新书推介:《语义网技术体系》
作者:瞿裕忠,胡伟,程龚
   XML论坛     W3CHINA.ORG讨论区     计算机科学论坛     SOAChina论坛     Blog     开放翻译计划     新浪微博  
 
  • 首页
  • 登录
  • 注册
  • 软件下载
  • 资料下载
  • 核心成员
  • 帮助
  •   Add to Google

    >> 本版讨论.NET,C#,ASP,VB技术
    [返回] 中文XML论坛 - 专业的XML技术讨论区计算机技术与应用『 Dot NET,C#,ASP,VB 』 → C# 内存内容修改方法 查看新帖用户列表

      发表一个新主题  发表一个新投票  回复主题  (订阅本版) 您是本帖的第 4876 个阅读者浏览上一篇主题  刷新本主题   树形显示贴子 浏览下一篇主题
     * 贴子主题: C# 内存内容修改方法 举报  打印  推荐  IE收藏夹 
       本主题类别: Description Logics    
     卷积内核 帅哥哟,离线,有人找我吗?
      
      
      威望:8
      头衔:总统
      等级:博士二年级(版主)
      文章:3942
      积分:27590
      门派:XML.ORG.CN
      注册:2004/7/21

    姓名:(无权查看)
    城市:(无权查看)
    院校:(无权查看)
    给卷积内核发送一个短消息 把卷积内核加入好友 查看卷积内核的个人资料 搜索卷积内核在『 Dot NET,C#,ASP,VB 』的所有贴子 访问卷积内核的主页 引用回复这个贴子 回复这个贴子 查看卷积内核的博客楼主
    发贴心情 C# 内存内容修改方法


    先通过

    System.Diagnostics.Process类获取想要编辑的进程

    调用API

      [Flags]
                        public enum ProcessAccessType
                        {
                            PROCESS_TERMINATE = (0x0001),
                            PROCESS_CREATE_THREAD = (0x0002),
                            PROCESS_SET_SESSIONID = (0x0004),
                            PROCESS_VM_OPERATION = (0x0008),
                            PROCESS_VM_READ = (0x0010),
                            PROCESS_VM_WRITE = (0x0020),
                            PROCESS_DUP_HANDLE = (0x0040),
                            PROCESS_CREATE_PROCESS = (0x0080),
                            PROCESS_SET_QUOTA = (0x0100),
                            PROCESS_SET_INFORMATION = (0x0200),
                            PROCESS_QUERY_INFORMATION = (0x0400)
                        }
                        [DllImport("kernel32.dll")]
                        public static extern IntPtr OpenProcess(UInt32 dwDesiredAccess, Int32 bInheritHandle, UInt32 dwProcessId);
                        [DllImport("kernel32.dll")]
                        public static extern Int32 CloseHandle(IntPtr hObject);
                        [DllImport("kernel32.dll")]
                        public static extern Int32 ReadProcessMemory(IntPtr hProcess, IntPtr lpBaseAddress, [In, Out] byte[] buffer, UInt32 size, out IntPtr lpNumberOfBytesRead);
                        [DllImport("kernel32.dll")]
                        public static extern Int32 WriteProcessMemory(IntPtr hProcess, IntPtr lpBaseAddress, [In, Out] byte[] buffer, UInt32 size, out IntPtr lpNumberOfBytesWritten);

    打开进程

    private IntPtr m_hProcess = IntPtr.Zero;   //这个保存打开了个进程句柄

       public void OpenProcess()
                    {
                        //   m_hProcess = ProcessMemoryReaderApi.OpenProcess(ProcessMemoryReaderApi.PROCESS_VM_READ, 1, (uint)m_ReadProcess.Id);
                        ProcessMemoryReaderApi.ProcessAccessType access;
                        access = ProcessMemoryReaderApi.ProcessAccessType.PROCESS_VM_READ
                            | ProcessMemoryReaderApi.ProcessAccessType.PROCESS_VM_WRITE
                            | ProcessMemoryReaderApi.ProcessAccessType.PROCESS_VM_OPERATION;
                        m_hProcess = ProcessMemoryReaderApi.OpenProcess((uint)access, 1, (uint)m_ReadProcess.Id);
                    }

    m_ReadProcess.Id 进程的ID编号   

    读取

    public byte[] ReadProcessMemory(IntPtr MemoryAddress, uint bytesToRead, out int bytesRead)
                    {
                        byte[] buffer = new byte[bytesToRead];

                        IntPtr ptrBytesRead;
                        ProcessMemoryReaderApi.ReadProcessMemory(m_hProcess, MemoryAddress, buffer, bytesToRead, out ptrBytesRead);

                        bytesRead = ptrBytesRead.ToInt32();

                        return buffer;
                    }

    IntPrt MemoryAddress 为要读取的内存地址

    uint bytesToRead 需要读的数量

    out int bytesRead 实际读出的数量

    写入

       public void WriteProcessMemory(IntPtr MemoryAddress, byte[] bytesToWrite, out int bytesWritten)
                    {
                        IntPtr ptrBytesWritten;
                        ProcessMemoryReaderApi.WriteProcessMemory(m_hProcess, MemoryAddress, bytesToWrite, (uint)bytesToWrite.Length, out ptrBytesWritten);

                        bytesWritten = ptrBytesWritten.ToInt32();
                    }

    IntPrt MemoryAddress 为要读取的内存地址

    byte[] bytesToWrite 需要写入的数据

    out int bytesWritten 实际写入多少


       收藏   分享  
    顶(0)
      




    ----------------------------------------------
    事业是国家的,荣誉是单位的,成绩是领导的,工资是老婆的,财产是孩子的,错误是自己的。

    点击查看用户来源及管理<br>发贴IP:*.*.*.* 2012/7/24 10:06:00
     
     GoogleAdSense
      
      
      等级:大一新生
      文章:1
      积分:50
      门派:无门无派
      院校:未填写
      注册:2007-01-01
    给Google AdSense发送一个短消息 把Google AdSense加入好友 查看Google AdSense的个人资料 搜索Google AdSense在『 Dot NET,C#,ASP,VB 』的所有贴子 访问Google AdSense的主页 引用回复这个贴子 回复这个贴子 查看Google AdSense的博客广告
    2024/5/5 16:04:28

    本主题贴数1,分页: [1]

    管理选项修改tag | 锁定 | 解锁 | 提升 | 删除 | 移动 | 固顶 | 总固顶 | 奖励 | 惩罚 | 发布公告
    W3C Contributing Supporter! W 3 C h i n a ( since 2003 ) 旗 下 站 点
    苏ICP备05006046号《全国人大常委会关于维护互联网安全的决定》《计算机信息网络国际联网安全保护管理办法》
    8,621.094ms