°Ù¶È¿Õ¼ä | °Ù¶ÈÊ×Ò³ 
 
ÎÄÕÂÁбí
 
ÄúÕýÔڲ鿴 "windowsÄÚºË̽Ë÷" ·ÖÀàϵÄÎÄÕÂ

2009-08-04 16:06
ring0²»µ÷apiͽÊÖÉèÖÃÓ²¼þ¶Ïµã
by flyingkisser
09.2.12
ʱ¼ä±È½ÏÓÐÏÞ£¬¼ñ¹Ø¼üµÄ˵˵

1.ÈçºÎдdr0,dr7£¬Ò»°ãÓÃNtSetContextThread£¬
ΪÁ˲»µ÷API£¬Õâ¸öÎÊÌâ¾Í³ÉÁËÈçºÎ¶¨Î»µ½Ö¸¶¨Ï̵߳Äcontext£¬°ì·¨ÊÇ£º
ÏÈÓÉtidÄõ½ethread
kthread.InitialStack-29ch¾ÍÊÇ£¬Èç¹ûÕâ¸öµØÖ·ÎÞЧ£¬¾ÍʹÓÃethread->TrapFrame
ÕâʱÄõ½µÄµØÖ·Ö¸Ïò½á¹¹KTRAP_FRAME£¬ÐÞ¸ÄËü¶ÔÓ¦µÄdrx¾ÍÐÐÁË¡£
ΪʲôÊÇ_KTHREAD.InitialStack-29ch£¬×Ô¼ºÄæÏòÒ»ÏÂPspGetSetContextSpecialApc¾ÍÖªµÀÁË¡£
xpÏÂÊÇ29ch,Æä
Àà±ð£ºwindowsÄÚºË̽Ë÷ | ÆÀÂÛ(4) | ä¯ÀÀ()
 
2009-03-02 23:34
typedef struct _SYSTEM_SERVICE_TABLE
{
    PNTPROC    ServiceTable ;    // array of entry points
    PULONG    CounterTable ;    // array of usage counters . be NULL
    ULONG    ServiceLimit ;    // number of table entries
    UCHAR*  
Àà±ð£ºwindowsÄÚºË̽Ë÷ | ÆÀÂÛ(1) | ä¯ÀÀ()
 
2009-02-26 12:45
Á´½Ó£º http://www.pediy.com/document/Windows_System_Call_Table/Windows_System_Call_Table.htm

Õâ¸ö±íËäȻûÓм°Ê±¸üУ¬µ«ÊÇÒÀÈ»ºÜÇ¿´ó¡£
Àà±ð£ºwindowsÄÚºË̽Ë÷ | ÆÀÂÛ(0) | ä¯ÀÀ()
 
2009-01-08 09:21
ÄÚºËdll,ÈçÏÂͼËùʾ:

ÈçͼÖеÄhookhelp.dll¾ÍÊÇÒ»¸öÄÚºËdll,¸úËûÏà¹ØÁªµÄ£¬ÊǼ¸¸öÄÚºËÎļþ¡£¶ø²»ÊÇntdllµÈ¡£

½ÓÏÂÀ´ÎÒÃÇÓÃRadasm×Ô¼º½¨Ò»¸öÕâÑùµÄdll¡£²½ÖèÈçÏ£º

1. ÓÃRadasmÏòµ¼½¨Á¢Ò»¸ö¿ÕµÄDriver(.sys)¹¤³Ì¡£
2. ÓÃpublicÉùÃ÷Òªµ¼³öµÄdllº¯Êý
3. ÔÚ¹¤³ÌÖÐÌí¼ÓÒ»¸ö.defÎļþ
     Õâ¸ö.defÎļþµÄ¸ñʽ¸úÎÒÃÇÔÚrin
Àà±ð£ºwindowsÄÚºË̽Ë÷ | ÆÀÂÛ(7) | ä¯ÀÀ()
 
2008-12-10 20:19

Ò»Ö±ÒÔÀ´£¬¶¼±È½ÏÀÁ£¬Ï²»¶ÓÃsyser»òÕßsofticeµ÷ÊÔ³ÌÐò¡£µ«ÊÇËæ×ÅwindbgµÄÇ¿´ó£¬ÒÔ¼°¶Ôwindows¸ß¶ÈµÄ¼æÈÝÐÔ£¬»¹ÊÇѧϰѧϰ°É¡£Ä¿Ç°Éî¶ÈµÄwindowsϵͳϰ²×°softiceºÍsyser¶¼»áÔì³É»úÆ÷ËÀµô¼°À¶ÆÁ¡£Ò²Ö»ÓÐwindbgºÃÓá£ÍøÉÏËÑÁËÏ£¬ÕûÀíÁËϾßÌå²½Öè¡£

²½Ö裺

1. ÏÂÔØhttp://msdl.microsoft.com/download/symbols/packages/windowsxp/WindowsXP-KB936929-SP3-x86-symbols-full-ENU.ex

Àà±ð£ºwindowsÄÚºË̽Ë÷ | ÆÀÂÛ(1) | ä¯ÀÀ()
 
2008-11-07 11:24
£¨ÓÉÓÚ°Ù¶ÈÎÄÕÂ×ÖÊýÏÞÖÆ£¬ÕâÀïÖ»ºÃ·Ö³ÉÉÏÏÂÆªÁË¡£ºÇºÇ£©
ÆäºóÃæ»¹Òþ²Ø×źܶàÐÅÏ¢¡£
KdVersionBlock ¶ÔÓ¦µÄ½á¹¹ÌåÓ¦¸ÃÊÇKDDEBUGGER_DATA32

DBGKD_DEBUG_DATA_HEADER32 STRUCT
    List        LIST_ENTRY    <> 
Àà±ð£ºwindowsÄÚºË̽Ë÷ | ÆÀÂÛ(2) | ä¯ÀÀ()
 
2008-11-07 11:23
Windows XPºÍWindows 2003ÒýÈëÁËÒ»¸öÐÂÄں˱äÁ¿£ºKdVersionBlock£¬ KdVersionBlockÊÇKPCRµÄÒ»¸ö³ÉÔ±¡£ KdVersionBlockÊÇλÓÚffdff034λÖã¬ÈçÏ£º
lkd> dt _kpcr ffdff000
nt!_KPCR
   +0x000 NtTib            : _NT_TIB
   +0x01c SelfPcr          : 0xffdff000 _KPCR
   +0x020 Prcb     
Àà±ð£ºwindowsÄÚºË̽Ë÷ | ÆÀÂÛ(1) | ä¯ÀÀ()
 
2008-10-28 14:50
SCSIÖ¸Áî¶¼ÊÇÒÔÖ¸ÁîÃèÊö¿é(CDB£¬Command descriptor block)µÄ¸ñʽÀ´±íʾ£¬ÆäÓõ½µÄ½á¹¹ÌåÈçÏ£º
typedef struct _SCSI_PASS_THROUGH_DIRECT
    {
        USHORT Length;            +0
        UCHAR ScsiStatus;         +2
      
Àà±ð£ºwindowsÄÚºË̽Ë÷ | ÆÀÂÛ(2) | ä¯ÀÀ()
 
2008-10-23 13:45

ÔÚÄÚºËÖÐÎÒÃǽøÐÐÎļþ²Ù×÷£¬¿ÉÒÔʹÓÃIoCreateFileÒ²¿ÉÒÔÓÃZwCreateFile¡£ µ«¾¿¾¹ÕâÁ½ÕßÓÐʲô²î±ðÄØ£¿ÏÂÃæÊÇÕâÁ½¸öº¯ÊýµÄ¸ñʽÈçÏ£º
NTSTATUS
IoCreateFile(
OUT PHANDLE
FileHandle,
IN ACCESS_MASK
DesiredAccess,
IN POB
Àà±ð£ºwindowsÄÚºË̽Ë÷ | ÆÀÂÛ(4) | ä¯ÀÀ()
 
2008-08-14 00:29
Òì²½¹ý³Ìµ÷ÓÃ(APCs) ÊÇNTÒì²½´¦ÀíÌåϵ½á¹¹ÖеÄÒ»¸ö»ù´¡²¿·Ö£¬Àí½âÁËËü£¬¶ÔÓÚÁ˽âNTÔõÑù²Ù×÷ºÍÖ´Ðм¸¸öºËÐĵÄϵͳ²Ù×÷ºÜÓаïÖú¡£

1) APCsÔÊÐíÓû§³ÌÐòºÍϵͳԪ¼þÔÚÒ»¸ö½ø³ÌµÄµØÖ·¿Õ¼äÄÚij¸öÏ̵߳ÄÉÏÏÂÎÄÖÐÖ´ÐдúÂë¡£
2) I/O¹ÜÀíÆ÷ʹÓÃAPCsÀ´Íê³ÉÒ»¸öÏ̷߳¢ÆðµÄÒì²½µÄI/O²Ù×÷¡£ÀýÈ磺µ±Ò»¸öÉ豸Çý¶¯µ÷ÓÃIoCompleteRequestÀ´Í¨ÖªI/O¹ÜÀíÆ÷£¬ËüÒѾ­½áÊø´¦ÀíÒ»¸öÒì²½I/OÇëÇóʱ£¬I/O¹ÜÀíÆ÷ÅŶÓÒ»¸öapcµ½·¢ÆðÇëÇóµÄÏ̡߳£È»ºóÏß³ÌÔÚÒ»¸ö½ÏµÍIRQL¼¶±ð£¬À´Ö´ÐÐAPC. APCµÄ×÷ÓÃÊÇ´Óϵͳ¿Õ¼ä¿½±´I/O²Ù×÷½á¹ûºÍ״̬ÐÅÏ¢µ½Ïß³ÌÐéÄâÄÚ´æ¿Õ
Àà±ð£ºwindowsÄÚºË̽Ë÷ | ÆÀÂÛ(12) | ä¯ÀÀ()
 
     
 
 
ÎÄÕ·ÖÀà
 
     
 
ÎÄÕ´浵
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
     
 
×îÐÂÎÄÕÂÆÀÂÛ
   

ºÃÎİ¡·Ç³£ÏêϸµÄ½²½â¡£
 

ºÃÎÄÕ £¬»¹ÆÚ´ýÄãµÄÊéÄØµÈÁ˺þÃһֱûµÈ´ýÒ»ÄêÁË¡£
 
 
 

¸ú׎̳ÌѧC лл¥Ö÷дÕâôºÃµÄ½Ì³Ì
 
     


©2009 Baidu