Quantcast
Channel: BOT24
Viewing all articles
Browse latest Browse all 8064

Hives & Trust issues

$
0
0
Some of you may have ever used RtlQueryRegistryValues, and probably wondered what Microsoft meant by saying:

Starting with Windows 8, if an RtlQueryRegistryValues call accesses an untrusted hive, and the caller sets the RTL_QUERY_REGISTRY_DIRECT flag for this call, the caller must additionally set the RTL_QUERY_REGISTRY_TYPECHECK flag.

A hive is marked as untrusted using the 0×1 flag in CMHIVE.Flags.

read more..........http://www.msuiche.net/2014/06/10/hives-trust-issues/

Viewing all articles
Browse latest Browse all 8064

Trending Articles