-
-
函数地址与SSDT索引的关系,以nt!NtFlushKey为例
-
-
函数地址与SSDT索引的关系,以nt!NtFlushKey为例
1 kd> dps 83e9443c L192
83e9443c 8408ffbf nt!NtAcceptConnectPort
83e94634 83ff5b06 nt!NtFlushKey
(83ff5b06-8408ffbf)/4 = 0x7E
2 pNtFlushKeyFuncAddr = 0xa6444dc8
kd> u 0xa6444dc8
a6444dc8 b87e000000 mov eax, 7Eh
a6444dcd ba0003fe7f mov edx, offset SharedUserData!SystemCallStub(7ffe0300)
a6444dd2 ff12 call dword ptr[edx]
3 (PUCHAR)pNtFlushKeyFuncAddr++;
kd> dd a6444dc9
a6444dc9 0000007e fe0300ba c212ff7f b8900004
[培训]科锐逆向工程师培训第53期2025年7月8日开班!