Dailydave mailing list archives

Re: Api hooking papers ?


From: Matt Hargett <matt () use net>
Date: Sat, 04 Dec 2004 12:20:46 +0000

nenads () mol com mk wrote:
Well I want to hook winsock (send and receive ), maybe my aproach is wrong
please correct me (???)  :> Or at least i wanna try :> I need so I can compress
and decompress the data before it is sent or received and it is for a project
(student), or maybe for a diploma work :>

Check out the source code for filemon, regmon, etc on www.sysinternals.com . There's some good articles linked to. Most of the NT Rootkit stuff was all based on this code.
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
https://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: