Solved

ReadProcessMemory

Posted on 2006-11-20
2
1,138 Views
Last Modified: 2008-02-07
Hi,

When using read process memory, here is an example:

dim lngBaseAdd as long
dim lngResult as long
dim lngReadBytes as long

lngBaseAdd = &HF0129F 'or some arbitrary base address

When using the read process memory API you must pass the lngBaseAdd by value, why?

ReadProcessMemory hProcess, lngBaseAdd, lngResult, 4, lngReadBytes '<--- FAILS
ReadProcessMemory hProcess, byVal lngBaseAdd, lngResult, 4, lngReadBytes '<--- WORKS

I dont get why you must pass it by value.



Thanks.
Brian

0
Comment
Question by:BrianGEFF719
2 Comments
 
LVL 27

Accepted Solution

by:
Ark earned 500 total points
ID: 17983709
Hi
Calling by ref is equal to calling by val using pointer to variable instead of variable itself:

ReadProcessMemory hProcess, lngBaseAdd, lngResult, 4, lngReadBytes

is equal to

ReadProcessMemory hProcess, ByVal VarPtr(lngBaseAdd), lngResult, 4, lngReadBytes

lngBaseAddress is a Long type variable, which is actual virtual address in remote process address space. When you pass it ByVal, you tell ReadProcessMemory API to read remote process memory, starting from this actual address, when pass it ByRef, you send to remote process not actual address, but pointer to your variable (VarPtr(lngBaseAddress)). Remote process get a value from this pointer in its own memory space (which can be 0 or any unpredicable value) and start reading from this value - and fail.
0
 
LVL 19

Author Comment

by:BrianGEFF719
ID: 17983809
Thanks Ark.


-Brian
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

If you have ever used Microsoft Word then you know that it has a good spell checker and it may have occurred to you that the ability to check spelling might be a nice piece of functionality to add to certain applications of yours. Well the code that…
Most everyone who has done any programming in VB6 knows that you can do something in code like Debug.Print MyVar and that when the program runs from the IDE, the value of MyVar will be displayed in the Immediate Window. Less well known is Debug.Asse…
As developers, we are not limited to the functions provided by the VBA language. In addition, we can call the functions that are part of the Windows operating system. These functions are part of the Windows API (Application Programming Interface). U…
Get people started with the process of using Access VBA to control Excel using automation, Microsoft Access can control other applications. An example is the ability to programmatically talk to Excel. Using automation, an Access application can laun…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now