flat assembler
Message board for the users of flat assembler.
Index
> Windows > Interesting stuff |
Author |
|
typedef 10 Aug 2011, 14:51
Recently I just got into the process of handling my own exceptions, but before I start, I thought I'd do a little reading and I got something from wikipedia.
http://en.wikipedia.org/wiki/Win32_Thread_Information_Block I like this part Quote:
Interesting huh ? |
|||
10 Aug 2011, 14:51 |
|
idle 10 Aug 2011, 15:40
observing own code with ollydbg on os-calls i saw fs:xxxx readings, and now i know what that is, thanks!
|
|||
10 Aug 2011, 15:40 |
|
AsmGuru62 10 Aug 2011, 16:41
Imagine if Microsoft will change TIB layout, so API works and 'direct' FS:XXXX manipulation fails! Probably far fetched, but it can happen.
|
|||
10 Aug 2011, 16:41 |
|
typedef 10 Aug 2011, 17:35
PS: I was thinking, if one can access the whole memmory and enumerate all the code and data in there(ie. running programs), can you not use the method above(Win32 Thread Information Block) to get the basic info about each & every particular program, thus bypassing API ?
Hmm?.... Just another day in the computer virus lab.. |
|||
10 Aug 2011, 17:35 |
|
< Last Thread | Next Thread > |
Forum Rules:
|
Copyright © 1999-2024, Tomasz Grysztar. Also on GitHub, YouTube.
Website powered by rwasa.