Solved

ReadProcessMemory

Posted on 2006-11-20
2
1,151 Views
Last Modified: 2008-02-07
Hi,

When using read process memory, here is an example:

dim lngBaseAdd as long
dim lngResult as long
dim lngReadBytes as long

lngBaseAdd = &HF0129F 'or some arbitrary base address

When using the read process memory API you must pass the lngBaseAdd by value, why?

ReadProcessMemory hProcess, lngBaseAdd, lngResult, 4, lngReadBytes '<--- FAILS
ReadProcessMemory hProcess, byVal lngBaseAdd, lngResult, 4, lngReadBytes '<--- WORKS

I dont get why you must pass it by value.



Thanks.
Brian

0
Comment
Question by:BrianGEFF719
2 Comments
 
LVL 28

Accepted Solution

by:
Ark earned 500 total points
ID: 17983709
Hi
Calling by ref is equal to calling by val using pointer to variable instead of variable itself:

ReadProcessMemory hProcess, lngBaseAdd, lngResult, 4, lngReadBytes

is equal to

ReadProcessMemory hProcess, ByVal VarPtr(lngBaseAdd), lngResult, 4, lngReadBytes

lngBaseAddress is a Long type variable, which is actual virtual address in remote process address space. When you pass it ByVal, you tell ReadProcessMemory API to read remote process memory, starting from this actual address, when pass it ByRef, you send to remote process not actual address, but pointer to your variable (VarPtr(lngBaseAddress)). Remote process get a value from this pointer in its own memory space (which can be 0 or any unpredicable value) and start reading from this value - and fail.
0
 
LVL 19

Author Comment

by:BrianGEFF719
ID: 17983809
Thanks Ark.


-Brian
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Introduction In a recent article (http://www.experts-exchange.com/A_7811-A-Better-Concatenate-Function.html) for the Excel community, I showed an improved version of the Excel Concatenate() function.  While writing that article I realized that no o…
You can of course define an array to hold data that is of a particular type like an array of Strings to hold customer names or an array of Doubles to hold customer sales, but what do you do if you want to coordinate that data? This article describes…
As developers, we are not limited to the functions provided by the VBA language. In addition, we can call the functions that are part of the Windows operating system. These functions are part of the Windows API (Application Programming Interface). U…
Show developers how to use a criteria form to limit the data that appears on an Access report. It is a common requirement that users can specify the criteria for a report at runtime. The easiest way to accomplish this is using a criteria form that a…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question