希望大吓们指点一下,我在脱netget的jdpak时使用ESP定律找到OEP
005A2698 55 PUSH EBP //OEP?????????
005A2699 8BEC MOV EBP,ESP
005A269B 83C4 F0 ADD ESP,-10
005A269E B8 B01F5A00 MOV EAX,NetGet.005A1FB0
005A26A3 E8 744EE6FF CALL NetGet.0040751C
005A26A8 B8 1C275A00 MOV EAX,NetGet.005A271C ; ASCII "285F170B-5A85-4E2A-8BF2-858B55970C54"
005A26AD E8 52F8FFFF CALL NetGet.005A1F04
005A26B2 84C0 TEST AL,AL
005A26B4 74 0E JE SHORT NetGet.005A26C4
005A26B6 A1 F0875A00 MOV EAX,DWORD PTR DS:[5A87F0]
005A26BB 8B00 MOV EAX,DWORD PTR DS:[EAX]
005A26BD E8 D22EEDFF CALL NetGet.00475594
005A26C2 EB 48 JMP SHORT NetGet.005A270C
005A26C4 A1 F0875A00 MOV EAX,DWORD PTR DS:[5A87F0]
005A26C9 8B00 MOV EAX,DWORD PTR DS:[EAX]
005A26CB E8 402DEDFF CALL NetGet.00475410
而我在脱壳当前调试程序后,用importREC修复不了,请问是我的OEP错了,还是别原因??
netget 下载 http://www.netget.com.cn/NetGetSetup.exe
[注意]传递专业知识、拓宽行业人脉——看雪讲师团队等你加入!