发新话题
打印

[转载]Defeating Kernel Native API Hookers by Direct KiServiceTable Restoration

[转载]Defeating Kernel Native API Hookers by Direct KiServiceTable Restoration

Defeating Kernel Native API Hookers by Direct KiServiceTable Restoration

文章作者:Tan Chew Keong
信息来源:邪恶八进制信息安全团队(www.eviloctal.com

--[ Table of contents

• User-space API calls and Native APIs
• Redirecting the execution path of Native APIs
• Locating and restoring the KiServiceTable
• Defeating Native API hooking rootkits and security tools.

Win2K Kernel Hidden Process Module Checker 0.1

附件

Defeating Kernel Native API Hookers by Direct KiServiceTable Restoration.rar (569 KB)

2008-1-23 14:05, 下载次数: 53352

Delphiscn Blog
http://blog.csdn.net/delphiscn

TOP

好文, 和SDTrestore有点儿像.用的就是90210的方法呀:lol
WINDOWS内核疯狂爱好者

TOP

发新话题