<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for inREVERSE</title>
	<atom:link href="http://www.inreverse.net/?feed=comments-rss2" rel="self" type="application/rss+xml" />
	<link>http://www.inreverse.net</link>
	<description></description>
	<lastBuildDate>Mon, 29 Aug 2011 13:20:26 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>Comment on More on callbacks: ObRegisterCallbacks by swirl</title>
		<link>http://www.inreverse.net/?p=1740&#038;cpage=1#comment-249</link>
		<dc:creator>swirl</dc:creator>
		<pubDate>Mon, 29 Aug 2011 13:20:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=1740#comment-249</guid>
		<description><![CDATA[thanks for the unknown field :)  Sure there are several ways to bypass MmVerifyCallbackFunction, also passing the address of a xor eax, eax retn 8 gadget inside some verified driver and then changing the address in the CallbackList  later to the real function.]]></description>
		<content:encoded><![CDATA[<p>thanks for the unknown field :)  Sure there are several ways to bypass MmVerifyCallbackFunction, also passing the address of a xor eax, eax retn 8 gadget inside some verified driver and then changing the address in the CallbackList  later to the real function.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on More on callbacks: ObRegisterCallbacks by Dmitry Varshavsky</title>
		<link>http://www.inreverse.net/?p=1740&#038;cpage=1#comment-248</link>
		<dc:creator>Dmitry Varshavsky</dc:creator>
		<pubDate>Mon, 29 Aug 2011 13:15:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=1740#comment-248</guid>
		<description><![CDATA[Unknown field is EX_RUNDOWN_REF used to wait for all callback function to be finished before ObUnRegisterCallbacks returns.
Also, callbacks can be inserted by hand without calling any api and fooling MmVerifyCallbackFunction ( DKOM : ObjectType -&gt; CallbackList and ObjectType -&gt; TypeLock for synchronization ).
Reverse deeper :) 
But still nice.]]></description>
		<content:encoded><![CDATA[<p>Unknown field is EX_RUNDOWN_REF used to wait for all callback function to be finished before ObUnRegisterCallbacks returns.<br />
Also, callbacks can be inserted by hand without calling any api and fooling MmVerifyCallbackFunction ( DKOM : ObjectType -&gt; CallbackList and ObjectType -&gt; TypeLock for synchronization ).<br />
Reverse deeper :)<br />
But still nice.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on More on callbacks: ObRegisterCallbacks by swirl</title>
		<link>http://www.inreverse.net/?p=1740&#038;cpage=1#comment-221</link>
		<dc:creator>swirl</dc:creator>
		<pubDate>Sun, 10 Jul 2011 18:34:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=1740#comment-221</guid>
		<description><![CDATA[the must be stable enough to use in production :) 
Don&#039;t know why Microsoft didn&#039;t enable other object types..]]></description>
		<content:encoded><![CDATA[<p>the must be stable enough to use in production :)<br />
Don&#8217;t know why Microsoft didn&#8217;t enable other object types..</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on More on callbacks: ObRegisterCallbacks by mj0011</title>
		<link>http://www.inreverse.net/?p=1740&#038;cpage=1#comment-220</link>
		<dc:creator>mj0011</dc:creator>
		<pubDate>Sun, 10 Jul 2011 18:26:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=1740#comment-220</guid>
		<description><![CDATA[the newest version of sandboxie has already use this tech to filter file/token/section/.....]]></description>
		<content:encoded><![CDATA[<p>the newest version of sandboxie has already use this tech to filter file/token/section/&#8230;..</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on More on callbacks: ObRegisterCallbacks by swirl</title>
		<link>http://www.inreverse.net/?p=1740&#038;cpage=1#comment-219</link>
		<dc:creator>swirl</dc:creator>
		<pubDate>Sun, 10 Jul 2011 18:15:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=1740#comment-219</guid>
		<description><![CDATA[thanks and fixed :)]]></description>
		<content:encoded><![CDATA[<p>thanks and fixed :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on More on callbacks: ObRegisterCallbacks by s4tan</title>
		<link>http://www.inreverse.net/?p=1740&#038;cpage=1#comment-218</link>
		<dc:creator>s4tan</dc:creator>
		<pubDate>Sun, 10 Jul 2011 17:44:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=1740#comment-218</guid>
		<description><![CDATA[As always great post :)

P.S.
there is a little typo in the link to d.hatena.ne.jp]]></description>
		<content:encoded><![CDATA[<p>As always great post :)</p>
<p>P.S.<br />
there is a little typo in the link to d.hatena.ne.jp</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on CARO2011 &#8211; Java Malware Presentation by Hooter</title>
		<link>http://www.inreverse.net/?p=1687&#038;cpage=1#comment-214</link>
		<dc:creator>Hooter</dc:creator>
		<pubDate>Thu, 09 Jun 2011 16:55:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=1687#comment-214</guid>
		<description><![CDATA[thx 4 sharing. good work :)]]></description>
		<content:encoded><![CDATA[<p>thx 4 sharing. good work :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Crimepack 3.1.3 &#8211; checking vital signs by why</title>
		<link>http://www.inreverse.net/?p=1401&#038;cpage=1#comment-211</link>
		<dc:creator>why</dc:creator>
		<pubDate>Tue, 31 May 2011 19:05:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=1401#comment-211</guid>
		<description><![CDATA[where i can get your python beta tool?]]></description>
		<content:encoded><![CDATA[<p>where i can get your python beta tool?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Driver packer by swirl</title>
		<link>http://www.inreverse.net/?p=327&#038;cpage=1#comment-209</link>
		<dc:creator>swirl</dc:creator>
		<pubDate>Wed, 18 May 2011 16:31:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=327#comment-209</guid>
		<description><![CDATA[fixed, thanks :)]]></description>
		<content:encoded><![CDATA[<p>fixed, thanks :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Driver packer by why</title>
		<link>http://www.inreverse.net/?p=327&#038;cpage=1#comment-208</link>
		<dc:creator>why</dc:creator>
		<pubDate>Wed, 18 May 2011 01:18:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.inreverse.net/?p=327#comment-208</guid>
		<description><![CDATA[+0x024 UNICODE_STRING DriverPath
		+0x000 Len
		+0x004 Max // errror - +0x002
		+0x008 Buffer //          +0x004]]></description>
		<content:encoded><![CDATA[<p>+0&#215;024 UNICODE_STRING DriverPath<br />
		+0&#215;000 Len<br />
		+0&#215;004 Max // errror &#8211; +0&#215;002<br />
		+0&#215;008 Buffer //          +0&#215;004</p>
]]></content:encoded>
	</item>
</channel>
</rss>
