libc_and_libc_ok.rar
我按照做法:
static int dlopenAddr = 0xD028; //opendl地址
static int InitArrayAddr = 0x00049E20 - 0x1000; //此处IDA的地址总是比UE中的多0x1000
static int asmAddr = 0x4A400; //代码插入位置
得到libc_ok.so,拉进IDA,发现汇编在0x4B400.如下,是正确的吗?
.data:0004B400
.data:0004B400 ; =============== S U B R O U T I N E =======================================
.data:0004B400
.data:0004B400
.data:0004B400 sub_4B400
.data:0004B400 FF 40 2D E9 STMFD SP!, {R0-R7,LR}
.data:0004B404 18 00 9F E5 LDR R0, =(aLibckis_so - 0x4B414)
.data:0004B408 00 10 A0 E3 MOV R1, #0
.data:0004B40C 00 00 8F E0 ADD R0, PC, R0 ; "libckis.so"
.data:0004B410 04 0B FF EB BL loc_E028
.data:0004B414 FF 40 BD E8 LDMFD SP!, {R0-R7,LR}
.data:0004B418 08 00 9F E5 LDR R0, =(loc_F2F8+1 - 0x4B424)
.data:0004B41C 00 00 8F E0 ADD R0, PC, R0 ; loc_F2F8
.data:0004B420 10 FF 2F E1 BX R0
.data:0004B420 ; End of function sub_4B400
.data:0004B420
.data:0004B420 ; ---------------------------------------------------------------------------
.data:0004B424 2C 00 00 00 off_4B424 DCD aLibckis_so - 0x4B414
.data:0004B424 ; DATA XREF: sub_4B400+4r
.data:0004B424 ; "libckis.so"
.data:0004B428 D5 3E FC FF off_4B428 DCD loc_F2F8+1 - 0x4B424
.data:0004B428 ; DATA XREF: sub_4B400+18r
.data:0004B42C 00 DCB 0
.data:0004B42D 00 DCB 0
.data:0004B42E 00 DCB 0
.data:0004B42F 00 DCB 0
.data:0004B430 00 DCB 0
.data:0004B431 00 DCB 0
.data:0004B432 00 DCB 0
.data:0004B433 00 DCB 0
.data:0004B434 00 DCB 0
.data:0004B435 00 DCB 0
.data:0004B436 00 DCB 0
.data:0004B437 00 DCB 0
.data:0004B438 00 DCB 0
.data:0004B439 00 DCB 0
.data:0004B43A 00 DCB 0
.data:0004B43B 00 DCB 0
.data:0004B43C 00 DCB 0
.data:0004B43D 00 DCB 0
.data:0004B43E 00 DCB 0
.data:0004B43F 00 DCB 0
.data:0004B440 6C 69 62 63 6B 69 73 2E+aLibckis_so DCB "libckis.so",0 ; DATA XREF: sub_4B400+Co
.data:0004B440 73 6F 00 ; .data:off_4B424o
.data:0004B44B 00 DCB 0
.data:0004B44C 00 DCB 0
.data:0004B44D 00 DCB 0
.data:0004B44E 00 DCB 0
.data:0004B44F 00 DCB 0
.data:0004B450 00 DCB 0
.data:0004B451 00 DCB 0
.data:0004B452 00 DCB 0
.data:0004B453 00 DCB 0
.data:0004B454 00 DCB 0
.data:0004B455 00 DCB 0
.data:0004B456 00 DCB 0
上传的附件: