首页
社区
课程
招聘
[ZT]DLL injection will be restricted in Vista
发表于: 2006-6-16 10:42 5190

[ZT]DLL injection will be restricted in Vista

2006-6-16 10:42
5190
There is an interesting thread in microsoft.public.win32.programmer.kernel

2006-02-17: After some update in this thread, the signing part seems to be wrong…

The question was: “Why is AppInit_DLLs not supported in Vista?”
And the answer is: “It is supported, but your DLL need to be signed!”
This leads me to my other post about required driver signing in Vista x64
But it seems that the signing for AppInit_DLLs are also for x86. Also injecting a DLL via this key after the process has started is not possible anymore.

The second point is: Global hooks will only work within a compatible desktop integrity level. I need to find out what this is…

This information is preliminary and based on the beta version of vista…

[注意]传递专业知识、拓宽行业人脉——看雪讲师团队等你加入!

收藏
免费 0
支持
分享
最新回复 (8)
雪    币: 2319
活跃值: (565)
能力值: (RANK:300 )
在线值:
发帖
回帖
粉丝
2
如果 Signed driver 将来在 32 bit 也推行,那么利用驱动的防破手段很难实现了

想不到现在连 dll 也这样
2006-6-16 11:03
0
雪    币: 207
活跃值: (40)
能力值: ( LV4,RANK:50 )
在线值:
发帖
回帖
粉丝
3
学习
想用内挂的就不要装Vista了
2006-6-16 11:06
0
雪    币: 603
活跃值: (617)
能力值: ( LV12,RANK:660 )
在线值:
发帖
回帖
粉丝
4
上层的限制越来越多,看来必须要往下钻了
2006-6-16 11:55
0
雪    币: 1852
活跃值: (504)
能力值: (RANK:1010 )
在线值:
发帖
回帖
粉丝
5
矛与盾共同发展
2006-6-16 12:28
0
雪    币: 342
活跃值: (323)
能力值: ( LV9,RANK:450 )
在线值:
发帖
回帖
粉丝
6
看来要学习打洞技术了.
2006-6-16 13:56
0
雪    币: 10733
活跃值: (2444)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
7
哈哈Vista 有人研究很久了 只是没人愿意说而已
2006-6-16 15:59
0
雪    币: 215
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
8
好消息啊.
2006-6-16 17:01
0
雪    币: 235
活跃值: (40)
能力值: ( LV8,RANK:130 )
在线值:
发帖
回帖
粉丝
9
最初由 wzmooo 发布
哈哈Vista 有人研究很久了 只是没人愿意说而已


老兄有玄外之音,似乎胸有成竹,希望共享
2006-6-16 20:20
0
游客
登录 | 注册 方可回帖
返回
//