Advertisement

11.21.2008 at 09:28AM PST, ID: 23925812 | Points: 500
[x]
Attachment Details

How does the Madshi LIB hack work ?

Can someone explain how the LIB hack at the URL below works ?

http://www.experts-exchange.com/Programming/System/Windows__Programming/Q_20853012.html

How can this method allow me to build a NTDLL.LIB that links properly to e.g. RtlInitUnicodeString on both Win2000 and WinXP, without calling GetProcAddress ?

Can someone explain what is going on when the PE loader loads an executable file linked with such hacked NTDLL.LIB ?

Finally, is there a documented way to accomplish the same effect as the Madshi LIB hack ?
 
 
 
Expert Comment by DanRollins:

All comments and solutions are available to Premium Service Members only. Start your 7-day free trial to view the solution to this question.

Already a member? Login to view this solution.

 
 
Author Comment by verpies:

All comments and solutions are available to Premium Service Members only. Start your 7-day free trial to view the solution to this question.

Already a member? Login to view this solution.

 
 
Expert Comment by DanRollins:

All comments and solutions are available to Premium Service Members only. Start your 7-day free trial to view the solution to this question.

Already a member? Login to view this solution.

 
 
20081119-EE-VQP-46 - Hierarchy / EE_QW_2_20070628