The new Xbox One home console from Microsoft is designed to increase the hardware power that developers and players can use and updates... The purpose of this video is to demonstrate a basic installation of Kali Linux from Offensive Security in a new Virtual Machine guest... | This DVD5 ISO image file contains the security updates for Windows released on Windows Update on May 14, 2013. The image does not... A standards organization has created a boot environment for tablets and PCs that could potentially run a 64-bit version of Windows RT. |
A standards organization has created a boot environment for tablets and PCs that could potentially run a 64-bit version of Windows RT. In this video we will install VMware vSphere vCenter Server 5.1.0b using the Simple Install method on Windows Server 2003 R2 X64 SP2 | Big thank you to all who've sent in Imogen plugins, they're excellent, Keep em' coming folks! This tutorial we'll look at some of the... In this tute we'll look at coding a C++ algorithm to negate a 128bpp image. This will be a benchmark to beat for the ASM versions we'll... |
The purpose of this video is to demonstrate a basic installation of Kali Linux from Offensive Security in a new Virtual Machine guest... Today, I had to install the Java plugin for 64bit Firefox on CentOS 6.4. The procedure wasn’t too bad, but it wasn’t exactly... | In this tute we'll get to coding some little ASM algorithms. First we have to look at how parameters will be passed from C++.
Today we'll look at integer data types, bits, bytes, words and all that. We'll also look at the general purpose register set. I didn't... |
Monday, 02 April 2012 19:35
Security vendor NoVirusThanks has released SSDT View, a 64-bit (only) tool that can show you the contents of your System Service Descriptor Table, perhaps highlighting changes made by rootkits and other stealthy malware.
There are of course plenty of antirootkit tools around that can do something similar, and a whole lot more, but these are generally aimed at Windows experts. SSDT View is safer, and far simpler, which makes the program accessible to a far wider audience.
What’s the SSDT? Whenever Windows or one of your applications wants to carry out some action -- check the Registry, read or write a file, launch or close a process, and so on -- then this will usually result in Windows calling a service in the System Service Descriptor Table. Writing to a file will call the NtWriteFile service to do the actual work, for instance; on our test PC that entry points to memory address 0xFFFF:F800:0356:B210, which is within the module C:\Windows\system32\ntoskrnl.exe – the Windows kernel.

