﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>C++博客-S.l.e!ep.￠%-随笔分类-RootKit</title><link>http://www.cppblog.com/sleepwom/category/12162.html</link><description>某天睡觉醒来，我发现我会开机了~~~ &lt;br&gt;
方法，过程，目标，成就 &lt;br&gt;
是时候起兵作反了~&lt;br&gt;
不要太多感情&lt;br&gt;
</description><language>zh-cn</language><lastBuildDate>Mon, 12 Jul 2010 03:44:08 GMT</lastBuildDate><pubDate>Mon, 12 Jul 2010 03:44:08 GMT</pubDate><ttl>60</ttl><item><title>Load Driver</title><link>http://www.cppblog.com/sleepwom/archive/2010/07/10/119977.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Sat, 10 Jul 2010 09:19:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/07/10/119977.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/119977.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/07/10/119977.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/119977.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/119977.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/07/10/119977.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/119977.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-07-10 17:19 <a href="http://www.cppblog.com/sleepwom/archive/2010/07/10/119977.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>protect_pwd.txt</title><link>http://www.cppblog.com/sleepwom/archive/2010/07/02/119170.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Fri, 02 Jul 2010 07:18:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/07/02/119170.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/119170.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/07/02/119170.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/119170.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/119170.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/07/02/119170.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/119170.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-07-02 15:18 <a href="http://www.cppblog.com/sleepwom/archive/2010/07/02/119170.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title> Windows下Hook API技术 inline hook</title><link>http://www.cppblog.com/sleepwom/archive/2010/07/02/119135.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Fri, 02 Jul 2010 00:20:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/07/02/119135.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/119135.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/07/02/119135.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/119135.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/119135.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/07/02/119135.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/119135.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-07-02 08:20 <a href="http://www.cppblog.com/sleepwom/archive/2010/07/02/119135.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>对付API-splicing的一种简单方法</title><link>http://www.cppblog.com/sleepwom/archive/2010/07/02/119134.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Fri, 02 Jul 2010 00:19:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/07/02/119134.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/119134.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/07/02/119134.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/119134.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/119134.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/07/02/119134.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/119134.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-07-02 08:19 <a href="http://www.cppblog.com/sleepwom/archive/2010/07/02/119134.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>修改IAT实现API HOOK</title><link>http://www.cppblog.com/sleepwom/archive/2010/07/01/119062.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Thu, 01 Jul 2010 06:57:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/07/01/119062.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/119062.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/07/01/119062.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/119062.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/119062.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/07/01/119062.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/119062.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-07-01 14:57 <a href="http://www.cppblog.com/sleepwom/archive/2010/07/01/119062.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>API-HOOK and ANTI-API-HOOK For Ring3</title><link>http://www.cppblog.com/sleepwom/archive/2010/03/15/109733.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Mon, 15 Mar 2010 06:36:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/03/15/109733.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/109733.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/03/15/109733.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/109733.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/109733.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/03/15/109733.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/109733.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-03-15 14:36 <a href="http://www.cppblog.com/sleepwom/archive/2010/03/15/109733.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>API Hook jmp 法</title><link>http://www.cppblog.com/sleepwom/archive/2010/03/12/109536.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Fri, 12 Mar 2010 07:32:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/03/12/109536.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/109536.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/03/12/109536.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/109536.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/109536.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/03/12/109536.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/109536.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-03-12 15:32 <a href="http://www.cppblog.com/sleepwom/archive/2010/03/12/109536.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title> DirectX Input 键盘实现 收藏 </title><link>http://www.cppblog.com/sleepwom/archive/2010/03/12/109533.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Fri, 12 Mar 2010 07:01:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/03/12/109533.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/109533.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/03/12/109533.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/109533.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/109533.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/03/12/109533.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/109533.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-03-12 15:01 <a href="http://www.cppblog.com/sleepwom/archive/2010/03/12/109533.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>一个反键盘记录工具的分析</title><link>http://www.cppblog.com/sleepwom/archive/2010/03/09/109281.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Tue, 09 Mar 2010 07:34:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/03/09/109281.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/109281.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/03/09/109281.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/109281.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/109281.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/03/09/109281.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/109281.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-03-09 15:34 <a href="http://www.cppblog.com/sleepwom/archive/2010/03/09/109281.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>不用hook 实现挂机锁</title><link>http://www.cppblog.com/sleepwom/archive/2010/02/08/107530.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Mon, 08 Feb 2010 13:28:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/08/107530.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107530.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/08/107530.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107530.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107530.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/08/107530.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107530.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-08 21:28 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/08/107530.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>about Injection (2)</title><link>http://www.cppblog.com/sleepwom/archive/2010/02/07/107441.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Sun, 07 Feb 2010 09:23:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/07/107441.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107441.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/07/107441.html#Feedback</comments><slash:comments>2</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107441.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107441.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/07/107441.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107441.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-07 17:23 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/07/107441.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>DLL_THREAD_DETACH 认识误区</title><link>http://www.cppblog.com/sleepwom/archive/2010/02/07/107440.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Sun, 07 Feb 2010 09:18:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/07/107440.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107440.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/07/107440.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107440.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107440.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/07/107440.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107440.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-07 17:18 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/07/107440.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>enum all modules</title><link>http://www.cppblog.com/sleepwom/archive/2010/02/06/107395.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Sat, 06 Feb 2010 10:36:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/06/107395.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107395.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/06/107395.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107395.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107395.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/06/107395.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107395.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-06 18:36 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/06/107395.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>about Injection</title><link>http://www.cppblog.com/sleepwom/archive/2010/02/06/107225.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Fri, 05 Feb 2010 20:38:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/06/107225.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107225.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/06/107225.html#Feedback</comments><slash:comments>2</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107225.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107225.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/06/107225.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107225.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-06 04:38 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/06/107225.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Injective Code inside Import Table</title><link>http://www.cppblog.com/sleepwom/archive/2010/02/05/107316.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Fri, 05 Feb 2010 15:36:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/05/107316.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107316.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/05/107316.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107316.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107316.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/05/107316.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107316.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-05 23:36 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/05/107316.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>CreateRemoteThread-实现进程代码注入</title><link>http://www.cppblog.com/sleepwom/archive/2010/02/05/107309.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Fri, 05 Feb 2010 13:33:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/05/107309.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107309.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/05/107309.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107309.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107309.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/05/107309.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107309.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-05 21:33 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/05/107309.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>利用CreateRemoteThread进行远程代码注入的技术在64位机上可能遇到的问题</title><link>http://www.cppblog.com/sleepwom/archive/2010/02/05/107306.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Fri, 05 Feb 2010 13:15:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/05/107306.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107306.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/05/107306.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107306.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107306.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/05/107306.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107306.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-05 21:15 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/05/107306.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>SeDebugPrivilege 特权</title><link>http://www.cppblog.com/sleepwom/archive/2010/02/05/107233.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Fri, 05 Feb 2010 04:07:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/05/107233.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107233.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/05/107233.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107233.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107233.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/05/107233.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107233.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-05 12:07 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/05/107233.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>SetProcessShutdownParameters Function</title><link>http://www.cppblog.com/sleepwom/archive/2010/02/05/107229.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Fri, 05 Feb 2010 03:28:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/05/107229.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107229.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/05/107229.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107229.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107229.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/05/107229.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107229.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-05 11:28 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/05/107229.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>ShutdownBlockReasonCreate Function</title><link>http://www.cppblog.com/sleepwom/archive/2010/02/05/107227.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Fri, 05 Feb 2010 03:18:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/05/107227.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107227.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/05/107227.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107227.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107227.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/05/107227.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107227.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-05 11:18 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/05/107227.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>windows平台.lnk文件感染技术研究</title><link>http://www.cppblog.com/sleepwom/archive/2010/02/04/107191.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Thu, 04 Feb 2010 09:42:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/04/107191.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107191.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/04/107191.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107191.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107191.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/04/107191.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107191.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-04 17:42 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/04/107191.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>绕过主动防御的代码Inject方法思考</title><link>http://www.cppblog.com/sleepwom/archive/2010/02/03/107096.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Wed, 03 Feb 2010 04:49:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/03/107096.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107096.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/03/107096.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107096.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107096.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/03/107096.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107096.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-03 12:49 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/03/107096.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>HOOK钩子机制学习笔记(3) - 钩子常用结构体MSDN翻译整理 收藏</title><link>http://www.cppblog.com/sleepwom/archive/2010/02/03/107093.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Wed, 03 Feb 2010 04:41:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/03/107093.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107093.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/03/107093.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107093.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107093.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/03/107093.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107093.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-03 12:41 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/03/107093.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>HOOK钩子机制学习笔记(4) - 钩子函数说明 收藏 </title><link>http://www.cppblog.com/sleepwom/archive/2010/02/03/107094.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Wed, 03 Feb 2010 04:41:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/03/107094.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107094.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/03/107094.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107094.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107094.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/03/107094.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107094.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-03 12:41 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/03/107094.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>HOOK钩子机制学习笔记(2) - 钩子类型MSDN翻译整理 收藏 </title><link>http://www.cppblog.com/sleepwom/archive/2010/02/03/107092.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Wed, 03 Feb 2010 04:40:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/03/107092.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107092.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/03/107092.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107092.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107092.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/03/107092.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107092.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-03 12:40 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/03/107092.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>HOOK钩子机制学习笔记(1) 收藏 </title><link>http://www.cppblog.com/sleepwom/archive/2010/02/03/107091.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Wed, 03 Feb 2010 04:39:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/03/107091.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107091.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/03/107091.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107091.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107091.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/03/107091.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107091.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-03 12:39 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/03/107091.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>DLL Inject -- 一、Windows 钩子（Hooks） - (2)</title><link>http://www.cppblog.com/sleepwom/archive/2010/02/03/107090.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Wed, 03 Feb 2010 04:38:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/03/107090.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107090.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/03/107090.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107090.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107090.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/03/107090.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107090.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-03 12:38 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/03/107090.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>DLL Inject -- 一、Windows 钩子（Hooks） - (1)</title><link>http://www.cppblog.com/sleepwom/archive/2010/02/03/106672.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Wed, 03 Feb 2010 04:07:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/03/106672.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/106672.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/03/106672.html#Feedback</comments><slash:comments>3</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/106672.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/106672.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/03/106672.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/106672.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-03 12:07 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/03/106672.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>显示某进程里所有模块信息</title><link>http://www.cppblog.com/sleepwom/archive/2010/02/02/107052.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Tue, 02 Feb 2010 14:39:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/02/107052.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107052.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/02/107052.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107052.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107052.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/02/107052.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107052.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-02 22:39 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/02/107052.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Hook Api lib 0.4 for C </title><link>http://www.cppblog.com/sleepwom/archive/2010/02/02/107051.html</link><dc:creator>S.l.e!ep.￠%</dc:creator><author>S.l.e!ep.￠%</author><pubDate>Tue, 02 Feb 2010 14:03:00 GMT</pubDate><guid>http://www.cppblog.com/sleepwom/archive/2010/02/02/107051.html</guid><wfw:comment>http://www.cppblog.com/sleepwom/comments/107051.html</wfw:comment><comments>http://www.cppblog.com/sleepwom/archive/2010/02/02/107051.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/sleepwom/comments/commentRss/107051.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/sleepwom/services/trackbacks/107051.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp; 摘要: &nbsp;&nbsp;<a href='http://www.cppblog.com/sleepwom/archive/2010/02/02/107051.html'>阅读全文</a><img src ="http://www.cppblog.com/sleepwom/aggbug/107051.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/sleepwom/" target="_blank">S.l.e!ep.￠%</a> 2010-02-02 22:03 <a href="http://www.cppblog.com/sleepwom/archive/2010/02/02/107051.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item></channel></rss>