| View previous topic :: View next topic |
| Author |
Message |
dnsi0 I post too much
Reputation: 0
Joined: 04 Jan 2007 Posts: 2674
|
Posted: Fri Jan 30, 2009 1:04 pm Post subject: Whats the KeServiceDescriptorTableShadow? |
|
|
Well... SDT is the NtStuff.
I read on the internet that the ServiceDescriptorShadow contains functions like NtUserSendInput. Is this right?
|
|
| Back to top |
|
 |
lurc Grandmaster Cheater Supreme
Reputation: 2
Joined: 13 Nov 2006 Posts: 1900
|
Posted: Fri Jan 30, 2009 3:17 pm Post subject: |
|
|
Yes
the KeServiceDescriptorTable contains all the exports of NTOSKRNL.exe whilest KeServiceDescriptorTableShadow contains the exports of Win32k.sys which are those functions that are used by Windowing from GDI32.dll and USER32.dll
_________________
|
|
| Back to top |
|
 |
dnsi0 I post too much
Reputation: 0
Joined: 04 Jan 2007 Posts: 2674
|
Posted: Fri Jan 30, 2009 8:15 pm Post subject: |
|
|
| lurc wrote: | Yes
the KeServiceDescriptorTable contains all the exports of NTOSKRNL.exe whilest KeServiceDescriptorTableShadow contains the exports of Win32k.sys which are those functions that are used by Windowing from GDI32.dll and USER32.dll |
Oh. Ok. So NtUserSendInput is in the Shadow not the table.
Quick question about calling a function:
type:
typedef ULONG (*NTWRITEVIRTUALMEMORY)(HANDLE, PVOID, PVOID, ULONG, PULONG);
code:
NTWRITEVIRTUALMEMORY myMemCall;
myMemCall=(NTWRITEVIRTUALMEMORY)0x8057b717;
myMemCall(pinp->processhandle,pinp->baseaddress,pinp->buffer,pinp->buffersize,pinp->BytesRet)
|
|
| Back to top |
|
 |
sphere90 Grandmaster Cheater
Reputation: 0
Joined: 24 Jun 2006 Posts: 912
|
Posted: Fri Jan 30, 2009 10:43 pm Post subject: |
|
|
| dnsi0 wrote: | Quick question about calling a function:
type:
typedef ULONG (*NTWRITEVIRTUALMEMORY)(HANDLE, PVOID, PVOID, ULONG, PULONG);
code:
NTWRITEVIRTUALMEMORY myMemCall;
myMemCall=(NTWRITEVIRTUALMEMORY)0x8057b717;
myMemCall(pinp->processhandle,pinp->baseaddress,pinp->buffer,pinp->buffersize,pinp->BytesRet) |
I don't see any questions but your typedef is wrong. The calling convention should be __stdcall instead of the default __cdecl. Use typedef ULONG (__stdcall *NTWRITEVIRTUALMEMORY)(HANDLE, PVOID, PVOID, ULONG, PULONG); instead.
_________________
Give a hungry man a fish and he'll be full for a day. Teach a hungry man how to fish and he'll be full for the rest of his life. |
|
| Back to top |
|
 |
|