希望大吓们指点一下,我在脱netget的jdpak时使用ESP定律找到OEP
005A2698 55 PUSH EBP //OEP?????????
005A2699 8BEC MOV EBP,ESP
005A269B 83C4 F0 ADD ESP,-10
005A269E B8 B01F5A00 MOV EAX,NetGet.005A1FB0
005A26A3 E8 744EE6FF CALL NetGet.0040751C
005A26A8 B8 1C275A00 MOV EAX,NetGet.005A271C ; ASCII "285F170B-5A85-4E2A-8BF2-858B55970C54"
005A26AD E8 52F8FFFF CALL NetGet.005A1F04
005A26B2 84C0 TEST AL,AL
005A26B4 74 0E JE SHORT NetGet.005A26C4
005A26B6 A1 F0875A00 MOV EAX,DWORD PTR DS:[5A87F0]
005A26BB 8B00 MOV EAX,DWORD PTR DS:[EAX]
005A26BD E8 D22EEDFF CALL NetGet.00475594
005A26C2 EB 48 JMP SHORT NetGet.005A270C
005A26C4 A1 F0875A00 MOV EAX,DWORD PTR DS:[5A87F0]
005A26C9 8B00 MOV EAX,DWORD PTR DS:[EAX]
005A26CB E8 402DEDFF CALL NetGet.00475410
而我在脱壳当前调试程序后,用importREC修复不了,请问是我的OEP错了,还是别原因??
netget 下载
068K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6h3&6W2N6r3N6W2N6q4)9J5k6h3y4G2L8g2)9J5k6h3y4F1i4K6u0r3e0X3g2@1c8$3g2@1f1$3g2@1N6i4m8Q4x3X3g2W2P5r3f1`.
[培训]科锐逆向工程师培训第53期2025年7月8日开班!