19 Commits
Author SHA1 Message Date
futile b76bb7a0d2 0.3.0 2025-12-05 15:18:39 +00:00
futile c18c427af5 process: move Identifier code to the bottom 2025-12-04 08:06:30 +00:00
futile 06123b5b7b process: improve type ergonomics 2025-12-04 08:05:37 +00:00
futile f30a4690df process: better doc on Process::find 2025-12-04 08:05:03 +00:00
futile b906ed044d cargo fmt 2025-12-04 06:02:08 +00:00
futile 3c26590c7c process: fix panic on single item chains 2025-12-04 05:59:35 +00:00
futile a22c9cd0ce add some basic unit tests 2025-12-04 05:59:20 +00:00
futile afc6724be1 improve resolve_pointer_chain implementation 2025-12-04 05:22:42 +00:00
futile 6ba282fd87 update readme 2025-12-04 05:22:38 +00:00
futile a92b59c808 process: rename from to find 2025-12-04 04:16:03 +00:00
futile 52b81d900c process: update Process base_address doc a little 2025-12-04 04:15:51 +00:00
futile 868ad9c191 rename CreateProcessError to ProcessError 2025-12-04 04:15:16 +00:00
futile a62b11df3f process: make searching for a module case-insensitive 2025-12-04 04:13:08 +00:00
futile b09fdc5fbf process: remove Default constraint on write_mem 2025-12-04 04:11:35 +00:00
futile 98689b682a remove redundant Send + Sync impls on Process 2025-12-03 16:06:15 +00:00
futile 8d4c796cce update readme 2025-12-03 14:03:40 +00:00
futile 637160d3ea format addresses and sizes as hex 2025-12-03 13:47:06 +00:00
futile 30b22107a1 add a modules function to Process 2025-12-03 13:37:57 +00:00
futile 334c4761a2 process: clarify that module is case-sensitive 2025-12-03 13:25:18 +00:00
8 changed files with 183 additions and 109 deletions
+5 -2
View File
@@ -1,6 +1,6 @@
[package]
name = "haxor"
version = "0.2.0"
version = "0.3.0"
edition = "2024"
readme = "README.md"
license = "Apache-2.0"
@@ -9,7 +9,7 @@ repository = "https://github.com/elituf/haxor"
keywords = ["memory", "game", "hacking", "process"]
[dependencies]
derive_more = { version = "2", features = ["display"] }
derive_more = { version = "2", features = ["debug", "display"] }
log = "0.4"
thiserror = "2"
@@ -21,3 +21,6 @@ features = [
"Win32_System_Diagnostics_ToolHelp",
"Win32_System_Diagnostics_Debug",
]
[lib]
doctest = false
+3 -3
View File
@@ -1,14 +1,14 @@
## haxor
memory hacking library
windows external memory hacking library
## using
```rust
let proc = Process::from("notepad.exe")?;
let proc = Process::find("notepad.exe")?;
let some_val = proc.read_mem::<i32>(0xDEADBEEF)?;
```
```rust
let proc = Process::from(1337)?;
let proc = Process::find(1337)?;
let chain: Vec<usize> = vec![proc.base_address, 0x4B1D, 0x8, 0x12];
let some_addr: usize = proc.resolve_pointer_chain(&chain)?;
let some_val = proc.read_mem::<u8>(some_addr)?;
+6 -3
View File
@@ -9,12 +9,15 @@ pub enum Error {
/// there was a failure when reading or writing the process's memory
#[error("failed to access process memory")]
AccessMemoryError(String),
/// there was a failure in building the Process or Module struct
#[error("failed to create process")]
CreateProcessError(String),
/// there was a failure in creating a snapshot of processes or modules
#[error("failed to create snapshot")]
CreateSnapshotError(String),
/// there was a failure in building the Process or Module struct
#[error("failed to get process/module")]
ProcessError(String),
/// there was a failure in resolving a pointer chain
#[error("failed to resolve pointer chain")]
ResolvePointerChainError(String),
/// there was a failure in conversion between integers
#[error("failed to convert integer")]
ConvertIntegerError(#[from] std::num::TryFromIntError),
+1
View File
@@ -5,5 +5,6 @@ mod error;
/// types and methods to ease the r/w of a process's memory
pub mod process;
mod sys;
mod tests;
pub use error::Error;
+137 -99
View File
@@ -2,7 +2,140 @@ use crate::{
Error,
sys::{handle::Handle, memory, snapshot},
};
use derive_more::derive::Display;
use derive_more::{Debug, derive::Display};
#[derive(Debug, Default, Clone)]
/// a process running on the system
pub struct Process {
/// the process name (szExeFile)
pub name: String,
/// the process id (th32ProcessID)
pub id: u32,
/// the base address of the module with the name `name` (modBaseAddr)
#[debug("0x{base_address:X}")]
pub base_address: usize,
/// the process handle (HANDLE)
pub handle: Handle,
}
impl Process {
/// initialize a `Process` from a pid or a process name
///
/// ### examples
///
/// ```rust
/// let proc = Process::find(1337)?;
/// ```
///
/// ```rust
/// let proc = Process::find("notepad.exe")?;
/// ```
pub fn find<T: Into<Identifier>>(identifier: T) -> Result<Self, Error> {
let identifier = identifier.into();
let snapshot = snapshot::ProcessSnapshot::get_processes()?
.into_iter()
.find(|snapshot| match identifier {
Identifier::Pid(pid) => snapshot.id == pid,
Identifier::Name(ref name) => snapshot.name == *name,
})
.ok_or_else(|| {
Error::ProcessError(format!(
"failed to find a process with identifier `{identifier}`",
))
})?;
let mut process = Self {
name: snapshot.name,
id: snapshot.id,
base_address: 0,
handle: Handle::from_pid(snapshot.id)?,
};
process.base_address = process.module(&process.name)?.base_address;
Ok(process)
}
/// get a `Module` of a `Process` by name (case-insensitive)
pub fn module<T: AsRef<str>>(&self, name: T) -> Result<Module, Error> {
let name = name.as_ref();
let Some(snapshot) = snapshot::ModuleSnapshot::get_modules(self.id)?
.into_iter()
.find(|snapshot| name.eq_ignore_ascii_case(&snapshot.name))
else {
return Err(Error::ProcessError(format!(
"failed to find a module with identifier `{name}`",
)));
};
let module = Module {
process_id: self.id,
name: snapshot.name,
path: snapshot.path,
base_address: snapshot.base_address,
base_size: snapshot.base_size,
};
Ok(module)
}
/// get all `Module`s of a `Process`
pub fn modules(&self) -> Result<Vec<Module>, Error> {
Ok(snapshot::ModuleSnapshot::get_modules(self.id)?
.iter()
.cloned()
.map(|snapshot| Module {
process_id: self.id,
name: snapshot.name,
path: snapshot.path,
base_address: snapshot.base_address,
base_size: snapshot.base_size,
})
.collect())
}
/// follow a pointer chain to the end and return an address
pub fn resolve_pointer_chain<T: AsRef<[usize]>>(&self, chain: T) -> Result<usize, Error> {
let chain = chain.as_ref();
if chain.is_empty() {
return Err(Error::ResolvePointerChainError("chain was empty".into()));
}
if chain.len() == 1 {
return Ok(chain[0]);
}
let mut address = chain[0];
for &offset in &chain[1..(chain.len() - 1)] {
address += offset;
address = self.read_mem(address)?;
}
Ok(address + chain.last().expect("chain should have a last element"))
}
/// read a given `address` of process's memory
pub fn read_mem<T: Default>(&self, address: usize) -> Result<T, Error> {
let mut value = Default::default();
memory::read(&self.handle, address, &mut value)?;
Ok(value)
}
/// write a `value` at given `address` of process's memory
pub fn write_mem<T>(&self, address: usize, mut value: T) -> Result<(), Error> {
memory::write(&self.handle, address, &mut value)?;
Ok(())
}
}
#[derive(Debug, Default)]
/// a module running within a process
pub struct Module {
/// the parent process id (th32ProcessID)
pub process_id: u32,
/// the module name (szModule)
pub name: String,
/// the module executable path (szExePath)
pub path: String,
/// the module base address (modBaseAddr)
#[debug("0x{base_address:X}")]
pub base_address: usize,
/// the module base size (modBaseSize)
#[debug("0x{base_size:X}")]
pub base_size: usize,
}
#[derive(Display)]
/// an identifier for searching for a process
@@ -25,103 +158,8 @@ impl From<&str> for Identifier {
}
}
#[derive(Debug, Default, Clone)]
/// a process running on the system
pub struct Process {
/// the process name (szExeFile)
pub name: String,
/// the process id (th32ProcessID)
pub id: u32,
/// the base address of the module with the same name as `name` (modBaseAddr)
pub base_address: usize,
/// the process handle (HANDLE)
pub handle: Handle,
}
unsafe impl Send for Process {}
unsafe impl Sync for Process {}
impl Process {
/// initialize a `Process` from a pid or a process name
pub fn from<T: Into<Identifier>>(identifier: T) -> Result<Self, Error> {
let identifier = identifier.into();
let snapshot = snapshot::ProcessSnapshot::get_processes()?
.into_iter()
.find(|snapshot| match identifier {
Identifier::Pid(pid) => snapshot.id == pid,
Identifier::Name(ref name) => snapshot.name == *name,
})
.ok_or_else(|| {
Error::CreateProcessError(format!(
"failed to find a process with identifier `{identifier}`",
))
})?;
let mut process = Self {
name: snapshot.name,
id: snapshot.id,
base_address: 0,
handle: Handle::from_pid(snapshot.id)?,
};
process.base_address = process.module(&process.name)?.base_address;
Ok(process)
}
/// get a `Module` of a `Process` by name
pub fn module(&self, name: &str) -> Result<Module, Error> {
let Some(snapshot) = snapshot::ModuleSnapshot::get_modules(self.id)?
.into_iter()
.find(|snapshot| snapshot.name == name)
else {
return Err(Error::CreateProcessError(format!(
"failed to find a module with identifier `{name}`",
)));
};
let module = Module {
process_id: self.id,
name: snapshot.name,
path: snapshot.path,
base_address: snapshot.base_address,
base_size: snapshot.base_size,
};
Ok(module)
}
/// follow a pointer chain to the end and return an address
pub fn resolve_pointer_chain(&self, chain: &[usize]) -> Result<usize, Error> {
let mut chain = chain.to_vec();
let mut address = chain.remove(0);
while chain.len() > 1 {
address += chain.remove(0);
address = self.read_mem(address)?;
}
Ok(address + chain.remove(0))
}
/// read a given `address` of process's memory
pub fn read_mem<T: Default>(&self, address: usize) -> Result<T, Error> {
let mut value = Default::default();
memory::read(&self.handle, address, &mut value)?;
Ok(value)
}
/// write a `value` at given `address` of process's memory
pub fn write_mem<T: Default>(&self, address: usize, mut value: T) -> Result<(), Error> {
memory::write(&self.handle, address, &mut value)?;
Ok(())
impl From<String> for Identifier {
fn from(value: String) -> Self {
Self::Name(value)
}
}
#[derive(Debug, Default)]
/// a module running within a process
pub struct Module {
/// the parent process id (th32ProcessID)
pub process_id: u32,
/// the module name (szModule)
pub name: String,
/// the module executable path (szExePath)
pub path: String,
/// the module base address (modBaseAddr)
pub base_address: usize,
/// the module base size (modBaseSize)
pub base_size: usize,
}
+1 -1
View File
@@ -1,4 +1,4 @@
use crate::{sys::handle::Handle, Error};
use crate::{Error, sys::handle::Handle};
use std::{ffi::c_void, ptr};
use windows::Win32::System::Diagnostics::Debug::{ReadProcessMemory, WriteProcessMemory};
+1 -1
View File
@@ -41,7 +41,7 @@ impl ProcessSnapshot {
}
}
#[derive(Debug)]
#[derive(Clone, Debug)]
pub struct ModuleSnapshot {
pub name: String,
pub path: String,
+29
View File
@@ -0,0 +1,29 @@
#![cfg(test)]
use super::process::*;
#[test]
fn resolve_pointer_chain_empty() {
let myself = Process::find(std::process::id()).unwrap();
let result = myself.resolve_pointer_chain(&[]);
assert!(result.is_err());
}
#[test]
fn resolve_pointer_chain_single() {
let myself = Process::find(std::process::id()).unwrap();
let result = myself.resolve_pointer_chain(&[myself.base_address]);
assert_eq!(result.unwrap(), myself.base_address);
}
#[test]
fn resolve_pointer_chain_multiple() {
let myself = Process::find(std::process::id()).unwrap();
let target_value = 1337;
let target_ptr = &target_value as *const i32 as usize;
let base_ptr = &target_ptr as *const usize as usize;
let address = myself.resolve_pointer_chain(&[base_ptr, 0x0, 0x0]).unwrap();
assert_eq!(address, target_ptr);
let value = myself.read_mem::<i32>(address).unwrap();
assert_eq!(value, target_value);
}