ServiceMain
Image File Execution Options
Debuggers
windbg
cdb
ntsd
dbgsrv
Debuggers\x64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
svchost.exe
debugger
C:\Users\cmtest\Desktop\x64\ntsd.exe -server tcp:port=1234 -noio -y srv*C:\win_symbols*afcK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3#2K6k6r3I4Q4x3X3g2E0K9h3y4J5L8%4y4G2k6Y4c8Q4x3X3g2U0L8$3#2Q4x3V1k6V1L8%4N6F1L8r3!0S2k6q4)9J5c8Y4y4&6L8h3u0G2L8s2x3`.
-y
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control
ServicesPipeTimeout
登录
允许服务与桌面交互
Connect to remote debugger
Connection strings
tcp:server=192.168.29.128,port=1234
OK
svchost2.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService
ImagePath
svchost2
ntdll!NtTerminateProcess
.reload
The system cannot find the file specified
ntsd -p <pid>
.reload /f
LdrInitializeThunk
termsrv.dll
LoadLibrary
GetServiceMainFunctions
System\\CurrentControlSet\\Services\\Parameters
ServiceDll
ServiceManifest
a1
a1 + 8
SvchostPushServiceGlobals
SvchostPushServiceGlobalsEx
a2
a3
a4
DllMainCRTStartup
EB FE
termsrv.pdb
termsrv!DllMainCRTStartup
CC
int 3
[招生]系统0day安全-IOT设备漏洞挖掘(第6期)!
yangya 直接改二进制文件不需要绕过签名吗?