OldFuncAddr = getOldFunAddress();MyFuncAddr =(ULONG)NewZwQuerySystemInformation;*((ULONG*)(hook_code+1)) = (ULONG)MyFuncAddr - ((ULONG)OldFu...
全文
回复(1) 2010-06-26 01:04 来自版块 - 内核编程
表情
anlinkong应该计算的是偏移,后面应该是jmp语句吧(2010-06-26 18:15)

返回顶部