-
-
[原创]一个可用于[注入DLL]的调用64位远程进程中的函数的通用命令行程序
-
发表于:
2017-1-19 16:12
4824
-
[原创]一个可用于[注入DLL]的调用64位远程进程中的函数的通用命令行程序
支持两种模式,使用CreateRemoteThread或RtlCreateUserThread+RtlExitUserThread
8d4K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6Z5j5h3I4^5z5e0W2Q4x3V1k6%4L8%4M7$3y4r3S2W2L8s2m8W2M7R3`.`.
cadK9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Q4x3X3g2G2M7$3y4Z5K9h3&6S2i4K6u0W2L8X3g2@1i4K6u0r3K9r3q4D9P5o6V1&6i4K6u0r3N6$3!0%4y4U0c8Z5k6h3I4H3k6i4t1`.
用法: 用VS2015编译为64位exe
wow64helper.exe Option PID OSModuleName ModuleProcName paramsTypes [parameters]...
Option:
0: CreateRemoteThread, 1: RtlCreateUserThread + RtlExitUserThread
paramsTypes:
u64 --> uint64_t or nullptr
s --> string
ws --> wstring
us --> UNICODE_STRING
示例:
0 13220 kernel.dll LoadLibraryW ws D:\dummy.dll
1 13220 ntdll.dll LdrLoadDll u64;u64;us;s 0 0 D:\dummy.dll 12345678
[培训]科锐逆向工程师培训第53期2025年7月8日开班!