Sheng-Hao Ma
Sheng-Hao Ma
could you give a reproductive example to test for sure? or this project crash on notepad.exe (win10+?). and what's your meaning of certain files, is catalog signed?
ensure that arch of DLL for hijacking is the same as LSASS e.g. 64-bit DLL for 64-bit LSASS? seems like your DLL is okay & mapped into symbol object directory...
same here. Orz
 got the same issue here.
thanks for the answer, but there's still a problem. ಥ_ಥ in angr 9.0.6885, `get_objects_by_offset()` return a useful `Definition` structure  but in latest angr, `load()` return me a VEX structure....