3 ms·
That hasn't been true since Windows 98/ME. Windows uses virtual addressing plus ASLR and DEP for process isolation/protection. See here: https://learn.microsof
by glitchc 3mo ago
That hasn't been true since Windows 98/ME. Windows uses virtual addressing plus ASLR and DEP for process isolation/protection. See here:
https://learn.microsoft.com/en-us/windows-hardware/drivers/gettingstarted/virtual-address-spaces https://learn.microsoft.com/en-us/windows-hardware/drivers/g...
- ChocolateGod 3mo agoYou can use system APIs to get the memory space of another application in Windows as long as their run by the same user. However iirc processes can opt out of this so only administrators can.
- Hikikomori 3mo ago>However iirc processes can opt out of this so only administrators can. Can override those opts without admin as well.
- charcircuit 3mo agoReadProcessMemory and WriteProcessMemory are APIs Windows exposes for using other processes memory. Even if a process changes the default DACL to block it, admin level access can bypass it. https://learn.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-readprocessmemory https://learn.microsoft.com/en-us/windows/win32/api/memoryap... https://learn.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-writeprocessmemory https://learn.microsoft.com/en-us/windows/win32/api/memoryap...