~
Position
Length
Windows Versions
Description
FS:[0x00]
4
Win9x and NT
Current Structured Exception Handling (SEH) frame
FS:[0x04]
4
Win9x and NT
Top of stack
FS:[0x08]
4
Win9x and NT
Current bottom of stack
FS:[0x0C]
4
Unknown - TIB Subsystem?
FS:[0x10]
4
NT
Fiber data
FS:[0x14]
4
Win9x and NT
Arbitrary data slot
FS:[0x18]
4
Win9x and NT
Linear address of TIB
---- End of NT subsystem independent part ----
FS:[0x1C]
4
NT
Environment Pointer
FS:[0x20]
4
NT
Process ID
FS:[0x24]
4
NT
Current thread ID
FS:[0x28]
4
NT
Active RPC Handle
FS:[0x2C]
4
Win9x and NT
Linear address of the thread-local storage array
FS:[0x30]
4
NT
Linear address of Process Environment Block (PEB)
FS:[0x34]
4
NT
Last error number
FS:[0x38]
4
NT
Count of owned critical sections
FS:[0x3C]
4
NT
Address of CSR Client Thread
FS:[0x40]
4
NT
Win32 Thread Information
~
~
~
FS:[0xF28]
4
NT
Thread error mode (RtlSetThreadErrorMode)
http://en.wikipedia.org/wiki/Win32_Thread_Information_Block
FS레지스터에 관한 정보,, 빨간색 글자가 많이 쓰임.
'유용한 지식 자료들 > 기타' 카테고리의 다른 글
PEB structure (0) | 2012.08.09 |
---|---|
TEB structure (0) | 2012.08.09 |
64비트 인지 아닌지 확인하기 (0) | 2012.07.18 |
Clustering VS Classification (0) | 2012.06.27 |
Aho Corasick String Matching in Python (0) | 2012.05.17 |