约有 112 项符合查询结果, 以下是第 1 - 12项。
费时 < 1 秒。
没检查NtQueryDirectoryFile的参数就直接做RtlInitunicodeString..基础啊。。太多没基础的小孩出来些驱动了
Posted in Windows内核调试
by
MJ0011
on 2010-02-04
low level的应是在原始进程context下执行的,不用DLL也可以。
Posted in Windows内核
by
MJ0011
on 2010-01-31
内核空间,EProcess->ObjectTable
windbg:!handle
Posted in Windows内核调试
by
MJ0011
on 2009-12-24
ERROR_CODE: (NTSTATUS) 0x80000003 -,应该是STATUS_SINGLE_STEP
Posted in Windows内核
by
MJ0011
on 2009-11-29
boot阶段何必用beep呢。。。用int 10不就可以了。。。最不济用0x6-4大法也可以了
Posted in Windows内核调试
by
MJ0011
on 2009-11-13