|
|
情报 : 微软对 kernel mode driver 的管制开始
每天出的驱动那么多,应该比较容易认证 |
|
|
|
|
|
help!!!winxp的消息断点断不下!!!
Syntax BMSG hWnd [L] [begin-msg [end-msg ]] [IF expression [DO "command1;command2;..."]] 格式: BMSG 窗口句柄 [记录] [消息范围起始 [消息范围末尾]] [如果 表达式 [做 "命令1;命令2;...."]] hWnd Window handle value returned from CreateWindow or CreateWindowEX. L Logs messages to the SoftICE Command window. begin-msg Single Windows message or lower message number in a range of Windows messages. If you do not specify a range with an end-msg, only the begin-msg will cause a break. Note: For both begin-msg and end-msg, the message numbers can be specified either in hexadecimal or by using the actual ASCII names of the messages, for example, WM_QUIT. end-msg Higher message number in a range of Windows messages. IF expression Conditional expression: the expression must evaluate to TRUE (non-zero) for the breakpoint to trigger. DO command Breakpoint action: A series of SoftICE commands can execute when the breakpoint triggers. Note: You can combine breakpoint count functions (BPCOUNT, BPMISS, BPTOTAL, BPLOG, and BPINDEX) with conditional expressions to monitor and control breakpoints based on the number of times a particular breakpoint has or has not triggered. See the chapter on “Using Breakpoints,” in the Using SoftICE document. Use The BMSG command is used to set breakpoints on a window’s message handler that will trigger when it receives messages that either match a specified message type, or fall within an indicated range of message types. If you do not specify a message range, the breakpoint applies to ALL Windows messages. If you specify the L parameter, SoftICE logs the messages into the Command window instead of popping up when the message occurs. When SoftICE does pop up on a BMSG breakpoint, the instruction pointer (CS:[E]IP) is set to the first instruction of the message handling procedure. Each time SoftICE breaks, the current message displays in the following format: hWnd=xxxx wParam=xxxx lParam=xxxxxxxx msg=xxxx message-name Note: These are the parameters that are passed to the message procedure. All numbers are hexadecimal. The message-name is the Windows defined name for the message. To display valid Windows messages, enter the WMSG command with no parameters. To obtain valid window handles, use the HWND command. You can set multiple BMSG breakpoints on one window-handle, but the message ranges for the breakpoints might not overlap. Example This command sets a breakpoint on the message handler for the Window that has the handle 9BC. The breakpoint triggers and SoftICE pops up when the message handler receives messages with a type within the range WM_MOUSEFIRST to WM_MOUSELAST, inclusive. This range includes all of the Windows mouse messages. :BMSG 9BC wm_mousefirst wm_mouselast The next command places a breakpoint on the message handler for the Window with the handle F4C. The L parameter causes SoftICE to log the breakpoint information to the SoftICE Command window when the breakpoint is triggered, instead of popping up. The message range on which the breakpoint triggers includes any message with a type value less than or equal to WM_CREATE. You can view the output from this breakpoint being triggered by popping into SoftICE and scrolling through the command buffer. :BMSG f4c L 0 wm_create |
|
|
发个新的狗壳给大家玩玩!HASP公司最新产品HASPHL
想必DALAO大侠已经搞定了这壳了。恭喜恭喜 |
|
|
[求助]那里可以找到linux下的IDA
用objdump |
|
|
|
|
|
|
|
|
|
|
|
[求助]代码不懂,谁帮忙解释一下.
:00610298 6A00 push 00000000 //入栈00000000 :0061029A 6A00 push 00000000 :0061029C 49 dec ecx // DEC是减1 ecx减1 :0061029D 75F9 jne 00610298 //不相等跳到00610298 :0061029F 51 push ecx //ecx寄存器入栈 :006102A0 53 push ebx //ebx寄存器入栈 :006102A1 56 push esi //esi寄存器入栈 :006102A2 8BF0 mov esi, eax //把eax 寄存器值传送esi :006102A4 33C0 xor eax, eax //eax清空 上面这段代码的作用是申请临时变量并将变量值清零 |
|
|
灰鸽子木马来源追踪
这个可是用到实处了 |
|
|
|
|
|
[通告]任命loveboom为『加壳与脱壳』版主
强贴必留名,我顶 |
|
|
[精华集]《看雪论坛精华7》,2006年1月发布
来晚了,来晚了。 |
|
|
如何编辑LINUX平台下的(某个)软件的启动画面(资源)?
你这个是嵌入式LINUX版本的吧。你把程序文件打包放上来,趁上午有空我看看。 |
|
|
如何编辑LINUX平台下的(某个)软件的启动画面(资源)?
关键在于是由什么库来编写,比如:GTK,XLIB,QT或者其它脚本语言。 |
|
|
How can i get the handles of Message Hook?
逆向ICEWORD可以到驱动开发网上找到SYSER DEBUG作者的一篇文章,ICEWORD有ANTI-SOFTICE的代码。 |
|
|
|
|
|
请问有?有叫tElock与TMG的新网址吗?
很久都不更新了。 |
|
|
|
操作理由
RANk
{{ user_info.golds == '' ? 0 : user_info.golds }}
雪币
{{ experience }}
课程经验
{{ score }}
学习收益
{{study_duration_fmt}}
学习时长
基本信息
荣誉称号:
{{ honorary_title }}
勋章
兑换勋章
证书
证书查询 >
能力值