随笔分类 - Win32
摘要:Chapter 6 I/O system Driver objects and device objects Experiment: Looking at device objects 1 !object \Device 2 !drvobj 3 !devobj 4 !process 0 0 dwm.
阅读全文
摘要:!idt dps nt!KeServiceDescriptorTable dds KiServiceTable dq KiServiceTable ln poi(KiServiceTable + 102 * 4) Hook SSDT(Shadow) Hooking the System Servic
阅读全文
摘要:$user - Display a structure with account information for the account running the application. For security reasons, the password information is not di
阅读全文
摘要:An asynchronous procedure call (APC) is a function that executes asynchronously in the context of a particular thread. QueueUserAPC A thread enters an
阅读全文
摘要:本文介绍Windows设备管理领域,重点讨论SetupDiXXX一族API的细节。 Devguid.h定义了经典设备的类GUID ,形如:GUID_DEVCLASS_Xxx 例: GUID_DEVCLASS_PRINTQUEUE 计算机\HKEY_LOCAL_MACHINE\SYSTEM\Curre
阅读全文
摘要:“类视图”和“对象浏览器”图标 VS2017调试小技巧 $ADDRESS Current instruction $CALLER Calling function name $CALLSTACK Call stack $FUNCTION Current function name $PID Proc
阅读全文