<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" version="2.0"><channel><title>MeiNanZi</title><link>http://localhost:65527</link><atom:link href="http://localhost:65527/feed.xml" rel="self" type="application/rss+xml"/><description>MeiNanZi</description><generator>Halo v2.25.4</generator><language>zh-cn</language><lastBuildDate>Thu, 25 Jun 2026 20:58:28 GMT</lastBuildDate><item><title><![CDATA[vs双机调试]]></title><link>http://localhost:65527/archives/vsshuang-ji-diao-shi</link><description><![CDATA[<img src="http://localhost:65527/plugins/feed/assets/telemetry.gif?title=vs%E5%8F%8C%E6%9C%BA%E8%B0%83%E8%AF%95&amp;url=/archives/vsshuang-ji-diao-shi" width="1" height="1" alt="" style="opacity:0;">1.VS201X 以下任一版本都可以： Visual Studio Community 201X， Visual Studio Professional 201X,Visual Studio Enterprise 201X. （根据：以前的 WDK 版本和其他下载 - Windows drivers]]></description><guid isPermaLink="false">/archives/vsshuang-ji-diao-shi</guid><dc:creator>Administrator</dc:creator><pubDate>Thu, 25 Jun 2026 20:13:53 GMT</pubDate></item><item><title><![CDATA[windows 内核鼠标源码]]></title><link>http://localhost:65527/archives/windows-nei-he-shu-biao-yuan-ma</link><description><![CDATA[<img src="http://localhost:65527/plugins/feed/assets/telemetry.gif?title=windows%20%E5%86%85%E6%A0%B8%E9%BC%A0%E6%A0%87%E6%BA%90%E7%A0%81&amp;url=/archives/windows-nei-he-shu-biao-yuan-ma" width="1" height="1" alt="" style="opacity:0;">1765185661-kernel-mouse-main.zip]]></description><guid isPermaLink="false">/archives/windows-nei-he-shu-biao-yuan-ma</guid><dc:creator>Administrator</dc:creator><pubDate>Thu, 25 Jun 2026 20:13:35 GMT</pubDate></item><item><title><![CDATA[Windows X64 平台驱动级内存读写库]]></title><link>http://localhost:65527/archives/windows-x64-ping-tai-qu-dong-ji-nei-cun-du-xie-ku</link><description><![CDATA[<img src="http://localhost:65527/plugins/feed/assets/telemetry.gif?title=Windows%20X64%20%E5%B9%B3%E5%8F%B0%E9%A9%B1%E5%8A%A8%E7%BA%A7%E5%86%85%E5%AD%98%E8%AF%BB%E5%86%99%E5%BA%93&amp;url=/archives/windows-x64-ping-tai-qu-dong-ji-nei-cun-du-xie-ku" width="1" height="1" alt="" style="opacity:0;">1765186975-ZfDriver-main.zip Windows X64 平台驱动级内存读写库，方便无痕游戏辅助开发 目前支持：Win10 ~ Latest Warning: Progressing Project... API: static BOOL Install(); // 驱动安装]]></description><guid isPermaLink="false">/archives/windows-x64-ping-tai-qu-dong-ji-nei-cun-du-xie-ku</guid><dc:creator>Administrator</dc:creator><pubDate>Thu, 25 Jun 2026 20:12:25 GMT</pubDate></item><item><title><![CDATA[另一个隐藏加载的驱动源码]]></title><link>http://localhost:65527/archives/ling-yi-ge-yin-cang-jia-zai-de-qu-dong-yuan-ma</link><description><![CDATA[<img src="http://localhost:65527/plugins/feed/assets/telemetry.gif?title=%E5%8F%A6%E4%B8%80%E4%B8%AA%E9%9A%90%E8%97%8F%E5%8A%A0%E8%BD%BD%E7%9A%84%E9%A9%B1%E5%8A%A8%E6%BA%90%E7%A0%81&amp;url=/archives/ling-yi-ge-yin-cang-jia-zai-de-qu-dong-yuan-ma" width="1" height="1" alt="" style="opacity:0;">1765187315-hidedriver-normal-main.zip 1.修复了原作者中ImageDirectoryEntryToData函数会异常，重写同样功能函数； 2......记不得了； 符号解析器：Oxygen1a1/oxgenPdb: a Windows kernel Pdb pa]]></description><guid isPermaLink="false">/archives/ling-yi-ge-yin-cang-jia-zai-de-qu-dong-yuan-ma</guid><dc:creator>Administrator</dc:creator><pubDate>Thu, 25 Jun 2026 20:11:41 GMT</pubDate></item><item><title><![CDATA[kdmapper加载无签名驱动]]></title><link>http://localhost:65527/archives/kdmapperjia-zai-wu-qian-ming-qu-dong</link><description><![CDATA[<img src="http://localhost:65527/plugins/feed/assets/telemetry.gif?title=kdmapper%E5%8A%A0%E8%BD%BD%E6%97%A0%E7%AD%BE%E5%90%8D%E9%A9%B1%E5%8A%A8&amp;url=/archives/kdmapperjia-zai-wu-qian-ming-qu-dong" width="1" height="1" alt="" style="opacity:0;">github地址]]></description><guid isPermaLink="false">/archives/kdmapperjia-zai-wu-qian-ming-qu-dong</guid><dc:creator>Administrator</dc:creator><pubDate>Thu, 25 Jun 2026 20:11:12 GMT</pubDate></item><item><title><![CDATA[自建时间戳服务器实现伪签名驱动证书]]></title><link>http://localhost:65527/archives/zi-jian-shi-jian-chuo-fu-wu-qi-shi-xian-wei-qian-ming-qu-dong-zheng-shu</link><description><![CDATA[<img src="http://localhost:65527/plugins/feed/assets/telemetry.gif?title=%E8%87%AA%E5%BB%BA%E6%97%B6%E9%97%B4%E6%88%B3%E6%9C%8D%E5%8A%A1%E5%99%A8%E5%AE%9E%E7%8E%B0%E4%BC%AA%E7%AD%BE%E5%90%8D%E9%A9%B1%E5%8A%A8%E8%AF%81%E4%B9%A6&amp;url=/archives/zi-jian-shi-jian-chuo-fu-wu-qi-shi-xian-wei-qian-ming-qu-dong-zheng-shu" width="1" height="1" alt="" style="opacity:0;">https://github.com/PIKACHUIM/FakeSign]]></description><guid isPermaLink="false">/archives/zi-jian-shi-jian-chuo-fu-wu-qi-shi-xian-wei-qian-ming-qu-dong-zheng-shu</guid><dc:creator>Administrator</dc:creator><pubDate>Thu, 25 Jun 2026 20:11:00 GMT</pubDate></item><item><title><![CDATA[传奇私服外挂开发(有源码)]]></title><link>http://localhost:65527/archives/chuan-qi-si-fu-wai-gua-kai-fa-you-yuan-ma</link><description><![CDATA[<img src="http://localhost:65527/plugins/feed/assets/telemetry.gif?title=%E4%BC%A0%E5%A5%87%E7%A7%81%E6%9C%8D%E5%A4%96%E6%8C%82%E5%BC%80%E5%8F%91%28%E6%9C%89%E6%BA%90%E7%A0%81%29&amp;url=/archives/chuan-qi-si-fu-wai-gua-kai-fa-you-yuan-ma" width="1" height="1" alt="" style="opacity:0;">引言: 论坛还没有关于传奇私服外挂开发的文章，于是把我前段时间开发过的一款外挂分享出来。传奇私服如火如荼，经过我们统计，有1000多个传奇私服登陆器。本文只针对一款特定的私服做外挂开发，但原理都是一样的。本文有基础介绍，有难点分析，有针对玩家挂机体验做优化，有源码(见附件)。但文章只做研究用，请勿用]]></description><guid isPermaLink="false">/archives/chuan-qi-si-fu-wai-gua-kai-fa-you-yuan-ma</guid><dc:creator>Administrator</dc:creator><pubDate>Thu, 25 Jun 2026 20:10:44 GMT</pubDate></item><item><title><![CDATA[隐蔽通讯常见种类介绍]]></title><link>http://localhost:65527/archives/yin-bi-tong-xun-chang-jian-zhong-lei-jie-shao</link><description><![CDATA[<img src="http://localhost:65527/plugins/feed/assets/telemetry.gif?title=%E9%9A%90%E8%94%BD%E9%80%9A%E8%AE%AF%E5%B8%B8%E8%A7%81%E7%A7%8D%E7%B1%BB%E4%BB%8B%E7%BB%8D&amp;url=/archives/yin-bi-tong-xun-chang-jian-zhong-lei-jie-shao" width="1" height="1" alt="" style="opacity:0;">正常通信流程： R3-&gt;符号链接-&gt;设备对象-&gt;驱动对象-&gt;驱动功能 驱动通信实质上是设备通信 设备是挂在驱动上的DeviceObject上面的 正常IO通信 R0： //创建设备名称 UNICODE_STRING&nbsp;Devicename; RtlInitUnicodeString(&amp;Devicena]]></description><guid isPermaLink="false">/archives/yin-bi-tong-xun-chang-jian-zhong-lei-jie-shao</guid><dc:creator>Administrator</dc:creator><pubDate>Thu, 25 Jun 2026 20:09:24 GMT</pubDate></item><item><title><![CDATA[无”痕”加载驱动模块之傀儡驱动 (上)]]></title><link>http://localhost:65527/archives/wu-hen-jia-zai-qu-dong-mo-kuai-zhi-gui-lei-qu-dong-shang</link><description><![CDATA[<img src="http://localhost:65527/plugins/feed/assets/telemetry.gif?title=%E6%97%A0%E2%80%9D%E7%97%95%E2%80%9D%E5%8A%A0%E8%BD%BD%E9%A9%B1%E5%8A%A8%E6%A8%A1%E5%9D%97%E4%B9%8B%E5%82%80%E5%84%A1%E9%A9%B1%E5%8A%A8%20%28%E4%B8%8A%29&amp;url=/archives/wu-hen-jia-zai-qu-dong-mo-kuai-zhi-gui-lei-qu-dong-shang" width="1" height="1" alt="" style="opacity:0;">驱动加载与ark遍历原理 正常通过服务加载的驱动会显示在ark工具的列表里 CreateServiceA OpenSCManagerA StartServiceA ControlService DeleteService]]></description><guid isPermaLink="false">/archives/wu-hen-jia-zai-qu-dong-mo-kuai-zhi-gui-lei-qu-dong-shang</guid><dc:creator>Administrator</dc:creator><pubDate>Thu, 25 Jun 2026 20:08:49 GMT</pubDate></item><item><title><![CDATA[无”痕”加载驱动模块之漏驱利用(下)]]></title><link>http://localhost:65527/archives/wu-hen-jia-zai-qu-dong-mo-kuai-zhi-lou-qu-li-yong-xia</link><description><![CDATA[<img src="http://localhost:65527/plugins/feed/assets/telemetry.gif?title=%E6%97%A0%E2%80%9D%E7%97%95%E2%80%9D%E5%8A%A0%E8%BD%BD%E9%A9%B1%E5%8A%A8%E6%A8%A1%E5%9D%97%E4%B9%8B%E6%BC%8F%E9%A9%B1%E5%88%A9%E7%94%A8%28%E4%B8%8B%29&amp;url=/archives/wu-hen-jia-zai-qu-dong-mo-kuai-zhi-lou-qu-li-yong-xia" width="1" height="1" alt="" style="opacity:0;">回顾傀儡驱动加载致命缺点 x64上微软增加了驱动签名机制，我们的傀儡驱动依旧需要签名，虽然泄露的sha1签名目测来看能用到微软倒闭，或者花钱买一张白签名(干坏事会被吊销)但是依然存在问题，如果能让微软的白驱动“帮忙”加载我们的功能驱动就好了。 kdmapper漏驱利用 早期驱动开发安全意识不足，导致]]></description><guid isPermaLink="false">/archives/wu-hen-jia-zai-qu-dong-mo-kuai-zhi-lou-qu-li-yong-xia</guid><dc:creator>Administrator</dc:creator><pubDate>Thu, 25 Jun 2026 20:08:27 GMT</pubDate></item><item><title><![CDATA[进程隐藏对抗]]></title><link>http://localhost:65527/archives/jin-cheng-yin-cang-dui-kang</link><description><![CDATA[<img src="http://localhost:65527/plugins/feed/assets/telemetry.gif?title=%E8%BF%9B%E7%A8%8B%E9%9A%90%E8%97%8F%E5%AF%B9%E6%8A%97&amp;url=/archives/jin-cheng-yin-cang-dui-kang" width="1" height="1" alt="" style="opacity:0;">进程隐藏作用 1.使用户无法在任务管理器中看到进程 2.躲避安全软件的信息查询 进程隐藏有两种实现方式： 1.通过hook 查询进程api来过滤要保护的进程，例如ZwQuerySystemInformation； 2.是通过抹除系统结构中关于进程的信息，如断链EPROCESS中的ActiveProc]]></description><guid isPermaLink="false">/archives/jin-cheng-yin-cang-dui-kang</guid><dc:creator>Administrator</dc:creator><pubDate>Thu, 25 Jun 2026 20:07:48 GMT</pubDate></item><item><title><![CDATA[进程伪装原理与破除]]></title><link>http://localhost:65527/archives/jin-cheng-wei-zhuang-yuan-li-yu-po-chu</link><description><![CDATA[<img src="http://localhost:65527/plugins/feed/assets/telemetry.gif?title=%E8%BF%9B%E7%A8%8B%E4%BC%AA%E8%A3%85%E5%8E%9F%E7%90%86%E4%B8%8E%E7%A0%B4%E9%99%A4&amp;url=/archives/jin-cheng-wei-zhuang-yuan-li-yu-po-chu" width="1" height="1" alt="" style="opacity:0;">首先演示下进程伪装的效果 伪装前 伪装后]]></description><guid isPermaLink="false">/archives/jin-cheng-wei-zhuang-yuan-li-yu-po-chu</guid><dc:creator>Administrator</dc:creator><pubDate>Thu, 25 Jun 2026 20:07:29 GMT</pubDate></item><item><title><![CDATA[从 UEFI 劫持启动链实现 Hyper-V 内核读写无需加载驱动]]></title><link>http://localhost:65527/archives/cong-uefi-jie-chi-qi-dong-lian-shi-xian-hyper-v-nei-he-du-xie-wu-xu-jia-zai-qu-dong</link><description><![CDATA[<img src="http://localhost:65527/plugins/feed/assets/telemetry.gif?title=%E4%BB%8E%20UEFI%20%E5%8A%AB%E6%8C%81%E5%90%AF%E5%8A%A8%E9%93%BE%E5%AE%9E%E7%8E%B0%20Hyper-V%20%E5%86%85%E6%A0%B8%E8%AF%BB%E5%86%99%E6%97%A0%E9%9C%80%E5%8A%A0%E8%BD%BD%E9%A9%B1%E5%8A%A8&amp;url=/archives/cong-uefi-jie-chi-qi-dong-lian-shi-xian-hyper-v-nei-he-du-xie-wu-xu-jia-zai-qu-dong" width="1" height="1" alt="" style="opacity:0;">本文档介绍基于 noahware/hyper-reV 的虚拟内存访问类 GuestMemory，以及用于定位目标进程 CR3、EPROCESS、PEB、模块基址的四个内核工具函数。]]></description><guid isPermaLink="false">/archives/cong-uefi-jie-chi-qi-dong-lian-shi-xian-hyper-v-nei-he-du-xie-wu-xu-jia-zai-qu-dong</guid><dc:creator>Administrator</dc:creator><pubDate>Thu, 25 Jun 2026 20:07:06 GMT</pubDate></item><item><title><![CDATA[ProxyBridge指定进程socks5代理工具]]></title><link>http://localhost:65527/archives/proxybridgezhi-ding-jin-cheng-socks5dai-li-gong-ju</link><description><![CDATA[<img src="http://localhost:65527/plugins/feed/assets/telemetry.gif?title=ProxyBridge%E6%8C%87%E5%AE%9A%E8%BF%9B%E7%A8%8Bsocks5%E4%BB%A3%E7%90%86%E5%B7%A5%E5%85%B7&amp;url=/archives/proxybridgezhi-ding-jin-cheng-socks5dai-li-gong-ju" width="1" height="1" alt="" style="opacity:0;">https://github.com/InterceptSuite/ProxyBridge]]></description><guid isPermaLink="false">/archives/proxybridgezhi-ding-jin-cheng-socks5dai-li-gong-ju</guid><dc:creator>Administrator</dc:creator><pubDate>Thu, 25 Jun 2026 20:06:35 GMT</pubDate></item><item><title><![CDATA[开启vmware中的vnc]]></title><link>http://localhost:65527/archives/kai-qi-vmwarezhong-de-vnc</link><description><![CDATA[<img src="http://localhost:65527/plugins/feed/assets/telemetry.gif?title=%E5%BC%80%E5%90%AFvmware%E4%B8%AD%E7%9A%84vnc&amp;url=/archives/kai-qi-vmwarezhong-de-vnc" width="1" height="1" alt="" style="opacity:0;">在vmware设置中开启vnc后，端口不能和其他有开启vnc服务的虚拟机重复，另外vnc客户端连接的时候要填127.0.0.1或者是宿主机局域网ip]]></description><guid isPermaLink="false">/archives/kai-qi-vmwarezhong-de-vnc</guid><dc:creator>Administrator</dc:creator><pubDate>Thu, 25 Jun 2026 20:06:21 GMT</pubDate></item><item><title><![CDATA[UnrealVTDbg_cv vt内核调试器源码]]></title><link>http://localhost:65527/archives/unrealvtdbg_cv-vtnei-he-diao-shi-qi-yuan-ma</link><description><![CDATA[<img src="http://localhost:65527/plugins/feed/assets/telemetry.gif?title=UnrealVTDbg_cv%20vt%E5%86%85%E6%A0%B8%E8%B0%83%E8%AF%95%E5%99%A8%E6%BA%90%E7%A0%81&amp;url=/archives/unrealvtdbg_cv-vtnei-he-diao-shi-qi-yuan-ma" width="1" height="1" alt="" style="opacity:0;">UnrealVTDbg_cv-master.zip 如何编译该项目 编译器：VS2019 SDK: 10.0.019041或最新版本 WKD: WDK10 打开UnrealDbg.sln然后直接编译就行了，注意，需要编译64位版本 UnrealDbgDll只能编译release版本，至于UI则是Un]]></description><guid isPermaLink="false">/archives/unrealvtdbg_cv-vtnei-he-diao-shi-qi-yuan-ma</guid><dc:creator>Administrator</dc:creator><pubDate>Thu, 25 Jun 2026 20:06:05 GMT</pubDate></item><item><title><![CDATA[VmwareHardenedLoader vmware过检测驱动源码]]></title><link>http://localhost:65527/archives/vmwarehardenedloader-vmwareguo-jian-ce-qu-dong-yuan-ma</link><description><![CDATA[<img src="http://localhost:65527/plugins/feed/assets/telemetry.gif?title=VmwareHardenedLoader%20vmware%E8%BF%87%E6%A3%80%E6%B5%8B%E9%A9%B1%E5%8A%A8%E6%BA%90%E7%A0%81&amp;url=/archives/vmwarehardenedloader-vmwareguo-jian-ce-qu-dong-yuan-ma" width="1" height="1" alt="" style="opacity:0;">VMwareHardenedLoader VMware Hardened VM detection mitigation loader For now, only Windows (vista~win10) x64 guests are supported. It get VMware guest]]></description><guid isPermaLink="false">/archives/vmwarehardenedloader-vmwareguo-jian-ce-qu-dong-yuan-ma</guid><dc:creator>Administrator</dc:creator><pubDate>Thu, 25 Jun 2026 20:03:50 GMT</pubDate></item></channel></rss>