-
-
[讨论]shadow请教
-
发表于:
2011-4-28 20:02
3866
-
NTSTATUS ZwDuplicateObject(
IN HANDLE SourceProcessHandle,
IN PHANDLE SourceHandle, IN HANDLE TargetProcessHandle,
OUT PHANDLE TargetHandle,
IN ACCESS_MASK DesiredAccess OPTIONAL,
IN BOOLEAN InheritHandle,
IN ULONG Options );
if (NT_SUCCESS(ZwDuplicateObject(Process,
(HANDLE)Handles->Information[r].Handle,NtCurrentProcess(), &hObject, 0, 0, DUPLICATE_SAME_ACCESS)))
这个是原创抄过来的,HANDLE 与 PHANDLE他是怎么通过编译的
[课程]FART 脱壳王!加量不加价!FART作者讲授!