logoalt Hacker News

dvttoday at 5:08 AM1 replyview on HN

Absolutely wrong. Are we writing the same code here? Page guards are for all userspace access. (In fact, I think kernel space might also trigger them, but can be circumvented. PS: I'm being polite :) Kernel space 100% triggers them, but can be cleverly circumvented by fucking with logs.)


Replies

Hikikomoritoday at 8:10 AM

Could you not use VirtualProtectEx to strip PAGE_GUARD?

Even so, none if these methods offer protection, at best you can get some detection, but that doesn't matter when they got your passwords already.

show 1 reply