REGISTER
desert eagle
main menu

home

forums
    Show me new threads!

bookmarks

view blogs

vault

you must be level 2 to upload files to your vault

downloads

you must be logged on, and level 1, to access downloads

Rootkit Collection

File Contributer Link
Hacker Def... hfn/a
HE4Hook adminn/a
BASIC CLAS... hoglundn/a
Vanquish xshadown/a
NT Rootkit hoglundn/a
FU fuzen_opn/a
WinlogonHi... JeFFOsZn/a
klister joannan/a
Patchfinde... joannan/a
MyNetwork hoglundn/a
MTDWin hoglundn/a
NTFSHider hoglundn/a
VideoCardK... hoglundn/a
VICE fuzen_opn/a
Klog Clandestin...n/a
NtIllusion Kdmn/a
AFX Rootki... TheRealAph...n/a
SInAR vulndevn/a
Shadow Wal... Clandestin...n/a
BootRootki... dereksoede...n/a
CHAZ - Nim... neocrackrn/a
Clandestin... merlvingia...n/a
FUTo petersilbe...n/a
Windows Me... alcapone66...n/a
RAIDE petersilbe...n/a
BOOT KIT vipinkumarn/a
BluePill Joanna and...n/a
DEFRAG blume1975n/a
Keyboard H... chpien/a
CheatEngin... DarkByten/a

search the site

Proper way to hide files/directories aka the FsFilter way aka bypass Flister : message board

post a message

Show all posts in this forum

view options: unpacked threads | | old style view

how many threads to display:

search board (text+titles):


Posted by bluesky (Untrusted stranger) [ip info hidden] - Feb 15 2005, 05:50 (UTC+0)
No guarantee for FileInfo value
It seems that the value for FileInformationClass is not guaranteed to be correct when the IRP is returning from the lower drivers. Thus would it be better if we retrieve the value of FileInfo before calling the driver?

this thread posts:

  • No guarantee for FileInfo value
    (by bluesky (Untrusted stranger) Feb 15 2005, 05:50 (UTC+0) )

    It seems that the value for FileInformationClass is not guaranteed to be correct when the IRP is returning from the lower drivers. Thus would it be better if we retrieve the value of FileInfo before calling the driver?


    • Re: No guarantee for FileInfo value
      (by valerino (Normal user) Feb 15 2005, 09:01 (UTC+0) )

      Who said that ?
      The irp is not yet completed (you must complete it yourself), so the buffer is ofcourse still valid.

      valerio



As a computer, I find your faith in technology amusing.