滴水逆向联盟

标题: Under Windows8 kernel mode development NDIS application-NDIS Filter explain [打印本页]

作者: 大灰狼    时间: 2014-9-26 08:43
标题: Under Windows8 kernel mode development NDIS application-NDIS Filter explain
Win8 system development driver, also need to drive the need for a digital certificate, the signature verification. Not like XP below as crazy drops bullying.


Win8 system kernel drastic changes, and XP system kernel have been great changes, the most significant is just to say: the need for signatures and certificates. There is: not at liberty HOOK SSDT.



WDK Development Kit provides a new framework in the development of the NDIS driver shouted NDIS Filter
NDIS Filter is an example of engineering.
False in my WDK installed on the E drive, then the engineering code:
C: \ WinDDK \ 8600.16385.1 \ src \ network \ ndis \ filter directory.




Example works and the original the Passthru project code to do, you will find the original need to be guided by the two types the callback function MiniportXXX and ProtocolXXX in the new framework is all hidden.
Microsoft provides a new function. Take a look at what Microsoft provides.
Here, in order to facilitate analysis, I function code do functional annotation, please take a look at.

Code is as follows:


[cpp] view plaincopy









欢迎光临 滴水逆向联盟 (http://dtdebug.com/) Powered by Discuz! X3.2