登录
首页 » Windows核心 » 有时候,我们遇到的情况时,我们需要一些内核函数钩子…

有时候,我们遇到的情况时,我们需要一些内核函数钩子…

于 2022-08-15 发布 文件大小:9.59 kB
0 115
下载积分: 2 下载次数: 1

代码说明:

Sometimes, we run into a situation when we badly need to hook some kernel function, but are unable to do it via conventional PE-based hooking. This article explains how kernel functions can be directly hooked. As a sample project, we are going to present a removable USB storage device as a basic disk to the system, so that we can create and manage multiple partitions on it (for this or that reason, Windows does not either allow or recognize multiple partitions on removable storage devices, so we are going to cheat the system). On this particular occasion, we will hook only one function, but the approach described in this article can be extended to handle multiple functions (for example, one of my projects required direct hooking of quite a few functions from the NDIS library). You should clearly realize that this article is about direct hooking and not about dealing with USB storage, so please don t tell me that the sample problem may have been solved differently.

下载说明:请别用迅雷下载,失败请重下,重下不扣分!

发表评论

0 个回复

  • 开发商使用多
    使用Delphi进行程序开发的一个多线程例子-Delphi developers to use a multi-threaded example
    2022-03-22 07:06:29下载
    积分:1
  • <;B & gt;点
    ;点阵字体比较工具;
    2022-01-23 10:04:51下载
    积分:1
  • 通过注册表查询,删除U盘使用记录,得到你的移动存储器的硬件编号...
    通过注册表查询,删除U盘使用记录,得到你的移动存储器的硬件编号-Look through the registry to remove U disk usage records
    2022-01-26 05:49:14下载
    积分:1
  • 一个wh_shell钩子程序,具体功能是使用管理应用…
    一个WH_SHELL的钩子程序,具体功能是管理应用程序的使用。在使用应用程序之前可以控制其启动和关闭。包含三个文件夹,HookDLL文件夹是全局钩子dll,HookServer文件夹是一个应用程序控制程序,ProgamControl文件夹是delphi编写的应用程序编辑器。-A WH_SHELL the hook procedure, the specific function is to use management application. In the use of applications can be controlled prior to its start-up and shut down. Contains three folders, HookDLL folder is a global hook dll, HookServer folder is an application process control procedures, ProgamControl folder is prepared applications delphi editor.
    2022-08-21 03:27:49下载
    积分:1
  • 他的一个简短的介绍如何使用EL梁库
    his a short introduction how to use the El Beem library and API. This release supports two versions that can be built: - a standalone test program that runs a small fluid simulation - a command line executable, that can be used to run fluid simulations using a text file for setup. To successfully compile you should have the following software installed: - a Linux/BSD systems with - gcc (3.4 or higher recommended) - the zlib libaries and headers.stay
    2022-08-12 18:50:10下载
    积分:1
  • 写一个保护模式下多任务磁盘驱动// 英文教程
    写一个保护模式下多任务磁盘驱动// 英文教程 -write a protected mode multi-tasking disk drive// English Directory
    2023-08-06 22:55:03下载
    积分:1
  • c语言编译器源代码
    c语言编译器源代码-c compiler source code!
    2022-05-21 15:57:00下载
    积分:1
  • 电子银行系统源码 本安装说明是以Microsoft SQL Server 2000中文开发版为例来阐述的,对于Microsoft SQL Server...
    电子银行系统源码 本安装说明是以Microsoft SQL Server 2000中文开发版为例来阐述的,对于Microsoft SQL Server其它版本,应用程序数据库的安装方法是类似的。 运行Microsoft SQL Server 2000的SQL 查询分析器,打开bank.sql文件,然后选择菜单“查询”|“执行”命令即可生成所需的数据库和数据库表。 2、把源程序目录从光盘上拷贝到硬盘上,取消文件夹及其子目录和文件的只读属性。如果您安装的是Microsoft Visual Studio .Net 2003,那么可以直接打开ATM文件夹、Bank文件夹和Client文件夹下的工程,查看代码并进行调试。-E-banking system is based on source of the installation instructions Microsoft SQL Server 2000 Developer Edition Chinese set out as an example for other versions of Microsoft SQL Server, applications, database installation methods are similar. Running Microsoft SQL Server 2000
    2022-05-22 21:51:32下载
    积分:1
  • 8皇后问题,N皇后问题,随机算法,提高速度
    8皇后问题,N皇后问题,随机算法,提高速度-this is a randomized solution of N Queens. with random algrithism, we can improve the speed of finding solution
    2022-07-18 12:37:32下载
    积分:1
  • Trace Facility for Use in Debugging
    Trace Facility for Use in Debugging
    2022-01-21 01:37:29下载
    积分:1
  • 696518资源总数
  • 105877会员总数
  • 14今日下载