Nouk
驱动中牛
驱动中牛
  • 注册日期2001-08-22
  • 最后登录2006-10-22
  • 粉丝0
  • 关注0
  • 积分0分
  • 威望0点
  • 贡献值0点
  • 好评度0点
  • 原创分0分
  • 专家分0分
阅读:1033回复:0

Anti-API Hook and App can access > 2GB address?

楼主#
更多 发布于:2002-07-31 13:02
1.Anti-API Hook.
1.1.CreateRemoteThread
I can chk the thread numbers and TLS Value.
1.2.IAT redirect on-the-fly.
I can compare my IAT with function address using dynamic load.
1.3.DLL Injection.(It\'s global way.)
Inject the \"int 3\" or \"jxx mem.\".
I don\'t know how to detect it,can anyone give me the concepts?
2.The PE Header have the flags that is \"access > 2GB address\",can app set the flag to do it?
Thx a lot.





Taiwan's Driver Developer
游客

返回顶部