draksetup
doesn't care if chosen explorer.exe for injection is 32-bit or 64-bit
#809
Labels
enhancement
New feature or request
draksetup
usesget-explorer-pid
tool (https://github.com/CERT-Polska/drakvuf-sandbox/blob/master/drakrun/drakrun/tools/get-explorer-pid.c) to choose target process for injection.Meanwhile the only criterion for choosing a process is name
explorer.exe
(https://github.com/CERT-Polska/drakvuf-sandbox/blob/master/drakrun/drakrun/tools/get-explorer-pid.c#L183). In the same time, on 64-bit Windows there can be twoexplorer.exe
, one for 32-bit processes and another one for 64-bit.Choosing 32-bit/64-bit randomly may cause bugs and makes debugging more difficult. I guess that in most injection operations we should avoid dealing with WoW stuff and choose 64-bit version on 64-bit Windows and 32-bit otherwise.
The text was updated successfully, but these errors were encountered: