当前位置:网站首页>To bypass obregistercallbacks, you need to drive the signature method

To bypass obregistercallbacks, you need to drive the signature method

2022-07-02 12:46:00 As the deer

windbg Change code directly
Before the change

nt!ObRegisterCallbacks+0x11d:
fffff800`052a1d3d e83e82faff      call    nt!MmVerifyCallbackFunction (fffff800`05249f80)
fffff800`052a1d42 3bc3            cmp     eax,ebx
fffff800`052a1d44 747b            je      nt!ObRegisterCallbacks+0x1a1 (fffff800`052a1dc1)  Branch

After modification

nt!ObRegisterCallbacks+0x11d:
fffff800`052a1d3d b801000000      mov     eax,1
 perhaps 
eb nt!ObRegisterCallbacks+0x11d b8 01 00 00 00

Won't STATUS_ACCESS_DENIED
The callback routines do not reside in a signed kernel binary image.

原网站

版权声明
本文为[As the deer ]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/183/202207020921080448.html