p118
重新运行程序,PacMe将打开KwazyWeb.bit文件,读取数据进行计算比较。代码如下:
004016E8 . 6A 00 push 0 ; /pOverlapped = NULL
004016EA . 68 48344000 push 00403448 ; |pBytesRead = PacMe.00403448
004016EF . 6A 01 push 1 ; |BytesToRead = 1
004016F1 . 68 FA344000 push 004034FA ; |Buffer = PacMe.004034FA
004016F6 . FF35 44344000 push dword ptr [403444] ; |hFile = NULL
004016FC . E8 11010000 call <jmp.&KERNEL32.ReadFile> ; \ReadFile
==============================
od中加载,怎么找到 地址 004016E8 处的代码的? 求过程!
我试了下对 check按钮 下消息断点,转到的代码处是 【地址:0040129A】
00401275 |> /6A 00 /push 0 ; /MsgFilterMax = 0
00401277 |. |6A 00 |push 0 ; |MsgFilterMin = 0
00401279 |. |6A 00 |push 0 ; |hWnd = NULL
0040127B |. |8D45 B4 |lea eax, dword ptr [ebp-4C] ; |
0040127E |. |50 |push eax ; |pMsg
0040127F |. |E8 0A050000 |call <jmp.&USER32.GetMessageA> ; \GetMessageA
00401284 |. |0BC0 |or eax, eax
00401286 |. |74 14 |je short 0040129C
00401288 |. |8D45 B4 |lea eax, dword ptr [ebp-4C]
0040128B |. |50 |push eax ; /pMsg
0040128C |. |E8 57050000 |call <jmp.&USER32.TranslateMessage> ; \TranslateMessage
00401291 |. |8D45 B4 |lea eax, dword ptr [ebp-4C]
00401294 |. |50 |push eax ; /pMsg
00401295 |. |E8 E8040000 |call <jmp.&USER32.DispatchMessageA> ; \DispatchMessageA
0040129A |.^\EB D9 \jmp short 00401275
==================================================
求转到4016e8地址处代码的过程!!!!!!!!!!!
[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)