1606, 1/81 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   havu
   http://havu.tistory.com
   [ÀÚÀÛ]ÇÁ·Î¼¼½º¸ð´ÏÅÍOperationÇÊÅÍ

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=1919 [º¹»ç]


- Process and Thread Activity ³»¿ë ºÐ¼®
   ? Process and Thread ActivityÀÇ Operation
      ¡æ Process/Thread Create : ÇÁ·Î¼¼½º/¾²·¹µå »ý¼º
      ¡æ Process/Thread Start : ÇÁ·Î¼¼½º/¾²·¹µå ½ÃÀÛ
      ¡æ Load Image : À̹ÌÁö¸¦ ÀÐÀ½

- File System Activity ³»¿ë ºÐ¼®
   ? Operation
      ¡æ CreateFile : ÆÄÀÏÀ» ¸¸µé°Å³ª ÀÌ¹Ì ¸¸µé¾îÁ® ÀÖ´Â ÆÄÀÏÀ» ¿°, ÆÄÀÏ »Ó¸¸ ¾Æ´Ï¶ó
                               ÆÄÀÌÇÁ, ¸ÞÀÏ ½½·Ô, ÄÜ¼Ö µîÀÇ ¿ÀºêÁ§Æ®¸¦ ¸¸µé°Å³ª ¿­±âµµ ÇÔ
      ¡æ WriteFile : ÆÄÀÏ¿¡ µ¥ÀÌÅ͸¦ ¾¸
      ¡æ ReadFile : ÆÄÀÏ¿¡¼­ µ¥ÀÌÅ͸¦ ÀÐÀ½
      ¡æ CopyFile : ÆÄÀÏÀ» º¹»ç
      ¡æ MoveFile : ÆÄÀÏÀ» À̵¿
      ¡æ DeleteFile : ÆÄÀÏÀ» »èÁ¦
      ¡æ CloseFile : ÆÄÀÏÀ» ´ÝÀ½
      ¡æ CreateFileMapping : MMF(Memory Mapped File) »ý¼º, ÀϹÝÀûÀ¸·Î ½ÇÇà                                       
          ÆÄÀÏ(EXE, DLL)µéÀÌ ½ÇÇàµÇ¸é MMF°¡ µÊ
      ¡æ LockFile : ¹ÙÀÌÆ® ¹üÀ§·Î ÁöÁ¤µÈ ÆÄÀÏ Àá±Ý
      ¡æ UnlockFileSingle : ¹ÙÀÌÆ® ¹üÀ§·Î Àá±ÝµÈ ÆÄÀÏÀ» ÇØÁ¦(unlock)
      ¡æ FileSystemControl : ÁöÁ¤µÈ ÆÄÀÏ ½Ã½ºÅÛÀ̳ª ÆÄÀÏ ½Ã½ºÅÛ ÇÊÅÍ µå¶óÀ̹ö¿¡ Á÷Á¢                         
          Á¦¾î Äڵ带 º¸³»¾î, ÇØ´ç µå¶óÀ̹ö°¡ ÁöÁ¤µÈ ÀÛ¾÷À» ¼öÇàÇÏ°Ô ÇÔ
      ¡æ QueryNameInformationFile : ÆÄÀÏ °´Ã¼¿¡ ´ëÇÑ Á¤º¸¸¦ ¹Ýȯ. À̸§ÀÇ Çü½Ä¿¡ ´ëÇÑ                         
          ÀÚ¼¼ÇÑ Á¤º¸¸¦ ¹Ýȯ
      ¡æ QueryStandardInformationFile : ÆÄÀÏ °´Ã¼¿¡ ´ëÇÑ Á¤º¸¸¦ ¹Ýȯ. ¹ÙÀÌÆ® ´ÜÀ§ ÆÄÀÏ                         
          ÇÒ´ç Å©±â, ¹ÙÀÌÆ® ¿ÀÇÁ¼ÂÀÇ ÆÄÀÏ À§Ä¡ÀÇ ³¡, ÆÄÀÏ¿¡ ´ëÇÑ Çϵ帵ũ¼ö, ÆÄÀÏ °´Ã¼°¡ µð·ºÅ丮ÀÎÁöÀÇ Á¤º¸
      ¡æ QueryInformationVolume : ƯÁ¤ ÆÄÀÏ, µð·ºÅ丮, ÀúÀåÀåÄ¡ ¶Ç´Â º¼·ý°ú ¿¬°áµÈ                         
          º¼·ý¿¡ ´ëÇÑ Á¤º¸¸¦ °Ë»ö
      ¡æ QueryDirectory : ±âÁ¸ µð·ºÅ丮¸¦ ¿°. µð·ºÅ丮 °³Ã¼¿¡ Äõ¸® ¾×¼¼½º

  Hit : 13279     Date : 2012/01/10 02:34



    
     [°øÁö] °­Á¸¦ ¿Ã¸®½Ç ¶§´Â ¸»¸Ó¸®¸¦ ´Þ¾ÆÁÖ¼¼¿ä^¤Ñ^ [29] ¸Û¸Û 02/27 19987
1605   ARP ½ºÇªÇÎ - Part.1 -     ÇØÅ·ÀßÇϰí½Í´Ù
04/20 32
1604   http ½º´ÏÆÛ ±¸Çö     ÇØÅ·ÀßÇϰí½Í´Ù
04/20 18
1603   pcapÀ¸·Î ÆÐŶ ½º´ÏÆÛ ±¸ÇöÇϱ⠠   ÇØÅ·ÀßÇϰí½Í´Ù
04/20 19
1602   ÇØÄ¿½ºÄ𠸸ȭÀÇ ÀÚµ¿À¸·Î ½ºÄµÇÏ´Â ÇÁ·Î±×·¥     ÇØÅ·ÀßÇϰí½Í´Ù
02/18 459
1601   ½Ã½ºÅÛ ÄÝ ÃßÀû È®ÀåÆÇ[2]     ÇØÅ·ÀßÇϰí½Í´Ù
01/19 616
1600   °£´ÜÇÑ ½Ã½ºÅÛ ÄÝ ÃßÀû ÇÁ·Î±×·¥ ¸¸µé±â     ÇØÅ·ÀßÇϰí½Í´Ù
01/18 608
1599   [overthewire.org] - leviathan1     ÇØÅ·ÀßÇϰí½Í´Ù
01/14 936
1598   [overthewire.org] - leviathan0     ÇØÅ·ÀßÇϰí½Í´Ù
01/14 670
1597   [Write Up] Crypto Cat's CTF 2024 - BabyFlow     ÇØÅ·ÀßÇϰí½Í´Ù
12/29 644
1596   [pwnable.kr] bof     ÇØÅ·ÀßÇϰí½Í´Ù
12/25 667
1595   [pwnable.kr] Shellshock[1]     ÇØÅ·ÀßÇϰí½Í´Ù
11/23 776
1594   ShellshockÀÇ ±âº» ¿ä¾à     ÇØÅ·ÀßÇϰí½Í´Ù
11/23 752
1593   [pwnable.kr] fd     ÇØÅ·ÀßÇϰí½Í´Ù
11/23 745
1592   VPNÀÌ ¿¬°áµÇ¾ú´Ù°¡ µµÁß¿¡ ²¨µµ À¥ ºê¶ó¿ìÀú»ó¿¡¼­ À¯ÁöµÇ´Â ÀÌÀ¯     ÇØÅ·ÀßÇϰí½Í´Ù
11/22 685
1591   ÇØÄ¿µéÀÌ ÇØÅ·½Ã »ç¿ëÇÏ´Â µð·ºÅ丮 °ø°£[1]     ÇØÅ·ÀßÇϰí½Í´Ù
11/22 770
1590   Keyboard Hooking -part2 - (Python3 ver)     ÇØÅ·ÀßÇϰí½Í´Ù
11/20 716
1589   [Windows API] Keyboard Hooking     ÇØÅ·ÀßÇϰí½Í´Ù
11/20 544
1588   [pwnable.kr] cmd1 °ø·«     ÇØÅ·ÀßÇϰí½Í´Ù
10/23 719
1587   netdiscover ÆÄÀ̽ãÀ¸·Î ±¸ÇöÇϱ⠠   ÇØÅ·ÀßÇϰí½Í´Ù
08/13 900
1 [2][3][4][5][6][7][8][9][10]..[81]

Copyright 1999-2025 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org