English
Regulars table & Café

puzzel: Big Brother is watching you...

 
- Page 1 -


Message: Microsoft has ex windows2000 The Meldepflicht for processes introduced! eachone User-Process has gefälligst on inquire its detailed whereabouts unverzüglichst anzugeben! with want can all rights deprived and the whereabouts polizeilich festgesetzt go!

in the attachment is To this Topic one small Polizeiprogramm.

my question: How are the?

as reward for guess there lovely yummy View source...

609 kB
Kurzbeschreibung: Big Brother - Meldepflicht for processes Version 3
Hochgeladen:10/10/06
Downloadcounter88
Download
 
10/09/06  
 



 
- Page 2 -


Info 2:
If you Toolhelp mean, are you there well on the incorrect steamer. It's all right here around the Current Directory, So the, what under Profan with CHDIR take on can..
 
10/10/06  
 




Frank
Abbing
Nene, there meant I integrally what other.
OK, for Half the processes have I already a Solution, but your Program was indeed not perfect
time see, whether I tonight once more moreover bastle.

ss.jpg  
82 kB
Hochgeladen:10/10/06
Downloadcounter57
Download
 
10/10/06  
 



Hello Frank...

the sees already integrally well from - mere me goes not around the way separate around the Current Directory.
Perhaps incorrect API?
 
10/10/06  
 




Sebastian
König
Hello Andreas,

I have time one little experimentiert and could following Variante offer:

hook,prf
CompileMarkSeparation
!$DLL
 $H windows.ph

if %DLLInit

    FileMapping öffnen:
    declare hFileMap&,pMem#
    hFileMap& = ~OpenFileMapping(~FILE_MAP_ALL_ACCESS,0,"$__skgetcurrentdir_1_")
    pMem# = ~MapViewOfFile(hFileMap&,~FILE_MAP_ALL_ACCESS,0,0,0)
    Daten auslesen:
    declare id&,window&
    id& = long(pMem#,0)
    window& = long(pMem#,4)

    if id& = ~GetCurrentProcessId() Bin ich gemeint?

        Verzeichnis ermitteln und in FileMapping schreiben:
        ~GetCurrentDirectory(~MAX_PATH,pMem#)
        Event-Objekt öffnen und signalisieren:
        declare hEvent&
        hEvent& = ~OpenEvent(~EVENT_ALL_ACCESS,0,"$__skgetcurrentdir_2_")
        ~SetEvent(hEvent&)
        ~CloseHandle(hEvent&)

    endif

    Aufräumen:
    ~UnmapViewOfFile(pMem#)
    ~CloseHandle(hFileMap&)

endif

declare g_hHook&

dllproc StartHook,0

    g_hHook& = ~SetWindowsHookEx(~WH_GETMESSAGE,ProcAddr("DummyHookProc",3),%hInstance,0)
    return g_hHook&

endproc

proc DummyHookProc Tut gar nichts...

    parameters nCode&,wParam&,lParam&
    return ~CallNextHookEx(g_hHook&,nCode&,wParam&,lParam&)

endproc


getdir.prf
CompileMarkSeparation
!$H windows.ph
 $H messages.ph
 $I hook.inc
Window Style 520
Window Title "Aktuelles directory stranger processes auslesen"
Cls
declare hFileMap&,pMem#
hFileMap& = ~CreateFileMapping($FFFFFFFF,0,~PAGE_READWRITE,0,512,"$__skgetcurrentdir_1_")
pMem# = ~MapViewOfFile(hFileMap&,~FILE_MAP_ALL_ACCESS,0,0,0)
print "hFileMap&:",hFileMap&
declare hEvent&
hEvent& = ~CreateEvent(0,1,0,"$__skgetcurrentdir_2_")
print "hEvent&:",hEvent&
declare hDLL&
hDLL& = UseDLL("hook.dll")
print "hDLL&:",hDLL&
declare id&
id& = Val(Input$("Eingabe","Bitte Process-ID angeben",""))
long pMem#,0 = id&,%hwnd
declare hHook&
hHook& = starthook()
print "hHook&:",hHook&
ought to harmless his and for care, that everything with of/ one Nachrichtenschleife The Hook-DLL loading:
~BroadcastSystemMessage(~BSF_POSTMESSAGE,0,~WM_COMMAND,0,0)

if ~WaitForSingleObject(hEvent&,2000) = ~WAIT_OBJECT_0

    print "Verzeichnis read:",string $(pMem#,0)

else

    print "Keine feedback receive :-("

endif

~UnHookWindowsHookEx(hHook&)
~UnmapViewOfFile(pMem#)
~CloseHandle(hFileMap&)
FreeDLL hDLL&
print "Taste to that terminate!"
WaitKey
end

functions but unfortunately long ago not all Prozessen, separate only with them, which somehow moreover persuade let, The Hook-DLL To loading. I suspect time, that You The data somehow differently (direct) ermittelst...

MfG

Sebastian

P.s.: @iF: Why go really with abgeschalteter code-Autoformatierung single führende space not displayed?
 
Windows XP, XProfan/Profan² 4.5 bis 11
Profan2Cpp-Homepage:  [...] 
Alte Profan²-Seite:  [...] 
10/10/06  
 




Jörg
Sellmeyer
<offtopic>Wenn You directly behind [_code_] one exclamation points setting keep You your Formatierung.
so [_code_]!</offtopic>
 
Windows XP SP2 XProfan X4
... und hier mal was ganz anderes als Profan ...
10/10/06  
 



[quote:67096e4b87]P.s.: @iF: Why go really with abgeschalteter code-Autoformatierung single führende space not displayed?[/quote:67096e4b87]
the lying on whom Browsern - The canceln The Dopplungen.
 
10/10/06  
 




Sebastian
König
[quote:3df4846fcf]
<offtopic>Wenn You directly behind [_code_] one exclamation points setting keep You your Formatierung.
so [_code_]!</offtopic>
[/quote:3df4846fcf]
the have so did i made (be no great fan the Autoformatierung *duck* ), but single space on the Beginning of the line go nevertheless not displayed, two and More against already... Well, if it on the Browser lying, can there well nothing make...
 
Windows XP, XProfan/Profan² 4.5 bis 11
Profan2Cpp-Homepage:  [...] 
Alte Profan²-Seite:  [...] 
10/10/06  
 



Hello Sebastian...

so GEHTS naturally too - so Have ichs but not made. No DLL-Injektion, there's only a View source!
your View source sees very interestingly from - whom take I me yet accurate to, best Thanks.

P.s. : Yes, The ermittele I direct!
 
10/10/06  
 



I geb time another couple Tipps:

Info 3: becomes the Proggi in the system Account launched, reads it More Current Directories from. who quite no others Possibility has, could the z.B. over PrivAktivate do:
- PrivAktivate as service started (over Menu)
- on the first Registrierkarte then application select clicking

Info 4: who driver program can, comes well on the fastest on The Solution the riddle
 
10/10/06  
 




Frank
Abbing
[quote:a144e540f8]Info 3: becomes the Proggi in the system Account launched, reads it More Current Directories from.

Info 4: who driver program can, comes well on the fastest on The Solution the riddle[/quote:a144e540f8]
OK, there custom I none moreover To puzzle over. isn't my Topic.
a driver To write, for a puzzel To solve, stops I additionally for exorbitant...
 
10/10/06  
 



No, wrong understood - my Program is no driver. the goes too with Profan not. mere who driver write can, hats plainer with the Solution. Accurate said is the one Info on The DLL, in the the API befindet, The I there use...one very guter Info, with the itself the puzzel well without Problems solve can .
 
10/10/06  
 




Michael
Wodrich
something The ZW...(something)-functions with Kernel-fashion Rechten?
 
Programmieren, das spannendste Detektivspiel der Welt.
10/10/06  
 




Answer


Topictitle, max. 100 characters.
 

Systemprofile:

no Systemprofil laid out. [anlegen]

XProfan:

 Posting  Font  Smilies  ▼ 

Please register circa a Posting To verfassen.
 

Topic-Options

4.636 Views

Untitledvor 0 min.
Ernst05/12/14
iF07/07/11

Themeninformationen



Admins  |  AGB  |  Applications  |  Authors  |  Chat  |  Privacy Policy  |  Download  |  Entrance  |  Help  |  Merchantportal  |  Imprint  |  Mart  |  Interfaces  |  SDK  |  Services  |  Games  |  Search  |  Support

One proposition all XProfan, The there's!


My XProfan
Private Messages
Own Storage Forum
Topics-Remember-List
Own Posts
Own Topics
Clipboard
Log off
 Deutsch English Français Español Italia
Translations

Privacy Policy


we use Cookies only as Session-Cookies because of the technical necessity and with us there no Cookies of Drittanbietern.

If you here on our Website click or navigate, stimmst You ours registration of Information in our Cookies on XProfan.Net To.

further Information To our Cookies and moreover, How You The control above keep, find You in ours nachfolgenden Datenschutzerklärung.


all rightDatenschutzerklärung
i want none Cookie