-
-
[讨论]访问win32k.sys 这样可以不!
-
发表于:
2011-12-15 01:30
4708
-
lkd> !process 0 0
**** NT ACTIVE PROCESS DUMP ****
PROCESS 8a5aca00 SessionId: 0 Cid: 0004 Peb: 00000000 ParentCid: 0000
DirBase: 0ac00020 ObjectTable: e1003e68 HandleCount: 218.
Image: System
PROCESS 8a1dd790 SessionId: none Cid: 0254 Peb: 7ffda000 ParentCid: 0004
DirBase: 0ac00040 ObjectTable: e17332b8 HandleCount: 17.
Image: smss.exe
PROCESS 8a15b698 SessionId: 0 Cid: 02e4 Peb: 7ffdc000 ParentCid: 0254
DirBase: 0ac00060 ObjectTable: e1aa2c30 HandleCount: 289.
Image: csrss.exe
PROCESS 8a15a698 SessionId: 0 Cid: 033c Peb: 7ffd3000 ParentCid: 0254
DirBase: 0ac00080 ObjectTable: e1a90e20 HandleCount: 300.
Image: winlogon.exe
PROCESS 8a089790 SessionId: 0 Cid: 03b0 Peb: 7ffd8000 ParentCid: 033c
DirBase: 0ac000a0 ObjectTable: e21503b8 HandleCount: 230.
Image: services.exe
我改了 System 进程的!SessionId:0
这样改了可以不需要GUI 线程就可以访问 win32k.sys吗???
[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)