Is there an easy way to get the real return address inside a madCodeHook hook function?
Some times it's nice to know this inside a hook so you can have the hook do different opperations depending on what function (inside the target app) called it.
I could sort of get it in a hacked way by just adding the right offset to the ESP on entry.
I guess I can make ASM stub for the hook and call a C funtion from inside of it..
Hmmm... Well... This is not really possible right now. The problem is that madCodeHook's safe unhooking automatic more or less obfuscates the return address. That's why there is a "GetCallingModule" API in madCodeHook. There's no "GetCallingFunction" or "GetReturnAddress" API yet, though.