-
-
[求助]过TP双机调试windbg重启
-
发表于:
2012-10-11 17:34
6670
-
按照常规思路:
直接返回KdDisableDebugger
绕过循环和mov dword ptr [ecx],eax 的KdpStub 赋值。
然后一旦g运行就windbg就重启,如下。求各位大大指导下!
Shutdown occurred at (Thu Oct 11 16:25:14.265 2012 (UTC + 8:00))...unloading all symbol tables.
Waiting to reconnect...
Connected to Windows XP 2600 x86 compatible target at (Thu Oct 11 16:25:14.984 2012 (UTC + 8:00)), ptr64 FALSE
Kernel Debugger connection established. (Initial Breakpoint requested)
[课程]FART 脱壳王!加量不加价!FART作者讲授!