12.07.2015 Views

sR6uWE

sR6uWE

sR6uWE

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IPC: INTERNAL OBJECTSViewFile Object (size 0x1C)Offset Size Field Comment04 UINT32 ui32ViewID Unique ID to identify respective untrusted file.08 HWND hOPHWnd hWnd for “OPH Previewer Window” class(Global MSO.015E9A9C = 0)File 1aFile 1b0C LPWSTR lpwFileName Pointer to full-path to original file10 LPWSTR lpwTemporaryFileName Pointer to full-path to temp file in sandbox dir14 LPVOID lpSameBrokerApp Pointer to SameBrokerApp objectFile 2aFile 2b18 UINT32 ui32SessionEnableHyperlinks Used in Tag 0x091000 (TRUE or FALSE)SameBrokerApp ObjectSameBrokerApp object missing(Global MSO.015E9A9C = 6)Offset Size Field Comment0C LPVOID lpWWLIBIPCMsg Pointer to WWLIBIPCMsg object84 HWND hOPHParentWnd Used in 0x061000 and 0x101000 IPC messageMSO-Group of IPC Messages90 LPVOID lpDRMStream Used in 0x081000 IPC messageB0 LPVOID lpTaskList Used in 0x0B1000 IPC messageWWLIBIPCMsg ObjectOffset Size Field Comment1C UINT32 ui32IPC0A1100 Used in 0x0A1100 IPC message20 UCHAR [0x2C] uchIPC091100Contents Buffer storing IPC 0x091100 message contents4C UINT32 ui32IPC071100MsgID MsgID of IPC 0x071100 message50 UINT32 ui32IPC081100MsgID MsgID of IPC 0x081100 message54 UINT32 ui32IPC091100MsgID MsgID of IPC 0x091100 message58 UINT32 ui32IPC031100MsgID MsgID of IPC 0x031100 messageWWLIB-Group of IPC Messages5C UINT32 ui32IPC041100MsgID MsgID of IPC 0x041100 message60 UINT32 ui32IPC0E1100MsgID MsgID of IPC 0x0E1100 message64 UCHAR [0x24] uchIPC041100Contents Buffer storing IPC 0x041100 message contents8C UCHAR [0x1D4] uchIPC031100Contents Buffer storing IPC 0x031100 message contentsLabs.mwrinfosecurity.com | © MWR Labs 26

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!