自定义博客皮肤VIP专享

*博客头图:

格式为PNG、JPG,宽度*高度大于1920*100像素,不超过2MB,主视觉建议放在右侧,请参照线上博客头图

请上传大于1920*100像素的图片!

博客底图:

图片格式为PNG、JPG,不超过1MB,可上下左右平铺至整个背景

栏目图:

图片格式为PNG、JPG,图片宽度*高度为300*38像素,不超过0.5MB

主标题颜色:

RGB颜色,例如:#AFAFAF

Hover:

RGB颜色,例如:#AFAFAF

副标题颜色:

RGB颜色,例如:#AFAFAF

自定义博客皮肤

-+

125096

我是125096,欢迎大家来我的csdn博客!

  • 博客(400)
  • 资源 (2)
  • 问答 (1)
  • 收藏
  • 关注

原创 窗口抖动

#include #include #include VOID JitterWindow(HWND hwnd){ RECT rect; int cxWidth, cyHeight, iIdx; if (!IsWindow(hwnd))return; GetWindowRect(hwnd, &rect); cxWidth = rect.right-rect.left;

2017-11-30 09:32:05 575

原创 自删除/删除目录下所有文件

#include #include #include #include #include #pragma comment(lib,"Shlwapi.lib")//获取文件名字 BOOL GetFileName(const wchar_t* pImageFilePath, wchar_t* pFileName) { if (IsBadReadPtr(pImageFi

2017-09-11 16:58:57 530

原创 GetWindowsProductKey

#include #include #include char* DecodeProductKey(BYTE digitalProductId[]){ static const char digits[] ={'B', 'C', 'D', 'F', 'G', 'H', 'J', 'K', 'M', 'P', 'Q', 'R', 'T', 'V', 'W', 'X', 'Y', '2

2017-08-16 19:36:19 655

原创 rc4

#include #include static UCHAR g_DeCryptKey[48] = {0xDB, 0x22, 0x98, 0x90, 0x5B, 0xCB, 0x3A, 0x91, 0x92, 0xCA, 0xC4, 0x33, 0x0E, 0xDB, 0xBB, 0x55, 0x78, 0x02, 0xD8, 0x24, 0x91, 0x5C, 0x25, 0xB

2017-08-03 17:13:03 469

原创 bin2cHex

#include #include #include #include #define BYTES_PER_LINE 0x10void main(void){ wchar_t binfilename[]=TEXT("d:\\x861.sys"); char cfilename[]="d:\\1234.h"; char* buffer=NULL; FILE *fp = NU

2017-07-04 17:43:08 442

原创 获取系统位数

#include typedef struct _SYSTEM_PROCESSOR_INFORMATION { USHORT ProcessorArchitecture; USHORT ProcessorLevel; USHORT ProcessorRevision; USHORT Reserved; ULONG ProcessorFeatureBits;} SYSTEM_

2017-06-29 19:06:06 760

原创 遍历_EPROCESS->Vm->WorkingSetExpansionLinks链表枚举进程

#include #include UCHAR * PsGetProcessImageFileName(__in PEPROCESS Process);HANDLE PsGetProcessInheritedFromUniqueProcessId(__in PEPROCESS Process);VOID HelloDDKUnload(IN PDRIVER_OBJECT pDrive

2017-06-19 17:47:57 462 1

原创 遍历_EPROCESS->ObjectTable->HandleTableList链表枚举进程

#include #include UCHAR * PsGetProcessImageFileName(__in PEPROCESS Process);HANDLE PsGetProcessInheritedFromUniqueProcessId(__in PEPROCESS Process);VOID HelloDDKUnload(IN PDRIVER_OBJECT pDrive

2017-06-19 17:31:29 1402

原创 遍历_EPROCESS->SessionProcessLinks链表枚举进程

#include #include UCHAR * PsGetProcessImageFileName(__in PEPROCESS Process);HANDLE PsGetProcessInheritedFromUniqueProcessId(__in PEPROCESS Process);VOID HelloDDKUnload(IN PDRIVER_OBJECT pDrive

2017-06-19 16:42:26 707

原创 遍历_EPROCESS->ActiveProcessLinks链表枚举进程

#include UCHAR * PsGetProcessImageFileName(__in PEPROCESS Process);HANDLE PsGetProcessInheritedFromUniqueProcessId(__in PEPROCESS Process);VOID HelloDDKUnload(IN PDRIVER_OBJECT pDriverObject){

2017-06-18 19:13:12 1029

原创 TLS回调

#include #pragma comment(linker, "/INCLUDE:__tls_used") #pragma comment(lib, "User32.lib") void NTAPI TLS_CALLBACK(PVOID DllHandle, DWORD Reason, PVOID Reserved){ if (IsDebuggerPresent())

2017-05-25 13:56:29 346

原创 ShellExecute使用管理员身份执行

#include #include#includeint main(void){ SHELLEXECUTEINFO sei = { sizeof(SHELLEXECUTEINFO) }; sei.lpVerb = TEXT("runas"); sei.lpFile = TEXT("cmd.exe");//add application which you want to run

2017-05-22 15:33:36 4654

原创 BASE64加密算法

#include #include char Chars[65] = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz1234567890+=";int GetIndex(BYTE b){ for (int i = 0; i < 64; i++) { if (b == Chars[i]) { return i;

2017-04-27 09:26:31 367

原创 inline hook

#include #include #include #include "ldasm.h"#ifdef _WIN64#define HOOKLEN 15#define ProxyJmpCodeLength 15 #else#define HOOKLEN 5#define ProxyJmpCodeLength 7 //siz

2017-04-22 17:41:40 446

原创 防止调试事件被发往调试器

typedef NTSTATUS(*fnZwSetInformationThread)(HANDLE ThreadHandle, THREADINFOCLASS ThreadInformationClass, PVOID ThreadInformation, ULONG ThreadInformationLength); fnZwSetInformationThread ZwSetInform

2017-04-14 11:27:47 753

原创 RtlGetVersion获取操作系统版本

#include #include //操作系统版本#define WINXP 51#define WINXP2600 512600#define WIN7 61#define WIN77600 617600#define WIN77601 617601#define WIN8 62#define WIN89200 62920

2017-03-08 13:52:13 7054 1

原创 遍历进程模块

#include #include #include #define ProcessBasicInformation 0#define NT_SUCCESS(Status) (((NTSTATUS)(Status)) >= 0)typedef struct _PROCESS_BASIC_INFORMATION { NTSTATUS ExitStatus; PVOID PebB

2017-01-22 15:31:48 2593

原创 枚举系统模块信息

#include #include #include typedef struct _SYSTEM_MODULE_INFORMATION { ULONG Reserved[2]; PVOID Base; ULONG Size; ULONG Flags; USHORT Index; USHORT Unknown; USHORT LoadCount; USHORT Modul

2017-01-22 14:39:09 2097

原创 EXE和SYS通信(FltSendMessage+FilterReplyMessage)

#ifndef _HEADER_HEAD_FILE#define _HEADER_HEAD_FILE#pragma once#include #include #ifndef MAX_PATH#define MAX_PATH 260#endiftypedef struct _SCANNER_NOTIFICATION { BOOLEAN bCreate; ULONG Res

2017-01-04 13:11:43 4707 4

原创 EXE和SYS通信MiniFilter基于事件方式

#ifndef _HEADER_HEAD_FILE#define _HEADER_HEAD_FILE#pragma once#include #include #include #include #ifndef MAX_PATH#define MAX_PATH 260#endifNTKERNELAPI UCHAR * PsGetProcessImageFileN

2016-12-30 16:06:05 1521

原创 EXE和SYS基于事件同步消息通知

#ifndef _HEADER_HEAD_FILE#define _HEADER_HEAD_FILE#pragma once#include #include #ifndef MAX_PATH#define MAX_PATH 260#endifNTKERNELAPI UCHAR * PsGetProcessImageFileName(__in PEPROCESS Proce

2016-12-30 15:50:35 647

原创 EXE和SYS通信MiniFilter方式

#ifndef _HEADER_HEAD_FILE#define _HEADER_HEAD_FILE#pragma once#include #include #ifndef MAX_PATH#define MAX_PATH 260#endif#define EVENT_NAMEXP L"\\BaseNamedObjects\\FileMonEvent" //xp下

2016-12-30 15:21:27 870

原创 RtlSetProcessIsCritical将进程设置为系统严重状态(防止进程被结束)

#include #include bool EnableDebugPrivilege();typedef NTSTATUS(__cdecl *fnRtlSetProcessIsCritical)(IN BOOLEAN NewValue, OUT PBOOLEAN OldValue OPTIONAL, IN BOOLEAN CheckFlag);fnRtlSetProcessI

2016-12-11 11:28:29 3646

原创 进程提权

#include #include bool EnableDebugPrivilege();bool UpPrivilege();BOOL EnablePrivilege(LPCTSTR lpszPrivilegeName, BOOL bEnable);int main(void){ if (EnableDebugPrivilege()) { wprintf(

2016-12-05 10:44:35 521

原创 重载内核(x86)

#include #include #include #include #include #include #include #ifndef MAX_PATH#define MAX_PATH 256#endiftypedef unsigned char *PBYTE;typedef unsigned char BYTE;typedef unsigned int UIN

2016-11-17 17:09:55 2232

原创 SSDT HOOK

#include #include NTKERNELAPI UCHAR * PsGetProcessImageFileName(__in PEPROCESS Process);#pragma pack(1) typedef struct _SystemServiceEntry { ULONG *ServiceTableBase; ULONG *Ser

2016-11-17 17:08:15 391

原创 内核隐藏进程

#include #include #include NTKERNELAPI UCHAR *PsGetProcessImageFileName(PEPROCESS Process);#ifndef MAX_PATH#define MAX_PATH 260#endifDWORD g_OsVersion;

2016-11-16 18:22:33 2492

原创 为进程设置代理

#include #include #include #include #pragma comment (lib,"Wininet.lib")//为进程设置代理bool SetConnectionProxy(const TCHAR *proxy_server){ TCHAR temp_string[256]; _tcscpy_s(temp_string, proxy_serve

2016-10-28 13:02:57 4032 1

转载 应用层蓝屏

#include #include typedef enum _HARDERROR_RESPONSE_OPTION { OptionAbortRetryIgnore, OptionOk, OptionOkCancel, OptionRetryCancel, OptionYesNo, OptionYesNoCancel, OptionShutdownSystem} HARD

2016-10-24 15:06:45 2038

转载 隐藏驱动模块

#include typedef unsigned long DWORD;typedef struct _KLDR_DATA_TABLE_ENTRY { LIST_ENTRY InLoadOrderLinks; PVOID ExceptionTable; ULONG ExceptionTableSize; PVOID GpValue; DWORD U

2016-10-20 19:46:02 2032 1

原创 C++调用本地js

#include #include #import "C:\\Windows\\SysWOW64\\msscript.ocx" // msscript.ocx using namespace MSScriptControl;#include #include using namespace std;/*test.js文件内容function add(a,b){return

2016-10-19 11:02:08 1623 2

原创 驱动中全局hook应用层API函数

extern "C" NTSTATUS DriverEntry(IN PDRIVER_OBJECT DriverObject, IN PUNICODE_STRING RegistryPath){ DbgBreakPoint(); DriverObject->DriverUnload = DriverUnload; NTSTATUS status; PEPROCESS Process =

2016-10-08 19:16:04 4890

原创 Intel XE 2016 + vs2013+ wdk8.1配置内嵌汇编

1.安装环境Intel XE 2016 + vs2013+ wdk8.12.工程属性 Platform toolset  Intel C++ Compiler 16.0Base Platform Toolset WindowsKernelModeDriver8.1Configuration  Driver

2016-09-13 11:07:47 1021 1

原创 inline hook IofCallDriver 调用ntfs时保护文件访问

#include #include NTSTATUS DriverUnload(IN PDRIVER_OBJECT DriverObject);int IsNeedProtect(DEVICE_OBJECT *DeviceObject, PIRP Irp);ULONG GetFunctionAddr(IN PCWSTR FunctionName);VOID InlineHook();

2016-09-05 14:33:00 653

原创 FSDHOOK恢复

WCHAR DriverName[] = L"\\FileSystem\\ntfs"; WCHAR DriverPath[] = L"\\??\\C:\\WINDOWS\\system32\\drivers\\ntfs.sys"; RestoreFSDMajorRoutine(&DriverName, &DriverPath, IRP_MJ_CREATE);//函数名: Resto

2016-08-30 16:10:57 587 1

原创 LSP网络监控

#include #include // 定义了WSCWriteProviderOrder函数#include #include #pragma comment(lib, "Ws2_32.lib")#pragma comment(lib, "Rpcrt4.lib") // 实现了UuidCreate函数// 要安装的LSP的硬编码,在移除的时候还要使用它GUID P

2016-08-09 16:21:58 2862 1

原创 域名获取IP

#include #include #include #include #pragma comment (lib, "Ws2_32.lib")int main(void){ //LoadLibrary(TEXT("LockHome.dll")); printf("%d\n", htons(80)); printf("%d\n", ntohs(20480)); prin

2016-08-09 16:07:48 330

原创 内核下文件操作

#include //创建文件NTSTATUS CreateFileText(void);//打开文件NTSTATUS OpenFileText(void);NTSTATUS OpenFileTest2(void);//写入文件NTSTATUS WriteFileText(void);//读取文件NTSTATUS ReadFileText(void);//文件属性

2016-08-01 18:02:59 911

原创 KdPrint使用方法

KdPrint使用方法类似printf,注意KdPrint((" ", ));使用的是双括号。用KdPrint(())来代替printf 输出信息。这些信息可以在DbgView 中看到。KdPrint(())自身是一个宏,为了完整传入参数所以使用了两重括弧。这个比DbgPrint 调用要稍好。因为在free 版不被编译。DebugPrint格式说明符 格式说明符

2016-07-20 16:15:42 1204

原创 安全的等待线程结束

#include //卸载函数VOID HelloDDKUnload(IN PDRIVER_OBJECT pDriverObject);extern "C" NTSTATUS DriverEntry(IN PDRIVER_OBJECT pDriverObject, IN PUNICODE_STRING pRegistryPath);VOID Test(void);BOOLEAN bIs

2016-07-15 09:48:22 823 1

OllyDBG 入门系列

OllyDBG 入门系列OllyDBG 入门系列(五)-消息断点及 RUN 跟踪.doc

2013-08-04

寒江独钓——Windows内核安全编程

寒江独钓——Windows内核安全编程.pdf

2013-08-04

TA创建的收藏夹 TA关注的收藏夹

TA关注的人

提示
确定要删除当前文章?
取消 删除