-
-
[求助]ring3下定位eprocess的问题
-
发表于:
2009-9-9 21:23
6670
-
0:000> dd fs:[30]
003b:00000030 7ffdb000 00000000 00000000 00000000
003b:00000040 00000000 00000000 00000000 00000000
003b:00000050 00000000 00000000 00000000 00000000
0:000> dt _eprocess 0x7ffdb000-0x1b0
ntdll!_EPROCESS
+0x000 Pcb : _KPROCESS
+0x1a0 ActiveThreads : ??
..............
..............
..............
+0x1a4 GrantedAccess : ??
+0x1a8 DefaultHardErrorProcessing : ??
+0x1ac LastThreadExitStatus : ??
+0x1b0 Peb : 0x00010000 _PEB
.....................
.....................
.....................
很明显得到的结果是错误的..为什么...
[课程]Android-CTF解题方法汇总!