The article uses ZwAdjustPrivilegesToken but it is only available on Windows
2000 and later, however NtAdjustPrivilegesToken is available on NT 4.0 also,
is it possible to use that function instead to get one binary for all
versions? If impersonating in a system thread one can asume that
ExGetPreviousMode always returns KernelMode right? and then the NtXxx
version works the same as the ZwXxx version?
Hitta rätt på nätet med MSN Search http://search.msn.se/