Rootkits (Part 5): Inline Function Patching -- Detours

Sourcefire
Sourcefire
2.8 هزار بار بازدید - 11 سال پیش - Inline function patching (also known
Inline function patching (also known as "detours") is a technique employed by user-mode rootkits to hide their presence on an infected system. In this video, Sourcefire Chief Scientist, Zulfikar Ramzan, describes the mechanics of this technique. This video is the fifth in a multi-part series on rootkits. For a comprehensive list of chalk talks, please visit http://sourcefire.com/chalktalks
11 سال پیش در تاریخ 1392/04/27 منتشر شده است.
2,825 بـار بازدید شده
... بیشتر