Update README.md

merge-requests/1/head
xerox 5 years ago
parent 84280b04f3
commit 5a71895e8a

@ -35,8 +35,7 @@ auto syscall_page_offet = rva % 0x1000;
``` ```
Now that we know that the syscalls bytes are going to be that far into the physical page we can map each physical page into our process 512 at a time (2mb) and then Now that we know that the syscalls bytes are going to be that far into the physical page we can map each physical page into our process 512 at a time (2mb) and then
check the page + page_offset and compare with the syscalls bytes. After we have the syscalls page mapped into our process we can pretty much call any function inside check the page + page_offset and compare with the syscalls bytes. After we have the syscalls page we can install inline hooks and then call into the function.
of the kernel simply by installing an inline hook into that mapped page and then calling into the syscall.
<img src="https://cdn.discordapp.com/attachments/687446832175251502/701355063939039292/unknown.png"/> <img src="https://cdn.discordapp.com/attachments/687446832175251502/701355063939039292/unknown.png"/>

Loading…
Cancel
Save