Click here to Skip to main content
15,881,139 members
Articles / Programming Languages / Objective C

Stealing Program's Memory

Rate me:
Please Sign up or sign in to vote.
4.79/5 (75 votes)
2 Dec 20032 min read 351K   4K   114   82
An advanced article on allocating and using memory in another process using the Win32 API.

Introduction

I was recently trying to steal strings from another program's listview control. You need to pass a pointer so it knows where to put the string. Normally, this wouldn't be a problem, but because Windows uses virtual memory, pointers are not valid across programs.

Virtual memory is how Windows deals out memory to all its programs. It makes programs think they have 2 Gb of memory to use. It also protects programs from using each other's memory so if one program crashes, it doesn't take down the whole system with it.

So after coding a fair bit, I realized my pointers were all invalid and it wouldn't work. A few hours of digging through MSDN brought me to the functions VirtualAllocEx(), VirtualFreeEx(), WriteProcessMemory() and ReadProcessMemory(). Armed with this new information, I set out to modify my code. Here is what I had so far:

#define WIN32_LEAN_AND_MEAN
#include <stdio.h>
#include <windows.h>
#include <commctrl.h>

int main(void) {
 /* Run through the windows until we find our listview. */
 HWND hwnd=FindWindow(NULL, "Stealing Program's Memory: ListView");
 HWND listview=FindWindowEx(hwnd, NULL, "SysListView32", NULL);

 int count=(int)SendMessage(listview, LVM_GETITEMCOUNT, 0, 0);
 int i;

 char item[512], subitem[512];

 /* Shove all items of listview into item and subitem
    and print out one by one. */

 LVITEM lvi;
 lvi.cchTextMax=512;

 for(i=0; i<count; i++) {
  lvi.iSubItem=0;
  lvi.pszText=item;
  SendMessage(listview, LVM_GETITEMTEXT, (WPARAM)i, (LPARAM)&lvi);

  lvi.iSubItem=1;
  lvi.pszText=subitem;
  SendMessage(listview, LVM_GETITEMTEXT, (WPARAM)i, (LPARAM)&lvi);

  printf("%s - %s\n", item, subitem);
 }
 return 0;
}

As I said before, this won't work. The pointers to lvi, item, and subitem all get screwed when they go across process. The solution? Use WriteProcessMemory() and ReadProcessMemory() to use the other programs memory, perform LVM_GETITEMTEXT on it, and read it back. Hackish yes, but then again reading items from another program's listview control is one giant hack.

First, we get the process of the listview like this:

unsigned long pid;
HANDLE process;
GetWindowThreadProcessId(listview, &pid);
process=OpenProcess(PROCESS_VM_OPERATION|PROCESS_VM_READ|
                    PROCESS_VM_WRITE|PROCESS_QUERY_INFORMATION, FALSE, pid);

Next, we create three pointers, LVITEM *_lvi, char *_item, and char *_subitem and allocate them in the other program's virtual memory space with VirtualAllocEx():

LVITEM *_lvi=(LVITEM*)VirtualAllocEx(process, NULL, sizeof(LVITEM),
                                     MEM_COMMIT, PAGE_READWRITE);
char *_item=(char*)VirtualAllocEx(process, NULL, 512, MEM_COMMIT,
                                  PAGE_READWRITE);
char *_subitem=(char*)VirtualAllocEx(process, NULL, 512, MEM_COMMIT,
                                     PAGE_READWRITE);

Now, we point lvi.pszText to _item, and copy its memory to _lvi using WriteMemoryProcess():

lvi.pszText=_item;
WriteProcessMemory(process, _lvi, &lvi, sizeof(LVITEM), NULL);

Now that we have an LVITEM pointer that is valid in the other programs virtual memory, we can shoot off LVM_GETITEMTEXT to listview and copy _item's text into item so we can read it in our program:

SendMessage(hwnd, LVM_GETITEMTEXT, (WPARAM)i, (LPARAM)_lvi);
ReadProcessMemory(process, _item, item, max, NULL);

Repeat that for subitem, then free the memory we used in the other program's memory:

VirtualFreeEx(process, _lvi, 0, MEM_RELEASE);
VirtualFreeEx(process, _item, 0, MEM_RELEASE);
VirtualFreeEx(process, _subitem, 0, MEM_RELEASE);

Yay, all done. In case that didn't make too much sense to you, here is our new code, all fixed up:

#define WIN32_LEAN_AND_MEAN
#include <stdio.h>
#include <windows.h>
#include <commctrl.h>

int main(void) {
 HWND hwnd=FindWindow(NULL, "Stealing Program's Memory: ListView");
 HWND listview=FindWindowEx(hwnd, NULL, "SysListView32", NULL);

 int count=(int)SendMessage(listview, LVM_GETITEMCOUNT, 0, 0);
 int i;

 LVITEM lvi, *_lvi;
 char item[512], subitem[512];
 char *_item, *_subitem;
 unsigned long pid;
 HANDLE process;

 GetWindowThreadProcessId(listview, &pid);
 process=OpenProcess(PROCESS_VM_OPERATION|PROCESS_VM_READ|
                     PROCESS_VM_WRITE|PROCESS_QUERY_INFORMATION, FALSE, pid);

 _lvi=(LVITEM*)VirtualAllocEx(process, NULL, sizeof(LVITEM),
                              MEM_COMMIT, PAGE_READWRITE);
 _item=(char*)VirtualAllocEx(process, NULL, 512, MEM_COMMIT,
                             PAGE_READWRITE);
 _subitem=(char*)VirtualAllocEx(process, NULL, 512, MEM_COMMIT,
                                PAGE_READWRITE);

 lvi.cchTextMax=512;

 for(i=0; i<count; i++) {
  lvi.iSubItem=0;
  lvi.pszText=_item;
  WriteProcessMemory(process, _lvi, &lvi, sizeof(LVITEM), NULL);
  SendMessage(listview, LVM_GETITEMTEXT, (WPARAM)i, (LPARAM)_lvi);

  lvi.iSubItem=1;
  lvi.pszText=_subitem;
  WriteProcessMemory(process, _lvi, &lvi, sizeof(LVITEM), NULL);
  SendMessage(listview, LVM_GETITEMTEXT, (WPARAM)i, (LPARAM)_lvi);

  ReadProcessMemory(process, _item, item, 512, NULL);
  ReadProcessMemory(process, _subitem, subitem, 512, NULL);

  printf("%s - %s\n", item, subitem);
 }

 VirtualFreeEx(process, _lvi, 0, MEM_RELEASE);
 VirtualFreeEx(process, _item, 0, MEM_RELEASE);
 VirtualFreeEx(process, _subitem, 0, MEM_RELEASE);

 return 0;
}

If you're looking to use a program's memory for another reason, or have had a similar problem to mine, adapting this should be fairly easy.

This article was originally written for int64.org.

License

This article has no explicit license attached to it, but may contain usage terms in the article text or the download files themselves. If in doubt, please contact the author via the discussion board below. A list of licenses authors might use can be found here.


Written By
Web Developer
United States United States
This member has not yet provided a Biography. Assume it's interesting and varied, and probably something to do with programming.

Comments and Discussions

 
GeneralRe: C# Version Pin
Karlheinz Godo15-Feb-07 8:40
Karlheinz Godo15-Feb-07 8:40 
GeneralCleaner C# Function Pin
dfhgesart7-Jul-07 16:10
dfhgesart7-Jul-07 16:10 
JokeThanks a lot! This is exactly what I'm looking for. Pin
songkiet9-Aug-06 8:58
songkiet9-Aug-06 8:58 
Questionretrieve text on statusbar Pin
doenoe31-Jul-06 22:22
doenoe31-Jul-06 22:22 
AnswerRe: retrieve text on statusbar Pin
andy66611-Nov-06 4:19
andy66611-Nov-06 4:19 
QuestionGet strings from Microsoft Outlook SUPERGRID Pin
kopyt19-Jul-06 2:13
kopyt19-Jul-06 2:13 
QuestionPossible to do same for delphi TStringGrid? Pin
Absorbant Pad13-Jun-06 0:10
Absorbant Pad13-Jun-06 0:10 
Questioncan we write text? Pin
aldo hexosa4-Mar-06 2:47
professionalaldo hexosa4-Mar-06 2:47 
can we write some text to list view?
AnswerRe: can we write text? Pin
shazzababs12-Oct-09 5:25
shazzababs12-Oct-09 5:25 
Questionleak? Pin
[cs2]27-Jan-06 7:11
[cs2]27-Jan-06 7:11 
GeneralProblem with one App Pin
clivet18-Sep-05 0:50
clivet18-Sep-05 0:50 
GeneralRe: Problem with one App Pin
___Charles___26-Jan-07 17:45
___Charles___26-Jan-07 17:45 
GeneralSelect and SetText Pin
J3ff28-Jul-05 10:30
J3ff28-Jul-05 10:30 
Generala Pin
Anonymous9-Dec-04 9:57
Anonymous9-Dec-04 9:57 
Generalb Pin
Anonymous10-May-05 0:39
Anonymous10-May-05 0:39 
Generalc Pin
Zaibot17-Dec-06 3:52
Zaibot17-Dec-06 3:52 
Generald Pin
games guru1-Aug-07 13:13
games guru1-Aug-07 13:13 
QuestionControl Propterties? Pin
riezebosch19-Oct-04 4:39
riezebosch19-Oct-04 4:39 
Generalhere is another crude way Pin
Member 11362553-Oct-04 9:03
Member 11362553-Oct-04 9:03 
GeneralRe: here is another crude way Pin
Synetech2-Mar-12 11:42
Synetech2-Mar-12 11:42 
GeneralAwesome!!! - Here's a mod to get data from all columns Pin
jjohnston30-Jan-04 17:46
jjohnston30-Jan-04 17:46 
GeneralRe: Awesome!!! - Got it working with a TreeView too... Pin
jjohnston30-Jan-04 21:51
jjohnston30-Jan-04 21:51 
GeneralRe: Awesome!!! - Got it working with a TreeView too... Pin
asdfasdf4tgfg23-Jan-07 11:06
asdfasdf4tgfg23-Jan-07 11:06 
GeneralRe: Awesome!!! - Got it working with a TreeView too... Pin
jjohnston30-Jan-04 22:00
jjohnston30-Jan-04 22:00 
GeneralRe: Awesome!!! - Here's a mod to get data from all columns Pin
Cory Nelson30-Jan-04 22:53
Cory Nelson30-Jan-04 22:53 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.