Matthieu Suiche On January - 31 - 2007

This paper exposes part II of my previous article about Windows Vista and internals structures. This one is talking about the 32bits version and aims to show new authencity tricks.

Download it from the following link:
Windows_Vista_32bits_and_unexported_kernel_symbols.pdf

Cheers,

One Response so far.

  1. Alex Ionescu says:

    ReactOS implements *all* of this to the letter, and the source code is in C and GPLed, so I’m not quite sure on why you went through the trouble of reversing it yourself and publishing it with unofficial structure definitions/constant names… nevertheless, a good read and I guess you learnt a lot while reversing it, but the final copy could’ve used the ROS code.

Sponsors