首页
社区
课程
招聘
[原创]Antirootkit: CodeWalker
发表于: 2008-12-12 15:02 25169

[原创]Antirootkit: CodeWalker

2008-12-12 15:02
25169
收藏
免费
支持
分享
最新回复 (75)
雪    币: 200
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
76

I just made an example like redirecting ntoskrnl.exe to cmd.exe
in fact i just use memory dump of the ntoskrnl.exe(i hooked) to xxx.exe
and redirect ntoskrnl.exe to xxx.exe

then the image in memory and on disk are the same.


Ah, I see :) Then this is the weakness of mismatch detection algorithm. I'll improve and make a fix. Thanks vxk ;)
2008-12-15 12:17
0
游客
登录 | 注册 方可回帖
返回

账号登录
验证码登录

忘记密码?
没有账号?立即免费注册