能力值:
( LV2,RANK:10 )
|
-
-
2 楼
没人理我????
|
能力值:
( LV2,RANK:10 )
|
-
-
3 楼
脱壳了限制也就没有了.
|
能力值:
( LV2,RANK:10 )
|
-
-
4 楼
ARM 3.6的壳.下bp GetModuleHandleA+5 然后修改MAGIC JMP.
00E24B82 8B4D 08 mov ecx,dword ptr ss:[ebp+8] ; kernel32.7C800000
00E24B85 3BC8 cmp ecx,eax
00E24B87 75 07 jnz short 00E24B90 //修改成 jnz 00E24BA9
00E24B89 B8 18D3E300 mov eax,0E3D318
00E24B8E EB 30 jmp short 00E24BC0
00E24B90 393D D8D7E300 cmp dword ptr ds:[E3D7D8],edi
00E24B96 B8 D8D7E300 mov eax,0E3D7D8
00E24B9B 74 0C je short 00E24BA9
00E24B9D 3B48 08 cmp ecx,dword ptr ds:[eax+8]
00E24BA0 74 1B je short 00E24BBD
00E24BA2 83C0 0C add eax,0C
00E24BA5 3938 cmp dword ptr ds:[eax],edi
00E24BA7 ^ 75 F4 jnz short 00E24B9D
|
|
|