Results 1 to 5 of 5

Thread: softice nmi hook

  1. #1

    softice nmi hook

    NMI (int 0x02) is by default setup as TaskGate, which means that it points to TSS Descriptor where is stored TSS needed to transfer execution to r0 when NMI occurs.

    sice not running:

    Code:
    00000002	0.00003269	TaskGate: 02 [58:00000000] DPL=0 P	
    00000003	0.00004917	 + TSS at 80872568 - cs:eip = [08:8086698C]
    sice running:
    Code:
    00000002	0.00004665	IdtGate : 02 [08:B45AE617] DPL=0 P
    No practical rce use, but still funny thing

  2. #2
    Administrator dELTA's Avatar
    Join Date
    Oct 2000
    Location
    Ring -1
    Posts
    4,206
    Blog Entries
    5
    Another SoftIce detection method (and general ring 0 gem) for the collection, thanks as usual deroko.
    "Give a man a quote from the FAQ, and he'll ignore it. Print the FAQ, shove it up his ass, kick him in the balls, DDoS his ass and kick/ban him, and the point usually gets through eventually."

  3. #3
    indeed it's sice detection, but I was playing with IPI and NMI when I saw this thingy, and completly forgot that it it can be used as sice detection

  4. #4
    parad0x
    Guest
    A little OT, but since we're talking about hooking... I was looking at your code under the "ultimate" project and had a question on where c:\tasm32\include\shitheap.inc came from? I see it referenced in many other projects but I don't see it included with the source. I'm using borland turbo assembler and tools 5.0, perhaps I should be incorporating other toolkits?
    I promise that I have read the FAQ and tried to use the Search to answer my question.

  5. #5
    parad0x:

    See my response in your "original" Post. Do not double post!

    http://www.woodmann.com/forum/showthread.php?p=72492#post72492

    Regards,
    JMI

Similar Threads

  1. Ask a question about hook again
    By dcskm4200 in forum The Newbie Forum
    Replies: 2
    Last Post: August 6th, 2006, 11:10
  2. this is a question about hook
    By dcskm4200 in forum The Newbie Forum
    Replies: 18
    Last Post: July 31st, 2006, 13:12
  3. ? hook to a dll export?
    By _Servil_ in forum OllyDbg Support Forums
    Replies: 2
    Last Post: November 17th, 2002, 11:36
  4. Best way to hook PrintScreen under Windows NT/2K
    By foxthree in forum Advanced Reversing and Programming
    Replies: 6
    Last Post: May 31st, 2002, 20:03
  5. windows hook help...
    By grosse in forum Advanced Reversing and Programming
    Replies: 3
    Last Post: March 17th, 2002, 14:05

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •