The two functions pgpnethandleoutgoingpacket and pgpnethandleincomingpacket are exported in firemp. SYS. After the inline hook is completed, the system returns 6. However, 8.5 is useless, and 8.5 is studied again. By the way, the latest McAfee feature is only for the TDI layer... No NDIS driver.
Supplement ~~ Inline is unstable and the hooks are incomplete.
Changed, and these functions are hooked.
"_ Pgpnethandleincomingpacket @ 8"
"_ Pgpnethandleoutgoingpacket @ 8"
"_ Pgpnetpmaskforrecvdg @ 8"
"_ Pgpnetpmaskforrecvicmp @ 8"
"_ Pgpnetpmaskuserforaccept @ 8"
"_ Pgpnetpmaskuserforbind @ 8"
"_ Pgpnetpmaskuserforconnect @ 8"
"_ Pgpnetpmaskuserforlisten @ 8"
"_ Pgpnetpmaskuserforsendicmp @ 8"
"_ Pgpnetpmaskuserforsendicmp @ 8"
IAT hook in firetdi and firehook
Fake Function
Moveax, 0x6
Retn8
You can
The firewall has been completely blind ..