Click here to Skip to main content
15,896,063 members
Articles / Programming Languages / C

Kernel-mode API spying - an ultimate hack

Rate me:
Please Sign up or sign in to vote.
4.96/5 (47 votes)
21 Apr 2004CPOL26 min read 255K   4.5K   215  
An article on kernel-mode API spying.

#include "ntddk.h"
#include <stdio.h>
typedef unsigned char BYTE;
typedef unsigned short WORD;
typedef unsigned long DWORD;


typedef struct tagRelocatedFunction{
LONG address;
LONG function;
} RelocatedFunction,*PRelocatedFunction;


typedef struct tagStorage{
	
	DWORD isfree;
	DWORD retaddress;
	DWORD prevEBP;
	RelocatedFunction* ptr;

}Storage,*PStorage;

By viewing downloads associated with this article you agree to the Terms of Service and the article's licence.

If a file you wish to view isn't highlighted, and is a text file (not binary), please let us know and we'll add colourisation support for it.

License

This article, along with any associated source code and files, is licensed under The Code Project Open License (CPOL)


Written By
Web Developer
Luxembourg Luxembourg
This member has not yet provided a Biography. Assume it's interesting and varied, and probably something to do with programming.

Comments and Discussions