bra1ny,
| Код | NTSTATUS MyAddDevice ( IN PDRIVER_OBJECT DriverObject , IN PDEVICE_OBJECT DeviceObject );
NTSTATUS DriverEntry( ) { ...
RtlInitUnicodeString( &usDriverName , L"\\Driver\\usbstor" ); ns = ObReferenceObjectByName( &usDriverName , OBJ_CASE_INSENSITIVE , NULL , 0 , IoDriverObjectType , KernelMode , 0 , &pDisk );
// // hook AddDevice routine of \\Driver\\usbstor // InterlockedExchange( (PLONG)&pDisk->DriverExtension->AddDevice , (LONG)MyAddDevice ); .... }
NTSTATUS MyAddDevice( IN PDRIVER_OBJECT DriverObject , IN PDEVICE_OBJECT DeviceObject ) { NTSTATUS ns; WCHAR Vendor[1024]; ULONG Ret;
RtlZeroMemory( Vendor , 1024 );
KdPrint(("in my handler!\n"));
ns = IoGetDeviceProperty( DeviceObject , DevicePropertyHardwareID , 1024 , &Vendor , &Ret );
if( !NT_SUCCESS(ns) ) { KdPrint(("IogetDeviceProperty failed with status : %08X\n" , ns )); goto __end; }
KdPrint(("Vendor : %ws\n" , Vendor ));
if( wcscmp( _FLASH_ , Vendor ) ) { MsgBox( L"You have no rights to use this device!" ); return STATUS_ACCESS_DENIED; } __end: return OldAddDevice( DriverObject , DeviceObject ); }
|
можешь объяснить как это работает? точнее по какому принципу оно должно работать .. я покаместь код боюсь набирать... уж сильно ээ... нереально он выглядит |