- UID
- 38834
注册时间2007-12-2
阅读权限10
最后登录1970-1-1
周游历练

该用户从未签到
|
发表于 2008-2-15 22:10:42
|
显示全部楼层
004DA481 |. E8 0E1AF7FF CALL RegEdite.0044BE94
004DA486 |. 8B45 FC MOV EAX,DWORD PTR SS:[EBP-4]
004DA489 |. E8 2678FCFF CALL RegEdite.004A1CB4 //这里F7进入
004DA48E |. 84C0 TEST AL,AL
004DA490 0F84 80000000 JE RegEdite.004DA516
004DA496 |. 8D55 F8 LEA EDX,DWORD PTR SS:[EBP-8]
004DA499 |. 8B83 F4020000 MOV EAX,DWORD PTR DS:[EBX+2F4]
004DA49F |. E8 F019F7FF CALL RegEdite.0044BE94
004DA4A4 |. 8B45 F8 MOV EAX,DWORD PTR SS:[EBP-8]
---------------------------------------------------------------------------------------
F7进入后的代码:
004A1CB4 55 PUSH EBP
004A1CB5 8BEC MOV EBP,ESP
004A1CB7 33C9 XOR ECX,ECX
004A1CB9 51 PUSH ECX
004A1CBA . 51 PUSH ECX
004A1CBB . 51 PUSH ECX
004A1CBC . 51 PUSH ECX
把
004A1CB4 55 PUSH EBP
改为
mov eax,1
ret
这个地方做为暴破点应该更合适一些 |
|