首页> 外文期刊>Digital investigation >Obtaining forensic value from the cbWndExtra structures as used by Windows Common Controls, specifically for the Editbox control
【24h】

Obtaining forensic value from the cbWndExtra structures as used by Windows Common Controls, specifically for the Editbox control

机译:从Windows公共控件使用的cbWndExtra结构获取取证值,专门用于Editbox控件

获取原文
获取原文并翻译 | 示例
           

摘要

The Windows Common Controls is a library which facilitates the construction of GUI controls commonly used by Windows applications. Each control is an extension of the basic 'Window' class. The difference in the extension results in one control over another; for example, an Edit control as opposed to a Button control. The basic window class is documented by Microsoft and the generic information about a Window can be extracted, but this is of very limited use. There is no documentation and very little research into how these extensions are laid out in memory. This paper demonstrates how the extension bytes for the Edit control can be parsed leading to identification of previously unobtainable data which reveal information about the state of the control at runtime. Most notably, the undo buffer, that is, text that was previously present in the control can be recovered - an aspect which traditional disk forensics would simply not provide. The paper explains why previous attempts to achieve similar goals have failed, and how the technique could be applied to any control from the Windows Common Controls library. (c) 2017 Elsevier Ltd. All rights reserved.
机译:Windows公共控件是一个库,可简化Windows应用程序通常使用的GUI控件的构造。每个控件都是基本“窗口”类的扩展。扩展上的差异导致对另一控件的控制。例如,一个Edit控件而不是Button控件。 Microsoft已记录了基本的窗口类,并且可以提取有关Window的一般信息,但这用途非常有限。没有文档,也很少研究这些扩展在内存中的布局方式。本文演示了如何解析Edit控件的扩展字节,从而导致识别以前无法获得的数据,这些数据揭示了有关运行时控件状态的信息。最值得注意的是,可以恢复撤消缓冲区,即控件中先前存在的文本,这是传统磁盘取证技术无法提供的一个方面。本文解释了为何以前为实现类似目标而进行的尝试都失败了,以及如何将该技术应用于Windows公共控件库中的任何控件。 (c)2017 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号