2009-11-13:

Windows Win32k syscall table

easy:windows:re:assembler
Just a quick info. j00ru has published on his blog a syscall number/name table for the Win32k syscall shadow table (user32.dll, gdi32.dll and DirectX use it) - http://j00ru.vexillium.org/win32k_syscalls/ (it's very similar to the Metasploit one, however the one on the Metasploit page contains only kernel syscalls, and this one contains only win32k syscalls). If you like digging in the low level stuff, this is definitely something worth checking out!

Add a comment:

Nick:
URL (optional):
Math captcha: 3 ∗ 8 + 4 =