1.理論:
從擊鍵到內核,前后的執行情況,之間沒有必然關聯
按鍵->csrss.exe->win32!RawInputThread->win32k!OpenDevice->ZwCreateFile->NtCreateFile->ntIopParseDevice->nt!IoGetAttachedDevice
->IoAllocateIrp->nt!ObCreateObject->nt!IopfCallDriver->nt!ObOpenObjectByName->ntObpCreateHandle->nt!ZwReadFile->中斷.........
簡單點就是csrss程序的?win32!RawInputThread 發起一個IRP_READ的請求給鍵盤驅動,當沒有按鍵時這個請求將等待,知道按下了鍵.
當按下鍵后將中斷,中斷服務程序由鍵盤驅動程序提供,然后鍵盤驅動從端口讀取掃描碼處理后發給csrss提交的IRP,最后win32!RawInputThread
通過nt!ZwReadFile讀取了按鍵的信息.
?
如果沒有其他過濾的程序,設備棧:
最頂層的設備對象是KdbClass生成的設備對象
中間層的設備對象是驅動i8042prt生成的設備對象
最底層的設備對象是驅動acpi生成的設備對象
?
?
?
?
鍵盤輸出鍵原理:
鍵盤與cpu交互方式是中斷和讀取端口,是串行的.發生一次中斷等于鍵盤發送一個通知(事件):某個鍵被按下或者某個鍵被彈起.cpu只接受通知并讀取端口的掃描碼
一般來說按下某個鍵的掃描碼比彈起該鍵的掃描碼低0x80
?
實例代碼:
//__stdcall #include<ntddk.h> #include<Ntddkbd.h> #include<ntstrsafe.h> #pragma code_seg("INT")extern POBJECT_TYPE IoDriverObjectType; #define KBD_DRIVER_NAME L"\\Driver\\kbdClass" //用于計時 #define DELAY_ONE_MICROSECOND (-10) #define DELAY_ONE_MILLISECOND (DELAY_ONE_MICROSECOND*1000) #define DELAY_ONE_SECOND (DELAY_ONE_MILLISECOND*1000) NTSTATUS ObReferenceObjectByName(PUNICODE_STRING objectName, ULONG Attributes, PACCESS_STATE AccessState, ACCESS_MASK DesiredAccess, POBJECT_TYPE objectType, KPROCESSOR_MODE AccessMode, PVOID ParseContext, PVOID *Object);ULONG keyCount=0;//設置大寫鎖定,小鍵盤鎖定和shift鍵狀態 #define S_SHIFT 1 #define S_CAPS 2 #define S_NUM 4 static int kb_status = S_NUM;#define KEY_UP 1 #define KEY_DOWN 0 //定義大寫鎖定鍵和ctrl鍵的掃描碼,其實可以定義一個全鍵盤的掃描碼 #define LCONTROL ((USHORT)0x1D) #define CAPS_LOCK ((USHORT)0x3A) unsigned char asciiTbl[] = {0x00, 0x1B, 0x31, 0x32, 0x33, 0x34, 0x35, 0x36, 0x37, 0x38, 0x39, 0x30, 0x2D, 0x3D, 0x08, 0x09, //normal0x71, 0x77, 0x65, 0x72, 0x74, 0x79, 0x75, 0x69, 0x6F, 0x70, 0x5B, 0x5D, 0x0D, 0x00, 0x61, 0x73,0x64, 0x66, 0x67, 0x68, 0x6A, 0x6B, 0x6C, 0x3B, 0x27, 0x60, 0x00, 0x5C, 0x7A, 0x78, 0x63, 0x76,0x62, 0x6E, 0x6D, 0x2C, 0x2E, 0x2F, 0x00, 0x2A, 0x00, 0x20, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x37, 0x38, 0x39, 0x2D, 0x34, 0x35, 0x36, 0x2B, 0x31,0x32, 0x33, 0x30, 0x2E,0x00, 0x1B, 0x31, 0x32, 0x33, 0x34, 0x35, 0x36, 0x37, 0x38, 0x39, 0x30, 0x2D, 0x3D, 0x08, 0x09, //caps0x51, 0x57, 0x45, 0x52, 0x54, 0x59, 0x55, 0x49, 0x4F, 0x50, 0x5B, 0x5D, 0x0D, 0x00, 0x41, 0x53,0x44, 0x46, 0x47, 0x48, 0x4A, 0x4B, 0x4C, 0x3B, 0x27, 0x60, 0x00, 0x5C, 0x5A, 0x58, 0x43, 0x56,0x42, 0x4E, 0x4D, 0x2C, 0x2E, 0x2F, 0x00, 0x2A, 0x00, 0x20, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x37, 0x38, 0x39, 0x2D, 0x34, 0x35, 0x36, 0x2B, 0x31,0x32, 0x33, 0x30, 0x2E,0x00, 0x1B, 0x21, 0x40, 0x23, 0x24, 0x25, 0x5E, 0x26, 0x2A, 0x28, 0x29, 0x5F, 0x2B, 0x08, 0x09, //shift0x51, 0x57, 0x45, 0x52, 0x54, 0x59, 0x55, 0x49, 0x4F, 0x50, 0x7B, 0x7D, 0x0D, 0x00, 0x41, 0x53,0x44, 0x46, 0x47, 0x48, 0x4A, 0x4B, 0x4C, 0x3A, 0x22, 0x7E, 0x00, 0x7C, 0x5A, 0x58, 0x43, 0x56,0x42, 0x4E, 0x4D, 0x3C, 0x3E, 0x3F, 0x00, 0x2A, 0x00, 0x20, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x37, 0x38, 0x39, 0x2D, 0x34, 0x35, 0x36, 0x2B, 0x31,0x32, 0x33, 0x30, 0x2E,0x00, 0x1B, 0x21, 0x40, 0x23, 0x24, 0x25, 0x5E, 0x26, 0x2A, 0x28, 0x29, 0x5F, 0x2B, 0x08, 0x09, //caps + shift0x71, 0x77, 0x65, 0x72, 0x74, 0x79, 0x75, 0x69, 0x6F, 0x70, 0x7B, 0x7D, 0x0D, 0x00, 0x61, 0x73,0x64, 0x66, 0x67, 0x68, 0x6A, 0x6B, 0x6C, 0x3A, 0x22, 0x7E, 0x00, 0x7C, 0x7A, 0x78, 0x63, 0x76,0x62, 0x6E, 0x6D, 0x3C, 0x3E, 0x3F, 0x00, 0x2A, 0x00, 0x20, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x37, 0x38, 0x39, 0x2D, 0x34, 0x35, 0x36, 0x2B, 0x31,0x32, 0x33, 0x30, 0x2E }; typedef struct _DEV_EXT {// 這個結構的大小 ULONG NodeSize;// 過濾設備對象 PDEVICE_OBJECT pFilterDeviceObject;// 綁定的設備對象 PDEVICE_OBJECT TargetDeviceObject;// 綁定前底層設備對象 PDEVICE_OBJECT LowerDeviceObject; } DEV_EXT, *PDEV_EXT;VOID initDevExt(PDEV_EXT pDevExt, PDEVICE_OBJECT pFdo, PDEVICE_OBJECT pTopDev, PDEVICE_OBJECT pKbdDeviceObject) {memset(pDevExt, 0, sizeof(pDevExt));pDevExt->NodeSize = sizeof(pDevExt);pDevExt->LowerDeviceObject = pTopDev;pDevExt->pFilterDeviceObject = pFdo;pDevExt->TargetDeviceObject = pKbdDeviceObject;}NTSTATUS MyAttachDevices(PDRIVER_OBJECT pDriverObject) {NTSTATUS status = STATUS_SUCCESS;PDRIVER_OBJECT kbdDriver = NULL;UNICODE_STRING kbdDriverName;PDEVICE_OBJECT pKbdDeviceObject = NULL;PDEVICE_OBJECT filterDeviceObject = NULL;PDEVICE_OBJECT pTopDev = NULL;PDEV_EXT pDevExt = NULL;//獲取驅動對象RtlInitUnicodeString(&kbdDriverName, KBD_DRIVER_NAME);status = ObReferenceObjectByName(&kbdDriverName, OBJ_CASE_INSENSITIVE, 0, 0, IoDriverObjectType, KernelMode, 0, &kbdDriver);if (status != STATUS_SUCCESS){DbgPrint("獲取驅動對象失敗\n");return status;}else{ObDereferenceObject(pDriverObject);//先解除引用,驅動對象引用計數-1,不影響后面代碼以免忘記//驅動對象的設備對象形成一個鏈表,一個一個生成過濾設備并綁定到它的設備棧棧頂pKbdDeviceObject = kbdDriver->DeviceObject;while (pKbdDeviceObject){status = IoCreateDevice(pDriverObject, sizeof(DEV_EXT), 0, pKbdDeviceObject->DeviceType, pKbdDeviceObject->Characteristics, 0, &filterDeviceObject);if (status != STATUS_SUCCESS){DbgPrint("創建設備失敗\n");return status;}else{pTopDev = IoAttachDeviceToDeviceStack(filterDeviceObject, pKbdDeviceObject);if (!pTopDev){DbgPrint("附加失敗\n");IoDeleteDevice(filterDeviceObject);status = STATUS_UNSUCCESSFUL;return status;}else{//綁定成功后先將實際被綁定的設備對象和驅動對象的設備對象添加到過濾設備的 //拓展對象(自定義的東西方便后續訪問他們)上pDevExt = (PDEV_EXT)filterDeviceObject->DeviceExtension;initDevExt(pDevExt, filterDeviceObject, pTopDev, pKbdDeviceObject);//復制特征filterDeviceObject->DeviceType = pTopDev->DeviceType;filterDeviceObject->Characteristics = pTopDev->Characteristics;filterDeviceObject->StackSize = pTopDev->StackSize + 1;filterDeviceObject->Flags |= pTopDev->Flags & (DO_BUFFERED_IO | DO_DIRECT_IO | DO_POWER_PAGABLE);}}//移動到下一個設備對象pKbdDeviceObject = pKbdDeviceObject->NextDevice;}return STATUS_SUCCESS;} }void __stdcall showKey(USHORT ch) {UCHAR c = 0;int off = 0;if ((ch & 0x80) == 0){if (ch<0x47||((ch>=0x47&&ch<0x54)&&(kb_status&S_NUM))){c = asciiTbl[ch + off];}switch (ch){case 0x3a:kb_status ^= S_CAPS;break;case 0x45:kb_status ^= S_NUM;break;//左shift和右shiftcase 0x2a:case 0x36:kb_status |= S_SHIFT;break;default:break;}}else{if (ch==0xaa||ch==0xb6){kb_status &= ~S_SHIFT;}}if (c>=0x20&&c<0x7f){DbgPrint("%c \n", c);}} NTSTATUS readComplete(PDEVICE_OBJECT pDeviceObject, PIRP pIrp, PVOID context) {//所有的其他代碼都是為這個函數準備的. PIO_STACK_LOCATION pIrpStack;ULONG buf_len = 0;PUCHAR buf = NULL;size_t i, numKeys;PKEYBOARD_INPUT_DATA KeyData;pIrpStack = IoGetCurrentIrpStackLocation(pIrp);if (NT_SUCCESS(pIrp->IoStatus.Status)){//獲取讀取的緩沖區和長度buf = pIrp->AssociatedIrp.SystemBuffer;buf_len = pIrp->IoStatus.Information;// //該緩沖區其實是KEYBOARD_INPUT_DATA結構體,KeyData獲取一個結構體,有numKeys個// //typedef struct _KEYBOARD_INPUT_DATA {// USHORT UnitId;// USHORT MakeCode; //掃描碼// USHORT Flags; //1是按下0是彈起// USHORT Reserved;// ULONG ExtraInformation;//} KEYBOARD_INPUT_DATA, *PKEYBOARD_INPUT_DATA;KeyData = (PKEYBOARD_INPUT_DATA)buf;numKeys = pIrp->IoStatus.Information / sizeof(KEYBOARD_INPUT_DATA);//對這些結構體包含的按鍵信息輸出即掃描碼和鍵是按下還是彈起for ( i = 0; i < numKeys; i++){DbgPrint("numkeys: %d\n", numKeys);DbgPrint("scanf code is %x\n", KeyData->MakeCode);DbgPrint("%s\n", KeyData->Flags ? "up" : "down");showKey(KeyData->MakeCode);//對大寫鎖定鍵進行過濾,替換為ctrlif (KeyData->MakeCode==CAPS_LOCK){KeyData->MakeCode = LCONTROL;}}}keyCount--;if (pIrp->PendingReturned){IoMarkIrpPending(pIrp);}return pIrp->IoStatus.Status; }NTSTATUS MyDisPatcher(PDEVICE_OBJECT pDeviceObject, PIRP pIrp) {//非power,pnp,read類型的irp一律跳過 IoSkipCurrentIrpStackLocation(pIrp);return IoCallDriver(((DEV_EXT*)pDeviceObject->DeviceExtension)->LowerDeviceObject, pIrp); } NTSTATUS MyPowerDisPatcher(PDEVICE_OBJECT pDeviceObject, PIRP pIrp) {//處理powerirp,其實和其他irp一樣只是將power類型irp交給棧下面的設備對象處理 PoStartNextPowerIrp(pIrp);IoSkipCurrentIrpStackLocation(pIrp);return PoCallDriver(((DEV_EXT*)pDeviceObject->DeviceExtension)->LowerDeviceObject,pIrp); } NTSTATUS MyPnpDisPatcher(PDEVICE_OBJECT pDeviceObject, PIRP pIrp) {//處理即插即用,對于大多數即插即用的設備基本都這樣處理就行DEV_EXT* devExt = (DEV_EXT*)pDeviceObject->DeviceExtension;PIO_STACK_LOCATION pIrpStack = IoGetCurrentIrpStackLocation(pIrp);NTSTATUS status = STATUS_SUCCESS;KIRQL oldIrql; //優先級KEVENT event;//設備被移除,插入的時候發生這些副irp消息.直接跳過即可,但是因為移除的時候需要將附加的設備//對象解除綁定并刪除switch (pIrpStack->MinorFunction){case IRP_MN_REMOVE_DEVICE:DbgPrint("鍵盤被移除\n");IoSkipCurrentIrpStackLocation(pIrp);IoCallDriver(devExt->LowerDeviceObject,pIrp); IoDetachDevice(devExt->LowerDeviceObject);IoDeleteDevice(pDeviceObject);status = STATUS_SUCCESS;break;default:IoSkipCurrentIrpStackLocation(pIrp);status = IoCallDriver(devExt->LowerDeviceObject, pIrp);status = STATUS_SUCCESS;break;}return status; }NTSTATUS MyReadDisPatcher(PDEVICE_OBJECT pDeviceObject, PIRP pIrp) {NTSTATUS status =STATUS_SUCCESS ;DEV_EXT* devExt;PIO_STACK_LOCATION pIrpStack;KEVENT waitEvent;KeInitializeEvent(&waitEvent, NotificationEvent, FALSE);if (pIrp->CurrentLocation==1){ULONG returnInformation = 0;DbgPrint("bogus current\n");status = STATUS_INVALID_DEVICE_REQUEST;pIrp->IoStatus.Status = status;pIrp->IoStatus.Information = returnInformation;IoCompleteRequest(pIrp, IO_NO_INCREMENT);return status;}else{//這里處理irp,因為irp從棧頂過來時是有I/O管理器發來的,還未被底層的設備對象處理//所以要先將irp向下發,然后等irp從棧底被寫入鍵盤按鍵信息后再從棧底往上發,這時//就可以截獲irp中的按鍵信息. 怎么截獲呢?通過注冊一個完成例程,因為當irp被處理完//會從底層向上調用他們注冊的完成例程.所以這里需要通過注冊完成例程獲取irp并處理//詳細原理參考:windows內核原理與實現 462頁//這里和跳過其實是一樣的,只是因為需要注冊完成例程而需要調用//函數IoCopyCurrentIrpStackLocationToNext而不是IoSkipCurrentIrpStackLocationkeyCount++;devExt = (DEV_EXT*)pDeviceObject->DeviceExtension;pIrpStack = IoGetCurrentIrpStackLocation(pIrp);IoCopyCurrentIrpStackLocationToNext(pIrp);//注冊完成例程函數IoSetCompletionRoutine(pIrp, readComplete, pDeviceObject, 1, 1, 1);return IoCallDriver(devExt->LowerDeviceObject, pIrp);} } VOID MyDetach(PDEVICE_OBJECT pDeviceObject) {DEV_EXT* devExt = pDeviceObject->DeviceExtension;__try{__try{IoDetachDevice(devExt->TargetDeviceObject);devExt->TargetDeviceObject = 0;IoDeleteDevice(pDeviceObject);devExt->pFilterDeviceObject = 0;DbgPrint("解除綁定\n");}__except(EXCEPTION_EXECUTE_HANDLER){}}__finally{} } VOID UnLoadDriver(PDRIVER_OBJECT pDriverObject) {PDEVICE_OBJECT pDeviceObject, pOldDeivceObject;DEV_EXT devExt;LARGE_INTEGER lDelay;PRKTHREAD CurrentThread;lDelay = RtlConvertLongToLargeInteger(100 * DELAY_ONE_MILLISECOND);//設置時間對象CurrentThread = KeGetCurrentThread();//將優先級降低 KeSetPriorityThread(CurrentThread, LOW_REALTIME_PRIORITY);UNREFERENCED_PARAMETER(pDriverObject);DbgPrint("開始卸載\n");pDeviceObject = pDriverObject->DeviceObject;while (pDeviceObject){MyDetach(pDeviceObject);//解除綁定并刪除pDeviceObject = pDeviceObject->NextDevice;}while (keyCount){KeDelayExecutionThread(KernelMode, FALSE, &lDelay);}DbgPrint("卸載完成!\n");return;} NTSTATUS DriverEntry(PDRIVER_OBJECT pDriverObject, PUNICODE_STRING us) {NTSTATUS status=STATUS_SUCCESS;//設置分發函數,專門處理電源irp,pnp的irp和read的irpULONG i = 0;for (; i < IRP_MJ_MAXIMUM_FUNCTION; i++){pDriverObject->MajorFunction[i] = MyDisPatcher;}pDriverObject->MajorFunction[IRP_MJ_READ] = MyReadDisPatcher;pDriverObject->MajorFunction[IRP_MJ_POWER] = MyPowerDisPatcher;pDriverObject->MajorFunction[IRP_MJ_PNP] = MyPnpDisPatcher;pDriverObject->DriverUnload = UnLoadDriver;MyAttachDevices(pDriverObject);return status; }
?