|
|
[注意]测试你的肺活量,按住键盘0,憋气,看你能有多少行,男人不做假!
00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 |
|
|
[讨论]详细的进程空间分布
主要就是堆和内存文件映射和xxx |
|
|
[求助]怎样实现控制台程序的命令输入自动化?
SendInput,记得让你的CMD拥有焦点 |
|
|
[原创]新鲜出炉 - MS12-004
win7 上确实没有这个洞啊,两位大哥 |
|
|
[半原创]内核中的数据结构:SplayTree
膜拜楼上楼上的太阳数~~ |
|
|
[求助]IDA能不能默认把 DWORD PTR 显示出来?
学习,再问一下为什么“去掉Create stack variables”就会显示操作数的字节宽度呢? |
|
|
工作已经找到
愿意来深圳不? |
|
|
|
|
|
[原创]病毒分析
API HASH,拷贝dll到新申请的空间里执行也是很多壳用到的技术~~ |
|
|
[求助]到达GetModuleHandle找不到main函数
[QUOTE=pc小波;1029316]0040208B |. 8B45 EC mov eax, dword ptr [ebp-14] 0040208E |. 8B08 mov ecx, dword ptr [eax] 00402090 |. 8B09 mov ...[/QUOTE] 00402071 |. FF75 9C push dword ptr [ebp-64] ; 命令行参数 00402074 |. 56 push esi 00402075 |. 56 push esi ; /pModule 00402076 |. FF15 60B04000 call dword ptr [<&kernel32.GetModuleH>; \GetModuleHandleA 0040207C |. 50 push eax ; hInstance 0040207D |. E8 6EF3FFFF call 004013F0 老大,004013F0的三个参数不正是main函数的三个参数吗?况且这个函数进去后就界面都出来了,难道还不是main!? |
|
|
[求助]到达GetModuleHandle找不到main函数
[QUOTE=pc小波;1029249]0040207D |. E8 6EF3FFFF call Unpack_.004013F0 //到此处就跟不下去了啊 00402082 |. 8945 A0 mov dword ptr ss:[ebp-60], eax 0040208...[/QUOTE] ‘你的到此处就跟不下去了啊’就是main函数了啊~~~ |
|
|
[原创]简单谈谈Java Exploit
顶顶更健康! |
|
|
[求助]怎样才能保护自己的ring3hook不被别人轻易恢复
如果不怕麻烦,把要HOOK的代码页拷贝出来,把要HOOK的代码页设置为PAGE_GUARD,然后加VEH,然后异常的时候跳到copy出来的代码处执行,当然要处理复杂的重定位,这样HOOK的点就可以大于4个了,不过就麻烦了 这样不修改内存当然就查不出HOOK了代码了~~~~ |
|
|
|
|
|
[求助]使用FileTimeToSystemTime时遇到的时区问题
[QUOTE='wofan[OCN];995349']FileTime--->FileLocalTime--->SystemTime 004030AC DB 07 05 00 01 00 17 00 01 00 38 00 3A 00 00 00 ?....8.:... 004030BC 00 11 EB B2 EC 18 CC ...[/QUOTE] 非常感谢大牛点拨,原来GetFileTime通过FILETIME数据结构获取的数据是UTC时间,所以我怎么改时区然后通过FileTimeToSystemTime函数得到的都是UTC时间 应该使用FileTimeToLocalTime函数先将时间转化为本地时间,比如我的机器是北京时区,也就是会将FILETIME加上8个小时 最后再使用FileTimeToSystemTime得到当前系统的时间,如果我的时区修改为+7或者其它情况,最终得到的值就是正确的了!! 也就是大牛所说的:FileTime--->FileLocalTime--->SystemTime |
操作理由
RANk
{{ user_info.golds == '' ? 0 : user_info.golds }}
雪币
{{ experience }}
课程经验
{{ score }}
学习收益
{{study_duration_fmt}}
学习时长
基本信息
荣誉称号:
{{ honorary_title }}
勋章
兑换勋章
证书
证书查询 >
能力值