<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SoftRCE.net &#187; 未分类</title>
	<atom:link href="http://www.softrce.net/archives/category/uncategorized/feed" rel="self" type="application/rss+xml" />
	<link>http://www.softrce.net</link>
	<description>Software Reverse Code Engineering</description>
	<lastBuildDate>Tue, 03 Aug 2010 10:06:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>SoftRCE官方T恤开始订购了~</title>
		<link>http://www.softrce.net/archives/320</link>
		<comments>http://www.softrce.net/archives/320#comments</comments>
		<pubDate>Tue, 03 Aug 2010 09:55:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[未分类]]></category>

		<guid isPermaLink="false">http://www.softrce.net/?p=320</guid>
		<description><![CDATA[样式： 有需求的朋友可以发邮件到robinh00d#sina.cn或lewis_amu#126.com 大小参考： S 小号 165 M 中号 170 L 大号 175 XL 特大 180 xxl最大号185 xxxl特大号190 Comments2010年08月3日, Lewis writes: 更正下 Reverse the fuckin... ]]></description>
			<content:encoded><![CDATA[<p>样式：<br />
<img src="http://www.softrce.net/wp-content/uploads/2010/08/1.jpg" alt="" title="Tshirt1" width="643" height="367" class="alignnone size-full wp-image-321" /></p>
<p><img src="http://www.softrce.net/wp-content/uploads/2010/08/2.jpg" alt="" title="2" width="618" height="353" class="alignnone size-full wp-image-322" /></p>
<p>有需求的朋友可以发邮件到robinh00d#sina.cn或lewis_amu#126.com<br />
大小参考：<br />
S 小号 165<br />
M 中号 170<br />
L 大号 175<br />
XL 特大 180<br />
xxl最大号185<br />
xxxl特大号190</p>
<hr /><h2>Comments</h2><ul><li><a href="http://www.softrce.net/archives/320#comment-173">2010年08月3日</a>, Lewis writes: 更正下 
Reverse the fucking *! 
修改为
Reverse the f**king *!</li><li><a href="http://www.softrce.net/archives/320#comment-176">2010年08月8日</a>, <a href='http://citypw.blogspot.com' rel='external nofollow' class='url'>Shawn</a> writes: Lewis啥时候发货?等不急了...........</li><li><a href="http://www.softrce.net/archives/320#comment-182">2010年09月3日</a>, <a href='http://citypw.blogspot.com' rel='external nofollow' class='url'>Shawn</a> writes: 这衣服不错,如果还要印的话说一声,估计这边还有人要买.</li><li><a href="http://www.softrce.net/archives/320#comment-183">2010年09月9日</a>, <a href='http://blog.5hoo.com' rel='external nofollow' class='url'>阿木</a> writes: 围观黑客</li><li><a href="http://www.softrce.net/archives/320#comment-184">2010年09月9日</a>, <a href='http://blog.5hoo.com' rel='external nofollow' class='url'>阿木</a> writes: 兄台交换个链接吧！！http://blog.5hoo.com</li><li><a href="http://www.softrce.net/archives/320#comment-185">2010年09月9日</a>, <a href='http://yoryu.97fish.com/' rel='external nofollow' class='url'>悠语</a> writes: 写的很好，关注~~！</li></ul><hr /><h2>Related posts:</h2><ul><li><a href="http://www.softrce.net/archives/1" rel="bookmark" title="Permanent Link: SoftRCE再次回归上线">SoftRCE再次回归上线</a></li><li><a href="http://www.softrce.net/archives/23" rel="bookmark" title="Permanent Link: SoftRCE的Mail Server开通了！">SoftRCE的Mail Server开通了！</a></li><li><a href="http://www.softrce.net/english-version" rel="bookmark" title="Permanent Link: English Version">English Version</a></li></ul><hr /><small>Copyright &copy; 2008<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. If this content is not in your news reader, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint:<br /> 8e761b2ea8edc3ca311452b020051837)</small><h3  class="related_post_title">随机日志</h3><ul class="related_post"></ul>]]></content:encoded>
			<wfw:commentRss>http://www.softrce.net/archives/320/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>RdpDr.sys Bug Check 0X7E{0xC0000005}</title>
		<link>http://www.softrce.net/archives/312</link>
		<comments>http://www.softrce.net/archives/312#comments</comments>
		<pubDate>Wed, 12 May 2010 12:54:49 +0000</pubDate>
		<dc:creator>eaglenet</dc:creator>
				<category><![CDATA[未分类]]></category>

		<guid isPermaLink="false">http://www.softrce.net/?p=312</guid>
		<description><![CDATA[公司测试组反馈一个BSOD，上下文如下 WARNING: Frame IP not in any known module. Following frames may be wrong. a99fd26c f6bdcd93 8591ec78 8591ec78 8591ec78 0&#215;0 a99fd284 f6bdd187 8591ec78 8591ec78 859ca8e0 rdpdr!RxLowIoCompletionTail+0&#... ]]></description>
			<content:encoded><![CDATA[<div>公司测试组反馈一个BSOD，上下文如下</div>
<div>
<div>WARNING: Frame IP not in any known module. Following frames may be wrong.</div>
<div>a99fd26c f6bdcd93 8591ec78 8591ec78 8591ec78 0&#215;0</div>
<div>a99fd284 f6bdd187 8591ec78 8591ec78 859ca8e0 rdpdr!RxLowIoCompletionTail+0&#215;33</div>
<div>a99fd298 f6bc0d2a 8591ec78 a99fd2c8 f6bc10a9 rdpdr!RxLowIoCompletion+0x3f</div>
<div>a99fd2a4 f6bc10a9 8591ec78 00000000 00000016 rdpdr!DrDevice::CompleteRxContext+0x2a</div>
<div>a99fd2c8 f6bb834d a99fd30c 00000000 00000016 rdpdr!DrDevice::CompleteBusyExchange+0x4d</div>
<div>a99fd2f8 f6bc1991 e1370000 856222d8 a99fd370 rdpdr!DrDrive::OnQueryFileInfoCompletion+0x2a5</div>
<div>a99fd31c f6bbe6f9 e1370000 0000002a a99fd370 rdpdr!DrDevice::OnDeviceIoCompletion+0xa9</div>
<div>a99fd33c f6bbe8b6 e1370000 0000002a a99fd370 rdpdr!DrExchangeManager::OnDeviceIoCompletion+0&#215;55</div>
<div>a99fd350 f6bbf543 e1370000 0000002a a99fd370 rdpdr!DrExchangeManager::HandlePacket+0&#215;26</div>
<div>a99fd37c f6bbee66 00000000 858481c3 85848150 rdpdr!DrSession::ReadCompletion+0xc5</div>
<div>a99fd394 804f26c0 00000000 85848150 85945c80 rdpdr!DrSession::ReadCompletionRoutine+0&#215;38</div>
<div>a99fd3c4 f7723864 85498628 00000000 e11cc008 nt!IopfCompleteRequest+0xa2</div>
<div>a99fd400 f772446b 85498628 00000005 00000000 termdd!IcaChannelInputInternal+0x1f4</div>
<div>a99fd428 a968b94e 85aa2fbc 00000005 00000000 termdd!IcaChannelInput+0&#215;41</div>
<div>a99fd45c a9685b25 e11cc008 00590e06 00000032 RDPWD!WDW_OnDataReceived+0&#215;180</div>
<div>a99fd484 a9685949 e11cc82c e11ce12c a99fd400 RDPWD!SM_MCSSendDataCallback+0x12d</div>
<div>a99fd4ec a9685770 00000045 a99fd524 0000004c RDPWD!HandleAllSendDataPDUs+0&#215;155</div>
<div>a99fd508 a9684632 00000045 a99fd524 806e7900 RDPWD!RecognizeMCSFrame+0&#215;32</div>
<div>a99fd530 f7727625 e11cc008 00000000 85590e38 RDPWD!MCSIcaRawInput+0x32c</div>
<div>a99fd550 f79ec1e5 85535504 00000000 85590dec termdd!IcaRawInput+0&#215;53</div>
<div>a99fdd90 f772622f 85590ca0 00000000 855acda8 TDTCP!TdInputThread+0x36f</div>
<div>a99fddac 805d0f72 85665950 00000000 00000000 termdd!_IcaDriverThread+0&#215;51</div>
<div>a99fdddc 805470ee f77261de 85463180 00000000 nt!PspSystemThreadStartup+0&#215;34</div>
<div>00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0&#215;16</div>
</div>
<div>触发行为：</div>
<div>3389连接到测试机器上，拷贝文件到测试机，测试机器直接蓝屏</div>
<div>原因：</div>
<div>MS的rdpdr本身就有一个BUG，不能处理以异步方式查询文件信息的IRP。如果上层传来一个异步查询信息的IRP，就会导致这个BSOD。这个BUG</div>
<div>直到VISTA才修补。</div>
<div>解决方法：</div>
<div>在自己初始化IRP的地方设置Irp-&gt;Flags = <span style="font-family: monospace;line-height: normal">IRP_SYNCHRONOUS_API;把IRP标志为同步IRP即可</span></div>
<div><span style="font-family: monospace;line-height: normal"><br />
</span></div>
<hr /><h2>Comments</h2><ul><li><a href="http://www.softrce.net/archives/312#comment-161">2010年05月12日</a>, 玄风残翼 writes: 我是来顶你的。</li><li><a href="http://www.softrce.net/archives/312#comment-175">2010年08月6日</a>, pk8995 writes: 我X，我也碰到这事了。
必须用同步的才行，原来是个BUG……</li></ul><hr /><h2>Related posts:</h2><ul><li><a href="http://www.softrce.net/english-version/baofeng-storm-activex-control-onbeforevideodownload-buffer-overflow-vulnerability" rel="bookmark" title="Permanent Link: BaoFeng Storm ActiveX Control &#8216;OnBeforeVideoDownload()&#8217; Buffer Overflow Vulnerability">BaoFeng Storm ActiveX Control &#8216;OnBeforeVideoDownload()&#8217; Buffer Overflow Vulnerability</a></li><li><a href="http://www.softrce.net/archives/12" rel="bookmark" title="Permanent Link: About Handling Nmi">About Handling Nmi</a></li></ul><hr /><small>Copyright &copy; 2008<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. If this content is not in your news reader, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint:<br /> 8e761b2ea8edc3ca311452b020051837)</small><h3  class="related_post_title">随机日志</h3><ul class="related_post"></ul>]]></content:encoded>
			<wfw:commentRss>http://www.softrce.net/archives/312/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>IoRegisterDriverReinitialization 和IoRegisterBootDriverReinitialization</title>
		<link>http://www.softrce.net/archives/310</link>
		<comments>http://www.softrce.net/archives/310#comments</comments>
		<pubDate>Fri, 07 May 2010 14:06:55 +0000</pubDate>
		<dc:creator>eaglenet</dc:creator>
				<category><![CDATA[未分类]]></category>

		<guid isPermaLink="false">http://www.softrce.net/?p=310</guid>
		<description><![CDATA[谁能告诉我下这两个函数注册的回调函数当时所处的系统环境到底有多么细小的区别？ 除开DDK中说的那些 我遇到了一个BSOD，SESSION5_INITIALIZATION_FAILED。现在已经解决，但是解决的是稀里糊涂。 ... ]]></description>
			<content:encoded><![CDATA[<p>谁能告诉我下这两个函数注册的回调函数当时所处的系统环境到底有多么细小的区别？ 除开DDK中说的那些</p>
<p>我遇到了一个BSOD，SESSION5_INITIALIZATION_FAILED。现在已经解决，但是解决的是稀里糊涂。</p>
<p>哪位兄弟姐妹能指点下迷经？</p>
<hr /><h2>Comments</h2><ul><li><a href="http://www.softrce.net/archives/310#comment-165">2010年06月6日</a>, yeluosong writes: 绕过主动防御的代码注入方法一点思考
思路实在是太妙了：）

不知道这两个函数当时所处的系统环境这个问题楼主弄明白没，说下我的看法：）
IoRegisterBootDriverReinitialization所注册的回调例程执行时机是在系统引导之时，所有boot型驱动加载完之后，执行的。那时内核已经加载，但尚未初始化。
IoRegisterDriverReinitialization所注册的回调例程执行时机有两处，其中一处是scm利用zw咯ader（）加载驱动时调用，另一处是在系统初始化phase3调用</li></ul><hr /><small>Copyright &copy; 2008<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. If this content is not in your news reader, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint:<br /> 8e761b2ea8edc3ca311452b020051837)</small><h3  class="related_post_title">随机日志</h3><ul class="related_post"></ul>]]></content:encoded>
			<wfw:commentRss>http://www.softrce.net/archives/310/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Symbian_S60_3rd_Application_Cracking_With_IDA_Remote_Debugger_Tutorial</title>
		<link>http://www.softrce.net/archives/210</link>
		<comments>http://www.softrce.net/archives/210#comments</comments>
		<pubDate>Sun, 27 Dec 2009 14:09:04 +0000</pubDate>
		<dc:creator>caterqiu</dc:creator>
				<category><![CDATA[未分类]]></category>

		<guid isPermaLink="false">http://www.softrce.net/?p=210</guid>
		<description><![CDATA[高手请无视



IDA 5.5 放出来了，强大的远程调试功能使得手机软件的调试变得更加轻松

为启明星辰的向日姑娘做了个动画

动画中用了自己很烂的英文

希望那位塞浦路斯的朋友能看懂... ]]></description>
			<content:encoded><![CDATA[<p style="text-align: center">高手请无视</p>
<p> </p>
<p>IDA 5.5 放出来了，强大的远程调试功能使得手机软件的调试变得更加轻松</p>
<p>为启明星辰的向日姑娘做了个动画</p>
<p>动画中用了自己很烂的英文</p>
<p>希望那位塞浦路斯的朋友能看懂。</p>
<p>===============================================================================================================================</p>
<p style="text-align: center"><img class="aligncenter" src="http://www.caterqiu.cn/upload/2009/12/061221123234322.jpg" alt="" /></p>
<p>DownLoad：<br />
<a href="http://rapidshare.com/files/326535837/Symbian_S60_3rd_Application_Cracking_With_IDA_Remote_Debuger_Tutorial_By_CaterQiu.Rar.html" target="_blank">http://rapidshare.com/files/326535837/Symbian_S60_3rd_Application_Cracking_With_IDA_Remote_Debuger_Tutorial_By_CaterQiu.Rar.html</a><br />
<a href="http://www.caterqiu.cn/UPLOAD/2009/12/Symbian_S60_3rd_Application_Cracking_With_IDA_Remote_Debuger_Tutorial_By_CaterQiu.Rar">http://www.caterqiu.cn/UPLOAD/2009/12/Symbian_S60_3rd_Application_Cracking_With_IDA_Remote_Debuger_Tutorial_By_CaterQiu.Rar</a></p>
<p><a href="http://www.caterqiu.cn/Article/Symbian_S60_3rd_Reverse_CrAcKiNg_Tutorial_By_CaterQiu.html">http://www.caterqiu.cn/Article/Symbian_S60_3rd_Reverse_CrAcKiNg_Tutorial_By_CaterQiu.html</a><br />
<a href="http://www.caterqiu.cn/Article/Symbian_S60_3rd_Application_Cracking_With_IDA_Remote_Debuger_Tutorial_By_CaterQiu.html">WwW.CaterQiu.Cn/Article/Symbian_S60_3rd_Application_Cracking_With_IDA_Remote_Debuger_Tutorial_By_CaterQiu.html</a></p>
<hr /><h2>Comments</h2><ul><li><a href="http://www.softrce.net/archives/210#comment-92">2009年12月27日</a>, 犇犇犇 writes: 第二个地址好快，700k+</li><li><a href="http://www.softrce.net/archives/210#comment-93">2009年12月28日</a>, ik writes: 你这个swf是用什么工具录的，谢谢</li><li><a href="http://www.softrce.net/archives/210#comment-94">2009年12月28日</a>, breach writes: 同上，请问您这个swf是用什么工具录的，谢谢</li><li><a href="http://www.softrce.net/archives/210#comment-95">2009年12月28日</a>, caterqiu writes: Instant Demo Pro
Download:http://www.hanzify.org/?Go=Show::List&amp;ID=9363</li><li><a href="http://www.softrce.net/archives/210#comment-100">2010年01月30日</a>, gz1x writes: WTF!这方面的文章好像真是蛮少，要赞。</li></ul><hr /><small>Copyright &copy; 2008<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. If this content is not in your news reader, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint:<br /> 8e761b2ea8edc3ca311452b020051837)</small><h3  class="related_post_title">随机日志</h3><ul class="related_post"></ul>]]></content:encoded>
			<wfw:commentRss>http://www.softrce.net/archives/210/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>
