forked from DarthTon/Blackbone
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy path_wow64_local_8h_source.html
362 lines (360 loc) · 38.1 KB
/
_wow64_local_8h_source.html
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/xhtml;charset=UTF-8"/>
<meta http-equiv="X-UA-Compatible" content="IE=9"/>
<meta name="generator" content="Doxygen 1.8.8"/>
<title>BlackBone: C:/Users/Ton/Documents/Visual Studio 2013/Projects/BlackBone/src/BlackBone/Subsystem/Wow64Local.h Source File</title>
<link href="tabs.css" rel="stylesheet" type="text/css"/>
<script type="text/javascript" src="jquery.js"></script>
<script type="text/javascript" src="dynsections.js"></script>
<link href="navtree.css" rel="stylesheet" type="text/css"/>
<script type="text/javascript" src="resize.js"></script>
<script type="text/javascript" src="navtree.js"></script>
<script type="text/javascript">
$(document).ready(initResizable);
$(window).load(resizeHeight);
</script>
<link href="search/search.css" rel="stylesheet" type="text/css"/>
<script type="text/javascript" src="search/search.js"></script>
<script type="text/javascript">
$(document).ready(function() { searchBox.OnSelectItem(0); });
</script>
<link href="doxygen.css" rel="stylesheet" type="text/css" />
</head>
<body>
<div id="top"><!-- do not remove this div, it is closed by doxygen! -->
<div id="titlearea">
<table cellspacing="0" cellpadding="0">
<tbody>
<tr style="height: 56px;">
<td style="padding-left: 0.5em;">
<div id="projectname">BlackBone
</div>
<div id="projectbrief">Windows memory hacking library</div>
</td>
</tr>
</tbody>
</table>
</div>
<!-- end header part -->
<!-- Generated by Doxygen 1.8.8 -->
<script type="text/javascript">
var searchBox = new SearchBox("searchBox", "search",false,'Search');
</script>
<div id="navrow1" class="tabs">
<ul class="tablist">
<li><a href="index.html"><span>Main Page</span></a></li>
<li><a href="annotated.html"><span>Classes</span></a></li>
<li class="current"><a href="files.html"><span>Files</span></a></li>
<li>
<div id="MSearchBox" class="MSearchBoxInactive">
<span class="left">
<img id="MSearchSelect" src="search/mag_sel.png"
onmouseover="return searchBox.OnSearchSelectShow()"
onmouseout="return searchBox.OnSearchSelectHide()"
alt=""/>
<input type="text" id="MSearchField" value="Search" accesskey="S"
onfocus="searchBox.OnSearchFieldFocus(true)"
onblur="searchBox.OnSearchFieldFocus(false)"
onkeyup="searchBox.OnSearchFieldChange(event)"/>
</span><span class="right">
<a id="MSearchClose" href="javascript:searchBox.CloseResultsWindow()"><img id="MSearchCloseImg" border="0" src="search/close.png" alt=""/></a>
</span>
</div>
</li>
</ul>
</div>
<div id="navrow2" class="tabs2">
<ul class="tablist">
<li><a href="files.html"><span>File List</span></a></li>
</ul>
</div>
</div><!-- top -->
<div id="side-nav" class="ui-resizable side-nav-resizable">
<div id="nav-tree">
<div id="nav-tree-contents">
<div id="nav-sync" class="sync"></div>
</div>
</div>
<div id="splitbar" style="-moz-user-select:none;"
class="ui-resizable-handle">
</div>
</div>
<script type="text/javascript">
$(document).ready(function(){initNavTree('_wow64_local_8h_source.html','');});
</script>
<div id="doc-content">
<!-- window showing the filter options -->
<div id="MSearchSelectWindow"
onmouseover="return searchBox.OnSearchSelectShow()"
onmouseout="return searchBox.OnSearchSelectHide()"
onkeydown="return searchBox.OnSearchSelectKey(event)">
<a class="SelectItem" href="javascript:void(0)" onclick="searchBox.OnSelectItem(0)"><span class="SelectionMark"> </span>All</a><a class="SelectItem" href="javascript:void(0)" onclick="searchBox.OnSelectItem(1)"><span class="SelectionMark"> </span>Classes</a><a class="SelectItem" href="javascript:void(0)" onclick="searchBox.OnSelectItem(2)"><span class="SelectionMark"> </span>Functions</a></div>
<!-- iframe showing the search results (closed by default) -->
<div id="MSearchResultsWindow">
<iframe src="javascript:void(0)" frameborder="0"
name="MSearchResults" id="MSearchResults">
</iframe>
</div>
<div class="header">
<div class="headertitle">
<div class="title">Wow64Local.h</div> </div>
</div><!--header-->
<div class="contents">
<div class="fragment"><div class="line"><a name="l00001"></a><span class="lineno"> 1</span> <span class="preprocessor">#pragma once</span></div>
<div class="line"><a name="l00002"></a><span class="lineno"> 2</span> </div>
<div class="line"><a name="l00003"></a><span class="lineno"> 3</span> <span class="preprocessor">#include "../Include/Winheaders.h"</span></div>
<div class="line"><a name="l00004"></a><span class="lineno"> 4</span> <span class="preprocessor">#include "../Include/NativeStructures.h"</span></div>
<div class="line"><a name="l00005"></a><span class="lineno"> 5</span> <span class="preprocessor">#include "../Include/Macro.h"</span></div>
<div class="line"><a name="l00006"></a><span class="lineno"> 6</span> <span class="preprocessor">#include "../Include/Types.h"</span></div>
<div class="line"><a name="l00007"></a><span class="lineno"> 7</span> </div>
<div class="line"><a name="l00008"></a><span class="lineno"> 8</span> <span class="preprocessor">#include <vector></span></div>
<div class="line"><a name="l00009"></a><span class="lineno"> 9</span> <span class="preprocessor">#include <type_traits></span></div>
<div class="line"><a name="l00010"></a><span class="lineno"> 10</span> </div>
<div class="line"><a name="l00011"></a><span class="lineno"> 11</span> <span class="keyword">namespace </span><a class="code" href="namespaceblackbone.html">blackbone</a></div>
<div class="line"><a name="l00012"></a><span class="lineno"> 12</span> {</div>
<div class="line"><a name="l00013"></a><span class="lineno"> 13</span> </div>
<div class="line"><a name="l00017"></a><span class="lineno"><a class="line" href="classblackbone_1_1_wow64_local.html"> 17</a></span> <span class="keyword">class </span><a class="code" href="classblackbone_1_1_wow64_local.html">Wow64Local</a></div>
<div class="line"><a name="l00018"></a><span class="lineno"> 18</span> {</div>
<div class="line"><a name="l00019"></a><span class="lineno"> 19</span> <span class="keyword">public</span>:</div>
<div class="line"><a name="l00020"></a><span class="lineno"> 20</span>  <a class="code" href="classblackbone_1_1_wow64_local.html">Wow64Local</a>( <span class="keywordtype">void</span> );</div>
<div class="line"><a name="l00021"></a><span class="lineno"> 21</span>  ~<a class="code" href="classblackbone_1_1_wow64_local.html">Wow64Local</a>( <span class="keywordtype">void</span> );</div>
<div class="line"><a name="l00022"></a><span class="lineno"> 22</span> </div>
<div class="line"><a name="l00023"></a><span class="lineno"> 23</span> </div>
<div class="line"><a name="l00024"></a><span class="lineno"> 24</span> <span class="comment">// unreferenced formal parameter, invalid operand size</span></div>
<div class="line"><a name="l00025"></a><span class="lineno"> 25</span> <span class="preprocessor">#pragma warning(disable : 4409 4100) </span></div>
<div class="line"><a name="l00026"></a><span class="lineno"> 26</span> </div>
<div class="line"><a name="l00033"></a><span class="lineno"> 33</span>  <span class="keyword">template</span>< <span class="keyword">typename</span>... Args ></div>
<div class="line"><a name="l00034"></a><span class="lineno"><a class="line" href="classblackbone_1_1_wow64_local.html#ac4f41d5aa750a506e1dcf72b76ef53e5"> 34</a></span>  DWORD64 <a class="code" href="classblackbone_1_1_wow64_local.html#ac4f41d5aa750a506e1dcf72b76ef53e5">X64Call</a>( ptr_t func, Args... args )</div>
<div class="line"><a name="l00035"></a><span class="lineno"> 35</span>  {</div>
<div class="line"><a name="l00036"></a><span class="lineno"> 36</span> </div>
<div class="line"><a name="l00037"></a><span class="lineno"> 37</span> <span class="preprocessor">#ifdef _M_IX86</span></div>
<div class="line"><a name="l00038"></a><span class="lineno"> 38</span> </div>
<div class="line"><a name="l00039"></a><span class="lineno"> 39</span>  <span class="keywordtype">int</span> argC = <span class="keyword">sizeof</span>...(Args);</div>
<div class="line"><a name="l00040"></a><span class="lineno"> 40</span>  <span class="keywordtype">int</span> i = 0;</div>
<div class="line"><a name="l00041"></a><span class="lineno"> 41</span>  std::vector<DWORD64> vargs{ ((DWORD64)args)... };</div>
<div class="line"><a name="l00042"></a><span class="lineno"> 42</span> </div>
<div class="line"><a name="l00043"></a><span class="lineno"> 43</span>  DWORD64 _rcx = (i < argC) ? vargs[i++] : 0;</div>
<div class="line"><a name="l00044"></a><span class="lineno"> 44</span>  DWORD64 _rdx = (i < argC) ? vargs[i++] : 0;</div>
<div class="line"><a name="l00045"></a><span class="lineno"> 45</span>  DWORD64 _r8 = (i < argC) ? vargs[i++] : 0;</div>
<div class="line"><a name="l00046"></a><span class="lineno"> 46</span>  DWORD64 _r9 = (i < argC) ? vargs[i++] : 0;</div>
<div class="line"><a name="l00047"></a><span class="lineno"> 47</span>  <a class="code" href="unionblackbone_1_1reg64.html">reg64</a> _rax;</div>
<div class="line"><a name="l00048"></a><span class="lineno"> 48</span>  _rax.v = 0;</div>
<div class="line"><a name="l00049"></a><span class="lineno"> 49</span> </div>
<div class="line"><a name="l00050"></a><span class="lineno"> 50</span>  DWORD64 restArgs = (i < argC) ? (DWORD64)&vargs[i] : 0;</div>
<div class="line"><a name="l00051"></a><span class="lineno"> 51</span>  </div>
<div class="line"><a name="l00052"></a><span class="lineno"> 52</span>  <span class="comment">// conversion to QWORD for easier use in inline assembly</span></div>
<div class="line"><a name="l00053"></a><span class="lineno"> 53</span>  DWORD64 _argC = argC - i;</div>
<div class="line"><a name="l00054"></a><span class="lineno"> 54</span>  DWORD64 _func = func;</div>
<div class="line"><a name="l00055"></a><span class="lineno"> 55</span> </div>
<div class="line"><a name="l00056"></a><span class="lineno"> 56</span>  DWORD back_esp = 0;</div>
<div class="line"><a name="l00057"></a><span class="lineno"> 57</span> </div>
<div class="line"><a name="l00058"></a><span class="lineno"> 58</span>  __asm</div>
<div class="line"><a name="l00059"></a><span class="lineno"> 59</span>  {</div>
<div class="line"><a name="l00060"></a><span class="lineno"> 60</span>  mov back_esp, esp</div>
<div class="line"><a name="l00061"></a><span class="lineno"> 61</span>  </div>
<div class="line"><a name="l00062"></a><span class="lineno"> 62</span>  ;<span class="comment">//align esp to 16</span></div>
<div class="line"><a name="l00063"></a><span class="lineno"> 63</span>  and esp, 0xFFFFFFF0</div>
<div class="line"><a name="l00064"></a><span class="lineno"> 64</span> </div>
<div class="line"><a name="l00065"></a><span class="lineno"> 65</span>  X64_Start();</div>
<div class="line"><a name="l00066"></a><span class="lineno"> 66</span> </div>
<div class="line"><a name="l00067"></a><span class="lineno"> 67</span>  ;<span class="comment">//fill first four arguments</span></div>
<div class="line"><a name="l00068"></a><span class="lineno"> 68</span>  push _rcx</div>
<div class="line"><a name="l00069"></a><span class="lineno"> 69</span>  X64_Pop(_RCX); </div>
<div class="line"><a name="l00070"></a><span class="lineno"> 70</span>  push _rdx</div>
<div class="line"><a name="l00071"></a><span class="lineno"> 71</span>  X64_Pop(_RDX);</div>
<div class="line"><a name="l00072"></a><span class="lineno"> 72</span>  push _r8</div>
<div class="line"><a name="l00073"></a><span class="lineno"> 73</span>  X64_Pop(_R8);</div>
<div class="line"><a name="l00074"></a><span class="lineno"> 74</span>  push _r9</div>
<div class="line"><a name="l00075"></a><span class="lineno"> 75</span>  X64_Pop(_R9);</div>
<div class="line"><a name="l00076"></a><span class="lineno"> 76</span>  </div>
<div class="line"><a name="l00077"></a><span class="lineno"> 77</span>  push edi</div>
<div class="line"><a name="l00078"></a><span class="lineno"> 78</span> </div>
<div class="line"><a name="l00079"></a><span class="lineno"> 79</span>  push restArgs</div>
<div class="line"><a name="l00080"></a><span class="lineno"> 80</span>  X64_Pop(_RDI);</div>
<div class="line"><a name="l00081"></a><span class="lineno"> 81</span> </div>
<div class="line"><a name="l00082"></a><span class="lineno"> 82</span>  push _argC</div>
<div class="line"><a name="l00083"></a><span class="lineno"> 83</span>  X64_Pop(_RAX);</div>
<div class="line"><a name="l00084"></a><span class="lineno"> 84</span> </div>
<div class="line"><a name="l00085"></a><span class="lineno"> 85</span>  ;<span class="comment">//put rest of arguments on the stack</span></div>
<div class="line"><a name="l00086"></a><span class="lineno"> 86</span>  test eax, eax</div>
<div class="line"><a name="l00087"></a><span class="lineno"> 87</span>  jz _ls_e</div>
<div class="line"><a name="l00088"></a><span class="lineno"> 88</span>  lea edi, dword ptr[edi + 8 * eax - 8]</div>
<div class="line"><a name="l00089"></a><span class="lineno"> 89</span> </div>
<div class="line"><a name="l00090"></a><span class="lineno"> 90</span>  _ls:</div>
<div class="line"><a name="l00091"></a><span class="lineno"> 91</span>  test eax, eax</div>
<div class="line"><a name="l00092"></a><span class="lineno"> 92</span>  jz _ls_e</div>
<div class="line"><a name="l00093"></a><span class="lineno"> 93</span>  push dword ptr [edi]</div>
<div class="line"><a name="l00094"></a><span class="lineno"> 94</span>  sub edi, 8</div>
<div class="line"><a name="l00095"></a><span class="lineno"> 95</span>  sub eax, 1</div>
<div class="line"><a name="l00096"></a><span class="lineno"> 96</span>  jmp _ls</div>
<div class="line"><a name="l00097"></a><span class="lineno"> 97</span>  _ls_e:</div>
<div class="line"><a name="l00098"></a><span class="lineno"> 98</span> </div>
<div class="line"><a name="l00099"></a><span class="lineno"> 99</span>  ;<span class="comment">//create stack space for spilling registers</span></div>
<div class="line"><a name="l00100"></a><span class="lineno"> 100</span>  sub esp, 0x20</div>
<div class="line"><a name="l00101"></a><span class="lineno"> 101</span>  call _func</div>
<div class="line"><a name="l00102"></a><span class="lineno"> 102</span> </div>
<div class="line"><a name="l00103"></a><span class="lineno"> 103</span>  ;<span class="comment">//cleanup stack</span></div>
<div class="line"><a name="l00104"></a><span class="lineno"> 104</span>  push _argC</div>
<div class="line"><a name="l00105"></a><span class="lineno"> 105</span>  X64_Pop(_RCX);</div>
<div class="line"><a name="l00106"></a><span class="lineno"> 106</span>  lea esp, dword ptr[esp + 8 * ecx + 0x20]</div>
<div class="line"><a name="l00107"></a><span class="lineno"> 107</span> </div>
<div class="line"><a name="l00108"></a><span class="lineno"> 108</span>  pop edi</div>
<div class="line"><a name="l00109"></a><span class="lineno"> 109</span> </div>
<div class="line"><a name="l00110"></a><span class="lineno"> 110</span>  <span class="comment">//set return value</span></div>
<div class="line"><a name="l00111"></a><span class="lineno"> 111</span>  X64_Push(_RAX);</div>
<div class="line"><a name="l00112"></a><span class="lineno"> 112</span>  pop _rax.dw[0]</div>
<div class="line"><a name="l00113"></a><span class="lineno"> 113</span> </div>
<div class="line"><a name="l00114"></a><span class="lineno"> 114</span>  X64_End();</div>
<div class="line"><a name="l00115"></a><span class="lineno"> 115</span> </div>
<div class="line"><a name="l00116"></a><span class="lineno"> 116</span>  mov esp, back_esp</div>
<div class="line"><a name="l00117"></a><span class="lineno"> 117</span>  }</div>
<div class="line"><a name="l00118"></a><span class="lineno"> 118</span>  </div>
<div class="line"><a name="l00119"></a><span class="lineno"> 119</span>  <span class="keywordflow">return</span> _rax.v;</div>
<div class="line"><a name="l00120"></a><span class="lineno"> 120</span> <span class="preprocessor">#else</span></div>
<div class="line"><a name="l00121"></a><span class="lineno"> 121</span>  <span class="keywordflow">return</span> (DWORD64)STATUS_NOT_SUPPORTED;</div>
<div class="line"><a name="l00122"></a><span class="lineno"> 122</span> <span class="preprocessor">#endif </span></div>
<div class="line"><a name="l00123"></a><span class="lineno"> 123</span>  }</div>
<div class="line"><a name="l00124"></a><span class="lineno"> 124</span> </div>
<div class="line"><a name="l00131"></a><span class="lineno"> 131</span>  <span class="keyword">template</span><<span class="keyword">typename</span> ...Args></div>
<div class="line"><a name="l00132"></a><span class="lineno"><a class="line" href="classblackbone_1_1_wow64_local.html#a84dda88f3559aa15e84bb1f557c40a5c"> 132</a></span>  DWORD64 <a class="code" href="classblackbone_1_1_wow64_local.html#a84dda88f3559aa15e84bb1f557c40a5c">X64Syscall</a>( <span class="keywordtype">int</span> idx, Args... args )</div>
<div class="line"><a name="l00133"></a><span class="lineno"> 133</span>  {</div>
<div class="line"><a name="l00134"></a><span class="lineno"> 134</span> <span class="preprocessor"> #ifdef _M_IX86</span></div>
<div class="line"><a name="l00135"></a><span class="lineno"> 135</span>  <span class="keywordtype">int</span> argC = <span class="keyword">sizeof</span>...(Args);</div>
<div class="line"><a name="l00136"></a><span class="lineno"> 136</span>  <span class="keywordtype">int</span> i = 0;</div>
<div class="line"><a name="l00137"></a><span class="lineno"> 137</span>  std::vector<DWORD64> vargs{ ((DWORD64)args)... };</div>
<div class="line"><a name="l00138"></a><span class="lineno"> 138</span> </div>
<div class="line"><a name="l00139"></a><span class="lineno"> 139</span>  DWORD64 _rcx = (i < argC) ? vargs[i++] : 0;</div>
<div class="line"><a name="l00140"></a><span class="lineno"> 140</span>  DWORD64 _rdx = (i < argC) ? vargs[i++] : 0;</div>
<div class="line"><a name="l00141"></a><span class="lineno"> 141</span>  DWORD64 _r8 = (i < argC) ? vargs[i++] : 0;</div>
<div class="line"><a name="l00142"></a><span class="lineno"> 142</span>  DWORD64 _r9 = (i < argC) ? vargs[i++] : 0;</div>
<div class="line"><a name="l00143"></a><span class="lineno"> 143</span>  <a class="code" href="unionblackbone_1_1reg64.html">reg64</a> _rax;</div>
<div class="line"><a name="l00144"></a><span class="lineno"> 144</span>  _rax.v = 0;</div>
<div class="line"><a name="l00145"></a><span class="lineno"> 145</span> </div>
<div class="line"><a name="l00146"></a><span class="lineno"> 146</span>  DWORD64 restArgs = (i < argC) ? (DWORD64)&vargs[i] : 0;</div>
<div class="line"><a name="l00147"></a><span class="lineno"> 147</span>  </div>
<div class="line"><a name="l00148"></a><span class="lineno"> 148</span>  <span class="comment">//conversion to QWORD for easier use in inline assembly</span></div>
<div class="line"><a name="l00149"></a><span class="lineno"> 149</span>  DWORD64 _argC = argC - i;</div>
<div class="line"><a name="l00150"></a><span class="lineno"> 150</span>  DWORD back_esp = 0;</div>
<div class="line"><a name="l00151"></a><span class="lineno"> 151</span> </div>
<div class="line"><a name="l00152"></a><span class="lineno"> 152</span>  __asm</div>
<div class="line"><a name="l00153"></a><span class="lineno"> 153</span>  {</div>
<div class="line"><a name="l00154"></a><span class="lineno"> 154</span>  ;<span class="comment">//keep original esp in back_esp variable</span></div>
<div class="line"><a name="l00155"></a><span class="lineno"> 155</span>  mov back_esp, esp</div>
<div class="line"><a name="l00156"></a><span class="lineno"> 156</span>  </div>
<div class="line"><a name="l00157"></a><span class="lineno"> 157</span>  ;<span class="comment">//align esp to 8, without aligned stack some syscalls may return errors !</span></div>
<div class="line"><a name="l00158"></a><span class="lineno"> 158</span>  and esp, 0xFFFFFFF8</div>
<div class="line"><a name="l00159"></a><span class="lineno"> 159</span> </div>
<div class="line"><a name="l00160"></a><span class="lineno"> 160</span>  X64_Start();</div>
<div class="line"><a name="l00161"></a><span class="lineno"> 161</span> </div>
<div class="line"><a name="l00162"></a><span class="lineno"> 162</span>  ;<span class="comment">//fill first four arguments</span></div>
<div class="line"><a name="l00163"></a><span class="lineno"> 163</span>  push _rcx</div>
<div class="line"><a name="l00164"></a><span class="lineno"> 164</span>  X64_Pop(_RCX);</div>
<div class="line"><a name="l00165"></a><span class="lineno"> 165</span>  push _rdx</div>
<div class="line"><a name="l00166"></a><span class="lineno"> 166</span>  X64_Pop(_RDX);</div>
<div class="line"><a name="l00167"></a><span class="lineno"> 167</span>  push _r8</div>
<div class="line"><a name="l00168"></a><span class="lineno"> 168</span>  X64_Pop(_R8);</div>
<div class="line"><a name="l00169"></a><span class="lineno"> 169</span>  push _r9</div>
<div class="line"><a name="l00170"></a><span class="lineno"> 170</span>  X64_Pop(_R9);</div>
<div class="line"><a name="l00171"></a><span class="lineno"> 171</span>  </div>
<div class="line"><a name="l00172"></a><span class="lineno"> 172</span>  push edi</div>
<div class="line"><a name="l00173"></a><span class="lineno"> 173</span> </div>
<div class="line"><a name="l00174"></a><span class="lineno"> 174</span>  push restArgs</div>
<div class="line"><a name="l00175"></a><span class="lineno"> 175</span>  X64_Pop(_RDI);</div>
<div class="line"><a name="l00176"></a><span class="lineno"> 176</span> </div>
<div class="line"><a name="l00177"></a><span class="lineno"> 177</span>  push _argC</div>
<div class="line"><a name="l00178"></a><span class="lineno"> 178</span>  X64_Pop(_RAX);</div>
<div class="line"><a name="l00179"></a><span class="lineno"> 179</span> </div>
<div class="line"><a name="l00180"></a><span class="lineno"> 180</span>  ;<span class="comment">//put rest of arguments on the stack</span></div>
<div class="line"><a name="l00181"></a><span class="lineno"> 181</span>  test eax, eax</div>
<div class="line"><a name="l00182"></a><span class="lineno"> 182</span>  jz _ls_e</div>
<div class="line"><a name="l00183"></a><span class="lineno"> 183</span>  lea edi, dword ptr [edi + 8*eax - 8]</div>
<div class="line"><a name="l00184"></a><span class="lineno"> 184</span> </div>
<div class="line"><a name="l00185"></a><span class="lineno"> 185</span>  _ls:</div>
<div class="line"><a name="l00186"></a><span class="lineno"> 186</span>  test eax, eax</div>
<div class="line"><a name="l00187"></a><span class="lineno"> 187</span>  jz _ls_e</div>
<div class="line"><a name="l00188"></a><span class="lineno"> 188</span>  push dword ptr [edi]</div>
<div class="line"><a name="l00189"></a><span class="lineno"> 189</span>  sub edi, 8</div>
<div class="line"><a name="l00190"></a><span class="lineno"> 190</span>  sub eax, 1</div>
<div class="line"><a name="l00191"></a><span class="lineno"> 191</span>  jmp _ls</div>
<div class="line"><a name="l00192"></a><span class="lineno"> 192</span>  _ls_e:</div>
<div class="line"><a name="l00193"></a><span class="lineno"> 193</span> </div>
<div class="line"><a name="l00194"></a><span class="lineno"> 194</span>  ;<span class="comment">//create stack space for spilling registers</span></div>
<div class="line"><a name="l00195"></a><span class="lineno"> 195</span>  sub esp, 0x28 </div>
<div class="line"><a name="l00196"></a><span class="lineno"> 196</span> </div>
<div class="line"><a name="l00197"></a><span class="lineno"> 197</span>  mov eax, idx</div>
<div class="line"><a name="l00198"></a><span class="lineno"> 198</span>  push _rcx</div>
<div class="line"><a name="l00199"></a><span class="lineno"> 199</span>  X64_Pop( _R10 );</div>
<div class="line"><a name="l00200"></a><span class="lineno"> 200</span>  EMIT( 0x0F ) EMIT( 0x05 ); <span class="comment">// syscall</span></div>
<div class="line"><a name="l00201"></a><span class="lineno"> 201</span> </div>
<div class="line"><a name="l00202"></a><span class="lineno"> 202</span>  ;<span class="comment">//cleanup stack</span></div>
<div class="line"><a name="l00203"></a><span class="lineno"> 203</span>  push _argC</div>
<div class="line"><a name="l00204"></a><span class="lineno"> 204</span>  X64_Pop(_RCX);</div>
<div class="line"><a name="l00205"></a><span class="lineno"> 205</span>  lea esp, dword ptr [esp + 8*ecx + 0x20]</div>
<div class="line"><a name="l00206"></a><span class="lineno"> 206</span> </div>
<div class="line"><a name="l00207"></a><span class="lineno"> 207</span>  pop edi</div>
<div class="line"><a name="l00208"></a><span class="lineno"> 208</span> </div>
<div class="line"><a name="l00209"></a><span class="lineno"> 209</span>  ;<span class="comment">//set return value</span></div>
<div class="line"><a name="l00210"></a><span class="lineno"> 210</span>  X64_Push(_RAX);</div>
<div class="line"><a name="l00211"></a><span class="lineno"> 211</span>  pop _rax.dw[0]</div>
<div class="line"><a name="l00212"></a><span class="lineno"> 212</span> </div>
<div class="line"><a name="l00213"></a><span class="lineno"> 213</span>  X64_End();</div>
<div class="line"><a name="l00214"></a><span class="lineno"> 214</span> </div>
<div class="line"><a name="l00215"></a><span class="lineno"> 215</span>  mov esp, back_esp</div>
<div class="line"><a name="l00216"></a><span class="lineno"> 216</span>  }</div>
<div class="line"><a name="l00217"></a><span class="lineno"> 217</span> </div>
<div class="line"><a name="l00218"></a><span class="lineno"> 218</span>  <span class="keywordflow">return</span> _rax.v;</div>
<div class="line"><a name="l00219"></a><span class="lineno"> 219</span> <span class="preprocessor"> #else</span></div>
<div class="line"><a name="l00220"></a><span class="lineno"> 220</span>  <span class="keywordflow">return</span> STATUS_NOT_SUPPORTED;</div>
<div class="line"><a name="l00221"></a><span class="lineno"> 221</span> <span class="preprocessor"> #endif</span></div>
<div class="line"><a name="l00222"></a><span class="lineno"> 222</span>  }</div>
<div class="line"><a name="l00223"></a><span class="lineno"> 223</span> <span class="preprocessor">#pragma warning(default : 4409 4100)</span></div>
<div class="line"><a name="l00224"></a><span class="lineno"> 224</span> </div>
<div class="line"><a name="l00231"></a><span class="lineno"> 231</span>  BLACKBONE_API <span class="keywordtype">void</span> <a class="code" href="classblackbone_1_1_wow64_local.html#a0920511e9d684d98149202cc67ebde52">memcpy64</a>( DWORD64 <span class="comment">/*dst*/</span>, DWORD64 <span class="comment">/*src*/</span>, DWORD <span class="comment">/*size*/</span> );</div>
<div class="line"><a name="l00232"></a><span class="lineno"> 232</span> </div>
<div class="line"><a name="l00238"></a><span class="lineno"> 238</span>  BLACKBONE_API DWORD64 <a class="code" href="classblackbone_1_1_wow64_local.html#a01c37ab48326da71251927c2588d6007">getTEB64</a>( <a class="code" href="structblackbone_1_1___t_e_b___t.html">_TEB64</a>& out );</div>
<div class="line"><a name="l00239"></a><span class="lineno"> 239</span> </div>
<div class="line"><a name="l00246"></a><span class="lineno"> 246</span>  BLACKBONE_API DWORD64 <a class="code" href="classblackbone_1_1_wow64_local.html#a6d3c6eabb469118efe5336616854d6a6">GetModuleHandle64</a>( <span class="keyword">const</span> <span class="keywordtype">wchar_t</span>* lpModuleName, DWORD* pSize = <span class="keyword">nullptr</span> );</div>
<div class="line"><a name="l00247"></a><span class="lineno"> 247</span> </div>
<div class="line"><a name="l00253"></a><span class="lineno"> 253</span>  BLACKBONE_API DWORD64 <a class="code" href="classblackbone_1_1_wow64_local.html#a824e3b962dcb79152158e06f41dc0656">getNTDLL64</a>( DWORD* pSize = <span class="keyword">nullptr</span> );</div>
<div class="line"><a name="l00254"></a><span class="lineno"> 254</span> </div>
<div class="line"><a name="l00259"></a><span class="lineno"> 259</span>  BLACKBONE_API DWORD64 <a class="code" href="classblackbone_1_1_wow64_local.html#aa0df6a1d2dd54d2fab9d37bb56e18871">getLdrGetProcedureAddress</a>();</div>
<div class="line"><a name="l00260"></a><span class="lineno"> 260</span> </div>
<div class="line"><a name="l00267"></a><span class="lineno"> 267</span>  BLACKBONE_API DWORD64 <a class="code" href="classblackbone_1_1_wow64_local.html#ab9d32f86880ef64b45d4d5ed05b495df">GetProcAddress64</a>( DWORD64 hModule, <span class="keyword">const</span> <span class="keywordtype">char</span>* funcName );</div>
<div class="line"><a name="l00268"></a><span class="lineno"> 268</span> </div>
<div class="line"><a name="l00274"></a><span class="lineno"> 274</span>  BLACKBONE_API DWORD64 <a class="code" href="classblackbone_1_1_wow64_local.html#a82fd956d4847d5cf2cdeb6396e5c30e1">LoadLibrary64</a>( <span class="keyword">const</span> <span class="keywordtype">wchar_t</span>* path );</div>
<div class="line"><a name="l00275"></a><span class="lineno"> 275</span> </div>
<div class="line"><a name="l00276"></a><span class="lineno"> 276</span> <span class="keyword">private</span>:</div>
<div class="line"><a name="l00277"></a><span class="lineno"> 277</span>  DWORD64 _ntdll64 = 0; <span class="comment">// 64bit ntdll address</span></div>
<div class="line"><a name="l00278"></a><span class="lineno"> 278</span>  DWORD64 _LdrGetProcedureAddress = 0; <span class="comment">// LdrGetProcedureAddress address in 64bit ntdll</span></div>
<div class="line"><a name="l00279"></a><span class="lineno"> 279</span>  DWORD _ntdll64Size = 0; <span class="comment">// size of ntdll64 image</span></div>
<div class="line"><a name="l00280"></a><span class="lineno"> 280</span> };</div>
<div class="line"><a name="l00281"></a><span class="lineno"> 281</span> </div>
<div class="line"><a name="l00282"></a><span class="lineno"> 282</span> }</div>
<div class="ttc" id="structblackbone_1_1___t_e_b___t_html"><div class="ttname"><a href="structblackbone_1_1___t_e_b___t.html">blackbone::_TEB_T</a></div><div class="ttdef"><b>Definition:</b> NativeStructures.h:71</div></div>
<div class="ttc" id="classblackbone_1_1_wow64_local_html_a0920511e9d684d98149202cc67ebde52"><div class="ttname"><a href="classblackbone_1_1_wow64_local.html#a0920511e9d684d98149202cc67ebde52">blackbone::Wow64Local::memcpy64</a></div><div class="ttdeci">BLACKBONE_API void memcpy64(DWORD64, DWORD64, DWORD)</div><div class="ttdoc">Copy memory beyond 4GB limit </div></div>
<div class="ttc" id="unionblackbone_1_1reg64_html"><div class="ttname"><a href="unionblackbone_1_1reg64.html">blackbone::reg64</a></div><div class="ttdef"><b>Definition:</b> Types.h:72</div></div>
<div class="ttc" id="classblackbone_1_1_wow64_local_html_a82fd956d4847d5cf2cdeb6396e5c30e1"><div class="ttname"><a href="classblackbone_1_1_wow64_local.html#a82fd956d4847d5cf2cdeb6396e5c30e1">blackbone::Wow64Local::LoadLibrary64</a></div><div class="ttdeci">BLACKBONE_API DWORD64 LoadLibrary64(const wchar_t *path)</div><div class="ttdoc">Load 64 bit module into current process </div><div class="ttdef"><b>Definition:</b> Wow64Local.cpp:229</div></div>
<div class="ttc" id="classblackbone_1_1_wow64_local_html_ac4f41d5aa750a506e1dcf72b76ef53e5"><div class="ttname"><a href="classblackbone_1_1_wow64_local.html#ac4f41d5aa750a506e1dcf72b76ef53e5">blackbone::Wow64Local::X64Call</a></div><div class="ttdeci">DWORD64 X64Call(ptr_t func, Args...args)</div><div class="ttdoc">Call 64 bit function </div><div class="ttdef"><b>Definition:</b> Wow64Local.h:34</div></div>
<div class="ttc" id="classblackbone_1_1_wow64_local_html_a01c37ab48326da71251927c2588d6007"><div class="ttname"><a href="classblackbone_1_1_wow64_local.html#a01c37ab48326da71251927c2588d6007">blackbone::Wow64Local::getTEB64</a></div><div class="ttdeci">BLACKBONE_API DWORD64 getTEB64(_TEB64 &out)</div><div class="ttdoc">Get native bit TEB </div><div class="ttdef"><b>Definition:</b> Wow64Local.cpp:65</div></div>
<div class="ttc" id="classblackbone_1_1_wow64_local_html_ab9d32f86880ef64b45d4d5ed05b495df"><div class="ttname"><a href="classblackbone_1_1_wow64_local.html#ab9d32f86880ef64b45d4d5ed05b495df">blackbone::Wow64Local::GetProcAddress64</a></div><div class="ttdeci">BLACKBONE_API DWORD64 GetProcAddress64(DWORD64 hModule, const char *funcName)</div><div class="ttdoc">64 bit implementation of GetProcAddress </div><div class="ttdef"><b>Definition:</b> Wow64Local.cpp:203</div></div>
<div class="ttc" id="classblackbone_1_1_wow64_local_html_a824e3b962dcb79152158e06f41dc0656"><div class="ttname"><a href="classblackbone_1_1_wow64_local.html#a824e3b962dcb79152158e06f41dc0656">blackbone::Wow64Local::getNTDLL64</a></div><div class="ttdeci">BLACKBONE_API DWORD64 getNTDLL64(DWORD *pSize=nullptr)</div><div class="ttdoc">Get 64 bit ntdll base </div><div class="ttdef"><b>Definition:</b> Wow64Local.cpp:140</div></div>
<div class="ttc" id="classblackbone_1_1_wow64_local_html"><div class="ttname"><a href="classblackbone_1_1_wow64_local.html">blackbone::Wow64Local</a></div><div class="ttdoc">WOW64-x64 interface </div><div class="ttdef"><b>Definition:</b> Wow64Local.h:17</div></div>
<div class="ttc" id="classblackbone_1_1_wow64_local_html_aa0df6a1d2dd54d2fab9d37bb56e18871"><div class="ttname"><a href="classblackbone_1_1_wow64_local.html#aa0df6a1d2dd54d2fab9d37bb56e18871">blackbone::Wow64Local::getLdrGetProcedureAddress</a></div><div class="ttdeci">BLACKBONE_API DWORD64 getLdrGetProcedureAddress()</div><div class="ttdoc">Get 'LdrGetProcedureAddress' address </div><div class="ttdef"><b>Definition:</b> Wow64Local.cpp:161</div></div>
<div class="ttc" id="classblackbone_1_1_wow64_local_html_a6d3c6eabb469118efe5336616854d6a6"><div class="ttname"><a href="classblackbone_1_1_wow64_local.html#a6d3c6eabb469118efe5336616854d6a6">blackbone::Wow64Local::GetModuleHandle64</a></div><div class="ttdeci">BLACKBONE_API DWORD64 GetModuleHandle64(const wchar_t *lpModuleName, DWORD *pSize=nullptr)</div><div class="ttdoc">Gets 64 bit module base </div><div class="ttdef"><b>Definition:</b> Wow64Local.cpp:99</div></div>
<div class="ttc" id="classblackbone_1_1_wow64_local_html_a84dda88f3559aa15e84bb1f557c40a5c"><div class="ttname"><a href="classblackbone_1_1_wow64_local.html#a84dda88f3559aa15e84bb1f557c40a5c">blackbone::Wow64Local::X64Syscall</a></div><div class="ttdeci">DWORD64 X64Syscall(int idx, Args...args)</div><div class="ttdoc">Perform a syscall </div><div class="ttdef"><b>Definition:</b> Wow64Local.h:132</div></div>
<div class="ttc" id="namespaceblackbone_html"><div class="ttname"><a href="namespaceblackbone.html">blackbone</a></div><div class="ttdef"><b>Definition:</b> AsmHelper32.cpp:6</div></div>
</div><!-- fragment --></div><!-- contents -->
</div><!-- doc-content -->
<!-- start footer part -->
<div id="nav-path" class="navpath"><!-- id is needed for treeview function! -->
<ul>
<li class="navelem"><a class="el" href="dir_aa9befc4bdfa617079e96718d920d9d2.html">Visual Studio 2013</a></li><li class="navelem"><a class="el" href="dir_9749fe1d1039c274ca5f4a0137bd5805.html">Projects</a></li><li class="navelem"><a class="el" href="dir_87d371cc6a3e9a1e307775a876c8e949.html">BlackBone</a></li><li class="navelem"><a class="el" href="dir_2dd5b37e3ce8f08186c1d7d6a8b43f79.html">src</a></li><li class="navelem"><a class="el" href="dir_c12349095ba230d0c7acc796e8f40ecd.html">BlackBone</a></li><li class="navelem"><a class="el" href="dir_0a8ec7ab03a1fd32c0fb70dac1a5341d.html">Subsystem</a></li><li class="navelem"><b>Wow64Local.h</b></li>
<li class="footer">Generated on Tue Sep 23 2014 11:46:47 for BlackBone by
<a href="http://www.doxygen.org/index.html">
<img class="footer" src="doxygen.png" alt="doxygen"/></a> 1.8.8 </li>
</ul>
</div>
</body>
</html>