flat assembler
Message board for the users of flat assembler.
![]() |
Author |
|
typedef
Recently I just got into the process of handling my own exceptions, but before I start, I thought I'd do a little reading and I got something from wikipedia.
http://en.wikipedia.org/wiki/Win32_Thread_Information_Block I like this part Quote:
Interesting huh ? |
|||
![]() |
|
idle
observing own code with ollydbg on os-calls i saw fs:xxxx readings, and now i know what that is, thanks!
|
|||
![]() |
|
AsmGuru62
Imagine if Microsoft will change TIB layout, so API works and 'direct' FS:XXXX manipulation fails! Probably far fetched, but it can happen.
|
|||
![]() |
|
typedef
PS: I was thinking, if one can access the whole memmory and enumerate all the code and data in there(ie. running programs), can you not use the method above(Win32 Thread Information Block) to get the basic info about each & every particular program, thus bypassing API ?
Hmm?.... Just another day in the computer virus lab.. ![]() |
|||
![]() |
|
< Last Thread | Next Thread > |
Forum Rules:
|
Copyright © 1999-2020, Tomasz Grysztar. Also on GitHub, YouTube, Twitter.
Website powered by rwasa.