Rootkits (Part 4): Import Address Table Hooking

Sourcefire
Sourcefire
9.7 هزار بار بازدید - 11 سال پیش - Import Address Table (IAT) hooking
Import Address Table (IAT) hooking is a technique employed by user-mode rootkits to hide their presence on an infected system by modifying code execution paths and transferring control to malicious code. In this video, Sourcefire Chief Scientist, Zulfikar Ramzan, describes the mechanics of this technique. This video is the fourth in a multi-part series on rootkits. For a comprehensive list of chalk talks, please visit http://sourcefire.com/chalktalks.
11 سال پیش در تاریخ 1392/04/27 منتشر شده است.
9,756 بـار بازدید شده
... بیشتر