SetWindowLongPtr返回ERROR_ACCESS_DENIED

时间:2013-05-19 11:09:15

标签: c windows winapi dll-injection setwindowshookex

我仍然在苦苦挣扎。

我的目标是:

  • 在notepad.exe中设置一个挂钩
  • 它的子类(我的最终目标是继承Edit类并在我自己的窗口中显示内容)

免责声明:我知道有更简单的方法从记事本中获取文本/内容,但这是我学习C,winapi,Subclassing和hooks的一种方式。

我的问题是SetWindowLongPtr总是返回ERROR_ACCESS_DENIED错误(代码5)。

2013年5月22日:这已经修复了! 问题是SetWindowLongPtr在错误的地方。它必须位于GetMsgProc函数内。

问题变得有点冗长,所以我重新写了这个问题(用更新的代码)

现在的问题是当目标是notepad.exe时,GetMsgProc被 NOT 调用。如果我将目标更改为simple.exe,GetMsgProc将被调用并运行!

(Simple.exe只是一个简单的GUI):

Simple.exe

代码如下所示:

exe.cpp

#include <windows.h>
#include "Resource.h"
#include <stdlib.h>
#include "stdafx.h"
#include <strsafe.h>

#include "C:\Users\Kristensen\Documents\Visual Studio 2012\Projects\Win32D\dll\dllHeader.h"

//---------------------------------------------------------------------------
HWND hWnd;

LRESULT CALLBACK DlgProc(HWND hWnd, UINT Msg, WPARAM wParam, LPARAM lParam);
//---------------------------------------------------------------------------
INT WINAPI WinMain(HINSTANCE hInstance, HINSTANCE hPrevInstance,
                   LPSTR lpCmdLine, int nCmdShow)
{
    DialogBox(hInstance, MAKEINTRESOURCE(IDD_DLGFIRST),
        hWnd, reinterpret_cast<DLGPROC>(DlgProc));

    return FALSE;
}
//---------------------------------------------------------------------------
LRESULT CALLBACK DlgProc(HWND hWndDlg, UINT Msg, WPARAM wParam, LPARAM lParam)
{
    switch(Msg)
    {
    case WM_INITDIALOG:
        return TRUE;

    case WM_COMMAND:
        switch(wParam)
        {
        case IDOK:
            hookNotepad();
            return TRUE;
        case IDCANCEL:
            removeHook();
            EndDialog(hWndDlg, 0);
        }
        break;
    }

    return FALSE;
}
//---------------------------------------------------------------------------

dllHeader.h

    #ifdef DLLAPI
    #else
    #define DLLAPI extern "C" __declspec(dllimport)
    #endif
    DLLAPI bool hookNotepad();
    DLLAPI bool removeHook();

dll.cpp:

#include "stdafx.h"
#include <windows.h>
#define DLLAPI extern "C" __declspec(dllexport)
#include "dllHeader.h"

// shared variables
#pragma data_seg("Shared")
HHOOK g_hHook = NULL; // Hook for Notepad 
HWND npHWND = NULL; // Notepad handle
#pragma data_seg()
#pragma comment(linker, "/section:Shared,rws")

// Forward references
LRESULT CALLBACK GetMsgProc(int nCode, WPARAM wParam, LPARAM lParam) ;
LRESULT CALLBACK NewWndProc(HWND Hwnd, UINT Message, WPARAM wParam, LPARAM lParam);
//LRESULT CALLBACK CBTProc(int nCode, WPARAM wParam, LPARAM lParam) ;


LONG OldWndProc; 
DWORD pid;
HINSTANCE g_hInstDll = NULL; // DllMain entry (DLL_PROCESS_ATTACH)
DWORD npThreadId = NULL; // Notepad thread ID

LRESULT CALLBACK GetMsgProc(int nCode, WPARAM wParam, LPARAM lParam) //Testing with CBTProc - same issues as with GetMsgProc.
{
    //If I hook notepad.exe, I never get called. (silence)

    //If I hook simple.exe, I get called (Beep beep!)

    // make some noise
    static DWORD dwTickKeep = 0;
    if ((GetTickCount()-dwTickKeep)>300)
    {   dwTickKeep = GetTickCount();
    Beep(2000, 100);
    }

    //Subclassing......
    //For simple.exe: (working)
    //HWND hwndEdit = ::FindWindowEx(npHWND,NULL,TEXT("WindowsForms10.RichEdit20W.app.0.2bf8098_r14_ad1"), NULL);
    //For notepad.exe: (not working)
    HWND hwndEdit = ::FindWindowEx(npHWND,NULL,TEXT("Edit"), NULL); 

    if (hwndEdit)
    {
        //Subclass it
        OldWndProc = GetWindowLongPtr(hwndEdit, GWLP_WNDPROC);
        SetWindowLongPtr(hwndEdit, GWL_WNDPROC, (LONG_PTR)NewWndProc);
    }
    return(CallNextHookEx(g_hHook, nCode, wParam, lParam));
}

BOOL APIENTRY DllMain( HMODULE hModule,  DWORD  ul_reason_for_call,   LPVOID lpReserved  )
{
    switch (ul_reason_for_call)
    {
    case DLL_PROCESS_ATTACH:
        g_hInstDll = hModule;
        break;

    case DLL_THREAD_ATTACH:
    case DLL_THREAD_DETACH:
    case DLL_PROCESS_DETACH:
        break;
    }
    return TRUE;
}

bool hookNotepad ()
{
    // If target is running
    // if (npHWND = FindWindow(NULL, TEXT("simpleGUI")))
    if (npHWND = FindWindow(TEXT("Notepad"), NULL))
    {
        // Finds the ThreadID for target. We use this in SetWindowsHookEx   
        npThreadId = GetWindowThreadProcessId(npHWND, &pid); 

        // Sets the hook in target
        g_hHook = SetWindowsHookEx(WH_GETMESSAGE, GetMsgProc, g_hInstDll, npThreadId); 
        //g_hHook = SetWindowsHookEx(WH_CBT, CBTProc, g_hInstDll, npThreadId); 

        // If the hook succesed
        if (g_hHook) 
        { 
            ////Add a menu in the notepad.exe, but not relevant for subclassing notepads edit class...
            //HMENU hCurrent = GetMenu(npHWND); //Get the CURRENT menu of the window.
            //HMENU hNew = CreateMenu(); //Create a new one. 
            //AppendMenu(hCurrent, MF_STRING | MF_POPUP, (unsigned int)hNew, TEXT("myMenu")); 
            //AppendMenu(hNew, MF_STRING, 2000, L"myButton"); //2000 is the ID of the new button. 
            //DrawMenuBar(npHWND); //redraw the Menu.

            //Force a msg to the messagequeue, so that the hook function(GetMsgProc) gets called
            PostThreadMessage(npThreadId, WM_NULL, 0, 0);
            return 1;
        }
        return 0;
    }
    else
        //Notepad is not running
        return 0;
}

bool removeHook()
{
    // Removes the hook
    if (g_hHook != NULL)
    {
        UnhookWindowsHookEx(g_hHook);
        g_hHook = NULL;
    }
    return 0;
}



LRESULT CALLBACK NewWndProc(HWND Hwnd, UINT Message, WPARAM wParam, LPARAM lParam)
{ 
    //We should come here and should be able to read the text from the Edit class...
    return CallWindowProc((WNDPROC)OldWndProc, Hwnd, Message, wParam, lParam); 
}

任何提示,评论或提示都非常感谢......

2 个答案:

答案 0 :(得分:2)

您的代码中存在3个问题:

(1)变量HWND npHWND意味着在host-exe和notepad-exe之间共享,因此它必须放在共享数据段块中。此值目前在'hookNotepad'调用内部进行评估,并且仅存在于host-exe中。此问题导致nepHWND句柄在notepad-exe中为空,因此SetWindowLongPtr调用失败。

(2)有2 SetWindowLongPtr个电话,其中一个是错误的。 GetMsgProc内的一个是正确的,因为它将在安装钩子时在notepad-exe上下文中执行。删除hookNotepad内的其他错误内容。

(3)即使解决了(1)和(2),SetWindowLongPtr的最终行为可能也不是你的预期,因为notepad-exe的主要UI交互元素是嵌入式编辑控件,不是主框架窗口。您应该枚举notepad-frame和子类的子窗口,只有Edit类的子窗口。

编辑#1 - 添加声音指示器代码以检查活动------------------------------------

GetMsgProc

中添加此代码块
// make some noise
static DWORD dwTickKeep = 0;
if ((GetTickCount()-dwTickKeep)>300)
{   dwTickKeep = GetTickCount();
    Beep(2000, 100);
}

答案 1 :(得分:1)

您必须在钩子化过程的上下文中执行此操作。您的hookNotepad()函数在不同的进程中运行,因此您的WndProc()函数位于不同的地址空间中。