Click here to Skip to main content
15,893,814 members

CreateRemoteThread and exported function issue

zoopp asked:

Open original thread
Good day.

I've made a DLL in which I export a function. I attach the DLL to a process and then I want to call that function in that process space from another process.

Here's the exported function:

C#
__declspec(dllexport) DWORD WINAPI doSomething(LPVOID param)
{
    MessageBox(NULL, "doSomething()", "", 0);
    if (Switch::getInstance().currentStatus() == ON) {
        Switch::getInstance().switchOff();
    } else {
        Switch::getInstance().switchOn();
    }

    return 0;
}



I figured it could be done the same way you do DLL injection so I just went ahead and made a small test app like this:

C++
HANDLE hProcess = OpenProcess(PROCESS_ALL_ACCESS, false, TARGET_PROCESS_PID);
assert(hProcess != NULL);

HMODULE dllModule = LoadLibrary("Switch.dll");
assert(dllModule != NULL);

FARPROC functionStart = GetProcAddress(dllModule, "?doSomething@@YGKPAX@Z");
assert(functionStart != NULL);

assert(CreateRemoteThread(hProcess, NULL, 0, (LPTHREAD_START_ROUTINE)functionStart, NULL, 0, NULL) != NULL);

printf("Switch toggled\n");
getchar();

FreeLibrary(dllModule);
CloseHandle(hProcess);


The idea is that instead of supplying the address of LoadLibrary (the way it's done during dll injection) to CreateRemoteThread I supply the address to my function.

Anyway, I inject the dll into the target process and then run the above code but the target proces crashes with 0xC0000005 error code (access violation if I'm not wrong).

Any ideas what's wrong?
Tags: C++, Windows

Plain Text
ASM
ASP
ASP.NET
BASIC
BAT
C#
C++
COBOL
CoffeeScript
CSS
Dart
dbase
F#
FORTRAN
HTML
Java
Javascript
Kotlin
Lua
MIDL
MSIL
ObjectiveC
Pascal
PERL
PHP
PowerShell
Python
Razor
Ruby
Scala
Shell
SLN
SQL
Swift
T4
Terminal
TypeScript
VB
VBScript
XML
YAML

Preview



When answering a question please:
  1. Read the question carefully.
  2. Understand that English isn't everyone's first language so be lenient of bad spelling and grammar.
  3. If a question is poorly phrased then either ask for clarification, ignore it, or edit the question and fix the problem. Insults are not welcome.
  4. Don't tell someone to read the manual. Chances are they have and don't get it. Provide an answer or move on to the next question.
Let's work to help developers, not make them feel stupid.
Please note that all posts will be submitted under the http://www.codeproject.com/info/cpol10.aspx.



CodeProject, 20 Bay Street, 11th Floor Toronto, Ontario, Canada M5J 2N8 +1 (416) 849-8900