NDIS and TDI hooking, Part II
By: Andreas
This is the second and last article on how to hook into the NDIS and TDI
Layer. The approach we will use will be slightly different from the NDIS
Case. However, a neat side effect is that this method can be used to hook
Into any device chain, for example the keyboard to sniff key strokes. It all boils down to getting a pointer to the device object and replace all major functions with our own dispatch function.
To be able to fully control the TDI layer, we need access to the IRP both
Before and after the original driver has processed it. If we have that, we
Can choose what the original driver shocould process and we can also alter
Results Before they are returned to user-Space. The "before filtering" Can
Be accomplished in our own, new dispatch function and the "After filtering" can be accomplished in a completion routine.
First, to be able to overwrite and insert our own dispatch function, we need a pointer to the driver object we are going to hook. an easy way to get this pointer is to call obreferenceobjectbyname with the appropriate driver name. then we only have to save all old functions pointers and overwrite the existing ones with our own. the code to do this wowould look something like the following:
DRIVER_OBJECT RealTDIDriverObject;
NTSTATUS HookTDI(void)
{
NTSTATUS Status;
UNICODE_STRING usDriverName;
PDRIVER_OBJECT DriverObjectToHookPtr;
UINT i;
RtlInitUnicodeString(&usDriverName,L"//Driver//Tcpip");
Status =
ObReferenceObjectByName(&usDriverName,OBJ_CASE_INSENSITIVE,NULL,0,IoDriverObjectType,KernelMode,NULL,&DriverObjectToHookPtr);
if(Status != STATUS_SUCCESS) return Status;
for(i = 0;i < IRP_MJ_MAXIMUM_FUNCTION;i++) {
RealTDIDriverObject.MajorFunction[i] =
DriverObjectToHookPtr->MajorFunction[i];
DriverObjectToHookPtr->MajorFunction[i] = TDIDeviceDispatch;
}
return STATUS_SUCCESS;
}
Realtdidriverobject is a driver_object where we save the original
Information to both be able to call the old functions and also be able
Unhook once we are done. the orignal driver gets all its major functions
Overwritten with a pointer to our own dispatch function, tdidevicedispatch.
We now have control over the IRPs before TDI can process them. but, we still have to make sure we can also control them once TDI is done with it but before it is returned to the IO handler and user-space. we will solve this in our dispatch function with the help of a completion routine. it is not as straight forward as it sounds, since we might be hooking the last entity in the chain, we can't just insert a completion routine
Iosetcompletionroutine (see the DDK Docs), since it in that case never will be called. completion routines are set in the next IRP stack location, not the current. if we are the last entity, there will be no next stack location in the IRP. searching through the header files reveal iosetcompletionroutine as a macro which only gets the next IRP stack location and sets the completionroutine pointer together with the control element. following the same principcal, we can set our own completion routine to regain control over the IRP with the following dispach function:
NTSTATUS TDIDeviceDispatch(IN PDEVICE_OBJECT DeviceObject,IN PIRP Irp)
{
NTSTATUS Status;
PIO_STACK_LOCATION StackLocationPtr;
if(Irp == NULL) return STATUS_SUCCESS;
StackLocationPtr = IoGetCurrentIrpStackLocation(Irp);
if(StackLocationPtr->CompletionRoutine != NULL) StackLocationPtr->Context =
StackLocationPtr->CompletionRoutine;
else StackLocationPtr->Context = NULL;
StackLocationPtr->CompletionRoutine =
(PIO_COMPLETION_ROUTINE)TDICompletionRoutine;
StackLocationPtr->Control = SL_INVOKE_ON_SUCCESS | SL_INVOKE_ON_ERROR |
SL_INVOKE_ON_CANCEL;
Status =
RealTDIDriverObject.MajorFunction[StackLocationPtr->MajorFunction](DeviceObject,Irp);
return Status;
}
What we actually do is faking a scenario where the layer above set
Completion routine for us. We also save a potentially already existing
Completion routine in the context element of the IRP. Control is set
Invoke the completion routine in all cases. There are 2 potential issues
With this code. First, we overwrite whatever is in the context element.
Second, we never save the control element, so we don't know when to invoke
An already existing completion routine. So far, I have not seen any
Side-effects from doing this.
The completion routine wowould look something like:
NTSTATUS TDICompletionRoutine(PDEVICE_OBJECT DeviceObject,PIRP Irp,PVOID
Context)
{
COMPLETIONROUTINE RealCompletionRoutine = (COMPLETIONROUTINE)Context;
if(Context != NULL) return RealCompletionRoutine(DeviceObject,Irp,NULL);
else return STATUS_SUCCESS;
}
It invokes a potential completion routine as soon as it is done and returns the status from it. Finally, unhooking the driver is just a question of restoring the pointers we overwrote in the hooking function:
NTSTATUS ReleaseTDIDevices(void)
{
NTSTATUS Status;
UNICODE_STRING usDriverName;
PDRIVER_OBJECT DriverObjectToHookPtr;
UINT i;
RtlInitUnicodeString(&usDriverName,L"//Driver//Tcpip");
Status =
ObReferenceObjectByName(&usDriverName,OBJ_CASE_INSENSITIVE,NULL,0,IoDriverObjectType,KernelMode,NULL,&DriverObjectToHookPtr);
if(Status != STATUS_SUCCESS) return Status;
for(i = 0;i < IRP_MJ_MAXIMUM_FUNCTION;i++)
DriverObjectToHookPtr->MajorFunction[i] =
RealTDIDriverObject.MajorFunction[i];
return STATUS_SUCCESS;
}
There is another way to accomplish the same result which utilizes a more
Offically supported mode of operation. It is based upon attaching to
Device chain with getdeviceobject and attachtodevice, which will allow us to process all IRPs before the real device. once in the dispatch function we Contruct a new IRP and add a completion routine to regain control of the IRP before it is returned to the IO system and user-space.
One last important thing to mention; this code is quite untested. It seems
To work as intended but it has never been used in any major applications, so use it on your own risk. With that said, hope you have enjoyed this little article series.
This is the second and last article on how to hook into the NDIS and TDI
Layer. The approach we will use will be slightly different from the NDIS
Case. However, a neat side effect is that this method can be used to hook
Into any device chain, for example the keyboard to sniff key strokes. It all boils down to getting a pointer to the device object and replace all major functions with our own dispatch function.
To be able to fully control the TDI layer, we need access to the IRP both
Before and after the original driver has processed it. If we have that, we
Can choose what the original driver shocould process and we can also alter
Results Before they are returned to user-Space. The "before filtering" Can
Be accomplished in our own, new dispatch function and the "After filtering" can be accomplished in a completion routine.
First, to be able to overwrite and insert our own dispatch function, we need a pointer to the driver object we are going to hook. an easy way to get this pointer is to call obreferenceobjectbyname with the appropriate driver name. then we only have to save all old functions pointers and overwrite the existing ones with our own. the code to do this wowould look something like the following:
DRIVER_OBJECT RealTDIDriverObject;
NTSTATUS HookTDI(void)
{
NTSTATUS Status;
UNICODE_STRING usDriverName;
PDRIVER_OBJECT DriverObjectToHookPtr;
UINT i;
RtlInitUnicodeString(&usDriverName,L"//Driver//Tcpip");
Status =
ObReferenceObjectByName(&usDriverName,OBJ_CASE_INSENSITIVE,NULL,0,IoDriverObjectType,KernelMode,NULL,&DriverObjectToHookPtr);
if(Status != STATUS_SUCCESS) return Status;
for(i = 0;i < IRP_MJ_MAXIMUM_FUNCTION;i++) {
RealTDIDriverObject.MajorFunction[i] =
DriverObjectToHookPtr->MajorFunction[i];
DriverObjectToHookPtr->MajorFunction[i] = TDIDeviceDispatch;
}
return STATUS_SUCCESS;
}
Realtdidriverobject is a driver_object where we save the original
Information to both be able to call the old functions and also be able
Unhook once we are done. the orignal driver gets all its major functions
Overwritten with a pointer to our own dispatch function, tdidevicedispatch.
We now have control over the IRPs before TDI can process them. but, we still have to make sure we can also control them once TDI is done with it but before it is returned to the IO handler and user-space. we will solve this in our dispatch function with the help of a completion routine. it is not as straight forward as it sounds, since we might be hooking the last entity in the chain, we can't just insert a completion routine
Iosetcompletionroutine (see the DDK Docs), since it in that case never will be called. completion routines are set in the next IRP stack location, not the current. if we are the last entity, there will be no next stack location in the IRP. searching through the header files reveal iosetcompletionroutine as a macro which only gets the next IRP stack location and sets the completionroutine pointer together with the control element. following the same principcal, we can set our own completion routine to regain control over the IRP with the following dispach function:
NTSTATUS TDIDeviceDispatch(IN PDEVICE_OBJECT DeviceObject,IN PIRP Irp)
{
NTSTATUS Status;
PIO_STACK_LOCATION StackLocationPtr;
if(Irp == NULL) return STATUS_SUCCESS;
StackLocationPtr = IoGetCurrentIrpStackLocation(Irp);
if(StackLocationPtr->CompletionRoutine != NULL) StackLocationPtr->Context =
StackLocationPtr->CompletionRoutine;
else StackLocationPtr->Context = NULL;
StackLocationPtr->CompletionRoutine =
(PIO_COMPLETION_ROUTINE)TDICompletionRoutine;
StackLocationPtr->Control = SL_INVOKE_ON_SUCCESS | SL_INVOKE_ON_ERROR |
SL_INVOKE_ON_CANCEL;
Status =
RealTDIDriverObject.MajorFunction[StackLocationPtr->MajorFunction](DeviceObject,Irp);
return Status;
}
What we actually do is faking a scenario where the layer above set
Completion routine for us. We also save a potentially already existing
Completion routine in the context element of the IRP. Control is set
Invoke the completion routine in all cases. There are 2 potential issues
With this code. First, we overwrite whatever is in the context element.
Second, we never save the control element, so we don't know when to invoke
An already existing completion routine. So far, I have not seen any
Side-effects from doing this.
The completion routine wowould look something like:
NTSTATUS TDICompletionRoutine(PDEVICE_OBJECT DeviceObject,PIRP Irp,PVOID
Context)
{
COMPLETIONROUTINE RealCompletionRoutine = (COMPLETIONROUTINE)Context;
if(Context != NULL) return RealCompletionRoutine(DeviceObject,Irp,NULL);
else return STATUS_SUCCESS;
}
It invokes a potential completion routine as soon as it is done and returns the status from it. Finally, unhooking the driver is just a question of restoring the pointers we overwrote in the hooking function:
NTSTATUS ReleaseTDIDevices(void)
{
NTSTATUS Status;
UNICODE_STRING usDriverName;
PDRIVER_OBJECT DriverObjectToHookPtr;
UINT i;
RtlInitUnicodeString(&usDriverName,L"//Driver//Tcpip");
Status =
ObReferenceObjectByName(&usDriverName,OBJ_CASE_INSENSITIVE,NULL,0,IoDriverObjectType,KernelMode,NULL,&DriverObjectToHookPtr);
if(Status != STATUS_SUCCESS) return Status;
for(i = 0;i < IRP_MJ_MAXIMUM_FUNCTION;i++)
DriverObjectToHookPtr->MajorFunction[i] =
RealTDIDriverObject.MajorFunction[i];
return STATUS_SUCCESS;
}
There is another way to accomplish the same result which utilizes a more
Offically supported mode of operation. It is based upon attaching to
Device chain with getdeviceobject and attachtodevice, which will allow us to process all IRPs before the real device. once in the dispatch function we Contruct a new IRP and add a completion routine to regain control of the IRP before it is returned to the IO system and user-space.
One last important thing to mention; this code is quite untested. It seems
To work as intended but it has never been used in any major applications, so use it on your own risk. With that said, hope you have enjoyed this little article series.