12.07.2015 Views

Advanced Mac OS X Rootkits.pdf - Reverse Engineering Mac OS X

Advanced Mac OS X Rootkits.pdf - Reverse Engineering Mac OS X

Advanced Mac OS X Rootkits.pdf - Reverse Engineering Mac OS X

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Deserializing <strong>Mac</strong>h Messages• Port names in the mach message must bereplaced with local port names• On Agent, this is done to receive the reply• On Proxy, this is done to replace transferredport names with proxy port names–Ensures that only the initial port must be manuallyobtained from the proxy, the rest are handledautomatically• OOL memory is mapped+copied into addressspace38

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!