flat assembler
Message board for the users of flat assembler.
![]() |
Author |
|
Apolo
How to find ntdll base address in kernel mode?
|
|||
![]() |
|
Apolo
No! I want to get the ntdll base with the PEB structure in kernel land. How to access PEB structure in kernel land with the GS register?
|
|||
![]() |
|
Apolo
I wait with impatience for your answer.
|
|||
![]() |
|
zhak
Why don't you use search on the Internet? There's plenty of information there. Here, could be a starting point for you https://sites.google.com/site/x64lab/home/notes-on-x64-windows-gui-programming/exploring-peb-process-environment-block
|
|||
![]() |
|
Apolo
I already search on google but I can't found how access PEB from kernel mode. The article above is to access PEB from user mode not ftom kernel mode. How to access EPROCESS to access PEB in EPROCESS with the GS register?
|
|||
![]() |
|
comrade
Ask on osronline.com
|
|||
![]() |
|
Furs
Apolo, no reason to get so mad at people. Most of us haven't done kernel or that kind of low level programming, so we don't know. I think this section is for userspace to begin with
![]() |
|||
![]() |
|
< Last Thread | Next Thread > |
Forum Rules:
|
Copyright © 1999-2020, Tomasz Grysztar. Also on GitHub, YouTube, Twitter.
Website powered by rwasa.