Solved

ReadProcessMemory

Posted on 2006-11-20
2
1,142 Views
Last Modified: 2008-02-07
Hi,

When using read process memory, here is an example:

dim lngBaseAdd as long
dim lngResult as long
dim lngReadBytes as long

lngBaseAdd = &HF0129F 'or some arbitrary base address

When using the read process memory API you must pass the lngBaseAdd by value, why?

ReadProcessMemory hProcess, lngBaseAdd, lngResult, 4, lngReadBytes '<--- FAILS
ReadProcessMemory hProcess, byVal lngBaseAdd, lngResult, 4, lngReadBytes '<--- WORKS

I dont get why you must pass it by value.



Thanks.
Brian

0
Comment
Question by:BrianGEFF719
2 Comments
 
LVL 27

Accepted Solution

by:
Ark earned 500 total points
ID: 17983709
Hi
Calling by ref is equal to calling by val using pointer to variable instead of variable itself:

ReadProcessMemory hProcess, lngBaseAdd, lngResult, 4, lngReadBytes

is equal to

ReadProcessMemory hProcess, ByVal VarPtr(lngBaseAdd), lngResult, 4, lngReadBytes

lngBaseAddress is a Long type variable, which is actual virtual address in remote process address space. When you pass it ByVal, you tell ReadProcessMemory API to read remote process memory, starting from this actual address, when pass it ByRef, you send to remote process not actual address, but pointer to your variable (VarPtr(lngBaseAddress)). Remote process get a value from this pointer in its own memory space (which can be 0 or any unpredicable value) and start reading from this value - and fail.
0
 
LVL 19

Author Comment

by:BrianGEFF719
ID: 17983809
Thanks Ark.


-Brian
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article describes some techniques which will make your VBA or Visual Basic Classic code easier to understand and maintain, whether by you, your replacement, or another Experts-Exchange expert.
If you need to start windows update installation remotely or as a scheduled task you will find this very helpful.
Get people started with the process of using Access VBA to control Outlook using automation, Microsoft Access can control other applications. An example is the ability to programmatically talk to Microsoft Outlook. Using automation, an Access applic…
This lesson covers basic error handling code in Microsoft Excel using VBA. This is the first lesson in a 3-part series that uses code to loop through an Excel spreadsheet in VBA and then fix errors, taking advantage of error handling code. This l…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now