好友
阅读权限30
听众
最后登录1970-1-1
|
-------------------------------------------------------------------
去检测
0042FB52 /0F84 0A000000 |je 奇易qq空.0042FB62 ; 因为这个跳 跳过去了
0042FB58 |. |B8 00000000 |mov eax,0x0
0042FB5D |. |E9 7C000000 |jmp 奇易qq空.0042FBDE ; 这里是jmp 无条件 为什么没跳呢?
0042FB62 |> \837D 08 00 |cmp [arg.1],0x0
0042FB66 |. 0F84 5D000000 |je 奇易qq空.0042FBC9
0042FB6C |. 8B1D 50F67900 |mov ebx,dword ptr ds:[0x79F650]
0042FB72 |. E8 0432FDFF |call 奇易qq空.00402D7B
0042FB77 |. 53 |push ebx
0042FB78 |. 51 |push ecx
0042FB79 |. 8B45 F4 |mov eax,[local.3]
0042FB7C |. 48 |dec eax
0042FB7D |. 79 0D |jns X奇易qq空.0042FB8C
0042FB7F |. 68 04000000 |push 0x4
0042FB84 |. E8 BEDD0200 |call 奇易qq空.0045D947
0042FB89 |. 83C4 04 |add esp,0x4
0042FB8C |> 59 |pop ecx
0042FB8D |. 5B |pop ebx
0042FB8E |. 3BC1 |cmp eax,ecx
0042FB90 |. 7C 0D |jl X奇易qq空.0042FB9F
0042FB92 |. 68 01000000 |push 0x1
0042FB97 |. E8 ABDD0200 |call 奇易qq空.0045D947 ; 获取进程ID call
0042FB9C |. 83C4 04 |add esp,0x4
0042FB9F |> C1E0 02 |shl eax,0x2
0042FBA2 |. 03D8 |add ebx,eax
0042FBA4 |. 8B1B |mov ebx,dword ptr ds:[ebx]
0042FBA6 |. 83C3 0C |add ebx,0xC
0042FBA9 |. 895D E4 |mov [local.7],ebx
0042FBAC |. 6A 01 |push 0x1
0042FBAE |. 8B5D E4 |mov ebx,[local.7]
0042FBB1 |. FF33 |push dword ptr ds:[ebx] ; 将OD 进程ID压入堆栈
0042FBB3 |. E8 28100000 |call 奇易qq空.00430BE0 ; 结束OD api
0042FB52 nop 掉
---------------------------------------------
爆破
00427F50 . 837D 08 03 cmp dword ptr ss:[ebp+0x8],0x3 ; 比较是否大于三个相册
00427F54 . 0F8E 8B000000 jle 奇易qq空.00427FE5 ; 跳到 下载代码块
00427F54 改为jmp
-------------------------------------------------------
|
|