-
-
[分享]orien脱壳脚本,欢迎测试
-
发表于:
2006-8-16 18:54
4219
-
虽然脱壳机都有了,我还是现一下丑好了:
#log
//orien 2.11-2.12 目标:走到OEP(若为密码壳没有密码就不行)
gpa "LoadLibraryA","kernel32.dll"
cmp $RESULT,0
je err
bp $RESULT
esto
bc $RESULT
rtu
var cool
mov cool,eip
and cool,FFFFF000
find cool,#3B83????000075# //特殊函数判断exitprocess,getcommandlinea/w
cmp $RESULT,0
je o1 //旧版
var a
mov a,$RESULT
add a,6
mov [a],#EB#
add a,33
mov [a],#EB#
add a,33
mov [a],#EB#
mov cool,eip
oep:
find cool,#FFE0# //jmp eax
cmp $RESULT,0
je err
go $RESULT
sto
ret
err:
msg "error"
ret
o1:
mov cool,eip
sub cool,1000
jmp oep
[课程]Linux pwn 探索篇!