-
-
[求助]汇编语句
-
发表于:
2017-12-11 19:22
2814
-
MEMORY:2081A jz near ptr unk_825
MEMORY:2081E or edx, 80000000h
MEMORY:20825 cli
MEMORY:20826 lgdt fword ptr ds:1500h
MEMORY:2082B lidt fword ptr ds:1508h
MEMORY:20830 mov eax, cr0
MEMORY:20833 or eax, edx
MEMORY:20836 mov cr0, eax
MEMORY:20839 xchg bx, bx
MEMORY:2083B nop
MEMORY:2083C jmp short near ptr unk_83F
MEMORY:2083C ; ---------------------------------------------------------------------------
MEMORY:2083E db 90h ;
MEMORY:2083F ; ---------------------------------------------------------------------------
MEMORY:2083F push 50h ; 'P'
MEMORY:20841 push 845h
MEMORY:20844 retf
MEMORY:20844 ; ---------------------------------------------------------------------------
MEMORY:20845 mov ax, 60h ; '`'
MEMORY:20848 mov ds, ax
MEMORY:2084A assume ds:nothing
MEMORY:2084A mov ss, ax
MEMORY:2084C assume ss:nothing
MEMORY:2084C mov es, ax
MEMORY:2084E assume es:nothing
MEMORY:2084E mov gs, ax
为什么EIP执行
MEMORY:2083F (push 50 push 845h retf) 到
MEMORY:20845。
原来cs是0x2000 执行push 50h push 845h retf cs为50h, 为什么到
MEMORY:20845
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课