- UID
- 2
注册时间2004-12-1
阅读权限255
最后登录1970-1-1
总坛主
TA的每日心情 | 难过 2024-4-22 14:49 |
---|
签到天数: 11 天 [LV.3]偶尔看看II
|
- .flat:0000000000401000 public start
- .flat:0000000000401000 start:
- .flat:0000000000401000 mov rax, 30h
- .flat:0000000000401007 mov rax, gs:[rax] ; 指向TEB
- .flat:000000000040100B mov rax, [rax+60h] ; 指向PEB
- .flat:000000000040100F mov rax, [rax+18h] ; 指向Ldr链
- .flat:0000000000401013 mov rax, [rax+10h] ; 指向 InLoadOrderModuleList 链表头 【你也可以指向 InMemoryOrderModuleList链、InInitializationOrderModuleList链~】
- .flat:0000000000401017 mov rax, [rax] ; Next
- .flat:000000000040101A mov rax, [rax] ; Next
- .flat:000000000040101D mov rax, [rax+30h] ; Kernel32基址
- .flat:000000000040101D ; ---------------------------------------------------------------------------
复制代码- .flat:0000000000401000 public start
- .flat:0000000000401000 start:
- .flat:0000000000401000 mov rax, 30h
- .flat:0000000000401007 mov rax, gs:[rax] ; 指向TEB
- .flat:000000000040100B mov rax, [rax+60h] ; 指向PEB
- .flat:000000000040100F mov rax, [rax+18h] ; 指向Ldr链
- .flat:0000000000401013 mov rax, [rax+20h] ; 指向InMemoryOrderModuleList链
- .flat:0000000000401017 mov rax, [rax] ; Next
- .flat:000000000040101A mov rax, [rax] ; Next
- .flat:000000000040101D mov rax, [rax+20h] ; Kernel32基址
- .flat:000000000040101D ; ---------------------------------------------------------------------------
复制代码
|
|