-
-
[求助]获得了system 里的句柄,怎么获得名字
-
发表于:
2010-12-30 13:30
3451
-
[求助]获得了system 里的句柄,怎么获得名字
类似这种
我用zwqueryobject
老报内存出错?
出错代码,谢谢。
if(handle_info->Handles[i].ProcessId == 4)
{
hObject =(HANDLE)handle_info->Handles[i].Handle;
ULONG nSize;
POBJECT_NAME_INFORMATION pObj;
ZwQueryObject( hObject, 1, NULL, 0, &nSize);
pObj = (POBJECT_NAME_INFORMATION) malloc(nSize);
if(ZwQueryObject( hObject, 1, pObj, nSize, &nSize) == 0)
{
pUnicodeString = (UNICODE_STRING *)pObj ;
printf( "Name:%ws 0x%x\n", pUnicodeString->Buffer, handle_info->Handles[i].Handle);
}
}
[课程]Android-CTF解题方法汇总!