-
-
[求助]R0中HOOK读写内存句柄转换问题
-
发表于:
2014-3-9 11:06
4593
-
NtReadVirtualMemory(
IN HANDLE ProcessHandle,
IN PVOID BaseAddress,
OUT PVOID Buffer,
IN ULONG BufferLength,
OUT PULONG ReturnLength OPTIONAL)
判断目标ProcessHandle的PID是否等于要保护的
我用
PROCESS_BASIC_INFORMATION pbi;
ns = ZwQueryInformationProcess(ProcessHandle, ProcessBasicInformation, (PVOID)&pbi, sizeof(ProcessBasicInformation), NULL);
pid = pbi.UniqueProcessId;
转换 结果不对 都是负数了
请教用什么方法把ProcessHandle转成PID呢
[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)