能力值:
( LV2,RANK:10 )
|
-
-
2 楼
|
能力值:
( LV2,RANK:10 )
|
-
-
3 楼
一般没啥反调试,调试环境下堆的分配不同造成的吧。
怎么调试可以参考这个
9a0K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3u0D9L8$3N6K6i4K6u0W2N6r3g2U0K9r3&6W2N6q4)9J5k6h3y4G2L8g2)9J5c8Y4y4J5k6q4)9J5c8X3q4J5j5$3S2A6N6X3g2Q4x3V1j5J5x3o6l9&6i4K6u0r3x3o6c8Q4x3V1j5H3x3W2)9J5c8X3W2F1N6X3g2K6N6r3W2Y4j5i4c8A6L8X3N6Q4x3X3c8@1K9r3g2Q4x3X3c8F1k6i4N6Q4x3X3c8H3L8%4N6W2M7Y4m8G2K9h3&6@1i4K6u0V1K9i4y4K6N6h3g2Q4x3X3g2S2M7%4m8^5
如果能找到样本里的shellcode,那也可以简单的加CC。
|
能力值:
( LV2,RANK:10 )
|
-
-
4 楼
128K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4u0S2M7r3W2V1M7$3S2S2M7X3g2Q4x3X3g2U0L8$3#2Q4x3V1k6X3K9h3I4W2M7#2)9J5c8U0t1$3x3U0M7^5z5o6t1J5x3q4)9J5c8W2)9#2k6W2)9#2k6W2)9#2k6U0t1$3x3o6R3#2i4K6g2X3i4K6g2X3i4K6g2X3x3K6b7$3y4o6g2Q4y4h3k6Q4y4h3k6Q4y4h3k6Q4y4h3j5J5x3e0f1H3z5q4)9#2k6W2)9#2k6W2)9#2k6U0t1K6y4o6M7^5i4K6g2X3i4K6g2X3i4K6g2X3x3K6l9@1y4e0k6Q4y4h3k6Q4y4h3k6Q4y4h3j5J5y4K6t1K6x3g2)9#2k6W2)9#2k6W2)9#2k6U0t1H3z5o6b7H3i4K6g2X3i4K6g2X3i4K6g2X3x3U0p5@1z5o6S2Q4y4h3k6Q4y4h3k6Q4y4h3j5J5x3o6V1&6z5q4)9#2k6W2)9#2k6W2)9#2k6U0t1H3x3e0x3&6i4K6g2X3i4K6u0W2y4%4A6Q4x3X3g2Z5N6r3#2D9
附送一个idb
用的API还是那一堆
|
|
|