반응형

Windows X86 System Call Table
- http://j00ru.vexillium.org/ntapi

Windows X86-64 System Call Table
- http://j00ru.vexillium.org/ntapi_64


출처 : j00ru.vx tech blog [ http://j00ru.vexillium.org ]



반응형
AND

반응형


11월 9일자로 XueTr v0.44 가 업데이트 되었습니다.


[ XueTr 블로그 : http://www.xuetr.com ]




반응형
AND

반응형


몰랐는데... -_-;;;;

Microsoft 에서 제공하는 Hooking 라이브러리 "Detour" 가 새버전이 올라왔네요..;;;


----------------------------------------------------------------------------------------

Detours 3.0 includes the following new features over Detours 2.x:
  • Support for 64-bit code on x64 and IA64 processors (Professional Edition only).
  • Support for all Windows processors (Professional Edition only).
  • Removed requirement for including detoured.dll in processes.
  • Compatibility improvements for detouring APIs used by managed-code (MSIL) programs, especially on x64 processors.
  • Addition of APIs to enumerate PE binary Imports and to determine the module referenced by a function pointer.

----------------------------------------------------------------------------------------

출처 :  http://research.microsoft.com/en-us/projects/detours/



반응형
AND