| ISSN for CodeBreakers Journal |
|
Side Story
Processless Applications Remotethreads on Microsoft Windows 2000, XP and 2003
The shown technique is able to run on all Windows operation systems. In order to avoid virus creation on it's best, this technique is shown for W2K/XP/2K3 only. NT4 systems doesn’t know several of the used API's, also it is possible to rewrite them. Non NTbased systems need other techniques to detect the correct process to inject the code. This essay was created while searching for new software protections to make ''crackers life'' even harder. Based on ''WatchDog theory'' another way to protect applications the idea is to create threads outside the main application which are able to continue workflow also if the main application terminates. This essay will show up a way to display a messagebox from process ''Explorer.Exe'', which is available on all OS. The created application is ''processless'' in that way that the ain application becomes terminated after creating the external thread. The shown source code is in Microsoft Assembler style. Download: Read More >> CodeBreakers Journal ISSN 1864-7049 |
Journal Issues
StatisticsMembers: 1925News: 293 Web Links: 1 Visitors: 3830485 Who's OnlineWe have 2 guests online |
Home
Articles - Black Hat Methods Reverse Code Engineering Reverse Engineering Backdoored Binaries
|
|||||||||||||||||

