登录
首页 » Process-Thread » Many people are aware of the process to port a free map of Fport FoundStone tool...

Many people are aware of the process to port a free map of Fport FoundStone tool...

于 2022-02-05 发布 文件大小:137.87 kB
0 102
下载积分: 2 下载次数: 1

代码说明:

很多人都知道端口到进程映射的一个免费工具FoundStone的Fport,可惜他不提供源码,我试着能从其二进制文件中找出一些信息,大致知道他使用了些未公开函数,诸如: ZwOpenSection,ZwQuerySystemInformation-Many people are aware of the process to port a free map of Fport FoundStone tool, but he does not provide source code, I tried from its binary documents to find some information, he is generally aware of the use of some functions not open to the public, such as : ZwOpenSection, ZwQuerySystemInformation

下载说明:请别用迅雷下载,失败请重下,重下不扣分!

发表评论

0 个回复

  • 一个可以方便地在Delphi下进行多线程编程的控件。很好用的。...
    一个可以方便地在Delphi下进行多线程编程的控件。很好用的。-a convenient in Delphi under multithreaded programming controls. Very good use.
    2022-03-18 11:06:30下载
    积分:1
  • LU decomposition of the serial algorithm (for Cache Optimization), LU decomposit...
    LU分解的串行算法(进行Cache优化),LU分解的多线程实现并行化。-LU decomposition of the serial algorithm (for Cache Optimization), LU decomposition of multi-threaded parallel.
    2022-08-23 12:55:14下载
    积分:1
  • the NT environment hidden process, the user is unaware of the conditions, the im...
    在NT环境下隐藏进程,也就是说在用户不知情的条件下,执行自己的代码的方法有很多种,比如说使用注 册表插入DLL,使用Windows挂钩等等。其中比较有代表性的是Jeffrey Richer在《Windows核心编程》中 介绍的LoadLibrary方法和罗云彬在《Windows环境下32位汇编语言程序设计》中介绍的方法。两种方法的 共同特点是:都采用远程线程,让自己的代码作为宿主进程的线程在宿主进程的地址空间中执行,从而达 到隐藏的目的。相比较而言,Richer的方法由于可以使用c/c++等高级语言完成,理解和实现都比较容易 ,但他让宿主进程使用LoadLibrary来装入新的DLL,所以难免留下蛛丝马迹,隐藏效果并不十分完美。罗 云彬的方法在隐藏效果上绝对一流,不过,由于他使用的是汇编语言,实现起来比较难(起码我写不了汇 编程序:))。笔者下面介绍的方法可以说是对上述两种方法的综合:采用c/c++编码,实现完全隐藏。并 且,笔者的方法极大的简化了远程线程代码的编写,使其编写难度与普通程序基本一致。-the NT environment hidden process, the user is unaware of the conditions, the implementation of their code There are various ways, for instance, the use of the registry into DLL, etc. linked to the use of Windows. The more representative Jeffrey Richer is the "core Windows programming" introduced by the LoadLibrary method and the Luo Bin, "under Windows 32 assembly language programming" introduced by the method. Two methods are common features are : remote threads are used to keep the code as host process threads in t
    2022-03-23 05:27:10下载
    积分:1
  • 得到一个进程的状态,如是否没有反应。
    得到一个进程的状态,如是否没有反应。-The status of a process, such as whether or not there was no response.
    2023-01-31 20:20:03下载
    积分:1
  • 关于多线程的专用书籍,很经典的哦 如果想学多线程的朋友不要错过...
    关于多线程的专用书籍,很经典的哦 如果想学多线程的朋友不要错过-on multithreading dedicated books, the classic Oh, if I wanted to learn multithreading friends not to mi
    2022-03-06 21:29:55下载
    积分:1
  • 定时器控制,高
    Timer控件、高性能频率记数、多媒体记时器-Timer controls, high-frequency counting, multimedia timer
    2022-09-06 13:55:03下载
    积分:1
  • os system management
    操作系统进程管理-os system management
    2022-07-06 13:08:09下载
    积分:1
  • Post trough technology used in the communication process between the routines. A...
    利用邮槽技术,在进程间进行通信的例程。希望和大家交流。-Post trough technology used in the communication process between the routines. And we hope that the exchanges.
    2022-03-21 22:34:53下载
    积分:1
  • vc a brief multi
    vc多线程编程简单介绍,有个实例介绍的录像。-vc a brief multi-threaded programming, a video examples.
    2022-03-29 22:41:47下载
    积分:1
  • 显示出系统中的所有进程和每个服务进程的完整路径的源代码...
    显示出系统中的所有进程和每个服务进程的完整路径的源代码-Shows that the system of all the process and the process of each service the full path to the source code
    2023-04-06 12:10:03下载
    积分:1
  • 696516资源总数
  • 106463会员总数
  • 0今日下载