当前位置:网站首页>Record the process of reverse task manager
Record the process of reverse task manager
2022-07-06 03:22:00 【Yulong_】
keyword :
Task manager , reverse ,WdcSafeOpenProcess,ResolveImagePath_Desktop,OpenProcess
Preface
Record the process of this reverse task manager , The whole process is relatively pleasant and easy .
There is no detailed analysis of the function implementation of the task manager , In this reverse , only Focus on a function point —— How does the task manager get the process id by 4 Of system Of relevant information ? Because I've done Windows The process related programming is clear , Microsoft offers API Function except to get System Process name and pid Outside , Other information ( Such as path 、 Command line, etc ) It's impossible to get .
Text
Let's take a look at the display of the task manager :
Where did the description information of this process come from ? We can even right-click to open the location of the file ...
First , open IDA, Let's start with a wave of Static analysis :
From the import table , See how the task manager gets the process handle ( Guess there is special treatment here ?)
We see OpenProcess function , Take a look at how it is called in the task manager , View the of this function Cross reference
边栏推荐
- 指针笔试题~走近大厂
- Audio audiorecord binder communication mechanism
- 【SLAM】ORB-SLAM3解析——跟踪Track()(3)
- [pointer training - eight questions]
- Microsoft Research, UIUC & Google research | antagonistic training actor critic based on offline training reinforcement learning
- My C language learning record (blue bridge) -- under the pointer
- Shell 传递参数
- Sign SSL certificate as Ca
- 记录一下逆向任务管理器的过程
- 3857墨卡托坐标系转换为4326 (WGS84)经纬度坐标
猜你喜欢
Princeton University, Peking University & UIUC | offline reinforcement learning with realizability and single strategy concentration
2022工作中遇到的问题四
指针笔试题~走近大厂
Research on cooperative control of industrial robots
Idea push rejected solution
下一个行业风口:NFT 数字藏品,是机遇还是泡沫?
真机无法访问虚拟机的靶场,真机无法ping通虚拟机
[pointer training - eight questions]
Recommended foreign websites for programmers to learn
【SLAM】lidar-camera外参标定(港大MarsLab)无需二维码标定板
随机推荐
Tomb. Weekly update of Finance (February 7 - February 13)
SD卡報錯“error -110 whilst initialising SD card
Princeton University, Peking University & UIUC | offline reinforcement learning with realizability and single strategy concentration
Esbuild & SWC: a new generation of construction tools
SAP ALV颜色代码对应颜色(整理)
canvas切积木小游戏代码
Eight super classic pointer interview questions (3000 words in detail)
【paddle】加载模型权重后预测报错AttributeError: ‘Model‘ object has no attribute ‘_place‘
Data and Introspection__ dict__ Attributes and__ slots__ attribute
MySQL learning notes-10-tablespace recycling
three.js网页背景动画液态js特效
【SLAM】ORB-SLAM3解析——跟踪Track()(3)
3857 Mercator coordinate system converted to 4326 (WGS84) longitude and latitude coordinates
MySQL advanced notes
ERA5再分析资料下载攻略
OCR文字识别方法综述
OCR文字識別方法綜述
Leetcode problem solving -- 173 Binary search tree iterator
数据分析——seaborn可视化(笔记自用)
Leetcode problem solving -- 99 Restore binary search tree