|
|
@ -18,8 +18,8 @@ vdm::vdm_ctx vdm;
|
|
|
|
nasa::mem_ctx my_proc(vdm);
|
|
|
|
nasa::mem_ctx my_proc(vdm);
|
|
|
|
|
|
|
|
|
|
|
|
const auto ntoskrnl_base =
|
|
|
|
const auto ntoskrnl_base =
|
|
|
|
reinterpret_cast<void*>(
|
|
|
|
reinterpret_cast<void*>(
|
|
|
|
util::get_kmodule_base("ntoskrnl.exe"));
|
|
|
|
util::get_kmodule_base("ntoskrnl.exe"));
|
|
|
|
|
|
|
|
|
|
|
|
const auto ntoskrnl_pde = my_proc.get_pde(ntoskrnl_base);
|
|
|
|
const auto ntoskrnl_pde = my_proc.get_pde(ntoskrnl_base);
|
|
|
|
std::printf("[+] pde.present -> %d\n", ntoskrnl_pde.second.present);
|
|
|
|
std::printf("[+] pde.present -> %d\n", ntoskrnl_pde.second.present);
|
|
|
|