Join us at IRC!
It is never to LATE to become what you never WERE.
Thursday, May 24, 2012
Navigation
Members Online
Total Online: 23
Web Spiders: 13
Guests Online: 21
Members Online: 2

Registered Members: 70188
Newest Member: nuk3d
Latest Articles
View Thread

HellBound Hackers | HellBound Hackers | Questions

Author

Hide Regkey

wakfu
Member



Posts: 10
Location: <(~_0)>
Joined: 13.11.08
Rank:
God
Posted on 15-04-09 13:25
Hi all :) , i would like to know if it is possible to hide a registry key ???
I have to hook the API function : RegOpenKeyEx / RegQueryValueEx , or there is a more simple way to do it ?
Thanks.
w4kfu.





Edited by wakfu on 15-04-09 13:30
      rm -rf /
Author

RE: Hide Regkey

Cyph3rHell
Member



Posts: 301
Location: Hackers Paradise
Joined: 25.06.08
Rank:
God
Posted on 15-04-09 14:51
I don't know if this is what you are looking for, but i know that you can hide registry values simply using very long names for it.
If you overflow the MAX_LENGTH constant (if is longer than 260 bytes), the Regedit utility won't show these Registry values, but they're still there.

I found this info here




What you see is not the hell... is the HACKERS PARADISE


A little boy asks his father, "Daddy, how much does it cost to get married?" His father replies, "I don't know, son. I'M STILL PAYING FOR IT!"

"It's just too hot to wear clothes today," said Bill as he stepped out of the shower. "Honey, what do you think the neighbors would think if I mowed the lawn like this?" "Probably that I married you for your money," she replied.
Ask me
Author

RE: Hide Regkey

wakfu
Member



Posts: 10
Location: <(~_0)>
Joined: 13.11.08
Rank:
God
Posted on 15-04-09 16:32
Very interesting vulnerability , thanks for the info Cyph3rHell.
Consequently for viewing this "hidden" registry value , we shouldn't not use the regedit utility , it is similar to hook the API function.
Yet this will be sufficient :) , i will not have to program an another "driver".
I am open to other ways to do this.



      rm -rf /
Guest
Username

Password

Remember Me


Bookmark This Page
Affiliates
Adverts

 

 

Links
By using, viewing or obtaining any information contained on this site, you agree to the disclaimer.

© HellBound Hackers 2008- 2009. Since 3rd December 2004.