- UID
- 14190
注册时间2006-5-26
阅读权限10
最后登录1970-1-1
周游历练
该用户从未签到
|
发表于 2007-2-12 09:39:05
|
显示全部楼层
00401650 55 push ebp
00401651 8BEC mov ebp, esp
00401653 6A FF push -1
00401655 68 50324000 push 00403250 ; SE句柄
0040165A 64:A1 00000000 mov eax, dword ptr fs:[0]
00401660 50 push eax
00401661 64:8925 0000000>mov dword ptr fs:[0], esp
00401668 83EC 2C sub esp, 2C
0040166B 53 push ebx
0040166C 56 push esi
0040166D 57 push edi
0040166E 8BF1 mov esi, ecx
00401670 6A 01 push 1
00401672 E8 6D170000 call <jmp.&MFC42.#6334>
00401677 8D4D E8 lea ecx, dword ptr [ebp-18]
0040167A E8 0B170000 call <jmp.&MFC42.#540>
0040167F 8D4D EC lea ecx, dword ptr [ebp-14]
00401682 C745 FC 0000000>mov dword ptr [ebp-4], 0
00401689 E8 FC160000 call <jmp.&MFC42.#540>
0040168E 8D4D E4 lea ecx, dword ptr [ebp-1C]
00401691 C645 FC 01 mov byte ptr [ebp-4], 1
00401695 E8 F0160000 call <jmp.&MFC42.#540>
0040169A 8B46 6C mov eax, dword ptr [esi+6C] ; crack1946
0040169D 8D5E 6C lea ebx, dword ptr [esi+6C]
004016A0 C645 FC 02 mov byte ptr [ebp-4], 2
004016A4 8B40 F8 mov eax, dword ptr [eax-8] ; 长度到eax
004016A7 83F8 06 cmp eax, 6
004016AA 0F8E 7B010000 jle 0040182B
004016B0 74 03 je short 004016B5 ; 花指令? nop
004016B2 75 01 jnz short 004016B5 ;nop
004016B4 68 8B46688D push 8D68468B ; push 一个常数?
004016B9 7E 68 jle short 00401723
004016BB 68 6C644000 push 0040646C
004016C0 50 push eax ; 下面是字节比较,引发异常
004016C1 FF15 94424000 call dword ptr [<&msvcrt._mbscmp>] ; msvcrt._mbscmp
我到SE句柄下断就回不来拉...55555555555555 |
|