Defense in depth — the Microsoft way (part 68): where compatibility means vulnerability

Posted by Stefan Kanthak on Dec 18

Hi @ll,

this post is a shortened version of

With Windows 2000 and Windows XP, Microsoft introduced the functions
SystemFunction035() alias RtlCheckSignatureInFile(),
SystemFunction036() alias RtlGenRandom(),
SystemFunction040() alias RtlEncryptMemory(), and
SystemFunction041() alias RtlDecryptMemory() in ADVAPI32.dll

Note: RtlCheckSignatureInFile() was never documented, it has the…

