04.08.2016 Views

Captain Hook

2aQumCA

2aQumCA

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

INJECTION METHODS – NTDLL.DLL/USER32.DLL PATCHING<br />

• Register load image callback using PsSetLoadImageNotifyRoutine<br />

and wait for ntdll.dll module to load<br />

Kernel Space<br />

Ntoskrnl.exe<br />

KiStartUserThread<br />

EvilDriver.sys<br />

Callback Routine<br />

User Space<br />

Application<br />

RtlUserThreadStart<br />

LdrLoadDll

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!