04.08.2016 Views

Captain Hook

2aQumCA

2aQumCA

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

INJECTION METHODS – USER APC<br />

Basic Steps (There are several variations):<br />

1. Register load image callback using PsSetLoadImageNotifyRoutine<br />

2. Write payload that injects a dll using LdrLoadDll<br />

(Other variations use LoadLibrary)<br />

3. Insert User APC using KeInsertQueueApc

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!