Skip to content

Sacrificial Process Hotpatch for PPID+BlockDLLs

Compare
Choose a tag to compare
@djhohnstein djhohnstein released this 27 Aug 04:48
· 758 commits to master since this release
545f9df

This hotpatch is meant as a quick-fix to some bugs I introduced with the latest PPID/Block DLLs release. Unfortunately, there were some unforeseen consequences about using the StartupInfoEx structure and thevarious CreateProcess calls. Those nuances had to be painstakingly teased out, and in the process I had to discover the boundaries of ppid spoofing. This release introduces significant guard rails in order to provide some stability.