Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 04-21-2004, 03:44
JMI JMI is offline
Leader
 
Join Date: Jan 2002
Posts: 1,627
Rept. Given: 5
Rept. Rcvd 199 Times in 99 Posts
Thanks Given: 0
Thanks Rcvd at 98 Times in 96 Posts
JMI Reputation: 100-199 JMI Reputation: 100-199
auroras:

I don't think "contributing" a certain number of posts means dividing your response into 3 posts and posting part of it every two minutes. That is called padding your post count. I've made one post out of your comments and deleted the other two.

Regards,
__________________
JMI

Last edited by JMI; 04-21-2004 at 09:18.
Reply With Quote
  #2  
Old 04-21-2004, 06:07
Barmaley
 
Posts: n/a
Look for "Debugging Applications" by John Robbins. "Inside MS Windows 2000" by David A. Solomon and Mark E. Russinovich may help you.
Reply With Quote
  #3  
Old 04-21-2004, 15:59
firstrose
 
Posts: n/a
SICE's core is a driver
Reply With Quote
  #4  
Old 04-21-2004, 16:31
zEr0 zEr0 is offline
Friend
 
Join Date: Mar 2002
Posts: 27
Rept. Given: 1
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 2
Thanks Rcvd at 0 Times in 0 Posts
zEr0 Reputation: 1
so then if SICE core is kernel driver i think that it can run under ring0 privileges

by u can find some useful thing about Ring mode in very useful virus ezines from 29A labs

http://29a.host.sk/
Reply With Quote
  #5  
Old 04-21-2004, 16:34
quasar
 
Posts: n/a
Look for mamaich's BlindStudio debugger with sources on Elicz's site
Reply With Quote
  #6  
Old 04-21-2004, 19:02
auroras
 
Posts: n/a
Quote:
Originally Posted by zEr0
so then if SICE core is kernel driver i think that it can run under ring0 privileges

by u can find some useful thing about Ring mode in very useful virus ezines from 29A labs

http://29a.host.sk/

I don't think it is about whether it is a kernel driver, but rather about when SoftICE loads. SoftICE seems to always start first, and can actually debug other kernel drivers when they load. Just wondering how they manage to do that....

Re: BlindStudio

Thanks a lot!

Last edited by auroras; 04-21-2004 at 19:15.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 20:18.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )