﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>博客园-木桩的Blog-最新评论</title><link>http://www.cnblogs.com/bits/CommentsRSS.aspx</link><description>慢慢整理自己的财富...</description><language>zh-cn</language><pubDate>Mon, 18 Jan 2010 06:05:18 GMT</pubDate><lastBuildDate>Mon, 18 Jan 2010 06:05:18 GMT</lastBuildDate><generator>cnblogs</generator><item><title>Re:[原创]FreeBSD下千兆双口数据包捕获的性能分析(SMP Kernel)</title><link>http://www.cnblogs.com/bits/archive/2010/08/19/1624550.html#1897019</link><dc:creator>火星一号</dc:creator><author>火星一号</author><pubDate>Thu, 19 Aug 2010 01:34:29 GMT</pubDate><guid>http://www.cnblogs.com/bits/archive/2010/08/19/1624550.html#1897019</guid><description><![CDATA[真是不错，谢谢楼主<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/bits/" target="_blank">火星一号</a> 2010-08-19 09:34 <a href="http://www.cnblogs.com/bits/archive/2010/08/19/1624550.html#1897019#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:[原创] Ring3挂钩实现网址过滤、重定向——《另类挂钩-RING3数据包监视》应用</title><link>http://www.cnblogs.com/bits/archive/2009/12/29/1598368.html#1736575</link><dc:creator>阿呆sssssssssss</dc:creator><author>阿呆sssssssssss</author><pubDate>Tue, 29 Dec 2009 01:45:18 GMT</pubDate><guid>http://www.cnblogs.com/bits/archive/2009/12/29/1598368.html#1736575</guid><description><![CDATA[请问如何注入？
<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/bits/" target="_blank">阿呆sssssssssss</a> 2009-12-29 09:45 <a href="http://www.cnblogs.com/bits/archive/2009/12/29/1598368.html#1736575#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:另类挂钩-RING3数据包监视（Delphi版）</title><link>http://www.cnblogs.com/bits/archive/2009/12/28/1401024.html#1736213</link><dc:creator>阿呆ssssssssss</dc:creator><author>阿呆ssssssssss</author><pubDate>Mon, 28 Dec 2009 12:42:18 GMT</pubDate><guid>http://www.cnblogs.com/bits/archive/2009/12/28/1401024.html#1736213</guid><description><![CDATA[ DLL_Inject有源码吗？
这个NDIC_Hook.dll 应该如何注入？<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/bits/" target="_blank">阿呆ssssssssss</a> 2009-12-28 20:42 <a href="http://www.cnblogs.com/bits/archive/2009/12/28/1401024.html#1736213#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:[原创]FreeBSD下千兆双口数据包捕获的性能分析(SMP Kernel)</title><link>http://www.cnblogs.com/bits/archive/2009/12/15/1624550.html#1724445</link><dc:creator>木桩</dc:creator><author>木桩</author><pubDate>Tue, 15 Dec 2009 05:18:05 GMT</pubDate><guid>http://www.cnblogs.com/bits/archive/2009/12/15/1624550.html#1724445</guid><description><![CDATA[CSS没调对，导致缩进后排版空出一大截。懒得改了，将就吧...<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/bits/" target="_blank">木桩</a> 2009-12-15 13:18 <a href="http://www.cnblogs.com/bits/archive/2009/12/15/1624550.html#1724445#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:另类挂钩-RING3数据包监视（Delphi版）</title><link>http://www.cnblogs.com/bits/archive/2009/11/16/1401024.html#1698905</link><dc:creator>博雅z</dc:creator><author>博雅z</author><pubDate>Sun, 15 Nov 2009 16:39:36 GMT</pubDate><guid>http://www.cnblogs.com/bits/archive/2009/11/16/1401024.html#1698905</guid><description><![CDATA[windows 7 下好像注入ie有问题。<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/bits/" target="_blank">博雅z</a> 2009-11-16 00:39 <a href="http://www.cnblogs.com/bits/archive/2009/11/16/1401024.html#1698905#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:怀念一下这些经常不记得的Delphi代码...</title><link>http://www.cnblogs.com/bits/archive/2009/09/11/1404220.html#1643765</link><dc:creator>Lenic</dc:creator><author>Lenic</author><pubDate>Fri, 11 Sep 2009 08:44:12 GMT</pubDate><guid>http://www.cnblogs.com/bits/archive/2009/09/11/1404220.html#1643765</guid><description><![CDATA[不错的东西

收藏了<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/bits/" target="_blank">Lenic</a> 2009-09-11 16:44 <a href="http://www.cnblogs.com/bits/archive/2009/09/11/1404220.html#1643765#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:怀念一下这些经常不记得的Delphi代码...</title><link>http://www.cnblogs.com/bits/archive/2009/09/03/1404220.html#1634557</link><dc:creator>木桩</dc:creator><author>木桩</author><pubDate>Thu, 03 Sep 2009 05:43:30 GMT</pubDate><guid>http://www.cnblogs.com/bits/archive/2009/09/03/1404220.html#1634557</guid><description><![CDATA[@QQ5555044
这是很久以前的代码了，最原始的方式。<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/bits/" target="_blank">木桩</a> 2009-09-03 13:43 <a href="http://www.cnblogs.com/bits/archive/2009/09/03/1404220.html#1634557#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:怀念一下这些经常不记得的Delphi代码...</title><link>http://www.cnblogs.com/bits/archive/2009/09/02/1404220.html#1633593</link><dc:creator>QQ5555044</dc:creator><author>QQ5555044</author><pubDate>Wed, 02 Sep 2009 08:22:43 GMT</pubDate><guid>http://www.cnblogs.com/bits/archive/2009/09/02/1404220.html#1633593</guid><description><![CDATA[自删写得不好，自删可以不借助外部文件，本身就可以实现，而且方法至少有两种。<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/bits/" target="_blank">QQ5555044</a> 2009-09-02 16:22 <a href="http://www.cnblogs.com/bits/archive/2009/09/02/1404220.html#1633593#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:编译 JWSCL(JEDI Windows Security Code Lib) 的方法（rev316）</title><link>http://www.cnblogs.com/bits/archive/2009/08/31/1553892.html#1630567</link><dc:creator>木桩</dc:creator><author>木桩</author><pubDate>Mon, 31 Aug 2009 01:23:27 GMT</pubDate><guid>http://www.cnblogs.com/bits/archive/2009/08/31/1553892.html#1630567</guid><description><![CDATA[新版的 jedi-apilib_r810 已经可以直接用dpk安装了，直接SVN下载源码，然后编译 JediApi_StaticRelease.dpk，自动生成dcu文件。
这个作废...<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/bits/" target="_blank">木桩</a> 2009-08-31 09:23 <a href="http://www.cnblogs.com/bits/archive/2009/08/31/1553892.html#1630567#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:[原创]把syslog接收的远程日志从/var/log/messages中分开</title><link>http://www.cnblogs.com/bits/archive/2009/08/26/1407075.html#1626420</link><dc:creator>qr_compaq</dc:creator><author>qr_compaq</author><pubDate>Wed, 26 Aug 2009 10:17:01 GMT</pubDate><guid>http://www.cnblogs.com/bits/archive/2009/08/26/1407075.html#1626420</guid><description><![CDATA[我想把apache的日志分出来：
vim /etc/httpd/conf/httpd.conf
将CustomLog logs/access_log combined
改成CustomLog &quot;| logger -t apache -p local1.info&quot; combined
vim /etc/syslog.conf
*.info;local1.none   /var/log/messages
local1.info          /var/log/apache.log
重启Apache后查看进程，有logger这个进程，但是apache日志就是转不出去，我刚想你是怎么回事，突然想起syslog服务没有重启。
嘿嘿！既然都写了，就和大家分享一下吧！

想和楼主交个朋友，能否告诉我你的邮箱啊！<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/bits/" target="_blank">qr_compaq</a> 2009-08-26 18:17 <a href="http://www.cnblogs.com/bits/archive/2009/08/26/1407075.html#1626420#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:[原创]把syslog接收的远程日志从/var/log/messages中分开</title><link>http://www.cnblogs.com/bits/archive/2009/08/26/1407075.html#1626403</link><dc:creator>bbvbvb</dc:creator><author>bbvbvb</author><pubDate>Wed, 26 Aug 2009 10:01:52 GMT</pubDate><guid>http://www.cnblogs.com/bits/archive/2009/08/26/1407075.html#1626403</guid><description><![CDATA[ok<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/bits/" target="_blank">bbvbvb</a> 2009-08-26 18:01 <a href="http://www.cnblogs.com/bits/archive/2009/08/26/1407075.html#1626403#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:一个开Telnet服务的脚本的分析（原来是这么给防火墙开洞的）</title><link>http://www.cnblogs.com/bits/archive/2009/08/10/1414292.html#1610668</link><dc:creator>？？？sdsada</dc:creator><author>？？？sdsada</author><pubDate>Mon, 10 Aug 2009 08:36:43 GMT</pubDate><guid>http://www.cnblogs.com/bits/archive/2009/08/10/1414292.html#1610668</guid><description><![CDATA[开了telnet才能建用户<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/bits/" target="_blank">？？？sdsada</a> 2009-08-10 16:36 <a href="http://www.cnblogs.com/bits/archive/2009/08/10/1414292.html#1610668#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 另类挂钩-RING3数据包监视（Delphi版）</title><link>http://www.cnblogs.com/bits/archive/2009/04/17/1401024.html#1505315</link><dc:creator>chjunkai</dc:creator><author>chjunkai</author><pubDate>Fri, 17 Apr 2009 01:50:12 GMT</pubDate><guid>http://www.cnblogs.com/bits/archive/2009/04/17/1401024.html#1505315</guid><description><![CDATA[今天晚上回家试试，如果可以的话，通知您一声<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/bits/" target="_blank">chjunkai</a> 2009-04-17 09:50 <a href="http://www.cnblogs.com/bits/archive/2009/04/17/1401024.html#1505315#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 另类挂钩-RING3数据包监视（Delphi版）</title><link>http://www.cnblogs.com/bits/archive/2009/04/17/1401024.html#1505191</link><dc:creator>木桩</dc:creator><author>木桩</author><pubDate>Thu, 16 Apr 2009 16:00:12 GMT</pubDate><guid>http://www.cnblogs.com/bits/archive/2009/04/17/1401024.html#1505191</guid><description><![CDATA[@chjunkai<br />这个代码是MJ0011的，原来的C语言版就没有提供卸载函数。不过从SuperHookDeviceIoControl()的挂钩过程可以大致看出还原方法：<br />uNtDeviceIoControl.pas:281<br />
<div class="cnblogs_code" twffan="done"><!--<br /><br />Code highlighting produced by Actipro CodeHighlighter (freeware)<br />http://www.CodeHighlighter.com/<br /><br />--><span style="color: #000000" twffan="done">&nbsp;&nbsp;OutputDebugString(PChar(Format(</span><span style="color: #800000" twffan="done">'</span><span style="color: #800000" twffan="done">[HOOK]&nbsp;Lock&nbsp;"%s"&nbsp;for&nbsp;HOOK.</span><span style="color: #800000" twffan="done">'</span><span style="color: #000000" twffan="done">,&nbsp;[StrPas(func_name)])));<br />&nbsp;&nbsp;</span><span style="color: #000000" twffan="done">//</span><span style="color: #000000" twffan="done"><br />&nbsp;&nbsp;</span><span style="color: #000000" twffan="done">//</span><span style="color: #000000" twffan="done">&nbsp;如果是，那么记录原始函数地址<br />&nbsp;&nbsp;</span><span style="color: #000000" twffan="done">//</span><span style="color: #000000" twffan="done">&nbsp;HOOK我们的函数地址<br />&nbsp;&nbsp;</span><span style="color: #000000" twffan="done">//</span><span style="color: #000000" twffan="done"><br />&nbsp;&nbsp;</span><span style="color: #000000" twffan="done">//</span><span style="color: #000000" twffan="done">&nbsp;序号&nbsp;&nbsp;&nbsp;RVA&nbsp;&nbsp;&nbsp;偏移&nbsp;&nbsp;Name<br />&nbsp;&nbsp;</span><span style="color: #000000" twffan="done">//</span><span style="color: #000000" twffan="done">&nbsp;&nbsp;&nbsp;9A&nbsp;&nbsp;D8E3&nbsp;&nbsp;CCE3&nbsp;&nbsp;NtDeviceIoControlFile<br />&nbsp;&nbsp;myaddr&nbsp;:</span><span style="color: #000000" twffan="done">=</span><span style="color: #000000" twffan="done">&nbsp;DWORD(@MyNtDeviceIoControlFile);<br />&nbsp;&nbsp;lpAddr&nbsp;:</span><span style="color: #000000" twffan="done">=</span><span style="color: #000000" twffan="done">&nbsp;Pointer(hMod&nbsp;</span><span style="color: #000000" twffan="done">+</span><span style="color: #000000" twffan="done">&nbsp;ImportDescriptor^.FirstThunk&nbsp;</span><span style="color: #000000" twffan="done">+</span><span style="color: #000000" twffan="done">&nbsp;DWORD(iNum</span><span style="color: #000000" twffan="done">-</span><span style="color: #800080" twffan="done">1</span><span style="color: #000000" twffan="done">)</span><span style="color: #000000" twffan="done">*</span><span style="color: #800080" twffan="done">4</span><span style="color: #000000" twffan="done">);<br />&nbsp;&nbsp;OldNtDeviceIoControl&nbsp;:</span><span style="color: #000000" twffan="done">=</span><span style="color: #000000" twffan="done">&nbsp;PDWORD(lpAddr)^;<br />&nbsp;&nbsp;<br />&nbsp;&nbsp;OutputDebugString(PChar(Format(</span><span style="color: #800000" twffan="done">'</span><span style="color: #800000" twffan="done">[HOOK]&nbsp;Base=%0.8X,&nbsp;Thunk=%0.8X,&nbsp;ID=%X</span><span style="color: #800000" twffan="done">'</span><span style="color: #000000" twffan="done">,&nbsp;[hMod,&nbsp;ImportDescriptor^.FirstThunk,&nbsp;iNum</span><span style="color: #000000" twffan="done">-</span><span style="color: #800080" twffan="done">1</span><span style="color: #000000" twffan="done">])));<br />&nbsp;&nbsp;OutputDebugString(PChar(Format(</span><span style="color: #800000" twffan="done">'</span><span style="color: #800000" twffan="done">[HOOK]&nbsp;Orign[0x%0.8X]=0x%0.8X,&nbsp;new&nbsp;Addr=0x%0.8X</span><span style="color: #800000" twffan="done">'</span><span style="color: #000000" twffan="done">,&nbsp;[DWORD(lpAddr),&nbsp;PDWORD(lpAddr)^,&nbsp;myaddr])));<br />&nbsp;&nbsp;<br />&nbsp;&nbsp;<strong>WriteProcessMemory</strong>(GetCurrentProcess(),&nbsp;lpAddr,&nbsp;@myaddr,&nbsp;</span><span style="color: #800080" twffan="done">4</span><span style="color: #000000" twffan="done">,&nbsp;btw);</span></div><br />卸载时将WriteProcessMemory修改的4个字节给还原就行了，也就是把 OldNtDeviceIoControl 中保存的原始函数地址写回去。<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/bits/" target="_blank">木桩</a> 2009-04-17 00:00 <a href="http://www.cnblogs.com/bits/archive/2009/04/17/1401024.html#1505191#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>re: 另类挂钩-RING3数据包监视（Delphi版）</title><link>http://www.cnblogs.com/bits/archive/2009/04/16/1401024.html#1504966</link><dc:creator>chjunkai</dc:creator><author>chjunkai</author><pubDate>Thu, 16 Apr 2009 09:25:23 GMT</pubDate><guid>http://www.cnblogs.com/bits/archive/2009/04/16/1401024.html#1504966</guid><description><![CDATA[你好，如果有好的当注入函数关闭时卸载浏览器NDIC_Hook.dll的方法，请写在博客里吧，或者发邮件给我，chjunkai@hotmail.com，MSN聊聊更好了<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/bits/" target="_blank">chjunkai</a> 2009-04-16 17:25 <a href="http://www.cnblogs.com/bits/archive/2009/04/16/1401024.html#1504966#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item></channel></rss>
