Flag: Tornado! Hurricane!

 Forums >>  Brainstorms - General  >>  Static UNICODE_STRING buffer in TIB

Topic created on: July 30, 2012 16:32 CDT by 0x200x20 .

On offset 0xBF8 in TIB there is some UNCODE_STRING buffer. It seems to be used permanently in ReactOS by ASCII Winapi functions but I cannot find where it is used by original Windows. I have tried to put hardware breakpoint on it (Win 7 x64) but it seems it has never been used. Could you please tell by which API could it be used?

  waleedassar     July 30, 2012 17:33.44 CDT
It is not used in Windows 7 (64-bit), neither in native x64 processes nor in Wow64 processes. In native x64 processes, the whole UNICODE_STRING structure is set to zero and in Wow64 processes, it just has an empty string

According to the link below, it has been found to be an anti-debug trick for Vista (32-bit). Actually i don't have Windows Vista (32-bit) to test.
http://www.symantec.com/connect/articles/windows-anti-debug-reference

  0x200x20     July 31, 2012 14:34.21 CDT
Thanks a lot, waleedassar.

  waleedassar     August 12, 2012 22:37.42 CDT
To investigate more about this structure, you can check the "ntdll!LdrpLoadImportModule" function in XP. Just in case someone needs that.

Note: Registration is required to post to the forums.

There are 29,892 total registered users.


Recently Created Topics
Decompiling raw bina...
May/22
Incorrect bitness wh...
May/20
PaiMei stalker modul...
May/19
Attach to program us...
May/13
IDA PRO how to make ...
May/12
FACT: OpenRCE is dead.
May/08
Int 3 anti debug?
May/05
help needed - Beginn...
May/03
Attaching IDA Pro to...
Apr/27
File type
Apr/21


Recent Forum Posts
Ollydbg 2.0 - Plugin...
openrce...
IDA PRO how to make ...
codeinject
FACT: OpenRCE is dead.
codeinject
IDA Resource Viewer ...
r2x64
FACT: OpenRCE is dead.
djnemo
FACT: OpenRCE is dead.
codeinject
FACT: OpenRCE is dead.
pedram
help needed - Beginn...
araujo
Attaching IDA Pro to...
codeinject
Int 3 anti debug?
codeinject


Recent Blog Entries
nfljerseysmart
May/23


nfljerseysmart
May/23


laangels
May/22
The Reason You Need A Mark ...

laangels
May/22
Buy Albert Pujols Jersey an...

lowpriority
Apr/13
OllyMigrate Plugin for Olly...

More ...


Recent Blog Comments
clarisonic on:
Apr/03
New version of Ollydbg!

clarisonic on:
Apr/03
New version of Ollydbg!

trackerx90 on:
Mar/04
SuppressDebugMsg As Anti-De...

coachfactory on:
Feb/25
Portable Executable Format ...

coachfactory on:
Feb/25
A new Anti-Olly trick.

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit