1.IDA 有象 word 撤销键吗?
2.IDA 我怎么知道如下过程的参数和返回值,但是F5居然知道耶
PAGE:00010964 sub_10964 proc near ; CODE XREF: sub_1129E+D3p
PAGE:00010964 ; DriverEntry+81p
PAGE:00010964
PAGE:00010964 pDeviceObject = dword ptr 4
PAGE:00010964
PAGE:00010964 mov ecx, [esp+pDeviceObject]
PAGE:00010968 mov eax, [ecx+28h] ; DeviceExtension
PAGE:0001096B mov [eax], ecx
PAGE:0001096D xor ecx, ecx
PAGE:0001096F mov [eax+4], ecx
PAGE:00010972 mov [eax+10h], ecx
PAGE:00010975 mov [eax+18h], ecx
PAGE:00010978 mov [eax+16h], cx
PAGE:0001097C mov [eax+14h], cx
PAGE:00010980 mov [eax+20h], ecx
PAGE:00010983 mov [eax+1Eh], cx
PAGE:00010987 mov [eax+1Ch], cx
PAGE:0001098B xor eax, eax
PAGE:0001098D retn 4
PAGE:0001098D sub_10964 endp
[课程]Android-CTF解题方法汇总!