flat assembler
Message board for the users of flat assembler.
![]() |
Author |
|
vid 25 Jul 2010, 23:18
What do you need this for? In almost every normal case, there is no need to do hackery like this.
|
|||
![]() |
|
david77 26 Jul 2010, 01:02
I tried an alternative approach using windows api functions here http://board.flatassembler.net/topic.php?t=11751, but it isn't working for ntoskrnl.exe/ntkrnlpa.exe. I think I need to manually get the data from the PE file for these files as the alternative approach isn't working.
|
|||
![]() |
|
vid 26 Jul 2010, 09:50
Are you going to patch NTOSKRNL.EXE? Do you need the address of procedure within file? or in memory?
|
|||
![]() |
|
f0dder 26 Jul 2010, 13:42
What's the purpose of this?
Anyway, read up on the PE file format and the export directory. |
|||
![]() |
|
Feryno 27 Jul 2010, 08:04
Quote: These files always have the default base so I'm not worried about them being rebased. under win2008 server R2 x64 (=win7) the nt kernel is loaded at different address every reboot (and I guess this is the same in win2008 server x64 = vista) KdSystemDebugControl with command SysDbgQueryVersion=7 returns some info including the address of nt kernel - you need a driver to obtain it |
|||
![]() |
|
sinsi 27 Jul 2010, 08:14
Just use IDA
|
|||
![]() |
|
< Last Thread | Next Thread > |
Forum Rules:
|
Copyright © 1999-2025, Tomasz Grysztar. Also on GitHub, YouTube.
Website powered by rwasa.