ÄúÕýÔڲ鿴 "windowsÄÚºË̽Ë÷" ·ÖÀàϵÄÎÄÕÂ
2009-08-04 16:06
ring0²»µ÷apiͽÊÖÉèÖÃÓ²¼þ¶Ïµã
by flyingkisser
09.2.12
ʱ¼ä±È½ÏÓÐÏÞ£¬¼ñ¹Ø¼üµÄ˵˵
1.ÈçºÎдdr0,dr7£¬Ò»°ãÓÃNtSetContextThread£¬
ΪÁ˲»µ÷API£¬Õâ¸öÎÊÌâ¾Í³ÉÁËÈçºÎ¶¨Î»µ½Ö¸¶¨Ï̵߳Äcontext£¬°ì·¨ÊÇ£º
ÏÈÓÉtidÄõ½ethread
kthread.InitialStack-29ch¾ÍÊÇ£¬Èç¹ûÕâ¸öµØÖ·ÎÞЧ£¬¾ÍʹÓÃethread->TrapFrame
ÕâʱÄõ½µÄµØÖ·Ö¸Ïò½á¹¹KTRAP_FRAME£¬ÐÞ¸ÄËü¶ÔÓ¦µÄdrx¾ÍÐÐÁË¡£
ΪʲôÊÇ_KTHREAD.InitialStack-29ch£¬×Ô¼ºÄæÏòÒ»ÏÂPspGetSetContextSpecialApc¾ÍÖªµÀÁË¡£
xpÏÂÊÇ29ch,Æä |
2009-03-02 23:34
typedef struct _SYSTEM_SERVICE_TABLE
{
PNTPROC ServiceTable ; // array of entry points
PULONG CounterTable ; // array of usage counters . be NULL
ULONG ServiceLimit ; // number of table entries
UCHAR* |
2009-02-26 12:45
2009-01-08 09:21
ÄÚºËdll,ÈçÏÂͼËùʾ:
ÈçͼÖеÄhookhelp.dll¾ÍÊÇÒ»¸öÄÚºËdll,¸úËûÏà¹ØÁªµÄ£¬ÊǼ¸¸öÄÚºËÎļþ¡£¶ø²»ÊÇntdllµÈ¡£
½ÓÏÂÀ´ÎÒÃÇÓÃRadasm×Ô¼º½¨Ò»¸öÕâÑùµÄdll¡£²½ÖèÈçÏ£º
1. ÓÃRadasmÏòµ¼½¨Á¢Ò»¸ö¿ÕµÄDriver(.sys)¹¤³Ì¡£
2. ÓÃpublicÉùÃ÷Òªµ¼³öµÄdllº¯Êý
3. ÔÚ¹¤³ÌÖÐÌí¼ÓÒ»¸ö.defÎļþ
Õâ¸ö.defÎļþµÄ¸ñʽ¸úÎÒÃÇÔÚrin |
2008-12-10 20:19
2008-11-07 11:24
£¨ÓÉÓÚ°Ù¶ÈÎÄÕÂ×ÖÊýÏÞÖÆ£¬ÕâÀïÖ»ºÃ·Ö³ÉÉÏÏÂÆªÁË¡£ºÇºÇ£©
ÆäºóÃæ»¹Òþ²Ø×źܶàÐÅÏ¢¡£KdVersionBlock ¶ÔÓ¦µÄ½á¹¹ÌåÓ¦¸ÃÊÇKDDEBUGGER_DATA32
DBGKD_DEBUG_DATA_HEADER32 STRUCT
List LIST_ENTRY <> |
2008-11-07 11:23
Windows XPºÍWindows 2003ÒýÈëÁËÒ»¸öÐÂÄں˱äÁ¿£ºKdVersionBlock£¬ KdVersionBlockÊÇKPCRµÄÒ»¸ö³ÉÔ±¡£ KdVersionBlockÊÇλÓÚffdff034λÖã¬ÈçÏ£º
lkd> dt _kpcr ffdff000
nt!_KPCR
+0x000 NtTib : _NT_TIB
+0x01c SelfPcr : 0xffdff000 _KPCR
+0x020 Prcb |
2008-10-28 14:50
SCSIÖ¸Áî¶¼ÊÇÒÔÖ¸ÁîÃèÊö¿é(CDB£¬Command descriptor block)µÄ¸ñʽÀ´±íʾ£¬ÆäÓõ½µÄ½á¹¹ÌåÈçÏ£º
typedef struct _SCSI_PASS_THROUGH_DIRECT
{
USHORT Length; +0
UCHAR ScsiStatus; +2
|
2008-10-23 13:45
ÔÚÄÚºËÖÐÎÒÃǽøÐÐÎļþ²Ù×÷£¬¿ÉÒÔʹÓà IoCreateFileÒ²¿ÉÒÔÓà ZwCreateFile¡£ µ«¾¿¾¹ÕâÁ½ÕßÓÐʲô²î±ðÄØ£¿ÏÂÃæÊÇÕâÁ½¸öº¯ÊýµÄ¸ñʽÈçÏ£º
|
2008-08-14 00:29
Òì²½¹ý³Ìµ÷ÓÃ(APCs) ÊÇNTÒì²½´¦ÀíÌåϵ½á¹¹ÖеÄÒ»¸ö»ù´¡²¿·Ö£¬Àí½âÁËËü£¬¶ÔÓÚÁ˽âNTÔõÑù²Ù×÷ºÍÖ´Ðм¸¸öºËÐĵÄϵͳ²Ù×÷ºÜÓаïÖú¡£
1) APCsÔÊÐíÓû§³ÌÐòºÍϵͳԪ¼þÔÚÒ»¸ö½ø³ÌµÄµØÖ·¿Õ¼äÄÚij¸öÏ̵߳ÄÉÏÏÂÎÄÖÐÖ´ÐдúÂë¡£
2) I/O¹ÜÀíÆ÷ʹÓÃAPCsÀ´Íê³ÉÒ»¸öÏ̷߳¢ÆðµÄÒì²½µÄI/O²Ù×÷¡£ÀýÈ磺µ±Ò»¸öÉ豸Çý¶¯µ÷ÓÃIoCompleteRequestÀ´Í¨ÖªI/O¹ÜÀíÆ÷£¬ËüÒѾ½áÊø´¦ÀíÒ»¸öÒì²½I/OÇëÇóʱ£¬I/O¹ÜÀíÆ÷ÅŶÓÒ»¸öapcµ½·¢ÆðÇëÇóµÄÏ̡߳£È»ºóÏß³ÌÔÚÒ»¸ö½ÏµÍIRQL¼¶±ð£¬À´Ö´ÐÐAPC. APCµÄ×÷ÓÃÊÇ´Óϵͳ¿Õ¼ä¿½±´I/O²Ù×÷½á¹ûºÍ״̬ÐÅÏ¢µ½Ïß³ÌÐéÄâÄÚ´æ¿Õ |
|
|