User-mode System Call Hooking


Interesting method to make compatible between sp2 and sp3, but couldn't you just use a short jump to the Mov ESP, [ESP] filler instructions following KiFastSystemCallRet and put long jump there?? Jmp+11 seems to be safe in both service packs :)

BoB, your method also works fine. I have also added it as a note to the blog post. Thanks for letting me know.

