Pre os injection

 HKLM\SYSTEM\CurrentControlSet\Control\ Session Manager\BootExecute (native in  C:\Windows\System32)


https://github.com/Fyyre/ntdll

https://github.com/winsiderss/phnt

 nmake msvc

linker -> system -> subsystem(native)

linker -> input -> addindependence -> path to ntdll

linker -> input -> ignore all default library -> yes

C/C++ -> general -> Add include dependence -> path to phnt

C/C++ -> code generation -> basic runtime check -> default

C/C++ -> code generation -> security check -> disable

C/C++ -> General -> debug information -> program database (/Zi)

C/C++ -> General -> SDL check -> no sdl

Nhận xét

Bài đăng phổ biến từ blog này

CVE-2023–41425 but only RCE part

Tanr man 2024