Tags » WoW64

DLL/PIC Injection on Windows from Wow64 process

Introduction

Injecting PIC (Position Independent Code) into a remote process is trivial enough for a programmer but if they try using CreateRemoteThread() API from Wow64 against a 64-bit process, it fails. 1,493 more words

Assembly

Asmcodes: Platform Independent PIC for Loading DLL and Executing Commands

Introduction

A PIC (Position Independent Code) is a set of CPU instructions that will execute successfully regardless of where it resides in memory.

The general idea is that it doesn’t depend on any external API or library and if it does, it’ll locate what it needs and still manage to run smoothly. 1,719 more words

Assembly

Windows 64-bit đạt mức an toàn cao

Fixix.net –
Fixix.net – Apple ngừng chặn SkyDrive của Microsoft.
.
Windows 64-bit hiện nay đều xuất hiện trên các máy tính mới trong thời gian gần đây, bao gồm cả Windows 7 lẫn Windows 8. 19 more words

Fixix

Windows 64-bit đạt mức an toàn cao

Fixix.net –
Fixix.net – Apple ngừng chặn SkyDrive của Microsoft.
.
Windows 64-bit hiện nay đều xuất hiện trên các máy tính mới trong thời gian gần đây, bao gồm cả Windows 7 lẫn Windows 8. 19 more words

Fixix

32-bit app on 64-bit Windows(32位应用程序 on 64位操作系统)

WOW64提供向后兼容的功能
|- WOW64代表Windows 32-bit on Windows 64-bit

WOW64文件位置
|- 32位应用程序 C:\Program Files (x86)
|- 64位应用程序 C:\Program Files
|- 32位系统文件 C:\Windows\System32(虽然叫32但并不是32位的意思)
|- 64位系统文件 C:\Windows\SysWOW64

WOW64向前兼容功能
|- 32位应用程序原本会调用C:\Program Files和C:\Windows\System32的文件 19 more words

Windows

Windows Installer error when upgrading from vCenter 4.x to 5.0

When upgrading a vCenter server from version 4.x to 5.0, you may encounter an error:

“The Windows installer service could not be accessed. This can occur if you are running windows in safe mode, or if windows installer is not correctly installed.

189 more words
Virtualization

[Delphi]PEB from WoW64 Process

playing PEB (Process Environment Block) again :D. Now try Extract PEB information from 64bit process, use Wow64 api.

about WoW64 :
http://en.wikipedia.org/wiki/WoW64
http://msdn.microsoft.com/en-us/library/aa384274(v=vs.85).aspx

Instead of using the x86 system-service call sequence, 32-bit binaries that make system calls are rebuilt to use a custom calling sequence.

1,107 more words
Coding