEMORY", "CMD_WRITEPROCESSMEMORY", "CMD_STARTDEBUG",
"CMD_STOPDEBUG", "CMD_WAITFORDEBUGEVENT", "CMD_CONTINUEFROMDEBUGEVENT", "CMD_SETBREAKPOINT",
"CMD_REMOVEBREAKPOINT", "CMD_SUSPENDTHREAD", "CMD_RESUMETHREAD", "CMD_GETTHREADCONTEXT",
"CMD_SETTHREADCONTEXT", "CMD_GETARCHITECTURE", "CMD_MODULE32FIRST", "CMD_MODULE32NEXT",
"CMD_GETSYMBOLLISTFROMFILE", "CMD_LOADEXTENSION", "CMD_ALLOC", "CMD_FREE", "CMD_CREATETHREAD",
"CMD_LOADMODULE", "CMD_SPEEDHACK_SETSPEED", "CMD_VIRTUALQUERYEXFULL", "CMD_GETREGIONINFO",
"CMD_AOBSCAN", "CMD_COMMANDLIST2"
};
if (cmd < 0 || cmd >= CMD_MAX)
{
return "Unknown Command";
}
return cmd_map[cmd];
}
#pragma warning(pop)
#pragma pack(1)
typedef struct {
int version;
unsigned char stringsize;
//append the versionstring
} CeVersion, * PCeVersion;
typedef struct {
DWORD dwFlags;
DWORD th32ProcessID;
} CeCreateToolhelp32Snapshot, * PCeCreateToolhelp32Snapshot;
typedef struct {
int result;
int pid;
int processnamesize;
//processname
} CeProcessEntry, * PCeProcessEntry;
typedef struct {
int result;
int64_t modulebase;
int modulesize;
int modulenamesize;
//modulename
} CeModuleEntry, * PCeModuleEntry;
typedef struct {
uint32_t handle;
uint64_t address;
uint32_t size;
uint8_t compress;
} CeReadProcessMemoryInput, * PCeReadProcessMemoryInput;
typedef struct {
int read;
} CeReadProcessMemoryOutput, * PCeReadProcessMemoryOutput;
typedef struct {
int32_t handle;
int64_t address;
int32_t size;
} CeWriteProcessMemoryInput, * PCeWriteProcessMemoryInput;
typedef struct {
int32_t written;
} CeWriteProcessMemoryOutput, * PCeWriteProcessMemoryOutput;
typedef struct {
int handle;
uint64_t baseaddress;
} CeVirtualQueryExInput, * PCeVirtualQueryExInput;
typedef struct {
uint8_t result;
uint32_t protection;
uint32_t type;
uint64_t baseaddress;
uint64_t size;
} CeVirtualQueryExOutput, * PCeVirtualQueryExOutput;
typedef struct {
int handle;
uint8_t flags;
} CeVirtualQueryExFullInput, * PCeVirtualQueryExFullInput;
typedef struct {
uint64_t baseaddress;
uint64_t size;
uint32_t protection;
uint32_t type;
} RegionInfo, * PRegionInfo;
#pragma pack()
class CEConnection {
public:
explicit CEConnection(SOCKET s) : m_sock(s) {}
SOCKET getSocket(void) { return m_sock; }
void closeSocket(void) { closesocket(m_sock); }
std::vector<PROCESS_DATA> m_cachedProcesses;
std::vector<MODULE_DATA> m_cachedModules;
std::vector<MEMORY_BASIC_INFORMATION> m_cachedPages;
private:
SOCKET m_sock;
};
|