Inject python into other processes and implement Hook and active calls, supporting x86 and x64
Project description
原理讲解
功能
将注入Python注入到任意进程后,实现hook和内部函数调用
安装
pip install py-process-hooker==0.1.2
使用
以微信进程为例, 使用Python运行以下代码就会监听并执行当前目录下的py文件。具体看WeChat-PyRobot
from py_process_hooker import inject_python_and_monitor_dir
if __name__ == "__main__":
process_name = "WeChat.exe"
open_console = True
inject_python_and_monitor_dir(process_name, __file__, open_console=open_console)
案例
- 在windows11上编译python
- 将python注入到其他进程并运行
- 注入Python并使用ctypes主动调用进程内的函数和读取内存结构体
- 调用汇编引擎实战发送文本和图片消息(支持32位和64位微信)
- 允许Python加载运行py脚本且支持热加载
- 利用汇编和反汇编引擎写一个x86任意地址hook,实战Hook微信日志
- 封装Detour为dll,用于Python中x64函数 hook,实战Hook微信日志
- 实战32位和64位接收消息和消息防撤回
- 实战读取内存链表结构体(好友列表)
- 做一个僵尸粉检测工具
- 根据bug反馈和建议进行细节上的优化
- 其他功能看心情加
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
File details
Details for the file py_process_hooker-0.3.0.tar.gz
.
File metadata
- Download URL: py_process_hooker-0.3.0.tar.gz
- Upload date:
- Size: 1.5 MB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/4.0.2 CPython/3.8.17
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | d7e78782d0c33c34f1b2865cf6f005a4a8a27c279f0975ff9ed0c6b2afb6e07b |
|
MD5 | 28b8e2b3131dbec2a70c523a8bf918cc |
|
BLAKE2b-256 | 008d9dfdb04f458f5ee51df30cc48b63a60611ed6dba68d7d2399798f55a469f |
File details
Details for the file py_process_hooker-0.3.0-py3-none-any.whl
.
File metadata
- Download URL: py_process_hooker-0.3.0-py3-none-any.whl
- Upload date:
- Size: 1.6 MB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/4.0.2 CPython/3.8.17
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 850608309f2d037cd2c269ca4708d29c5fd8b6dc80486fd5ed8e6f51e4d48ffb |
|
MD5 | 44115c33a44972c43f036afa2584dacf |
|
BLAKE2b-256 | 9dc47b2c4781f6ba7cb29f7d38e73bb96ce1837634dd7513ea4f17d6166de5fe |