能力值:
( LV2,RANK:10 )
|
-
-
2 楼
正在学习中,第一次在看雪抢个沙发。
|
能力值:
( LV2,RANK:10 )
|
-
-
3 楼
mac,小弟也暴搜kisevicetab一波,可里面的数组值很诧异
|
能力值:
( LV2,RANK:10 )
|
-
-
4 楼
有没有研究 名取 索引号。?
|
能力值:
( LV2,RANK:10 )
|
-
-
5 楼
楼主脚本呢?
|
能力值:
( LV2,RANK:10 )
|
-
-
6 楼
楼主,下面没有了?
|
能力值:
( LV2,RANK:10 )
|
-
-
7 楼
补充下对应脚本: aS ufLinkS "<u><col fg=\\\"emphfg\\\"><link name=\\\"%p\\\" cmd=\\\"uf 0x%p\\\">"; aS ufLinkE "</link></col></u>"; r $t1 = nt!KeServiceDescriptorTable; r $t2 = poi(@$t1 + 0x10); r $t1 = poi(@$t1); .printf "\n\nKeServiceDescriptorTable->KiServiceTable: %p\nKeServiceDescriptorTable->Count: %d\n", @$t1, @$t2; .printf "\nOrd Address fnAddr Symbols\n"; .printf "--------------------------------\n\n"; .for (r $t0 = 0; @$t0 != @$t2; r $t0 = @$t0 + 1) { r @$t3 = (poi(@$t1 + @$t0 * 4)) & 0x00000000`FFFFFFFF; $$.printf "2. %p\n", @$t3; .if ( @$t3 & 0x80000000 ) { r @$t3 = (@$t3 >> 4) | 0xFFFFFFFF`F0000000; r @$t3 = 0 - @$t3; r @$t3 = @$t1 - @$t3; } .else { r @$t3 = (@$t3 >> 4); r @$t3 = (@$t1 + @$t3); } .printf /D "[%3d] ${ufLinkS}%p${ufLinkE} (%y)\n", @$t0, @$t3, @$t3, @$t3, @$t3; } .printf "\n- end -\n";
|
能力值:
( LV2,RANK:10 )
|
-
-
8 楼
补充下对应脚本: aS ufLinkS "<u><col fg=\\\"emphfg\\\"><link name=\\\"%p\\\" cmd=\\\"uf 0x%p\\\">"; aS ufLinkE "</link></col></u>"; r $t1 = nt!KeServiceDescriptorTable; r $t2 = poi(@$t1 + 0x10); r $t1 = poi(@$t1); .printf "\n\nKeServiceDescriptorTable->KiServiceTable: %p\nKeServiceDescriptorTable->Count: %d\n", @$t1, @$t2; .printf "\nOrd Address fnAddr Symbols\n"; .printf "--------------------------------\n\n"; .for (r $t0 = 0; @$t0 != @$t2; r $t0 = @$t0 + 1) { r @$t3 = (poi(@$t1 + @$t0 * 4)) & 0x00000000`FFFFFFFF; $$.printf "2. %p\n", @$t3; .if ( @$t3 & 0x80000000 ) { r @$t3 = (@$t3 >> 4) | 0xFFFFFFFF`F0000000; r @$t3 = 0 - @$t3; r @$t3 = @$t1 - @$t3; } .else { r @$t3 = (@$t3 >> 4); r @$t3 = (@$t1 + @$t3); } .printf /D "[%3d] ${ufLinkS}%p${ufLinkE} (%y)\n", @$t0, @$t3, @$t3, @$t3, @$t3; } .printf "\n- end -\n";
|
能力值:
( LV2,RANK:10 )
|
-
-
9 楼
谢谢分享,刚刚试验了下可以成功查看
|
|
|