![]() |
|
#1
|
|||
|
|||
|
Dumping protected memory?
Hi folks,
i have done a small loader which loads a process and changed the access flags via VirtualProtectEx() but if i try to read memory of the loaded process i got an error (can't remember which one). I know that some protections set the NO_ACCESS or PAGE_GUARD flags on creation of memory so is there a way to circumvent this? maybe with a kernel driver? or is there another way under ring3? thx for help tr1stan |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Question regarding .NET dumping | 0x22 | General Discussion | 3 | 08-23-2014 16:37 |
| Dumping protected DLL 'perplex' data section | grimm | General Discussion | 4 | 02-28-2005 08:19 |
| Dumping Armadillo protected DLL? | FEARHQ | General Discussion | 10 | 02-09-2005 11:08 |
| Dumping | sfld | General Discussion | 2 | 03-20-2004 23:56 |
| Dumping a dll with ollydump | ceK52z | General Discussion | 6 | 02-08-2004 19:39 |