能力值:
( LV2,RANK:10 )
|
-
-
5 楼
然后我在OD中根据这图像提示,找到了相关代码。
008948FA . C780 38060000>mov dword ptr [eax+638], 1
00894904 . 8B45 FC mov eax, dword ptr [ebp-4]
00894907 . C680 C1060000>mov byte ptr [eax+6C1], 1
0089490E . 8B45 FC mov eax, dword ptr [ebp-4]
00894911 . C680 C2060000>mov byte ptr [eax+6C2], 1
00894918 . 8B45 FC mov eax, dword ptr [ebp-4]
0089491B . 8B90 00030000 mov edx, dword ptr [eax+300]
00894921 B9 08518900 mov ecx, 00895108 ; select count(*) as t_num from t_man
00894926 . 8B45 FC mov eax, dword ptr [ebp-4]
00894929 . E8 06F8FFFF call 00894134
0089492E . 8B45 FC mov eax, dword ptr [ebp-4]
00894931 . 8B80 00030000 mov eax, dword ptr [eax+300]
00894937 . BA 34518900 mov edx, 00895134 ; t_num
0089493C . E8 C795C3FF call 004CDF08
00894941 . 8B10 mov edx, dword ptr [eax]
00894943 . FF52 58 call dword ptr [edx+58]
00894946 . 8BD8 mov ebx, eax
00894948 . 6A FF push -1
0089494A . 8B45 FC mov eax, dword ptr [ebp-4]
0089494D . 8B80 B4060000 mov eax, dword ptr [eax+6B4]
00894953 . B9 44518900 mov ecx, 00895144 ; max
00894958 . BA 50518900 mov edx, 00895150 ; config
0089495D . 8B30 mov esi, dword ptr [eax]
0089495F . FF56 08 call dword ptr [esi+8]
00894962 . 8BF0 mov esi, eax
00894964 . 8D8D 3CFBFFFF lea ecx, dword ptr [ebp-4C4]
0089496A . A1 04B78F00 mov eax, dword ptr [8FB704]
0089496F . 8B00 mov eax, dword ptr [eax]
00894971 . 8B90 40060000 mov edx, dword ptr [eax+640]
00894977 . A1 ACB08F00 mov eax, dword ptr [8FB0AC]
0089497C . 8B00 mov eax, dword ptr [eax]
0089497E . E8 95DFFFFF call 00892918
00894983 . 8B95 3CFBFFFF mov edx, dword ptr [ebp-4C4]
00894989 . A1 04B78F00 mov eax, dword ptr [8FB704]
0089498E . 8B00 mov eax, dword ptr [eax]
00894990 . 8B80 44060000 mov eax, dword ptr [eax+644]
00894996 . E8 7505B7FF call 00404F10
0089499B . 75 6C jnz short 00894A09
0089499D . A1 04B78F00 mov eax, dword ptr [8FB704]
008949A2 . 8B00 mov eax, dword ptr [eax]
008949A4 . C680 3C060000>mov byte ptr [eax+63C], 0
008949AB . 81FB C8000000 cmp ebx, 0C8
008949B1 . 7D 08 jge short 008949BB
008949B3 . 81FE C8000000 cmp esi, 0C8
008949B9 . 7C 4E jl short 00894A09
008949BB > 8B45 FC mov eax, dword ptr [ebp-4]
008949BE . 80B8 C1060000>cmp byte ptr [eax+6C1], 0
008949C5 . 75 10 jnz short 008949D7
008949C7 . A1 04B78F00 mov eax, dword ptr [8FB704]
008949CC . 8B00 mov eax, dword ptr [eax]
008949CE . C680 3C060000>mov byte ptr [eax+63C], 0
008949D5 . EB 32 jmp short 00894A09
008949D7 > A1 04B78F00 mov eax, dword ptr [8FB704]
008949DC . 8B00 mov eax, dword ptr [eax]
008949DE . C680 3C060000>mov byte ptr [eax+63C], 1
008949E5 . A1 04B78F00 mov eax, dword ptr [8FB704]
008949EA . 8B00 mov eax, dword ptr [eax]
008949EC . 33D2 xor edx, edx
008949EE . 8990 38060000 mov dword ptr [eax+638], edx
008949F4 . 6A 00 push 0
008949F6 . 66:8B0D 58518>mov cx, word ptr [895158]
008949FD . B2 03 mov dl, 3
008949FF . B8 64518900 mov eax, 00895164 ; 您使用的是试用版,请联系里诺软件购买正式版本!
00894A04 . E8 E3AABAFF call 0043F4EC
00894A09 > A1 04B78F00 mov eax, dword ptr [8FB704]
00894A0E . 8B00 mov eax, dword ptr [eax]
00894A10 . 80B8 3C060000>cmp byte ptr [eax+63C], 0
00894A17 . 74 29 je short 00894A42
00894A19 . 83FB 1E cmp ebx, 1E
00894A1C . 7C 24 jl short 00894A42
00894A1E . A1 04B78F00 mov eax, dword ptr [8FB704]
00894A23 . 8B00 mov eax, dword ptr [eax]
00894A25 . 33D2 xor edx, edx
00894A27 . 8990 38060000 mov dword ptr [eax+638], edx
00894A2D . 6A 00 push 0
00894A2F . 66:8B0D 58518>mov cx, word ptr [895158]
00894A36 . B2 03 mov dl, 3
00894A38 . B8 9C518900 mov eax, 0089519C ; 数量超过限制,请联系我们购买正式版本!
00894A3D . E8 AAAABAFF call 0043F4EC
00894A42 > 8D95 34FBFFFF lea edx, dword ptr [ebp-4CC]
00894A48 . A1 94BD8F00 mov eax, dword ptr [8FBD94]
00894A4D . 8B00 mov eax, dword ptr [eax]
00894A4F . E8 44D7C1FF call 004B2198
00894A54 . 8B85 34FBFFFF mov eax, dword ptr [ebp-4CC]
00894A5A . 8D95 38FBFFFF lea edx, dword ptr [ebp-4C8]
00894A60 . E8 835FB7FF call 0040A9E8
我知道问题肯定在select语句那,但是不知道如何屏蔽,请大神指点下啊。
|