- UID
- 6804
注册时间2006-1-11
阅读权限30
最后登录1970-1-1
龙战于野
该用户从未签到
|
发表于 2009-12-29 14:59:17
|
显示全部楼层
试下我这个去掉登录框直接进入外挂,是灭了一个CALL,改了一个跳转。
去登录框:004B3C2C /. 55 PUSH EBP
004B3C2D |. 8BEC MOV EBP,ESP
004B3C2F |. 6A 00 PUSH 0
004B3C31 |. 6A 00 PUSH 0
004B3C33 |. 53 PUSH EBX
004B3C34 |. 56 PUSH ESI
004B3C35 |. 8BF0 MOV ESI,EAX
004B3C37 |. 33C0 XOR EAX,EAX
004B3C39 |. 55 PUSH EBP
004B3C3A |. 68 433D4B00 PUSH 004B3D43
004B3C3F |. 64:FF30 PUSH DWORD PTR FS:[EAX]
004B3C42 |. 64:8920 MOV DWORD PTR FS:[EAX],ESP
004B3C45 |. E8 E2FBFFFF CALL 004B382C
004B3C4A |. 8BCE MOV ECX,ESI
004B3C4C |. B2 01 MOV DL,1
004B3C4E |. A1 902C4B00 MOV EAX,DWORD PTR DS:[4B2C90]
004B3C53 |. E8 9C7EFAFF CALL 0045BAF4
004B3C58 |. 8BD8 MOV EBX,EAX
004B3C5A |. 8D83 28030000 LEA EAX,DWORD PTR DS:[EBX+328]
004B3C60 |. BA 583D4B00 MOV EDX,004B3D58 ; 如何获得“Boss使用资格”
004B3C65 |. E8 E604F5FF CALL 00404150
004B3C6A |. 8D83 2C030000 LEA EAX,DWORD PTR DS:[EBX+32C]
004B3C70 |. BA 7C3D4B00 MOV EDX,004B3D7C ; http://bbs.56seer.com/thread-1682-1-1.html
004B3C75 |. E8 D604F5FF CALL 00404150
004B3C7A |. 8D83 30030000 LEA EAX,DWORD PTR DS:[EBX+330]
004B3C80 |. BA B03D4B00 MOV EDX,004B3DB0 ; 您无权使用,点击查看如何获得“Boss使用资格”?
004B3C85 |. E8 C604F5FF CALL 00404150
004B3C8A |. 8D83 34030000 LEA EAX,DWORD PTR DS:[EBX+334]
004B3C90 |. BA E83D4B00 MOV EDX,004B3DE8 ; _exgp:1732
004B3C95 |. E8 B604F5FF CALL 00404150
004B3C9A |. 8BC3 MOV EAX,EBX
004B3C9C |. 8B10 MOV EDX,DWORD PTR DS:[EAX]
004B3C9E FF92 EC000000 CALL DWORD PTR DS:[EDX+EC] 调用登录框 nop
004B3CA4 |. 48 DEC EAX
004B3CA5 74 15 JE SHORT 004B3CBC 进入外挂 jmp
004B3CA7 |. 8BC3 MOV EAX,EBX
004B3CA9 |. E8 5AF6F4FF CALL 00403308
004B3CAE |. A1 0C7F4B00 MOV EAX,DWORD PTR DS:[4B7F0C]
这样就比较完美了
[ 本帖最后由 freewold 于 2009-12-29 15:06 编辑 ] |
|