Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #include<stdio.h>
- #include<windows.h>
- #include "PEB.h"
- typedef DWORD(WINAPI*pNtQueryInformationProcess)(HANDLE, enum PROCESSINFOCLASS, PVOID, ULONG, PULONG);
- int main() {
- PROCESS_BASIC_INFORMATION ProcessInformation;
- PULONG size = 0;
- pNtQueryInformationProcess NtQueryInformationProcess =
- (pNtQueryInformationProcess)GetProcAddress(
- LoadLibrary(L"Ntdll.dll"), "NtQueryInformationProcess");
- NTSTATUS status = NtQueryInformationProcess(GetCurrentProcess(), ProcessBasicInformation,
- &ProcessInformation, sizeof(PROCESS_BASIC_INFORMATION), size);
- printf("%x\n", status);
- printf("PEB location : %08x", ProcessInformation);
- return 0;
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement