3 ms·
Between a 40b strcmp method (If I had/if it was more widely supported I could use sse4.2 strcmp) and ~74b of resolving said exports a couple syscalls sounds pre
by mcountryman 6y ago
Between a 40b strcmp method (If I had/if it was more widely supported I could use sse4.2 strcmp) and ~74b of resolving said exports a couple syscalls sounds pretty nice provided the context switch isn't more expensive than resolving the imports.
- deleted 6y ago[deleted]
- ChrisSD 6y agoWell if you really want to you can get the output handle from the PEB[0]. You can then call NtWriteFile[1] using syscall `0x0008` (Windows 10 x64 only)[2]. [0]: https://processhacker.sourceforge.io/doc/struct___r_t_l___u_s_e_r___p_r_o_c_e_s_s___p_a_r_a_m_e_t_e_r_s.html https://processhacker.sourceforge.io/doc/struct___r_t_l___u_... [1]: https://docs.microsoft.com/en-us/windows-hardware/drivers/ddi/ntifs/nf-ntifs-ntwritefile https://docs.microsoft.com/en-us/windows-hardware/drivers/dd... [2]: https://j00ru.vexillium.org/syscalls/nt/64/ https://j00ru.vexillium.org/syscalls/nt/64/
- mcountryman 6y agoI completely forgot stdout handle is in the PEB! Thanks! After learning how the windows x64 syscall calling convention works I got it working on win10. https://i.imgur.com/ErHU7Kr.png https://i.imgur.com/ErHU7Kr.png https://github.com/mcountryman/min-sized-rust-windows/commit/4d54424edef96d4a3bca91e8ee75d534bda25d43 https://github.com/mcountryman/min-sized-rust-windows/commit...