Flag: Tornado! Hurricane!

 Forums >>  Brainstorms - General  >>  Static UNICODE_STRING buffer in TIB

Topic created on: July 30, 2012 16:32 CDT by 0x200x20 .

On offset 0xBF8 in TIB there is some UNCODE_STRING buffer. It seems to be used permanently in ReactOS by ASCII Winapi functions but I cannot find where it is used by original Windows. I have tried to put hardware breakpoint on it (Win 7 x64) but it seems it has never been used. Could you please tell by which API could it be used?

  waleedassar     July 30, 2012 17:33.44 CDT
It is not used in Windows 7 (64-bit), neither in native x64 processes nor in Wow64 processes. In native x64 processes, the whole UNICODE_STRING structure is set to zero and in Wow64 processes, it just has an empty string

According to the link below, it has been found to be an anti-debug trick for Vista (32-bit). Actually i don't have Windows Vista (32-bit) to test.
http://www.symantec.com/connect/articles/windows-anti-debug-reference

  0x200x20     July 31, 2012 14:34.21 CDT
Thanks a lot, waleedassar.

  waleedassar     August 12, 2012 22:37.42 CDT
To investigate more about this structure, you can check the "ntdll!LdrpLoadImportModule" function in XP. Just in case someone needs that.

Note: Registration is required to post to the forums.

There are 31,041 total registered users.


Recently Created Topics
Ultimate Hacking Cha...
Jun/21
CreateMutex
May/31
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Immunity Debugger Re...
Aug/03


Recent Forum Posts
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n
OOP_RE tool available?
van7hu
Should binaries be n...
Kolisar
Problem with ollydbg
nullx42
!findtrampoline Immu...
skycrack


Recent Blog Entries
crystalwade
Jul/20
test

nieo
Mar/22
Android Application Reversing

halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit