一般如下:
00401000 E8 51060000 call <jmp.&KERNEL32.GetCommandLineA>
00401005 0BC0 or eax,eax
00401007 0F84 D8000000 je Vgcrypt.004010E5
Submitted by ╰☆往事如风 on 2005, July 31, 5:14 AM
一般如下:
00401000 E8 51060000 call <jmp.&KERNEL32.GetCommandLineA>
00401005 0BC0 or eax,eax
00401007 0F84 D8000000 je Vgcrypt.004010E5
Submitted by ╰☆往事如风 on 2005, July 30, 6:27 PM
在脱fsg1.33壳时候。使用内存虚拟跟踪的办法快速的到达程序的oep
» 阅读全文
Submitted by ╰☆往事如风 on 2005, July 30, 4:39 PM
使用esp定律脱壳
» 阅读全文
Submitted by ╰☆往事如风 on 2005, July 30, 5:28 AM
» 阅读全文
Submitted by ╰☆往事如风 on 2005, July 15, 6:48 PM
» 阅读全文