-
-
[求助]R0中HOOK读写内存句柄转换问题
-
发表于:
2014-3-9 11:06
4592
-
NtReadVirtualMemory(
IN HANDLE ProcessHandle,
IN PVOID BaseAddress,
OUT PVOID Buffer,
IN ULONG BufferLength,
OUT PULONG ReturnLength OPTIONAL)
判断目标ProcessHandle的PID是否等于要保护的
我用
PROCESS_BASIC_INFORMATION pbi;
ns = ZwQueryInformationProcess(ProcessHandle, ProcessBasicInformation, (PVOID)&pbi, sizeof(ProcessBasicInformation), NULL);
pid = pbi.UniqueProcessId;
转换 结果不对 都是负数了
请教用什么方法把ProcessHandle转成PID呢
[注意]传递专业知识、拓宽行业人脉——看雪讲师团队等你加入!