Scrambling system Memory for regular expression strings in Windows

Any ideas on where to start?

+3
source share
3 answers

If the process you want to scan is currently running, you can connect to it as a debugger and clear its address space.

If you want to clear the memory as a whole, you will need to install a driver or something similar to exit the user space.

+1
source

SoftICE (wiki) -, , Windows. , , Windows, . , SoftICE ( ), : IceStealth IceExt. , , . : Sysersoft , , SoftICE ( ), , Rasta Ring 0 Debugger, 2006 .

+1

, , root... Administrator - - (, mode) -, , (, ). ( ) , - .

, , ring0, , BSOD . , VirtualBox Windows .

You will need to start searching for the Windows Kernel Mode SDK driver, which will allow you to write drivers. Other than that, I would not know how to do this! :)

This is what I'm going to stick to my favorite questions.

Good luck and hope this helps, Best regards, Tom.

+1
source

Source: https://habr.com/ru/post/1725568/


All Articles