NDIS Driver Filter VS API Hooking
- by Smarty Twiti
I've seen many developers asking for "How to intercept in/out HTTP packets ", "How to modify them on the fly". The most "clean" answer I've seen is to make a kernel-mode-driver filter from the scratch (TDI for XP and earlier winx9 or NDIS for NT systems).
An other way, is to use a user-mode-driver like Windivert, also Komodia has a great solution…