Delphi Hook API ÒÑ·è¿ñ
×÷Õß: yangyxd ×ªÔØÇë×¢Ã÷³ö´¦ http://hi.baidu.com/yangyxd 2009-3-12
ÂÛ̳ÀïÓйØÓÚHOOK APIµÄÌù×Ó£¬ µ«ÆäʵÏÖÔÚ·½Ê½ÏÔʾµÃÂé·³£¬ ÆäʵÏÖÔÚÀ¹½ØAPIÒ»°ã²»ÓÃÄÇÖÖ·½Ê½£¬ ´ó¶¼²ÉÓÃinline Hook API·½Ê½¡£ÆäʵҲ¾ÍÊÇÖ±½ÓÐÞ¸ÄÁËÒªÀ¹½ØµÄAPIÔ´ÂëµÄÍ·²¿£¬ÈÃËüÎÞÌõ¼þÌø×ªµ½ÎÒÃÇ×Ô¼ºµÄ´¦Àí¹ý³Ì¡£
²»¶à˵±ðµÄÁË£¬¿ªÊ¼ÎÒÃÇ×Ô¼ºµÄHook API°É¡£
ÎÒÃǽñÌìÒªÀ¹½ØµÄAPIÈçÏ£º
MessageBoxA¡¢MessageBoxW¡¢MessageBeep ºÍ OpenProcess ¡£
Ê×ÏÈ£¬´ó¼Ò¶¼ÖªµÀÒªÔÚÕû¸öϵͳ·¶Î§ÖÐÀ¹½Ø£¬ÐèҪʹÓÃDllÀ´Íê³É¡£ÏÖÔÚÎÒÃÇ´ò¿ªDelphi 2009£¬Ð½¨Ò»¸öDll¹¤³Ì£ºhookDll¡£ÐèҪ˵Ã÷µÄÊÇ£¬DelphiÊÇÍêÈ«ÃæÏò¶ÔÏóµÄ±à³ÌÓïÑÔ£¬ËùÒÔÎÒÃDz»ÒªÀË·Ñ£¬Õâ¸öDll´òËãÓÃÀàµÄ·½Ê½Íê³É¡£ÓÚÊÇ£¬ÔÚн¨µÄDLL¹¤³ÌÖÐÔÚÌí¼ÓÒ»¸öUnit Pas£¬ÃüÃûΪunitHook£¬ ÓÃÀ´Ð´À¹½ØÀàµÄ´¦Àí¡£unitHook.pasÖеĴúÂëÈçÏ£º
unit unitHook;
interface
uses
Windows, Messages, Classes, SysUtils;
type
//NtHookÀàÏà¹ØÀàÐÍ
TNtJmpCode=packed record //8×Ö½Ú
MovEax:Byte;
Addr:DWORD;
JmpCode:Word;
dwReserved:Byte;
end;
TNtHookClass=class(TObject)
private
hProcess:THandle;
NewAddr:TNtJmpCode;
OldAddr:array[0..7] of Byte;
ReadOK:Boolean;
public
BaseAddr:Pointer;
constructor Create(DllName,FuncName:string;NewFunc:Pointer);
destructor Destroy; override;
procedure Hook;
procedure UnHook;
end;
implementation
//==================================================
//NtHOOK À࿪ʼ
//==================================================
constructor TNtHookClass.Create(DllName: string; FuncName: string;NewFunc:Pointer);
var
DllModule:HMODULE;
dwReserved:DWORD;
begin
//»ñȡģ¿é¾ä±ú
DllModule:=GetModuleHandle(PChar(DllName));
//Èç¹ûµÃ²»µ½ËµÃ÷δ±»¼ÓÔØ
if DllModule=0 then DllModule:=LoadLibrary(PChar(DllName));
//µÃµ½Ä£¿éÈë¿ÚµØÖ·£¨»ùÖ·£©
BaseAddr:=Pointer(GetProcAddress(DllModule,PChar(FuncName)));
//»ñÈ¡µ±Ç°½ø³Ì¾ä±ú
hProcess:=GetCurrentProcess;
//Ö¸ÏòеØÖ·µÄÖ¸Õë
NewAddr.MovEax:=$B8;
NewAddr.
Ïà¹ØÎĵµ£º
WinExecÖ÷ÒªÔËÐÐEXEÎļþ¡£È磺
WinExec("Notepad.exe Readme.txt", SW_SHOW);
ShellExecute²»½ö¿ÉÒÔÔËÐÐEXEÎļþ£¬Ò²¿ÉÒÔÔËÐÐÒѾ¹ØÁªµÄÎļþ¡£
Ê×ÏȱØÐëÒýÓÃshellapi.pasµ¥Ôª£ºuses ShellAPI;
1.±ê×¼Ó÷¨
¡¡¡¡ ShellExecuteº¯ÊýÔÐͼ°²ÎÊýº¬ÒåÈçÏ£º
function ShellExecute(hWnd: HWND; Operati ......
DelphiÖи߼¶DLLµÄ±àдºÍµ÷Óü¼ÇÉ
¸ù¾ÝDelphiÌṩµÄÓÐ¹Ø DLL±àдºÍµ÷ÓõİïÖúÐÅÏ¢£¬Äã¿ÉÒԺܿìÍê³ÉÒ»°ãµÄ DLL±àдºÍµ÷ÓÃµÄ Ó¦ÓóÌÐò¡£±¾ÎĽéÉܵÄÖ÷ÌâÊÇÈçºÎ±àдºÍµ÷ÓÃÄܹ»´«µÝ¸÷ÖÖ²ÎÊý£¨°üÀ¨¶ÔÏóʵÀý£©µÄ DLL¡£ÀýÈ磬 Ö÷½Ð³ÌÐò´«µÝ¸ø DLLÒ»¸öADOConnection ¶ÔÏóʾÀý×÷Ϊ²ÎÊý£¬ DLLÖеĺ¯ÊýºÍ
¸ù¾ÝDelphiÌṩµÄÓÐ¹Ø DLL±àÐ ......
procedure TForm1.Button3Click(Sender: TObject);
begin
//ÏÔʾ´´½¨µÄÊý¾Ý¼¯: dbgrid->datasource->clientdataset
//Èç¹ûÊÖ¹¤¿ØÖÆdbgridÏÔʾ¿í¶È,dbgridÓÒ¼ü´´½¨Á½¸ö×Ö¶Îaa,bb,·Ö±ðÉèÖÿí¶È¼´¿É
cds1.FieldDefs.Add('aa',ftString,40);
......
procedure mc_SplitStr(sourStr:String;splitChar:String;desLst:TStringList);
var
tmpStr:String;
sValue:String;
iStart,iPos:Integer;
begin
try
desLst.Clear; //ºÜÖØÒª£¬·ñÔò£¬»áÒ» ......
¸ÅÒª
×ÔÈ¥ÄêCodeGear±»Ó¢°Í¿¨µÏŵ£¨Embarcadero Technologies£©ÊÕ¹ººó£¬´ó¼Ò¶ÔDelphiµÄδÀ´·¢Õ¹·Ç³£¹ØÐÄ¡£½üÈÕ£¬InfoQÖÐÎÄÕ¾ÓÐÐÒ¶ÔDavid I½øÐÐÁ˶À¼Òר·Ã£¬ÒÔÁ˽â¸ü¶à¹ØÓÚDelphiµÄÏà¹ØÐÅÏ¢¡£
¸öÈ˼ò½é
David Intersimone£¨¼ò³ÆDavid I£©£¬Ó¢°Í¿¨µÏŵ¸ºÔ𿪷¢Õß¹ØÏµµÄ¸±×ܲúÍÊ×ϯÐû´«¹Ù£¨Chief Evangelist£©¡£David¸º ......