388 lines
18 KiB
HTML
Executable File
388 lines
18 KiB
HTML
Executable File
<?xml version="1.0" encoding="ascii"?>
|
|
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
|
|
"DTD/xhtml1-transitional.dtd">
|
|
<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">
|
|
<head>
|
|
<title>Libs.libhook</title>
|
|
<link rel="stylesheet" href="epydoc.css" type="text/css" />
|
|
<script type="text/javascript" src="epydoc.js"></script>
|
|
</head>
|
|
|
|
<body bgcolor="white" text="black" link="blue" vlink="#204080"
|
|
alink="#204080">
|
|
<!-- ==================== NAVIGATION BAR ==================== -->
|
|
<table class="navbar" border="0" width="100%" cellpadding="0"
|
|
bgcolor="#a0c0ff" cellspacing="0">
|
|
<tr valign="middle">
|
|
|
|
<!-- Tree link -->
|
|
<th> <a
|
|
href="module-tree.html">Trees</a> </th>
|
|
|
|
<!-- Index link -->
|
|
<th> <a
|
|
href="identifier-index.html">Indices</a> </th>
|
|
|
|
<!-- Help link -->
|
|
<th> <a
|
|
href="help.html">Help</a> </th>
|
|
|
|
<!-- Project homepage -->
|
|
<th class="navbar" align="right" width="100%">
|
|
<table border="0" cellpadding="0" cellspacing="0">
|
|
<tr><th class="navbar" align="center"
|
|
>Immunity Debugger API Reference</th>
|
|
</tr></table></th>
|
|
</tr>
|
|
</table>
|
|
<table width="100%" cellpadding="0" cellspacing="0">
|
|
<tr valign="top">
|
|
<td width="100%">
|
|
<span class="breadcrumbs">
|
|
Package Libs ::
|
|
Module libhook
|
|
</span>
|
|
</td>
|
|
<td>
|
|
<table cellpadding="0" cellspacing="0">
|
|
<!-- hide/show private -->
|
|
<tr><td align="right"><span class="options">[<a href="javascript:void(0);" class="privatelink"
|
|
onclick="toggle_private();">hide private</a>]</span></td></tr>
|
|
<tr><td align="right"><span class="options"
|
|
>[<a href="frames.html" target="_top">frames</a
|
|
>] | <a href="Libs.libhook-module.html"
|
|
target="_top">no frames</a>]</span></td></tr>
|
|
</table>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
<!-- ==================== MODULE DESCRIPTION ==================== -->
|
|
<h1 class="epydoc">Module libhook</h1><p class="nomargin-top"><span class="codelink"><a href="Libs.libhook-pysrc.html">source code</a></span></p>
|
|
<p>(c) Immunity, Inc. 2004-2007</p>
|
|
<p><a href="http://www.immunityinc.com" target="_top">Immunity
|
|
Inc.</a></p>
|
|
|
|
<!-- ==================== CLASSES ==================== -->
|
|
<a name="section-Classes"></a>
|
|
<table class="summary" border="1" cellpadding="3"
|
|
cellspacing="0" width="100%" bgcolor="white">
|
|
<tr bgcolor="#70b0f0" class="table-header">
|
|
<td colspan="2" class="table-header">
|
|
<table border="0" cellpadding="0" cellspacing="0" width="100%">
|
|
<tr valign="top">
|
|
<td align="left"><span class="table-header">Classes</span></td>
|
|
<td align="right" valign="top"
|
|
><span class="options">[<a href="#section-Classes"
|
|
class="privatelink" onclick="toggle_private();"
|
|
>hide private</a>]</span></td>
|
|
</tr>
|
|
</table>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a href="Libs.libhook.FastLogHook-class.html" class="summary-name">FastLogHook</a>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a href="Libs.libhook.STDCALLFastLogHook-class.html" class="summary-name">STDCALLFastLogHook</a>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a href="Libs.libhook.Hook-class.html" class="summary-name">Hook</a>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a href="Libs.libhook.BpHook-class.html" class="summary-name">BpHook</a>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a href="Libs.libhook.LogBpHook-class.html" class="summary-name">LogBpHook</a>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a href="Libs.libhook.PreBpHook-class.html" class="summary-name">PreBpHook</a>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a href="Libs.libhook.AllExceptHook-class.html" class="summary-name">AllExceptHook</a>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a href="Libs.libhook.PostAnalysisHook-class.html" class="summary-name">PostAnalysisHook</a>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a href="Libs.libhook.AccessViolationHook-class.html" class="summary-name">AccessViolationHook</a>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a href="Libs.libhook.RunUntilAV-class.html" class="summary-name">RunUntilAV</a>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a href="Libs.libhook.LoadDLLHook-class.html" class="summary-name">LoadDLLHook</a>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a href="Libs.libhook.UnloadDLLHook-class.html" class="summary-name">UnloadDLLHook</a>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a href="Libs.libhook.CreateThreadHook-class.html" class="summary-name">CreateThreadHook</a>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a href="Libs.libhook.ExitThreadHook-class.html" class="summary-name">ExitThreadHook</a>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a href="Libs.libhook.CreateProcessHook-class.html" class="summary-name">CreateProcessHook</a>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a href="Libs.libhook.ExitProcessHook-class.html" class="summary-name">ExitProcessHook</a>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
<!-- ==================== VARIABLES ==================== -->
|
|
<a name="section-Variables"></a>
|
|
<table class="summary" border="1" cellpadding="3"
|
|
cellspacing="0" width="100%" bgcolor="white">
|
|
<tr bgcolor="#70b0f0" class="table-header">
|
|
<td colspan="2" class="table-header">
|
|
<table border="0" cellpadding="0" cellspacing="0" width="100%">
|
|
<tr valign="top">
|
|
<td align="left"><span class="table-header">Variables</span></td>
|
|
<td align="right" valign="top"
|
|
><span class="options">[<a href="#section-Variables"
|
|
class="privatelink" onclick="toggle_private();"
|
|
>hide private</a>]</span></td>
|
|
</tr>
|
|
</table>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a name="__VERSION__"></a><span class="summary-name">__VERSION__</span> = <code title="'1.1'"><code class="variable-quote">'</code><code class="variable-string">1.1</code><code class="variable-quote">'</code></code>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a name="FS_UNHOOK"></a><span class="summary-name">FS_UNHOOK</span> = <code title="0">0</code>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a name="FS_HOOK"></a><span class="summary-name">FS_HOOK</span> = <code title="1">1</code>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a name="FS_PAUSE"></a><span class="summary-name">FS_PAUSE</span> = <code title="2">2</code>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a href="Libs.libhook-module.html#HookTypes" class="summary-name">HookTypes</a> = <code title="{'ACCESS_VIOLATION_HOOK': 3910,
|
|
'CREATE_PROCESS_HOOK': 3907,
|
|
'CREATE_THREAD_HOOK': 3905,
|
|
'EVERY_EXCEPTION_HOOK': 3901,
|
|
'EXIT_PROCESS_HOOK': 3908,
|
|
'EXIT_THREAD_HOOK': 3906,
|
|
'LOAD_DLL_HOOK': 3903,
|
|
'LOG_BP_HOOK': 3909,
|
|
..."><code class="variable-group">{</code><code class="variable-quote">'</code><code class="variable-string">ACCESS_VIOLATION_HOOK</code><code class="variable-quote">'</code><code class="variable-op">: </code>3910<code class="variable-op">, </code><code class="variable-quote">'</code><code class="variable-string">CREATE_PROCESS_HO</code><code class="variable-ellipsis">...</code></code>
|
|
</td>
|
|
</tr>
|
|
<tr>
|
|
<td width="15%" align="right" valign="top" class="summary">
|
|
<span class="summary-type"> </span>
|
|
</td><td class="summary">
|
|
<a href="Libs.libhook-module.html#HOOK_REG" class="summary-name">HOOK_REG</a> = <code title="{'EAX': '[ESP+0x1C]',
|
|
'EBP': '[ESP+0x8 ]',
|
|
'EBX': '[ESP+0x10]',
|
|
'ECX': '[ESP+0x18]',
|
|
'EDI': '[ESP]',
|
|
'EDX': '[ESP+0x14]',
|
|
'ESI': '[ESP+4 ]',
|
|
'ESP': '[ESP+0xC ]'}"><code class="variable-group">{</code><code class="variable-quote">'</code><code class="variable-string">EAX</code><code class="variable-quote">'</code><code class="variable-op">: </code><code class="variable-quote">'</code><code class="variable-string">[ESP+0x1C]</code><code class="variable-quote">'</code><code class="variable-op">, </code><code class="variable-quote">'</code><code class="variable-string">EBP</code><code class="variable-quote">'</code><code class="variable-op">: </code><code class="variable-quote">'</code><code class="variable-string">[ESP+0x8 ]</code><code class="variable-quote">'</code><code class="variable-op">, </code><code class="variable-quote">'</code><code class="variable-string">EBX</code><code class="variable-quote">'</code><code class="variable-op">: </code><code class="variable-quote">'</code><code class="variable-ellipsis">...</code></code>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
<!-- ==================== VARIABLES DETAILS ==================== -->
|
|
<a name="section-VariablesDetails"></a>
|
|
<table class="details" border="1" cellpadding="3"
|
|
cellspacing="0" width="100%" bgcolor="white">
|
|
<tr bgcolor="#70b0f0" class="table-header">
|
|
<td colspan="2" class="table-header">
|
|
<table border="0" cellpadding="0" cellspacing="0" width="100%">
|
|
<tr valign="top">
|
|
<td align="left"><span class="table-header">Variables Details</span></td>
|
|
<td align="right" valign="top"
|
|
><span class="options">[<a href="#section-VariablesDetails"
|
|
class="privatelink" onclick="toggle_private();"
|
|
>hide private</a>]</span></td>
|
|
</tr>
|
|
</table>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
<a name="HookTypes"></a>
|
|
<div>
|
|
<table class="details" border="1" cellpadding="3"
|
|
cellspacing="0" width="100%" bgcolor="white">
|
|
<tr><td>
|
|
<h3 class="epydoc">HookTypes</h3>
|
|
|
|
<dl class="fields">
|
|
</dl>
|
|
<dl class="fields">
|
|
<dt>Value:</dt>
|
|
<dd><table><tr><td><pre class="variable">
|
|
<code class="variable-group">{</code><code class="variable-quote">'</code><code class="variable-string">ACCESS_VIOLATION_HOOK</code><code class="variable-quote">'</code><code class="variable-op">: </code>3910<code class="variable-op">,</code>
|
|
<code class="variable-quote">'</code><code class="variable-string">CREATE_PROCESS_HOOK</code><code class="variable-quote">'</code><code class="variable-op">: </code>3907<code class="variable-op">,</code>
|
|
<code class="variable-quote">'</code><code class="variable-string">CREATE_THREAD_HOOK</code><code class="variable-quote">'</code><code class="variable-op">: </code>3905<code class="variable-op">,</code>
|
|
<code class="variable-quote">'</code><code class="variable-string">EVERY_EXCEPTION_HOOK</code><code class="variable-quote">'</code><code class="variable-op">: </code>3901<code class="variable-op">,</code>
|
|
<code class="variable-quote">'</code><code class="variable-string">EXIT_PROCESS_HOOK</code><code class="variable-quote">'</code><code class="variable-op">: </code>3908<code class="variable-op">,</code>
|
|
<code class="variable-quote">'</code><code class="variable-string">EXIT_THREAD_HOOK</code><code class="variable-quote">'</code><code class="variable-op">: </code>3906<code class="variable-op">,</code>
|
|
<code class="variable-quote">'</code><code class="variable-string">LOAD_DLL_HOOK</code><code class="variable-quote">'</code><code class="variable-op">: </code>3903<code class="variable-op">,</code>
|
|
<code class="variable-quote">'</code><code class="variable-string">LOG_BP_HOOK</code><code class="variable-quote">'</code><code class="variable-op">: </code>3909<code class="variable-op">,</code>
|
|
<code class="variable-ellipsis">...</code>
|
|
</pre></td></tr></table>
|
|
</dd>
|
|
</dl>
|
|
</td></tr></table>
|
|
</div>
|
|
<a name="HOOK_REG"></a>
|
|
<div>
|
|
<table class="details" border="1" cellpadding="3"
|
|
cellspacing="0" width="100%" bgcolor="white">
|
|
<tr><td>
|
|
<h3 class="epydoc">HOOK_REG</h3>
|
|
|
|
<dl class="fields">
|
|
</dl>
|
|
<dl class="fields">
|
|
<dt>Value:</dt>
|
|
<dd><table><tr><td><pre class="variable">
|
|
<code class="variable-group">{</code><code class="variable-quote">'</code><code class="variable-string">EAX</code><code class="variable-quote">'</code><code class="variable-op">: </code><code class="variable-quote">'</code><code class="variable-string">[ESP+0x1C]</code><code class="variable-quote">'</code><code class="variable-op">,</code>
|
|
<code class="variable-quote">'</code><code class="variable-string">EBP</code><code class="variable-quote">'</code><code class="variable-op">: </code><code class="variable-quote">'</code><code class="variable-string">[ESP+0x8 ]</code><code class="variable-quote">'</code><code class="variable-op">,</code>
|
|
<code class="variable-quote">'</code><code class="variable-string">EBX</code><code class="variable-quote">'</code><code class="variable-op">: </code><code class="variable-quote">'</code><code class="variable-string">[ESP+0x10]</code><code class="variable-quote">'</code><code class="variable-op">,</code>
|
|
<code class="variable-quote">'</code><code class="variable-string">ECX</code><code class="variable-quote">'</code><code class="variable-op">: </code><code class="variable-quote">'</code><code class="variable-string">[ESP+0x18]</code><code class="variable-quote">'</code><code class="variable-op">,</code>
|
|
<code class="variable-quote">'</code><code class="variable-string">EDI</code><code class="variable-quote">'</code><code class="variable-op">: </code><code class="variable-quote">'</code><code class="variable-string">[ESP]</code><code class="variable-quote">'</code><code class="variable-op">,</code>
|
|
<code class="variable-quote">'</code><code class="variable-string">EDX</code><code class="variable-quote">'</code><code class="variable-op">: </code><code class="variable-quote">'</code><code class="variable-string">[ESP+0x14]</code><code class="variable-quote">'</code><code class="variable-op">,</code>
|
|
<code class="variable-quote">'</code><code class="variable-string">ESI</code><code class="variable-quote">'</code><code class="variable-op">: </code><code class="variable-quote">'</code><code class="variable-string">[ESP+4 ]</code><code class="variable-quote">'</code><code class="variable-op">,</code>
|
|
<code class="variable-quote">'</code><code class="variable-string">ESP</code><code class="variable-quote">'</code><code class="variable-op">: </code><code class="variable-quote">'</code><code class="variable-string">[ESP+0xC ]</code><code class="variable-quote">'</code><code class="variable-group">}</code>
|
|
</pre></td></tr></table>
|
|
</dd>
|
|
</dl>
|
|
</td></tr></table>
|
|
</div>
|
|
<br />
|
|
<!-- ==================== NAVIGATION BAR ==================== -->
|
|
<table class="navbar" border="0" width="100%" cellpadding="0"
|
|
bgcolor="#a0c0ff" cellspacing="0">
|
|
<tr valign="middle">
|
|
|
|
<!-- Tree link -->
|
|
<th> <a
|
|
href="module-tree.html">Trees</a> </th>
|
|
|
|
<!-- Index link -->
|
|
<th> <a
|
|
href="identifier-index.html">Indices</a> </th>
|
|
|
|
<!-- Help link -->
|
|
<th> <a
|
|
href="help.html">Help</a> </th>
|
|
|
|
<!-- Project homepage -->
|
|
<th class="navbar" align="right" width="100%">
|
|
<table border="0" cellpadding="0" cellspacing="0">
|
|
<tr><th class="navbar" align="center"
|
|
>Immunity Debugger API Reference</th>
|
|
</tr></table></th>
|
|
</tr>
|
|
</table>
|
|
<table border="0" cellpadding="0" cellspacing="0" width="100%%">
|
|
<tr>
|
|
<td align="left" class="footer">
|
|
Generated by Epydoc 3.0.1 on Thu Sep 11 14:06:32 2008
|
|
</td>
|
|
<td align="right" class="footer">
|
|
<a target="mainFrame" href="http://epydoc.sourceforge.net"
|
|
>http://epydoc.sourceforge.net</a>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
|
|
<script type="text/javascript">
|
|
<!--
|
|
// Private objects are initially displayed (because if
|
|
// javascript is turned off then we want them to be
|
|
// visible); but by default, we want to hide them. So hide
|
|
// them unless we have a cookie that says to show them.
|
|
checkCookie();
|
|
// -->
|
|
</script>
|
|
</body>
|
|
</html>
|