Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

locate the base address in a 32-bit process of NTDLL ( Use inline assembly or straight assembly (demod in class), load the value of NTDLL

locate the base address in a 32-bit process of NTDLL (Use inline assembly or straight assembly (demod in class), load the value of NTDLL base into memory or a register)

The goal of part 1 is to locate the base address (i.e. image base) of NTDLL. To do this, we will utilize the FS register and a structure called the Process Environment Block (PEB). You can find more information about the PEB structure on MSDN: https://msdn.microsoft.com/en-us/library/windows/desktop/aa813706(v=vs.85).aspx.

Use inline assembly or straight assembly (demod in class), load the value of NTDLL base into memory or a register, and print the value as proof that you were successful. For example:

image text in transcribed

(#] Found NT DLL Base at 0x776b0000

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

101 Database Exercises Text Workbook

Authors: McGraw-Hill

2nd Edition

0028007484, 978-0028007489

More Books

Students also viewed these Databases questions

Question

When is it appropriate to use a root cause analysis

Answered: 1 week ago