当前位置:网站首页>记录一下逆向任务管理器的过程
记录一下逆向任务管理器的过程
2022-07-06 03:12:00 【宇龍_】
关键字:
任务管理器,逆向,WdcSafeOpenProcess,ResolveImagePath_Desktop,OpenProcess
前言
记录一下本次逆向任务管理器的过程,整个过程相对愉悦轻松。
这里不详细分析任务管理器的各个功能实现,在本次逆向中,只关注一个功能点——任务管理器是如何获取进程id为4的system的相关信息的?因为做过Windows进程相关编程的都清楚,微软提供的API函数除了获取System的进程名及pid外,其他信息(如路径、命令行等)是获取不到的。
正文
我们看一下任务管理器的展示情况:
这个进程的描述信息是哪儿来的? 我们甚至能右键打开文件所在位置...
首先,打开IDA,先来一波静态分析:
从导入表看起,看看任务管理器是如何获取进程句柄的(猜想难道在这里有特殊处理?)
我们看到导入表中有OpenProcess函数,看一下在任务管理器里是如何调用的,查看该函数的交叉引用
边栏推荐
- 1. Dynamic parameters of function: *args, **kwargs
- The next industry outlet: NFT digital collection, is it an opportunity or a foam?
- [ruoyi] enable Mini navigation bar
- The real machine cannot access the shooting range of the virtual machine, and the real machine cannot Ping the virtual machine
- Self made CA certificate and SSL certificate using OpenSSL
- 适合程序员学习的国外网站推荐
- An article about liquid template engine
- [Li Kou] the second set of the 280 Li Kou weekly match
- . Net 6 and Net core learning notes: Important issues of net core
- C # create self host webservice
猜你喜欢
[ruoyi] enable Mini navigation bar
1. Dynamic parameters of function: *args, **kwargs
MPLS experiment
Microservice registration and discovery
Installation and use tutorial of cobaltstrike-4.4-k8 modified version
[network security interview question] - how to penetrate the test file directory through
MySQL advanced notes
[Yu Yue education] basic reference materials of digital electronic technology of Xi'an University of Technology
Recommended foreign websites for programmers to learn
4. File modification
随机推荐
Prototype design
codeforces每日5题(均1700)-第六天
Analyze 菜单分析
BUUCTF刷题笔记——[极客大挑战 2019]EasySQL 1
Audio audiorecord binder communication mechanism
js凡客banner轮播图js特效
Codeforces 5 questions par jour (1700 chacune) - jour 6
SD卡報錯“error -110 whilst initialising SD card
4. File modification
Zhang Lijun: penetrating uncertainty depends on four "invariants"
Tomb. Weekly update of Finance (February 7 - February 13)
微服务注册与发现
jsscript
MySQL advanced notes
Mysql database operation
Data and Introspection__ dict__ Attributes and__ slots__ attribute
Redis SDS principle
StrError & PERROR use yyds dry inventory
Crazy, thousands of netizens are exploding the company's salary
tcpdump: no suitable device found