00565405 8B45 FC mov eax, dword ptr [ebp-4]
00565408 50 push eax //压入参数
00565409 8B4D F4 mov ecx, dword ptr [ebp-C]
0056540C 8B51 28 mov edx, dword ptr [ecx+28]
0056540F 8B45 F4 mov eax, dword ptr [ebp-C]
00565412 8B48 28 mov ecx, dword ptr [eax+28] //寄存器参数
00565415 8B12 mov edx, dword ptr [edx]
00565417 8B42 14 mov eax, dword ptr [edx+14]
0056541A FFD0 call eax ; //eax = 0x008551D0 即明文发包函数
0056541C 8945 F8 mov dword ptr [ebp-8], eax
0056541F 8B4D FC mov ecx, dword ptr [ebp-4]
00565422 8B11 mov edx, dword ptr [ecx]
00565424 8B45 FC mov eax, dword ptr [ebp-4]
00565427 50 push eax
00565428 8B4A 08 mov ecx, dword ptr [edx+8]
0056542B FFD1 call ecx
0056542D 837D F8 00 cmp dword ptr [ebp-8], 0
00565431 75 23 jnz short 00565456
00565433 68 A8E7A800 push 00A8E7A8 //SendMsg2GateWay
typedef struct _SendParamSt
{
DWORD dwMMSend_A; //参数A,固定基址
DWORD dwMMSend_B; //参数B,固定基址
DWORD dwUnknow; //未知,默认1
DWORD dwLen0; //协议长度
DWORD dwLen; //协议长度
DWORD dwBuff; //协议数据内存地址
}TSendParamSt,*PSendParamSt;
0085A88A C700 10E5AB00 MOV DWORD PTR DS:[EAX],game.00ABE510
0085A890 C740 04 F8E4AB00 MOV DWORD PTR DS:[EAX+4],game.00ABE4F8
0085A897 C740 08 01000000 MOV DWORD PTR DS:[EAX+8],1
0085A89E 8948 14 MOV DWORD PTR DS:[EAX+14],ECX
0085A8A1 5B POP EBX
0085A8A2 C3 RETN
00428657 83F8 0A CMP EAX,0A
0042865A 75 07 JNZ SHORT game.00428663
0042865C 33C0 XOR EAX,EAX
0042865E E9 A5040000 JMP game.00428B08
00428663 A1 E45FB600 MOV EAX,DWORD PTR DS:[B65FE4]//B65FE4即基址
00428668 8B10 MOV EDX,DWORD PTR DS:[EAX]
0042866A 8B0D E45FB600 MOV ECX,DWORD PTR DS:[B65FE4]
00428670 8B42 10 MOV EAX,DWORD PTR DS:[EDX+10]
00428673 FFD0 CALL NEAR EAX
0056540C 8B51 28 mov edx, dword ptr [ecx+28] //0x28偏移
0056540F 8B45 F4 mov eax, dword ptr [ebp-C]
00565412 8B48 28 mov ecx, dword ptr [eax+28]
005977B4 8B0D F085C201 MOV ECX,DWORD PTR DS:[1C285F0]//1C285F0
005977BA 8B11 MOV EDX,DWORD PTR DS:[ECX]
005977BC 8B0D F085C201 MOV ECX,DWORD PTR DS:[1C285F0]
005977C2 8B02 MOV EAX,DWORD PTR DS:[EDX]
005977C4 FFD0 CALL NEAR EAX
00529F20 8B51 30 MOV EDX,DWORD PTR DS:[ECX+30]
00529F23 8B45 F4 MOV EAX,DWORD PTR SS:[EBP-C]
00529F26 8B48 30 MOV ECX,DWORD PTR DS:[EAX+30]
[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)