-
-
[原创]我也帖一下我第一题的做法
-
发表于:
2008-10-5 14:57
11671
-
IMAGE_EXPORT_DIRECTORY STRUCT
Characteristics DWORD ? ;总是0
TimeDateStamp DWORD ? ;0
MajorVersion WORD ? ;0
MinorVersion WORD ? ;0
nName DWORD ? ;DLL名字字符串的地址
nBase DWORD ? ;1
NumberOfFunctions DWORD ? ;1
NumberOfNames DWORD ? ;1
AddressOfFunctions DWORD ? ;函数的地址了
AddressOfNames DWORD ? ;名称的地址
AddressOfNameOrdinals DWORD ? ;序号的地址了!
IMAGE_EXPORT_DIRECTORY ENDS
Offset 0 1 2 3 4 5 6 7 8 9 A B C D E F
00000500 00 00 00 00 00 00 00 00 00 00 00 00 32 11 00 00 ............2...
00000510 01 00 00 00 01 00 00 00 01 00 00 00 28 11 00 00 ............(...
00000520 2C 11 00 00 30 11 00 00 08 10 00 00 3C 11 00 00 ,...0.......<...
00000530 00 00 70 65 64 69 79 2E 64 6C 6C 00 4F 70 65 6E ..pediy.dll.Open
00000540 55 72 6C 41 00 00 00 00 00 00 00 00 00 00 00 00 UrlA............
HINSTANCE ShellExecute(
HWND hwnd,
LPCTSTR lpOperation,
LPCTSTR lpFile,
LPCTSTR lpParameters,
LPCTSTR lpDirectory,
INT nShowCmd
);
008D3050 68 74 74 70 3A 2F 2F 62 62 73 2E 70 65 64 69 79 [URL="http://bbs.pediy/"]50aK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3u0T1M7#2)9J5k6i4m8W2k6r3W2&6i4K6g2n7i4K6u0r3g2g2u0x3i4K6g2p5
008D3060 2E 63 6F 6D 2F 00 00 00 00 00 00 00 00 00 00 00 .com/...........
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课