Description: DLL注入的源码和bin文件,简单易用学习远程线程的好例子-nice example for DLL injection. use createremotethread. include bin and src Platform: |
Size: 203776 |
Author:linzhixin |
Hits:
Description: 提升程序源码权限,创建远程线程的源码。在别的进程中创建一个自己写的线程。创建线程本来只是一个函数的事,CreateRemoteThread()。其中的参数包含线程函数体。但是这是在远程进程的地盘上,所所以此此函数体的地址必须映射到远程进程的空间中去。线程中引用的全部地址,包含函数与指针与字符串等等,都必须映射到远程进程的空间中去。映射的步骤有三1、在远程进程中分配空间,函数VirtualAllocE
-Permission to enhance the program source code, source to create a remote thread. In the other process to create a thread to write their own. Create a thread was just a function, CreateRemoteThread (). Which parameter contains the thread function body. But this is a remote process on the site, the address of this function must be mapped to the remote process space. Address referenced in the thread that contains the function pointer with string, and so on, must be mapped to the remote process space. Mapping steps 1, the space allocated in the remote process, function VirtualAllocE Platform: |
Size: 58368 |
Author:guli |
Hits:
Description: 这个示例演示了如何将一个DLL到一个远程过程CreateRemoteThread使用。具体地说,这个应用程序工具栏添加一个Windows记事本应用程序。这个程序适用于Windows NT、2000和XP。-This sample demonstrates how to inject a DLL into a remote process using CreateRemoteThread. Specifically, this application adds a toolbar to the Windows Notepad application. This program will work on Windows NT, 2000 and XP. Platform: |
Size: 36864 |
Author:小打小闹 |
Hits:
Description: NP启动后通过WriteProcessMemory跟CreateRemoteThread向所有进程注入代码(除了系统进程smss.exe),代码通过np自己的LoadLibrary向目标进程加载npggNT.des。npggNT.des一旦加载就马上开始干“坏事”,挂钩(HOOK)系统关键函数如OpenProcess,ReadProcessMemory,WriteProcessMemory,PostMessage等等。
挂钩方法是通过改写系统函数头,在函数开始JMP到npggNT.des中的替换函数。用户调用相应的系统函数时,会首先进入到npggNT.des模块等待NP的检查,-NP starts with CreateRemoteThread via WriteProcessMemory inject code to all processes (in addition to system process smss.exe), np own code through LoadLibrary to load the target process npggNT.des. npggNT.des Once loaded immediately start doing "bad", hooks (HOOK) system-critical functions such as OpenProcess, ReadProcessMemory, WriteProcessMemory, PostMessage and so on.
Hook method is through rewriting system function head start in the function of JMP to npggNT.des replacement function. Users call the corresponding system function, will first enter into npggNT.des module waits for NP examination, Platform: |
Size: 129024 |
Author:ghgh |
Hits:
Description: Win7下CreateRemoteThread的代替函数-Win7 substitute for the function under the CreateRemoteThread Platform: |
Size: 1024 |
Author:fflql647baz |
Hits: