<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Journaling on Defender TD5</title><link>https://td5.390er.de/kategorien/journaling/</link><description>Recent content in Journaling on Defender TD5</description><generator>Hugo</generator><language>de</language><lastBuildDate>Sun, 05 Jul 2026 11:35:18 +0200</lastBuildDate><atom:link href="https://td5.390er.de/kategorien/journaling/index.xml" rel="self" type="application/rss+xml"/><item><title>Driving a Foreign Application's Menus: A Global MenuSelect Trap Patch Installed at Boot</title><link>https://td5.390er.de/applebridge/driving-a-foreign-application-s-menus-a-global-menuselect-trap-patch-installed-at-boot/</link><pubDate>Sun, 05 Jul 2026 11:35:18 +0200</pubDate><guid>https://td5.390er.de/applebridge/driving-a-foreign-application-s-menus-a-global-menuselect-trap-patch-installed-at-boot/</guid><description>&lt;p&gt;Two earlier reports left the problem of driving an &lt;em&gt;arbitrary front application&amp;rsquo;s&lt;/em&gt; menus unresolved. The journaling driver reaches only the daemon&amp;rsquo;s own menus, because &lt;code&gt;MenuSelect&lt;/code&gt; uses the calling process&amp;rsquo;s menu list. The jGNE filter could read a foreign application&amp;rsquo;s menu structure but crashed the host when used to drive one. This report closes the problem with the third mechanism the literature pointed to — a global &lt;code&gt;MenuSelect&lt;/code&gt; trap patch installed at startup from a system extension — and records two findings that the closing required: that a patch installed by a running application is process-local, and that a trap patch&amp;rsquo;s presence must be verified by scanning memory rather than by reading the trap vector.&lt;/p&gt;</description></item></channel></rss>