MCPcopy Create free account
hub / github.com/qilingframework/qiling / hook_WriteFile

Function hook_WriteFile

qiling/os/windows/dlls/kernel32/fileapi.py:192–212  ·  view source on GitHub ↗
(ql: Qiling, address: int, params)

Source from the content-addressed store, hash-verified

190 'lpOverlapped' : LPOVERLAPPED
191})
192def hook_WriteFile(ql: Qiling, address: int, params):
193 hFile = params["hFile"]
194 lpBuffer = params["lpBuffer"]
195 nNumberOfBytesToWrite = params["nNumberOfBytesToWrite"]
196 lpNumberOfBytesWritten = params["lpNumberOfBytesWritten"]
197
198 handle = ql.os.handle_manager.get(hFile)
199
200 if handle is None:
201 ql.os.last_error = ERROR_INVALID_HANDLE
202 return 0
203
204 data = ql.mem.read(lpBuffer, nNumberOfBytesToWrite)
205
206 if hFile in (STD_OUTPUT_HANDLE, STD_ERROR_HANDLE):
207 ql.os.stats.log_string(data.decode())
208
209 written = handle.obj.write(bytes(data))
210 ql.mem.write_ptr(lpNumberOfBytesWritten, written, 4)
211
212 return 1
213
214def _CreateFile(ql: Qiling, address: int, params):
215 s_lpFileName = params["lpFileName"]

Callers

nothing calls this directly

Calls 5

write_ptrMethod · 0.80
getMethod · 0.45
readMethod · 0.45
log_stringMethod · 0.45
writeMethod · 0.45

Tested by

no test coverage detected