Showing posts with label How. Show all posts
Showing posts with label How. Show all posts

Thursday, December 31, 2009

How to modify an application behavior when you don't have the source

How to modify an application behavior when you don't have the source


From time to time we need to help customers change the way an application interacts with the operating system or SDKs. The challenge is often the access to the code. Sometimes neither party may own the application in question and none of the parties have access to the source. Luckily, the Microsoft Research team came up with the Detours SDK to address this problem a number of years ago and the latest version makes it easy to implement a solution to a situation like this. In short, Detours allows you to create a DLL that hooks one or more operating system functions, so that when that function is called, the caller will actually invoke your custom Detours code instead.




The process is very simple:



· Download the detours SDK http://research.microsoft.com/sn/detours/ and build it.

· You can start with the SIMPLE Sample or our included sample that builds in the Visual Studio command-line environment.

· Create a function pointer prototype for the API you want to detour (TrueCreateFile in the example below). It should have the same parameters and return value as the function you will detour. As part of the declaration set the function pointer value to the real API Address. In the following sample we will detour the CreateFile API.

· You will also need to create your own version of the API you are detouring (ModifyCreateFile below). In this case we are creating our own Createfile, which will call the original CreateFile with the FILE_FLAG_WRITE_THROUGH flag OR’d into the dwFlagsAndAttributes parameter.



static HANDLE (WINAPI * TrueCreateFile)(LPCTSTR lpFileName, DWORD dwDesiredAccess, DWORD dwShareMode, LPSECURITY_ATTRIBUTES lpSecurityAttributes, DWORD dwCreationDisposition, DWORD dwFlagsAndAttributes, HANDLE hTemplateFile) = CreateFile;



HANDLE WINAPI ModifyCreateFile(LPCTSTR lpFileName, DWORD dwDesiredAccess, DWORD dwShareMode,

LPSECURITY_ATTRIBUTES lpSecurityAttributes, DWORD dwCreationDisposition, DWORD dwFlagsAndAttributes, HANDLE hTemplateFile)

{

dwFlagsAndAttributes |= FILE_FLAG_WRITE_THROUGH;

return TrueCreateFile(lpFileName, dwDesiredAccess, dwShareMode, lpSecurityAttributes,

dwCreationDisposition, dwFlagsAndAttributes, hTemplateFile);

}



· You will need to write your detour code in the DLLmain of your dll. This should be executed when your DLL loads and dwReason is == DLL_PROCESS_ATTACH. In our call to DetourAttach we pass our TrueCreateFile pointer (the real CreateFile address), and the address of ModifyCreateFile (our custom create file api). The detour API handles the intercept for us.

DetourRestoreAfterWith();

DetourTransactionBegin();

DetourUpdateThread(GetCurrentThread());

DetourAttach(&(PVOID&)TrueCreateFile, ModifyCreateFile);

DetourTransactionCommit();



· When the DLL_PROCESS_DETACH happens you will need to clean up the detour and unhook the real API.



DetourTransactionBegin();

DetourUpdateThread(GetCurrentThread());

DetourDetach(&(PVOID&)TrueCreateFile, ModifyCreateFile);

DetourTransactionCommit();



So how do you get the DLL loaded into the target process? There are a couple ways. I recommend using the setdll tool that comes as part of the Detour SDK. In the following case we are modifying NTBackup to automatically load our detoured DLL when NTbackup runs.



C:\test>setdll /d:nocache.dll ntbackup.exe

Adding nocache.dll to binary files.

ntbackup.exe:

nowritethru.dll

MFC42u.dll -> MFC42u.dll

msvcrt.dll -> msvcrt.dll

ADVAPI32.dll -> ADVAPI32.dll

KERNEL32.dll -> KERNEL32.dll

GDI32.dll -> GDI32.dll

USER32.dll -> USER32.dll

ntdll.dll -> ntdll.dll

COMCTL32.dll -> COMCTL32.dll

SHELL32.dll -> SHELL32.dll

MPR.dll -> MPR.dll

comdlg32.dll -> comdlg32.dll

NETAPI32.dll -> NETAPI32.dll

RPCRT4.dll -> RPCRT4.dll

ole32.dll -> ole32.dll

SETUPAPI.dll -> SETUPAPI.dll

USERENV.dll -> USERENV.dll

NTMSAPI.dll -> NTMSAPI.dll

CLUSAPI.dll -> CLUSAPI.dll

query.dll -> query.dll

sfc_os.dll -> sfc_os.dll

SYSSETUP.dll -> SYSSETUP.dll

OLEAUT32.dll -> OLEAUT32.dll

VSSAPI.DLL -> VSSAPI.DLL



Note that if you modify a binary that is protected by Windows File Protection the modified binary will be replaced by the OS with the original binary. I recommend keeping your modified version in another directory so it does not get replaced.

Wednesday, December 30, 2009

How to modify scheduled tasks in Windows XP

How to modify scheduled tasks in Windows XP



This article describes how to modify a scheduled task in Windows XP. After you create a scheduled task in Windows XP, you can modify the task's settings, stop or pause the task, or remove the task from the schedule.



Opening scheduled tasks to modify them
To modify a scheduled task, click Start, click All Programs, point to Accessories, point to System Tools, and then click Scheduled Tasks. The Scheduled Tasks window opens so that you can modify the settings.


Changing settings for scheduled tasks
To change the settings for a task, right-click the task you want to modify, click Properties, and then use either or both of the following methods:

* To change the schedule for the task, click the Schedule tab.
* To customize the settings for the task, such as the maximum run time, idle time requirements, and power management options, click the Settings tab.

After you change the scheduled task, the task temporarily stops. To restart the task, follow these steps:

1. Click Start, click Control panel, and then click Scheduled Tasks.
2. Right-click the scheduled task, and then click Rename.
3. Right-click the renamed task, and then click Run.

Saturday, December 26, 2009

How to modify blog

How to modify blog

You can change your blog header or add favicons by modifying the HTML code of main index template

  1. Login to the Blogs system and enter a blog.
  2. Click Design in the top menu then select Templates.
  3. Click the link for Main Index (also called "index.html").The HTML displays a set of MT variables in orange and blue.
    Template window with HTML
  4. To modify the header, click the Header link under the Includes and Widgets category on the right. The HTML for the header will be displayed.
    Widgets and Includes menu
  5. To change the header, change code within the
    class.
    Note: Tags beginning with $MT are pulled from Movable Type and should not be changed unless there is a specific reasonClick Save then click the Publish button in the top links.
    Note: Just licking Save saves the changes, but does not publish them to the blog. to.
  6. Click Save then click the Publish button in the top links.
    Note: Just licking Save saves the changes, but does not publish them to the blog.
  7. To test the file, click the View Site button in the top links. Hit Shift+Control+R (Win) or Command+Shift+R (Mac) to refresh the blog in your browser.

Identifying Key Divs in the Header

The HTML Includes the following divisions (which refer to the CSS stylesheet)

  • is the main body of the blog excluding background images

Undo Template Changes

If you find a serious flaw in a new template, then open it up and select Refresh from the More Actions menu in the lower right. This will restore the template to the previous version.

Modifying other Parts of the Template

Caution should be used when modifying other parts of the template since many involve the use of MovableType variables.

  1. Login to the Blogs system and enter a blog.
  2. Click Design in the top menu then select Templates.
    • For the main body with entries, select Main Index. This opens to the HTML for an individual entry.
    • For information beneath each entry, click Entry Summary in in the Includes and Widgets menu.
    • For the footer, click Footer in the Includes and Widgets menu.
    • For the header, click Header in the Includes and Widgets menu.
    • For the sidebar, click Footer, then click Sidebar.
      Note: It is usually recommended that you use the Widget Manager to edit the sidebar.
  3. The Insert menu in the template allows you to insert different variables.