<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Update: bpmtk with hook-createprocess.dll</title>
	<atom:link href="http://blog.didierstevens.com/2009/11/19/update-bpmtk-with-hook-createprocess-dll/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2009/11/19/update-bpmtk-with-hook-createprocess-dll/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Sat, 11 Feb 2012 16:16:49 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: EnforcePermanentDEP &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2009/11/19/update-bpmtk-with-hook-createprocess-dll/#comment-40469</link>
		<dc:creator><![CDATA[EnforcePermanentDEP &#171; Didier Stevens]]></dc:creator>
		<pubDate>Mon, 08 Nov 2010 00:46:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1841#comment-40469</guid>
		<description><![CDATA[[...] load this DLL inside a process, you can add it to the import table of the target process (EnforcePermanentDEP.dll exports function Dummy), use LoadDLLViaAppInit or use your own preferred [...]]]></description>
		<content:encoded><![CDATA[<p>[...] load this DLL inside a process, you can add it to the import table of the target process (EnforcePermanentDEP.dll exports function Dummy), use LoadDLLViaAppInit or use your own preferred [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: s0meb0dy</title>
		<link>http://blog.didierstevens.com/2009/11/19/update-bpmtk-with-hook-createprocess-dll/#comment-40269</link>
		<dc:creator><![CDATA[s0meb0dy]]></dc:creator>
		<pubDate>Thu, 14 Oct 2010 16:13:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1841#comment-40269</guid>
		<description><![CDATA[Thank you!

You always have very interesting post]]></description>
		<content:encoded><![CDATA[<p>Thank you!</p>
<p>You always have very interesting post</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2009/11/19/update-bpmtk-with-hook-createprocess-dll/#comment-40241</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Tue, 12 Oct 2010 06:17:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1841#comment-40241</guid>
		<description><![CDATA[@s0meb0dy Entrypoint DllMain is called when the DLL is loaded, and DllMain calls the function to patch the IAT.]]></description>
		<content:encoded><![CDATA[<p>@s0meb0dy Entrypoint DllMain is called when the DLL is loaded, and DllMain calls the function to patch the IAT.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: s0meb0dy</title>
		<link>http://blog.didierstevens.com/2009/11/19/update-bpmtk-with-hook-createprocess-dll/#comment-40234</link>
		<dc:creator><![CDATA[s0meb0dy]]></dc:creator>
		<pubDate>Mon, 11 Oct 2010 22:03:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1841#comment-40234</guid>
		<description><![CDATA[I know, quite old post, but I have a little question.

Adding hook-createprocess.dll to the import table loads the dll in the virtualaddress space of the corresponding executable, but how does the main module execute the function in the dll to patch functions of KERNEL32.dll?]]></description>
		<content:encoded><![CDATA[<p>I know, quite old post, but I have a little question.</p>
<p>Adding hook-createprocess.dll to the import table loads the dll in the virtualaddress space of the corresponding executable, but how does the main module execute the function in the dll to patch functions of KERNEL32.dll?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LowerMyRights &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2009/11/19/update-bpmtk-with-hook-createprocess-dll/#comment-40221</link>
		<dc:creator><![CDATA[LowerMyRights &#171; Didier Stevens]]></dc:creator>
		<pubDate>Mon, 11 Oct 2010 08:41:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1841#comment-40221</guid>
		<description><![CDATA[[...] You can load LowerMyRights inside all processes by adding it to the AppInit_DLL registry key, but be careful, this might cripple your system as it is loaded inside every process (even at boot time), so please test first. Or else you use LoadDLLViaAppInit, or add it to the import table like explained here. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] You can load LowerMyRights inside all processes by adding it to the AppInit_DLL registry key, but be careful, this might cripple your system as it is loaded inside every process (even at boot time), so please test first. Or else you use LoadDLLViaAppInit, or add it to the import table like explained here. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: There is a way to patch Adobe Reader (or&#8230; &#171; SecurityGuy.org</title>
		<link>http://blog.didierstevens.com/2009/11/19/update-bpmtk-with-hook-createprocess-dll/#comment-37992</link>
		<dc:creator><![CDATA[There is a way to patch Adobe Reader (or&#8230; &#171; SecurityGuy.org]]></dc:creator>
		<pubDate>Wed, 31 Mar 2010 16:49:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1841#comment-37992</guid>
		<description><![CDATA[[...] http://blog.didierstevens.com/2009/11/19/update-bpmtk-with-hook-createprocess-dll/ [...]]]></description>
		<content:encoded><![CDATA[<p>[...] <a href="http://blog.didierstevens.com/2009/11/19/update-bpmtk-with-hook-createprocess-dll/" rel="nofollow">http://blog.didierstevens.com/2009/11/19/update-bpmtk-with-hook-createprocess-dll/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LoadDLLViaAppInit &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2009/11/19/update-bpmtk-with-hook-createprocess-dll/#comment-37319</link>
		<dc:creator><![CDATA[LoadDLLViaAppInit &#171; Didier Stevens]]></dc:creator>
		<pubDate>Wed, 23 Dec 2009 12:20:38 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1841#comment-37319</guid>
		<description><![CDATA[[...] you can&#8217;t use this key to load hook-createprocess.dll, because it will load it in every process, and your Windows machine will stop [...]]]></description>
		<content:encoded><![CDATA[<p>[...] you can&#8217;t use this key to load hook-createprocess.dll, because it will load it in every process, and your Windows machine will stop [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Plaats hier software gerelateerd nieuws! - Page 14</title>
		<link>http://blog.didierstevens.com/2009/11/19/update-bpmtk-with-hook-createprocess-dll/#comment-36506</link>
		<dc:creator><![CDATA[Plaats hier software gerelateerd nieuws! - Page 14]]></dc:creator>
		<pubDate>Mon, 23 Nov 2009 17:41:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/?p=1841#comment-36506</guid>
		<description><![CDATA[[...] bestand al aan, maar nu is het voor iedereen via de &quot;basic process manipulation toolkit&quot; beschikbaar.   Een nadeel van het bestand is dat Adobe Reader en Acrobat zichzelf niet meer kunnen updaten. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] bestand al aan, maar nu is het voor iedereen via de &quot;basic process manipulation toolkit&quot; beschikbaar.   Een nadeel van het bestand is dat Adobe Reader en Acrobat zichzelf niet meer kunnen updaten. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

