004DA486|.8B45 FC MOV EAX,DWORD PTR SS:
004DA489|.E8 2678FCFF CALL RegEdite.004A1CB4 //这里F7进入
004DA48E|.84C0 TEST AL,AL
004DA490 0F84 80000000 JE RegEdite.004DA516
004DA496|.8D55 F8 LEA EDX,DWORD PTR SS:
004DA499|.8B83 F4020000 MOV EAX,DWORD PTR DS:
004DA49F|.E8 F019F7FF CALL RegEdite.0044BE94
004DA4A4|.8B45 F8 MOV EAX,DWORD PTR SS:
---------------------------------------------------------------------------------------
F7进入后的代码:
004A1CB4 55 PUSH EBP
004A1CB5 8BEC MOV EBP,ESP
004A1CB7 33C9 XOR ECX,ECX
004A1CB9 51 PUSH ECX
004A1CBA .51 PUSH ECX
004A1CBB .51 PUSH ECX
004A1CBC .51 PUSH ECX
把
004A1CB4 55 PUSH EBP
改为
mov eax,1
ret
这个地方做为暴破点应该更合适一些 学习了,感谢楼主分享交流,顶起 菜鸟学习一下了,感谢分享了哦
页:
1
[2]