Thankyou for the reply.
I got it. Now final question. Which is a better way to develop a kernel level firewall – NDIS hooking or IM driver???
I am not able to take a decision on this!!!
What parameters should I consider when taking the decision?
Microsoft doesnot support NDIS hooking…so it can change the undocumented data structures used by NDIS hooking any time.
So I was having a debate with my friend over this topic (who favours hooking method).
Can am IM driver be built that is atleast source compatiable wiht Win98?
Why do most commertial personal firewalls use NDIS hooking when it can be done with IM driver?