-
-
函数地址与SSDT索引的关系,以nt!NtFlushKey为例
-
发表于:
2017-4-2 16:26
2881
-
函数地址与SSDT索引的关系,以nt!NtFlushKey为例
1 kd> dps 83e9443c L192
83e9443c 8408ffbf nt!NtAcceptConnectPort
83e94634 83ff5b06 nt!NtFlushKey
(83ff5b06-8408ffbf)/4 = 0x7E
2 pNtFlushKeyFuncAddr = 0xa6444dc8
kd> u 0xa6444dc8
a6444dc8 b87e000000 mov eax, 7Eh
a6444dcd ba0003fe7f mov edx, offset SharedUserData!SystemCallStub(7ffe0300)
a6444dd2 ff12 call dword ptr[edx]
3 (PUCHAR)pNtFlushKeyFuncAddr++;
kd> dd a6444dc9
a6444dc9 0000007e fe0300ba c212ff7f b8900004
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课