• XSS.stack #1 – первый литературный журнал от юзеров форума

Bypassing Firewall Through Process Injection - Bypasser Source Code

ihateronaldo11

floppy-диск
Пользователь
Регистрация
08.01.2024
Сообщения
5
Реакции
1
It uses a lot of common WinAPI calls for internet connection. Will be interest to see active detection on the bin on execution. Simple pseudo code on how the above code work.

C:
if (VirtualExecuteEx is called
    AND (WinINet functions are called
         OR CreateRemoteThread or WriteProcessMemory are called)
    AND TargetProcessID is in Blacklist) {
    Trigger Alert;
}
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх