Qiming Star Information Security interview
Qiming Star interview questions:
1: I just asked myself to introduce the items on my resume.
2: it is known that a virus injected a pe file into svchost.exe (this process is a system process, cannot attach), and erased all the pe information, the virus that released pe has been deleted by itself, and it is known that there is an outward contact behavior, how to dump out this pe file?
3: how much do you know about process hiding technology? at present, there may be more than 20 hidden technologies, more than a dozen of them are displayed, and just say a few?
4: what do you know about zombies, worms, tell me about understanding, give you a virus, how do you judge these three viruses?
5: tell me if you want to write one, how would you write it? What is the typical behavior of one? What are the steps?
6: what anti-debugging methods do you know? Tell me the one you are most familiar with?
Have you ever used 7:pchunter? What are the common functions? Have you tried any functions related to dump threads? 8: have you analyzed the Android virus? How do you analyze it? Is there any confusion?
9: will Android debug dynamically? How did you do it?
10: how do you analyze the vulnerabilities in your CVE-2012-0158?
11: do you know how to protect it? Tell me about it.
12: the kernel is the problem with kProcess
13: injection and hook, virus injection is commonly used, do you understand? Do you know about atomic injection?
Understanding of 14:pe files
15: the problem of multithreaded communication