![]() |
|
#11
|
|||
|
|||
|
Quote:
message sended to the device (ioctl code = 1800h). It gets some procedures addresses from ntoskrnl: -PsGetCurrentProcessId -IoGetCurrentProcess -Ke386IoSetAccessProcess -ObReferenceObjectByHandle -PsProcessType -Ke386SetIoAccessMap Saves vector 1 and 3 of IDT. Changes the access flags of some blocks of memory allocated at runtime and IDT page from super-visor to user-mode. The ioctl 1800h returns some data in the 50h chars long buffer, including locations of those allocated memory blocks. Besides of other to-study-or-not-facts.... There are other ioctls parsed with id: 1801,1802,1A00. Making some memory shared between the device and the exe is an open door to lotsa things I guess... gotta do more tracing later
|
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Turbo Attack | UnknwnGaming | Source Code | 2 | 11-20-2022 01:18 |
| known-plaintext attack | eychei | General Discussion | 6 | 04-08-2018 06:03 |
| RC4 Attack | DARKER | General Discussion | 1 | 02-27-2015 02:44 |
| Zip Plaintext Attack Query | Numega Softice | General Discussion | 1 | 03-26-2004 01:30 |