Windows Kernel

Posts 1–4 of 4 · Page 1 of 1
Windows Kernel
Heya guys,
just a quick question. It's true that drivers and kernel modules can access all memory and can cross memory boundaries right?
... not that its wise to do so
Quote Originally Posted by why06 View Post
... not that its wise to do so
It's to late for that it has already begun

Code:
NTSTATUS DriverEntry( IN PDRIVER_OBJECT DriverObject, IN PUNICODE_STRING theRegistryPath ){

	NTSTATUS ntStatus = STATUS_SUCCESS;
	UNICODE_STRING DeviceName;
	UNICODE_STRING SymbolicLinkNameString;

	DriverObject->DriverUnload = OnUnload;

	RtlInitUnicodeString (&DeviceName, deviceNameBuffer );
	RtlInitUnicodeString (&SymbolicLinkNameString, SymbolicLinkName);

	ntStatus = IoCreateDevice ( DriverObject,0, &DeviceName, FILE_DEVICE_UNKNOWN, FILE_DEVICE_SECURE_OPEN, FALSE, &g_DevicePointer);
	CheckErrors(ntStatus);

	if(ntStatus == STATUS_SUCCESS){

		ntStatus = IoCreateSymbolicLink( &SymbolicLinkNameString,  &DeviceName);
		CheckErrors(ntStatus);
	
	}

	for(y = 0; y < IRP_MJ_MAXIMUM_FUNCTION; y++ ){
		DriverObject->MajorFunction[y] = OnStubDispatch;
	}
	
	DriverObject->MajorFunction[IRP_MJ_WRITE] = WriteNeither;
	DriverObject->MajorFunction[IRP_MJ_READ] = ReadNeitherIo;
	

return STATUS_SUCCESS;
}

I've working I/O handlers and I'm working on the next fase of my driver. I'm going to make something like kernel detective
Posts 1–4 of 4 · Page 1 of 1

Post a Reply

Tags for this Thread

None

Talk with us