Process hollowing and the Import Address Table
I have been learning and implementing Process Hollowing attacks, and even after I got the thing work, I have some questions.
Why aren’t we building the IAT when we load our injected PE? All we do is copy the headers and the sections, fix … Continue reading Process hollowing and the Import Address Table