
مكتبة لاستيراد الدوال من ملفات dll بطريقة مخفية وغير صديقة للهندسة العكسية
مكتبة بسيطة وسهلة الاستخدام تعتمد على الترويسة فقط لجعل حياة مهندس الهندسة العكسية أكثر صعوبة بكثير.
LI_FN(OutputDebugStringA)("hello world");
LI_FN(VirtualProtect).in(LI_MODULE("kernel32.dll").cached());
مخرجات IDA عند تصريف السطر الأول
LI_FN(function_pointer) -> lazy_functionLI_FN_DEF(function_type) -> lazy_functionLI_MODULE(module_name) -> lazy_modulesafe تشير إلى أنه عندما لا تتمكن الدالة من إكمال مهمتها بنجاح، يتم إرجاع 0 بدلاً من ظهور سلوك غير معرّف.cached تشير إلى أن النتيجة تُحسب فقط خلال الاستدعاء الأول ثم يُعاد استخدامها لاحقًا.forwarded تشير إلى أنه سيتم حل تصدير إعادة التوجيه بشكل صحيح.lazy_module| function | safe | cached | |
|---|---|---|---|
| Attempts to find the given module and returns its address | |||
get<T = void*>() -> T |
:x: | :x: | |
safe<T = void*>() -> T |
:white_check_mark: | :x: | |
cached<T = void*>() -> T |
:x: | :white_check_mark: | |
safe_cached<T = void*>() -> T |
:white_check_mark: | :white_check_mark: | |
| Attemps to find the given module using the given LDR_DATA_TABLE_ENTRY pointer | |||
in<T = void*, Ldr>(Ldr ldr_entry) -> T |
:white_check_mark: | :x: | |
in_cached<T = void*, Ldr>(Ldr ldr_entry) -> T |
:white_check_mark: | :white_check_mark: | |
lazy_function<F>| function | safe | cached | forwarded |
|---|---|---|---|
| calls resolved export using given arguments | |||
operator()(...) -> result_of<F, ...> |
:x: | :x: | :x: |
| attempts to resolve an export in all loaded modules and returns the function address | |||
get<T = F>() -> T |
:x: | :x: | :x: |
safe<T = F>() -> T |
:white_check_mark: | :x: | :x: |
cached<T = F>() -> T |
:x: | :white_check_mark: | :x: |
safe_cached<T = F>() -> T |
:white_check_mark: | :white_check_mark: | :x: |
forwarded<T = F>() -> T |
:x: | :x: | :white_check_mark: |
forwarded_safe<T = F>() -> T |
:white_check_mark: | :x: | :white_check_mark: |
forwarded_cached<T = F>() -> T |
:x: | :white_check_mark: | :white_check_mark: |
forwarded_safe_cached<T = F>() -> T |
:white_check_mark: | :white_check_mark: | :white_check_mark: |
| attempts to resolve an export in the given module and returns the function address | |||
in<T = F, A>(A module_address) -> T |
:x: | :x: | :x: |
in_safe<T = F, A>(A module_address) -> T |
:white_check_mark: | :x: | :x: |
in_cached<T = F, A>(A module_address) -> T |
:x: | :white_check_mark: | :x: |
in_safe_cached<T = F, A>(A module_address) -> T |
:white_check_mark: | :white_check_mark: | :x: |
attempts to resolve an export in ntdll and returns the function address |
|||
nt<T = F>() -> T |
:x: | :x: | :x: |
nt_safe<T = F>() -> T |
:white_check_mark: | :x: | :x: |
nt_cached<T = F>() -> T |
:x: | :white_check_mark: | :x: |
nt_safe_cached<T = F>() -> T |
:white_check_mark: | :white_check_mark: | :x: |
#define | effects |
|---|---|
LAZY_IMPORTER_NO_FORCEINLINE | disables force inlining |
LAZY_IMPORTER_CASE_INSENSITIVE | enables case insensitive comparison. Might be required for forwarded export resolution. |
LAZY_IMPORTER_CACHE_OPERATOR_PARENS | uses cached() instead of get() in operator() of lazy_function |
LAZY_IMPORTER_RESOLVE_FORWARDED_EXPORTS | uses forwarded() in get(). WARNING does not apply to nt() and in(). |
LAZY_IMPORTER_HARDENED_MODULE_CHECKS | adds extra sanity checks to module enumeration. |
LAZY_IMPORTER_NO_CPP_FORWARD | Removes dependence on <utility> c++ header. |