Jump to content

Implementation of a standalone TEB and PEB read Method for the Simulation of GetModuleHandle and GetProcAddress functions for loaded PE Module


Recommended Posts

Posted (edited)

I'm not a C/C++ experienced. But I think you can't adapt this code due to intrinsics. Can be done partially but I think It would be  redundant, impractical etc...

Edit: Seem to be my dear trancexx answer already... :sweating:

Saludos

Edited by Danyfirex
Posted
1 hour ago, trancexx said:

Dodgy how?
Just go with it. It's been done before, and works just fine if proper privileges are set for your process and thread accessed with correct flags ...as far as I know.

Everywhere I look, people say it could be removed at any time from ntdll.dll.

I'll stick with it since it appears to work, at least on most process threads that aren't protected in some fashion, like system, audiodg, wininit, csrss so far.

AutoIt Absolute Beginners    Require a serial    Pause Script    Video Tutorials by Morthawt   ipify 

Monkey's are, like, natures humans.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...