带有User32.dll的LoadLibraryA在ntdll.dll(x64程序集)

时间:2015-08-22 21:07:25

标签: windows assembly crash 64-bit

所以我有一个汇编代码块来初始化程序,解析kernel32,找到GetProcAddress,然后找到LoadLibarayA来加载User32.dll。它可以工作到LoadLibraryA。它在函数调用中崩溃,但我可以看到在调试器中加载了User32.dll。如果我尝试在不同的模块(如Kernel32.dll)上使用LoadLibraryA,它将返回并成功。

如果你想查看它,这是完整的来源 https://gist.github.com/mojobojo/921a5af897e86bb940a2

Exception thrown at 0x00007FFAFAE8E91C (ntdll.dll) in Small.exe: 0xC0000005: Access violation reading location 0xFFFFFFFFFFFFFFFF.

以下是试图加载user32的代码段。

    mov rcx, ActualAddress + User32DllStr ; ActualAddress is the program address in memory
    call rax ; LoadLibararyA
    cmp rax, 0
    je  EndFunction ; Failed to open user32.dll

LoadLibraryAStr:
    db "LoadLibraryA", 0

以下是调用堆栈。

ntdll.dll!RtlDosPathNameToRelativeNtPathName()  Unknown
ntdll.dll!LdrpResolveDllName()  Unknown
ntdll.dll!LdrpFindLoadedDll()   Unknown
ntdll.dll!LdrGetDllHandleEx()   Unknown
ntdll.dll!LdrGetDllHandle() Unknown
KernelBase.dll!00007ffaf82d2984()   Unknown
KernelBase.dll!00007ffaf82d29ef()   Unknown
user32.dll!00007ffaf934e7e8()   Unknown
user32.dll!00007ffaf934dc92()   Unknown
ntdll.dll!LdrpCallInitRoutine() Unknown
ntdll.dll!LdrpInitializeNode()  Unknown
ntdll.dll!LdrpInitializeGraph() Unknown
ntdll.dll!LdrpPrepareModuleForExecution()   Unknown
ntdll.dll!LdrpLoadDll() Unknown
ntdll.dll!LdrLoadDll()  Unknown
KernelBase.dll!00007ffaf82d8e4a()   Unknown
KernelBase.dll!00007ffaf82d97e5()   Unknown
kernel32.dll!00007ffaf8b5499a() Unknown
Small.exe!0000000140010253()    Unknown

1 个答案:

答案 0 :(得分:2)

我明白了。我的堆栈没有16字节对齐。