0441BFE2 8B55 F8 mov edx, dword ptr [ebp-8]
0441BFE5 B8 BCC44104 mov eax, 0441C4BC ; |
0441BFEA E8 2151FFFF call <jmp.&rtl100.System::Pos>
0441BFEF 8BC8 mov ecx, eax
0441BFF1 49 dec ecx
0441BFF2 BA 01000000 mov edx, 1
0441BFF7 8B45 F8 mov eax, dword ptr [ebp-8]
0441BFFA E8 0151FFFF call <jmp.&rtl100.System::LStrCopy>
0441BFFF 8B45 F4 mov eax, dword ptr [ebp-C]
0441C002 E8 C950FFFF call <jmp.&rtl100.System::LStrLen>
0441C007 8BC8 mov ecx, eax
0441C009 41 inc ecx
0441C00A 8D45 F8 lea eax, dword ptr [ebp-8]
0441C00D BA 01000000 mov edx, 1
0441C012 E8 F150FFFF call <jmp.&rtl100.System::LStrDelete>
0441C017 8D45 FC lea eax, dword ptr [ebp-4]
0441C01A 8B55 F4 mov edx, dword ptr [ebp-C] ; EDX为连接数
0441C01D E8 B650FFFF call <jmp.&rtl100.System::LStrCat>
0441C022 8D45 FC lea eax, dword ptr [ebp-4]
0441C025 BA C4C54104 mov edx, 0441C5C4 ; 连接】
0441C02A E8 A950FFFF call <jmp.&rtl100.System::LStrCat>
0441C02F 8B45 EC mov eax, dword ptr [ebp-14]
0441C032 8B80 84030000 mov eax, dword ptr [eax+384]
0441C038 E8 935AFFFF call <jmp.&cxEditorsD10.Cxmemo::TcxCustomMemo::>
0441C03D 8B55 FC mov edx, dword ptr [ebp-4]
0441C040 8B08 mov ecx, dword ptr [eax]
0441C042 FF51 38 call dword ptr [ecx+38]
0441C045 8D45 FC lea eax, dword ptr [ebp-4]
0441C048 BA D4C54104 mov edx, 0441C5D4
0441C04D E8 6650FFFF call <jmp.&rtl100.System::LStrLAsg>
0441C052 8B45 EC mov eax, dword ptr [ebp-14]
0441C055 8B80 84030000 mov eax, dword ptr [eax+384]
0441C05B E8 705AFFFF call <jmp.&cxEditorsD10.Cxmemo::TcxCustomMemo::>
0441C060 8B55 FC mov edx, dword ptr [ebp-4]
0441C063 8B08 mov ecx, dword ptr [eax]
0441C065 FF51 38 call dword ptr [ecx+38]
0441C068 8D45 F4 lea eax, dword ptr [ebp-C]
0441C06B 50 push eax
0441C06C 8B55 F8 mov edx, dword ptr [ebp-8]
0441C06F B8 BCC44104 mov eax, 0441C4BC ; |
在这里用看OD的堆栈可知默认用户是35 00 00 00,即5用户,如果把35改成
39,就可以看到是9用户,但这样得到的用户数,下次运行又变成5了。
如何在想改成9或者10用户,改怎么做?
0441C01A 8B55 F4 mov edx, dword ptr [ebp-C]
我也试过用inline loader,但不得要领,修改无效!
[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)