首页
社区
课程
招聘
[旧帖] [求助]ObOpenObjectByPointer地址 0.00雪花
发表于: 2009-6-8 23:16 1324

[旧帖] [求助]ObOpenObjectByPointer地址 0.00雪花

2009-6-8 23:16
1324
MmGetSystemRoutineAddress能得到吗?

[课程]Android-CTF解题方法汇总!

收藏
免费 0
支持
分享
最新回复 (3)
雪    币: 150
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
2
RtlInitUnicodeString(&ObOpen_Name, L"ObOpenObjectByPointer");
AddrObOpen = (ULONG)MmGetSystemRoutineAddress(&ObOpen_Name);

可以吗?
2009-7-30 20:54
0
雪    币: 360
活跃值: (77)
能力值: ( LV9,RANK:250 )
在线值:
发帖
回帖
粉丝
3
MmGetSystemRoutineAddress is available on Windows 2000 and later.
Drivers can use this routine to determine if a routine is available on a specific version of Windows. It can only be used for routines exported by the kernel or HAL, not for any driver-defined routine.
This routine can only be called at IRQL = PASSIVE_LEVEL.
2009-7-30 22:31
0
雪    币: 150
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
4
ObOpenObjectByPointer导出了吧~~是不是可以得到?
2009-7-30 22:57
0
游客
登录 | 注册 方可回帖
返回
//