|
|
#11 |
|
Banned
Join Date: Nov 2010
Posts: 7
|
@Wizou: If you check my BgWorker plugin, you can see that I'm checking for kernel32::lstrcatW in the import table.
I also have some sample code in there that checks $pluginsdir, but like you said, you don't know the offset, so it has to use IsBadReadPtr() and there could be false positives. Unfortunately, it turns out that writing hybrid plugins is a huge pain in the ass, and I can't recommend doing it on anything except very simple plugins _______________ [ADMIN EDIT] Warning: Spam(?) links removed! |
|
|
|
|
|||||||
| Thread Tools | Search this Thread |
| Display Modes | |
|
|