1606, 9/81 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   havu
   http://havu.tistory.com
   [ÀÚÀÛ]ÇÁ·Î¼¼½º¸ð´ÏÅÍOperationÇÊÅÍ

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=1919 [º¹»ç]


- Process and Thread Activity ³»¿ë ºÐ¼®
   ? Process and Thread ActivityÀÇ Operation
      ¡æ Process/Thread Create : ÇÁ·Î¼¼½º/¾²·¹µå »ý¼º
      ¡æ Process/Thread Start : ÇÁ·Î¼¼½º/¾²·¹µå ½ÃÀÛ
      ¡æ Load Image : À̹ÌÁö¸¦ ÀÐÀ½

- File System Activity ³»¿ë ºÐ¼®
   ? Operation
      ¡æ CreateFile : ÆÄÀÏÀ» ¸¸µé°Å³ª ÀÌ¹Ì ¸¸µé¾îÁ® ÀÖ´Â ÆÄÀÏÀ» ¿°, ÆÄÀÏ »Ó¸¸ ¾Æ´Ï¶ó
                               ÆÄÀÌÇÁ, ¸ÞÀÏ ½½·Ô, ÄÜ¼Ö µîÀÇ ¿ÀºêÁ§Æ®¸¦ ¸¸µé°Å³ª ¿­±âµµ ÇÔ
      ¡æ WriteFile : ÆÄÀÏ¿¡ µ¥ÀÌÅ͸¦ ¾¸
      ¡æ ReadFile : ÆÄÀÏ¿¡¼­ µ¥ÀÌÅ͸¦ ÀÐÀ½
      ¡æ CopyFile : ÆÄÀÏÀ» º¹»ç
      ¡æ MoveFile : ÆÄÀÏÀ» À̵¿
      ¡æ DeleteFile : ÆÄÀÏÀ» »èÁ¦
      ¡æ CloseFile : ÆÄÀÏÀ» ´ÝÀ½
      ¡æ CreateFileMapping : MMF(Memory Mapped File) »ý¼º, ÀϹÝÀûÀ¸·Î ½ÇÇà                                       
          ÆÄÀÏ(EXE, DLL)µéÀÌ ½ÇÇàµÇ¸é MMF°¡ µÊ
      ¡æ LockFile : ¹ÙÀÌÆ® ¹üÀ§·Î ÁöÁ¤µÈ ÆÄÀÏ Àá±Ý
      ¡æ UnlockFileSingle : ¹ÙÀÌÆ® ¹üÀ§·Î Àá±ÝµÈ ÆÄÀÏÀ» ÇØÁ¦(unlock)
      ¡æ FileSystemControl : ÁöÁ¤µÈ ÆÄÀÏ ½Ã½ºÅÛÀ̳ª ÆÄÀÏ ½Ã½ºÅÛ ÇÊÅÍ µå¶óÀ̹ö¿¡ Á÷Á¢                         
          Á¦¾î Äڵ带 º¸³»¾î, ÇØ´ç µå¶óÀ̹ö°¡ ÁöÁ¤µÈ ÀÛ¾÷À» ¼öÇàÇÏ°Ô ÇÔ
      ¡æ QueryNameInformationFile : ÆÄÀÏ °´Ã¼¿¡ ´ëÇÑ Á¤º¸¸¦ ¹Ýȯ. À̸§ÀÇ Çü½Ä¿¡ ´ëÇÑ                         
          ÀÚ¼¼ÇÑ Á¤º¸¸¦ ¹Ýȯ
      ¡æ QueryStandardInformationFile : ÆÄÀÏ °´Ã¼¿¡ ´ëÇÑ Á¤º¸¸¦ ¹Ýȯ. ¹ÙÀÌÆ® ´ÜÀ§ ÆÄÀÏ                         
          ÇÒ´ç Å©±â, ¹ÙÀÌÆ® ¿ÀÇÁ¼ÂÀÇ ÆÄÀÏ À§Ä¡ÀÇ ³¡, ÆÄÀÏ¿¡ ´ëÇÑ Çϵ帵ũ¼ö, ÆÄÀÏ °´Ã¼°¡ µð·ºÅ丮ÀÎÁöÀÇ Á¤º¸
      ¡æ QueryInformationVolume : ƯÁ¤ ÆÄÀÏ, µð·ºÅ丮, ÀúÀåÀåÄ¡ ¶Ç´Â º¼·ý°ú ¿¬°áµÈ                         
          º¼·ý¿¡ ´ëÇÑ Á¤º¸¸¦ °Ë»ö
      ¡æ QueryDirectory : ±âÁ¸ µð·ºÅ丮¸¦ ¿°. µð·ºÅ丮 °³Ã¼¿¡ Äõ¸® ¾×¼¼½º

  Hit : 13293     Date : 2012/01/10 02:34



    
1446   °³ÀÎÁ¤º¸ À̿볻¿ª ÅëÁöÁ¦µµ¶õ     HongMK900
08/13 13946
1445   ±¸±Û ÇØÅ·?[7]     nsh009
11/06 13849
1444   3¹øÂ°c°­ÁÂÀÔ´Ï´Ù~¤»[8]     ±«µµjs
07/14 13818
1443   ³×Æ®¿öÅ© °³³ä ÈÖ¾îÀâ±â 5[10]     ¼ÒÀ¯
09/14 13781
1442   [ÀÚÀÛ] W's ¾ÏÈ£ÇÐ(Cryptology) - ½ºÆÄ¸£Åº ¾ÏÈ£,½ÃÀú(¾ËÆÄºªÄ¡È¯)¾ÏÈ£[11]     williamlee
07/28 13731
1441   "ÇØÄ¿°¡ µÇ·Á¸é ¹«¾ùÀ» ¾Ë¾Æ¾ß Çϳª¿ä?" ÀÇ ´äº¯(¹ßÃé)[48]     mati
08/01 13715
1440   c¾ð¾î for¹®      hacs98
06/15 13682
1439   * ÇØÄ¿°¡ µÇ°í½Í³ª ? *[19]     HackerMapia
03/01 13601
1438   [Reverse Engineering] ¸®¹ö½ÌÀÇ ±âÃÊ - ¹ü¿ë ·¹Áö½ºÅÍ¿Í Assembly(Pop,Mov)     zen0c1de
07/18 13599
1437   Ãʺ¸°¡ Àû¾îº» À©µµ¿ì ħÅõ[6]     awsedr45
12/06 13537
1436   [Æß]ÇØÄ¿µéÀÇ ÈçÀûÁö¿ì´Â¹æ¹ý[28]     starztp
10/08 13524
1435   ÇØÄ¿°¡ µÇ±âÀ§ÇØ ¾Ë¾Æ¾ßÇÒ 30°¡Áö Ãâó :ÇØÄ¿´ëÇÐ[5]     asdzxc301
12/12 13519
1434   ping¾Æ´Â Ä«Æä ÇØÅ· °í¼ö´Ô¿¡°Ô µéÀº ¼Ò¸®ÀÔ´Ï´Ù[21]     Àå¼¼¸¸
07/14 13466
1433   [Æß] ¾Ë°íÀÖÀ¸¸é À¯¿ëÇÑ µµ½º ¸í·É¾îµé.[2]     dzhfldk
08/22 13460
1432   C¾ð¾î(Áø¹ý)[9]     whqkdnf000
02/25 13422
1431   cmd [¸í·ÉÇÁ·ÒÇÁÆ®] ·Î ÇØÄ¿½ºÄðÁ¢¼Ó¹æ¹ý[30]     HackerMapia
01/12 13420
1430   C¾ð¾î ±âº»±¸Á¶[1]     ±«µµjs
07/02 13325
1429   C¾ð¾î ÇÔ¼ö ¿ä¾à[5]     qkreoghks00
11/15 13318
1428   [Æß] À©µµ¿ì XP ¼Óµµ Çâ»ó ÆÁ     dzhfldk
08/04 13313
1427   GetProcAddress ·Î ¾Ë¾Æº¸´Â Ű¿öµå     HongMK900
08/13 13301
[1][2][3][4][5][6][7][8] 9 [10]..[81]

Copyright 1999-2025 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org