手动加载dll后,想要达到隐藏,所以不能挂peb,但不挂peb就会出错,请问还有什么方法可以做到
[培训]科锐逆向工程师培训第53期2025年7月8日开班!
bb4K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6K6N6s2u0A6N6X3g2^5K9Y4g2F1i4K6u0r3e0h3g2E0L8%4u0&6e0h3!0V1N6h3I4W2f1q4l9`.
9deK9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6T1j5U0p5H3y4#2)9J5c8V1#2W2L8h3!0J5P5f1#2G2k6s2g2D9k6g2m8b7
AperOdry f0cK9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6K6N6s2u0A6N6X3g2^5K9Y4g2F1i4K6u0r3e0h3g2E0L8%4u0&6e0h3!0V1N6h3I4W2f1q4l9`. 1b9K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6T1j5U0p5H3y4#2)9J5c8V1#2W2L8h3!0J5P5f1#2G2k6s2g2D9k6g2m8b7
AperOdry 15cK9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6K6N6s2u0A6N6X3g2^5K9Y4g2F1i4K6u0r3e0h3g2E0L8%4u0&6e0h3!0V1N6h3I4W2f1q4l9`. 48aK9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6T1j5U0p5H3y4#2)9J5c8V1#2W2L8h3!0J5P5f1#2G2k6s2g2D9k6g2m8b7
我看了源代码,这个还是挂的链表啊。
GloryRef 我看了源代码,这个还是挂的链表啊。
Windows处理seh时会使用RtlIsValidHandler来验证处理程序是否合法(防止通过seh劫持控制流),验证主要是通过查找InvertedFunctionTable来实现的。因此你需要将模块的信息插入到表中,实现的方式有两个:使用ntdll中的RtlInsertInvertedFunctionTable(未导出),或者搜索LdrpInvertedFunctionTable后自己实现插入函数。我选择了后者,因为前者是通过特征码搜索,需要不断更新。参考:[RtlInsertInvertedFunctionTable]e88K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6T1j5U0p5H3y4#2)9J5c8V1#2W2L8h3!0J5P5f1#2G2k6s2g2D9k6g2m8b7i4K6u0r3j5X3I4G2j5W2)9J5c8X3#2S2M7%4c8W2M7W2)9J5c8V1#2W2L8h3!0J5P5f1#2G2k6s2g2D9k6g2)9J5c8V1W2F1N6X3g2J5N6r3g2V1c8Y4g2F1j5%4c8A6L8$3&6f1j5h3u0D9k6g2)9J5k6h3y4H3M7l9`.`.
[FindLdrpInvertedFunctionTable]66eK9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6Y4K9i4c8Z5N6h3u0Q4x3X3g2U0L8$3#2Q4x3V1k6T1j5U0p5H3y4#2)9J5c8V1#2W2L8h3!0J5P5f1#2G2k6s2g2D9k6g2m8b7i4K6u0r3j5X3I4G2j5W2)9J5c8X3#2S2M7%4c8W2M7W2)9J5c8V1#2W2L8h3!0J5P5f1#2G2k6s2g2D9k6g2)9J5c8V1W2F1K9i4c8A6j5h3I4A6P5X3g2Q4x3X3g2U0M7s2l9`.
Boring勇哥 Windows处理seh时会使用RtlIsValidHandler来验证处理程序是否合法(防止通过seh劫持控制流),验证主要是通过查找InvertedFunctionTable来实现的。因此你需要将 ...