A tool to automatically generate cpp/asm codes for wrapping a dynamic-link library.
- All the wrapper functions perform a
jmpinstruction that jumps to the real function. - A CMake project is generated under the directory with the same name as the DLL.
- If the signature of any of the functions is known, the user can replace the default implementation with a custom function that performs API hooking / code injection.
- Both
x64orWin32DLLs are supported. - The original real DLL is prefixed with
real_and copied to the project directory. - C++ functions are demangled, a C function name is created in the generated project but it is exported as the original mangled symbol.
__stdcall,__fastcallsymbols are undecorated, but exported as the original symbol. The user is responsible to ensure the overriding function has the same calling convention.
No installation is necessary, but you need python>=3.7 to run it, and want to install the dependencies through
pip install -r requirements.txtcurrently there's only jinja2 for rendering the code templates.
Make sure you installed Visual Studio, the script by default assumes the dumpbin.exe and undname.exe tools are available in the PATH. Mine is located at C:\Program Files (x86)\Microsoft Visual Studio\2019\Community\VC\Tools\MSVC\14.27.29110\bin\Hostx64\x64\, so add it to your path. Otherwise pass the --dumpbin and --undname arguments.
python3 wrap_dll.py C:\Windows\System32\AudioSes.dll
cd AudioSes
cmake -f CMakeLists.txtpython3 wrap_dll.py C:\Windows\SysWOW64\AudioSes.dll
cd AudioSes
cmake -f CMakeLists.txtTo override some of the functions, provide a hook.h file.
Say if we wrap abc_dll.dll with the function int abc(const char* a, int b, float c), override it in the hook.h with
/*
* content of file: hook.h
*/
#include "hook_macro.h"
/*
* define a variable that is uppercase of the function name that you want to override.
* which notifies the generated code that a override of the function is provided.
*/
#define ABC
/*
* Arguments of the FAKE macro is (return_type, call_convention, function_name, arg_type1 arg1, arg_type2 arg2, ...).
*/
FAKE(int, __cdecl, abc, const char* a, int b, float c) { // currently, the parsing code only support __cdecl functions.
b = 0; // custom code before calling the real function.
int ret = abc_real(a, b, c); // call the real function, FAKE macro prepares abc_real for you, which can be called directly.
ret += 1; // custom code after calling the real function.
return ret;
}Now generate the wrapper with
python3 wrap_dll.py --hook hook.h abc_dll.dll
cd abc_dll
cmake -f CMakeLists.txtThis tool seems to be useful for some people, as I saw a few forks recently. Therefore I performed a major refactor to make the code more professional.
Changes:
- Remove the
dumpbin.exeincluded, the user can specify their owndumpbin.exethat comes with their visual studio installation. e.g. Mine is located atC:\Program Files (x86)\Microsoft Visual Studio\2019\Community\VC\Tools\MSVC\14.27.29110\bin\Hostx64\x64\dumpbin.exe. The script by default assumesdumpbin.exeis available in the user'sPATH. - Use
cmaketo generate visual studio solution file. - Use
jinja2to separate thec++/asmcode into independent template files. - Support
--dryflag to perform dry run, which only prints all the files to be generated.