| 1 | #ifndef DBKFUNC_H |
|---|
| 2 | #define DBKFUNC_H |
|---|
| 3 | |
|---|
| 4 | #include "ntifs.h" |
|---|
| 5 | #include <windef.h> |
|---|
| 6 | |
|---|
| 7 | #include "interruptHook.h" |
|---|
| 8 | |
|---|
| 9 | int _fltused; |
|---|
| 10 | |
|---|
| 11 | |
|---|
| 12 | |
|---|
| 13 | typedef struct _criticalSection |
|---|
| 14 | { |
|---|
| 15 | int locked; |
|---|
| 16 | int cpunr; |
|---|
| 17 | int lockcount; |
|---|
| 18 | int oldIFstate; |
|---|
| 19 | } criticalSection, *PcriticalSection; |
|---|
| 20 | |
|---|
| 21 | |
|---|
| 22 | struct PTEStruct |
|---|
| 23 | { |
|---|
| 24 | unsigned P : 1; |
|---|
| 25 | unsigned RW : 1; |
|---|
| 26 | unsigned US : 1; |
|---|
| 27 | unsigned PWT : 1; |
|---|
| 28 | unsigned PCD : 1; |
|---|
| 29 | unsigned A : 1; |
|---|
| 30 | unsigned Reserved : 1; |
|---|
| 31 | unsigned PS : 1; |
|---|
| 32 | unsigned G : 1; |
|---|
| 33 | unsigned A1 : 1; |
|---|
| 34 | unsigned A2 : 1; |
|---|
| 35 | unsigned A3 : 1; |
|---|
| 36 | unsigned PFN : 20; |
|---|
| 37 | }; |
|---|
| 38 | |
|---|
| 39 | typedef struct tagDebugregs |
|---|
| 40 | { |
|---|
| 41 | ULONG DR0; |
|---|
| 42 | ULONG DR1; |
|---|
| 43 | ULONG DR2; |
|---|
| 44 | ULONG DR3; |
|---|
| 45 | ULONG DR5; |
|---|
| 46 | ULONG DR6; |
|---|
| 47 | ULONG DR7; |
|---|
| 48 | } Debugregs; |
|---|
| 49 | |
|---|
| 50 | |
|---|
| 51 | |
|---|
| 52 | typedef struct |
|---|
| 53 | { |
|---|
| 54 | unsigned CF :1; |
|---|
| 55 | unsigned reserved1 :1; |
|---|
| 56 | unsigned PF :1; |
|---|
| 57 | unsigned reserved2 :1; |
|---|
| 58 | unsigned AF :1; |
|---|
| 59 | unsigned reserved3 :1; |
|---|
| 60 | unsigned ZF :1; |
|---|
| 61 | unsigned SF :1; |
|---|
| 62 | unsigned TF :1; |
|---|
| 63 | unsigned IF :1; |
|---|
| 64 | unsigned DF :1; |
|---|
| 65 | unsigned OF :1; |
|---|
| 66 | unsigned IOPL :2; |
|---|
| 67 | unsigned NT :1; |
|---|
| 68 | unsigned reserved4 :1; |
|---|
| 69 | unsigned RF :1; |
|---|
| 70 | unsigned VM :1; |
|---|
| 71 | unsigned AC :1; |
|---|
| 72 | unsigned VIF :1; |
|---|
| 73 | unsigned VIP :1; |
|---|
| 74 | unsigned ID :1; |
|---|
| 75 | unsigned reserved5 :10; |
|---|
| 76 | #ifdef AMD64 |
|---|
| 77 | unsigned reserved6 :8; |
|---|
| 78 | unsigned reserved7 :8; |
|---|
| 79 | unsigned reserved8 :8; |
|---|
| 80 | unsigned reserved9 :8; |
|---|
| 81 | #endif |
|---|
| 82 | |
|---|
| 83 | } EFLAGS,*PEFLAGS; |
|---|
| 84 | |
|---|
| 85 | typedef struct tagDebugReg7 |
|---|
| 86 | { |
|---|
| 87 | unsigned L0 :1; |
|---|
| 88 | unsigned G0 :1; |
|---|
| 89 | unsigned L1 :1; |
|---|
| 90 | unsigned G1 :1; |
|---|
| 91 | unsigned L2 :1; |
|---|
| 92 | unsigned G2 :1; |
|---|
| 93 | unsigned L3 :1; |
|---|
| 94 | unsigned G3 :1; |
|---|
| 95 | unsigned GL :1; |
|---|
| 96 | unsigned GE :1; |
|---|
| 97 | unsigned undefined1 :3; |
|---|
| 98 | unsigned GD :1; |
|---|
| 99 | unsigned undefined2 :2; |
|---|
| 100 | unsigned RW0 :2; |
|---|
| 101 | unsigned LEN0 :2; |
|---|
| 102 | unsigned RW1 :2; |
|---|
| 103 | unsigned LEN1 :2; |
|---|
| 104 | unsigned RW2 :2; |
|---|
| 105 | unsigned LEN2 :2; |
|---|
| 106 | unsigned RW3 :2; |
|---|
| 107 | unsigned LEN3 :2; |
|---|
| 108 | #ifdef AMD64 |
|---|
| 109 | unsigned undefined3 :8; |
|---|
| 110 | unsigned undefined4 :8; |
|---|
| 111 | unsigned undefined5 :8; |
|---|
| 112 | unsigned undefined6 :8; |
|---|
| 113 | #endif |
|---|
| 114 | |
|---|
| 115 | } DebugReg7; |
|---|
| 116 | |
|---|
| 117 | typedef struct DebugReg6 |
|---|
| 118 | { |
|---|
| 119 | unsigned B0 :1; |
|---|
| 120 | unsigned B1 :1; |
|---|
| 121 | unsigned B2 :1; |
|---|
| 122 | unsigned B3 :1; |
|---|
| 123 | unsigned undefined1 :9; |
|---|
| 124 | unsigned BD :1; |
|---|
| 125 | unsigned BS :1; |
|---|
| 126 | unsigned BT :1; |
|---|
| 127 | unsigned undefined2 :16; |
|---|
| 128 | #ifdef AMD64 |
|---|
| 129 | unsigned undefined3 :8; |
|---|
| 130 | unsigned undefined4 :8; |
|---|
| 131 | unsigned undefined5 :8; |
|---|
| 132 | unsigned undefined6 :8; |
|---|
| 133 | #endif |
|---|
| 134 | |
|---|
| 135 | } DebugReg6; |
|---|
| 136 | |
|---|
| 137 | |
|---|
| 138 | |
|---|
| 139 | |
|---|
| 140 | #pragma pack(2) //allignment of 2 bytes |
|---|
| 141 | typedef struct tagGDT |
|---|
| 142 | { |
|---|
| 143 | WORD wLimit; |
|---|
| 144 | PVOID vector; |
|---|
| 145 | } GDT, *PGDT; |
|---|
| 146 | #pragma pack() |
|---|
| 147 | |
|---|
| 148 | UCHAR BufferSize; |
|---|
| 149 | |
|---|
| 150 | void GetIDT(PIDT pIdt); |
|---|
| 151 | |
|---|
| 152 | #ifdef AMD64 |
|---|
| 153 | extern void GetGDT(PGDT pGdt); |
|---|
| 154 | extern WORD GetLDT(); |
|---|
| 155 | extern WORD GetTR(void); |
|---|
| 156 | #else |
|---|
| 157 | |
|---|
| 158 | void GetGDT(PGDT pGdt); |
|---|
| 159 | WORD GetLDT(); |
|---|
| 160 | WORD GetTR(void); |
|---|
| 161 | #endif |
|---|
| 162 | |
|---|
| 163 | |
|---|
| 164 | |
|---|
| 165 | |
|---|
| 166 | UINT64 readMSR(DWORD msr); |
|---|
| 167 | UINT64 getDR7(void); |
|---|
| 168 | void setCR0(UINT64 newCR0); |
|---|
| 169 | UINT64 getCR0(void); |
|---|
| 170 | UINT64 getCR2(void); |
|---|
| 171 | void setCR3(UINT64 newCR3); |
|---|
| 172 | UINT64 getCR3(void); |
|---|
| 173 | UINT64 getCR4(void); |
|---|
| 174 | void setCR4(UINT64 newcr4); |
|---|
| 175 | UINT64 getTSC(void); |
|---|
| 176 | |
|---|
| 177 | #ifdef AMD64 |
|---|
| 178 | extern WORD getCS(void); |
|---|
| 179 | extern WORD getSS(void); |
|---|
| 180 | extern WORD getDS(void); |
|---|
| 181 | extern WORD getES(void); |
|---|
| 182 | extern WORD getFS(void); |
|---|
| 183 | extern WORD getGS(void); |
|---|
| 184 | extern UINT64 getRSP(void); |
|---|
| 185 | extern UINT64 getRBP(void); |
|---|
| 186 | extern UINT64 getRAX(void); |
|---|
| 187 | extern UINT64 getRBX(void); |
|---|
| 188 | extern UINT64 getRCX(void); |
|---|
| 189 | extern UINT64 getRDX(void); |
|---|
| 190 | extern UINT64 getRSI(void); |
|---|
| 191 | extern UINT64 getRDI(void); |
|---|
| 192 | #else |
|---|
| 193 | |
|---|
| 194 | WORD getCS(void); |
|---|
| 195 | WORD getSS(void); |
|---|
| 196 | WORD getDS(void); |
|---|
| 197 | WORD getES(void); |
|---|
| 198 | WORD getFS(void); |
|---|
| 199 | WORD getGS(void); |
|---|
| 200 | ULONG getRSP(void); |
|---|
| 201 | ULONG getRBP(void); |
|---|
| 202 | ULONG getRAX(void); |
|---|
| 203 | ULONG getRBX(void); |
|---|
| 204 | ULONG getRCX(void); |
|---|
| 205 | ULONG getRDX(void); |
|---|
| 206 | ULONG getRSI(void); |
|---|
| 207 | ULONG getRDI(void); |
|---|
| 208 | #endif |
|---|
| 209 | |
|---|
| 210 | |
|---|
| 211 | extern UINT64 getR8(void); |
|---|
| 212 | extern UINT64 getR9(void); |
|---|
| 213 | extern UINT64 getR10(void); |
|---|
| 214 | extern UINT64 getR11(void); |
|---|
| 215 | extern UINT64 getR12(void); |
|---|
| 216 | extern UINT64 getR13(void); |
|---|
| 217 | extern UINT64 getR14(void); |
|---|
| 218 | extern UINT64 getR15(void); |
|---|
| 219 | |
|---|
| 220 | |
|---|
| 221 | int getCpuCount(void); |
|---|
| 222 | |
|---|
| 223 | int PTESize; |
|---|
| 224 | UINT_PTR PAGE_SIZE_LARGE; |
|---|
| 225 | UINT_PTR MAX_PDE_POS; |
|---|
| 226 | |
|---|
| 227 | int isPrefix(unsigned char b); |
|---|
| 228 | EFLAGS getEflags(void); |
|---|
| 229 | int cpunr(void); |
|---|
| 230 | void disableInterrupts(void); |
|---|
| 231 | void enableInterrupts(void); |
|---|
| 232 | |
|---|
| 233 | |
|---|
| 234 | void csEnter(PcriticalSection CS); |
|---|
| 235 | void csLeave(PcriticalSection CS); |
|---|
| 236 | |
|---|
| 237 | |
|---|
| 238 | #endif; |
|---|