Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 01-07-2005, 20:35
LAVA
 
Posts: n/a
Question Tracking file activities

It seems that tracking file activities on win NT family, is not such an easy task to do. I've used API spying techniques to do that, but I can't track activities made by CreateFileMapping and MapViewOfFile functions. Just ReadFile WriteFile and their family can be tracked using API Spying techniques.

Please help me.
Reply With Quote
  #2  
Old 01-07-2005, 23:00
WhoCares's Avatar
WhoCares WhoCares is offline
who cares
 
Join Date: Jan 2002
Location: Here
Posts: 468
Rept. Given: 11
Rept. Rcvd 32 Times in 25 Posts
Thanks Given: 69
Thanks Rcvd at 247 Times in 94 Posts
WhoCares Reputation: 32
the best solution is to write a file system filter driver, but it's a pain for most ppl to do this. You can refer to OSR web site(www.osr.com) and the leaked Microsoft IFS kit, and FileMon source code.
__________________
AKA Solomon/blowfish.
Reply With Quote
  #3  
Old 01-08-2005, 01:26
killy
 
Posts: n/a
imo get a debugger(preffered ollydbg) look at the api calls,make a olly script to log details.
Reply With Quote
  #4  
Old 01-10-2005, 23:21
LAVA
 
Posts: n/a
Killy it's all about writing a program not just using tools like FileMon
Reply With Quote
  #5  
Old 01-11-2005, 02:48
zzsx
 
Posts: n/a
Maybe you can try strace for NT. I have not used it personaly and was told it is a quite reliable API log application.
Reply With Quote
  #6  
Old 01-11-2005, 03:38
dyn!o's Avatar
dyn!o dyn!o is offline
Friend
 
Join Date: Nov 2003
Location: Own mind
Posts: 214
Rept. Given: 1
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 8
Thanks Rcvd at 0 Times in 0 Posts
dyn!o Reputation: 1
Guys, this thread should end with the second topic.

What are you looking for if you can get FileMon with sources? (it includes NT based source too) It is the best tool and it has been made by "the masters of drivers", so just get it and you will own "a bible".

By the way: I encountered similar challenge as you, but 2 years ago and I should tell you that in my humble opinion "API spying techniques" are not the way... (you will understand it after analysing FileMon structure - of course get source first).

Good luck.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Media Descriptor File (MDF/MDS) file format NimDa2k General Discussion 0 03-22-2009 16:49


All times are GMT +8. The time now is 19:31.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )