能力值:
( LV9,RANK:610 )
|
-
-
2 楼
自己把Win10的内核文件加上符号扔到IDA里一目了然吧?
|
能力值:
( LV12,RANK:760 )
|
-
-
3 楼
typedef LONG32 (NEAR CDECL FUNCT_0091_1820_ParseProcedure) (VOID*, VOID*, struct _ACCESS_STATE*, CHAR, ULONG32, struct _UNICODE_STRING*, struct _UNICODE_STRING*, VOID*, struct _SECURITY_QUALITY_OF_SERVICE*, VOID**); typedef LONG32 (NEAR CDECL FUNCT_0091_182C_ParseProcedureEx) (VOID*, VOID*, struct _ACCESS_STATE*, CHAR, ULONG32, struct _UNICODE_STRING*, struct _UNICODE_STRING*, VOID*, struct _SECURITY_QUALITY_OF_SERVICE*, struct _OB_EXTENDED_PARSE_PARAMETERS*, VOID**);
Win10 15063上Parse过程是union模式,有2种函数形态。由ObjectTypeFlag中的UseExtendedParameters来决定是否使用Ex
|
|
|