Content deleted Content added
Ira Leviton (talk | contribs) Fixed a typo found with Wikipedia:Typo_Team/moss. Context and removal of jargon is needed. |
GreenC bot (talk | contribs) Move 1 url. Wayback Medic 2.5 per WP:URLREQ#symantec.com |
||
(3 intermediate revisions by 3 users not shown) | |||
Line 11:
== Hooking ==
Modification of the SSDT allows to redirect syscalls to routines outside the kernel. These routines can be either used to hide the presence of software or to act as a backdoor to allow attackers permanent code execution with kernel privileges. For both reasons, [[
In 2010, many computer security products which relied on hooking SSDT calls were shown to be vulnerable to [[Exploit (computer security)|exploits]] using [[race condition]]s to attack the products' security checks.<ref name="ZDNET2010"/>
Line 28:
[[Category:Windows technology]]
[[Category:Computer security]]
[[Category:Windows NT kernel]]
[[Category:Windows rootkit techniques]]
|