Changeset 147 for trunk/include/regfi.h
- Timestamp:
- 02/22/09 14:31:52 (15 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/include/regfi.h
r146 r147 46 46 #include <assert.h> 47 47 48 #include "talloc.h" 48 49 #include "smb_deps.h" 49 50 #include "winsec.h" … … 84 85 #define REG_KEY 0x7FFFFFFF 85 86 86 #define REGFI_REGF_SIZE 0x1000 /* "regf" header block size */87 #define REGFI_HBIN_ALLOC 0x1000 /* Minimum allocation unit for HBINs */88 87 #define REGFI_MAX_DEPTH 512 89 88 #define REGFI_OFFSET_NONE 0xffffffff … … 93 92 94 93 /* Header sizes and magic number lengths for various records */ 94 #define REGFI_HBIN_ALLOC 0x1000 /* Minimum allocation unit for HBINs */ 95 #define REGFI_REGF_SIZE 0x1000 /* "regf" header block size */ 95 96 #define REGFI_REGF_MAGIC_SIZE 4 96 97 #define REGFI_HBIN_MAGIC_SIZE 4 … … 107 108 * been reported that Windows timestamps are never more than a 108 109 * certain granularity (250ms?), which could be used to help 109 * eliminate false positives. Would need to v alidatethis and110 * eliminate false positives. Would need to verify this and 110 111 * perhaps conservatively implement a check. 111 112 */
Note: See TracChangeset
for help on using the changeset viewer.