Commit Graph

18 Commits

Author SHA1 Message Date
wj32 53d7c69bb4 first 64-bit KPH build (version-specific info still needs to be fixed, and KProcessHacker.cs needs to be fixed as well)
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1715 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-08-15 05:43:33 +00:00
wj32 5bb2c4f1b3 fixed object type retrieval on Windows 7
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1669 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-08-06 07:03:28 +00:00
wj32 66333c166f added object/handle code to KPH
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1612 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-07-20 05:04:01 +00:00
wj32 fe52a61b6b * kernel-mode stack traces!
* pool tag cleanup

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1439 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-06-20 23:41:17 +00:00
wj32 a17e10d425 * added KphQueryProcessHandles
* added KphOpenThreadProcess
* hidden processes scanner can now detect FUTo
* KPH cleanup - added argument attributes
* improved auto-ForeColor

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1436 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-06-20 02:47:04 +00:00
wj32 5808bbcfc6 * added transparency hooking to NProcessHacker
* added some registry-related things to ProcessHacker.Native

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1379 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-06-06 09:50:14 +00:00
wj32 ed0a990aa8 fixed comments
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1309 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-22 00:58:51 +00:00
wj32 3812cfaab3 handle duplication is now protected (through object open hooks)
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1308 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-22 00:52:19 +00:00
wj32 860d7b751d * dynamic PEB offsets
* hooking/unhooking is now completely safe on multi-processor systems

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1303 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-21 06:13:09 +00:00
wj32 5a25f7aeeb fixed "don't allow kernel-mode to bypass protection" by allowing rule creators to bypass the rules
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1296 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-18 09:11:21 +00:00
wj32 03db5a1fd2 * removes protection when the process is terminated
* new ObOpenObjectByPointer now checks if the object is a process/thread
* calling ProtectRemove and ProtectQuery no longer initializes process protection if it hasn't been initialized

git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1295 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-18 08:24:49 +00:00
wj32 36e5e1bc33 use IoThreadToProcess instead of offset
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1294 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-17 11:43:48 +00:00
wj32 69cad00589 added worst case scenario check
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1293 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-17 11:18:02 +00:00
wj32 fdab46f9b0 added option to protect from kernel-mode callers
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1292 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-17 10:55:05 +00:00
wj32 e7ab345289 protected processes can no longer have full access to other protected processes
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1291 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-17 10:33:12 +00:00
wj32 7108fd4750 simplied KphProtectDeinit
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1290 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-17 10:21:50 +00:00
wj32 7f2f872b96 fixed BSOD when unloading KPH after ObOpenObjectByPointer has been hooked - forgot to delete the lookaside list
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1289 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-17 10:17:50 +00:00
wj32 91d061b663 added experimental feature: protect processes
git-svn-id: svn://svn.code.sf.net/p/processhacker/code@1287 21ef857c-d57f-4fe0-8362-d861dc6d29cd
2009-05-17 02:59:06 +00:00