January 01, 1997
Windows NT System-Call Hooking
Windows NT System-Call HookingBy Mark Russinovich and Bryce CogswellDr. Dobb's Journal January 1997
ZwCreateFile: mov eax, 17h ; system call number lea edx, [esp+4] ; pointer to params int 2Eh ; NT x86 syscall trap ret 2Ch ; pop params
Example 1: ZwCreateFile disassembly.
Copyright © 1997, Dr. Dobb's Journal
|
|
|||||||||||||||||
|
|
|
|