From 88122a928a0c718ff37459d1a4790ca67d02051f Mon Sep 17 00:00:00 2001 From: Michael Dirks Date: Wed, 30 Dec 2015 06:19:44 +0100 Subject: [PATCH] - Fixed BP_GetReturnAddress not returning the correct address. - Changed BP_GetFunctionPointer to use intelligent stackframe reading instead of memory scanning (faster & safer). --- BlitzPointer.cpp | 39 ++++++++++++++------------------------- 1 file changed, 14 insertions(+), 25 deletions(-) diff --git a/BlitzPointer.cpp b/BlitzPointer.cpp index 9b4e359..014e1f8 100644 --- a/BlitzPointer.cpp +++ b/BlitzPointer.cpp @@ -21,46 +21,35 @@ #include "BlitzPointer.h" DLL_METHOD intptr_t DLL_CALL BP_GetReturnAddress() { - intptr_t StackPointer, ReturnAddress; + intptr_t BasePointer, ReturnAddress; __asm { //ASM. Do touch if suicidal. - mov StackPointer, esp; // Store current Stack Pointer - mov esp, ebp; // On X86, EBP[0] is our own function and EBP[1] is the return address. - add esp, 4; // Which means that we can just take it from there into our own variable. - pop ReturnAddress; // Just like this. - mov esp, [StackPointer]; // And then reset the Stack Pointer. + mov BasePointer, ebp; // Store current BasePointer } + // Blitz uses X86 Call-Near (E8) instructions to call its own functions. + // We can simply deduce the Return Address like this because of that. + ReturnAddress = *reinterpret_cast(*reinterpret_cast(*reinterpret_cast(BasePointer)) - 8); + return ReturnAddress; } #pragma comment(linker, "/EXPORT:BP_GetReturnAddress=_BP_GetReturnAddress@0") DLL_METHOD intptr_t DLL_CALL BP_GetFunctionPointer() { - intptr_t StackPointer, ReturnAddress; + intptr_t BasePointer, ReturnAddress, FunctionPointer; __asm { //ASM. Do touch if suicidal. - mov StackPointer, esp; // Store current Stack Pointer - mov esp, ebp; // On X86, EBP[0] is our own function and EBP[1] is the return address. - add esp, 4; // Which means that we can just take it from there into our own variable. - pop ReturnAddress; // Just like this. - mov esp, [StackPointer]; // And then reset the Stack Pointer. + mov BasePointer, ebp; // Store current BasePointer } - // Let's look backwards in memory for the function signature (0x53 0x56 0x57 0x55 0x89 0xE5) for at most one megabyte. - uint8_t* startPtr = (uint8_t*)ReturnAddress; - uint8_t* endPtr = (uint8_t*)(ReturnAddress - 1048576); - for (uint8_t* curPtr = startPtr; curPtr != endPtr; curPtr--) { - if (*(curPtr) == 0x53) // push ebx - if (*(curPtr + 1) == 0x56) // push esi - if (*(curPtr + 2) == 0x57) // push edi - if (*(curPtr + 3) == 0x55) // push ebp - if (*(curPtr + 4) == 0x89 && *(curPtr + 5) == 0xE5) // mov ebp,esp - return reinterpret_cast(curPtr); - } - // This can be done more efficiently, just look twice for the return address. + // Blitz uses X86 Call-Near (E8) instructions to call its own functions. + // We can simply deduce the Return Address like this because of that. + ReturnAddress = *reinterpret_cast(*reinterpret_cast(*reinterpret_cast(BasePointer)) - 8); + // And since it's a Call-Near, the call is offset to the return address. + FunctionPointer = ReturnAddress + *reinterpret_cast(ReturnAddress - 4); - return 0; + return FunctionPointer; } #pragma comment(linker, "/EXPORT:BP_GetFunctionPointer=_BP_GetFunctionPointer@0")