Jump to content
Tuts 4 You

User-mode System Call Hooking


Recommended Posts

Interesting method to make compatible between sp2 and sp3, but couldn't you just use a short jump to the Mov ESP, [ESP] filler instructions following KiFastSystemCallRet and put long jump there?? Jmp+11 seems to be safe in both service packs :)

Link to comment

BoB, your method also works fine. I have also added it as a note to the blog post. Thanks for letting me know.

Edited by waliedassar
Link to comment

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Create New...