bin = 读入文件 (“C:\Windows\System32\kernel32.dll”)sign = “8B FF 55 8B EC ?? ?? ?? 51” 签名寻找_字节集 (bin, sign, offset )调试输出 (offset )返回 (0 ) |
| 签名寻找_指针版 | 整数型 | | |
| pdata | 整数型 | | | | len | 整数型 | | | | 签名 | 文本型 | | | | 返回偏移数组 | 整数型 | | | | 置入代码 ({ 139, 125, 16, 139, 55, 49, 219, 137, 241, 133, 246, 15, 132, 3, 1, 0, 0, 138, 1, 65, 60, 32, 116, 249, 67, 132, 192, 117, 244, 131, 251, 1, 15, 134, 238, 0, 0, 0, 247, 195, 1, 0, 0, 0, 15, 132, 226, 0, 0, 0, 41, 241, 131, 193, 7, 131, 225, 252, 41, 204, 137, 231, 138, 6, 70, 60, 32, 116, 249, 136, 7, 71, 132, 192, 117, 242, 198, 7, 0, 137, 230, 139, 77, 8, 131, 235, 1, 133, 201, 15, 132, 181, 0, 0, 0, 209, 235, 139, 69, 12, 133, 192, 15, 132, 168, 0, 0, 0, 49, 210, 247, 243, 141, 80, 1, 137, 216, 131, 195, 7, 137, 85, 252, 131, 227, 252, 41, 220, 137, 231, 80, 131, 192, 3, 255, 12, 36, 193, 232, 2, 80, 87, 86, 82, 81, 232, 55, 0, 0, 0, 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 0, 0, 0, 0, 0, 0, 0, 10, 11, 12, 13, 14, 15, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 10, 11, 12, 13, 14, 15, 90, 49, 201, 131, 234, 48, 102, 139, 4, 14, 65, 102, 133, 192, 116, 43, 102, 61, 63, 63, 116, 27, 136, 199, 193, 232, 8, 138, 28, 16, 136, 248, 138, 60, 16, 198, 6, 255, 192, 231, 4, 70, 8, 223, 136, 63, 71, 235, 213, 198, 6, 0, 198, 7, 0, 70, 71, 235, 203, 199, 6, 0, 0, 0, 0, 199, 7, 0, 0, 0, 0 })重定义数组 (返回偏移数组, 假, i )置入代码 ({ 199, 64, 4, 0, 0, 0, 0, 85, 137, 68, 36, 8, 131, 125, 252, 0, 116, 114, 139, 117, 8, 139, 109, 12, 1, 245, 139, 92, 36, 12, 139, 124, 36, 16, 139, 27, 139, 63, 139, 6, 70, 33, 216, 49, 248, 116, 6, 57, 238, 114, 243, 235, 79, 139, 76, 36, 20, 73, 116, 43, 139, 92, 36, 12, 139, 124, 36, 16, 141, 86, 3, 131, 195, 4, 131, 199, 4, 139, 2, 131, 194, 4, 35, 3, 131, 195, 4, 51, 7, 117, 191, 141, 127, 4, 73, 116, 6, 57, 234, 114, 232, 235, 29, 141, 94, 255, 139, 68, 36, 8, 3, 116, 36, 24, 139, 72, 4, 43, 92, 36, 4, 255, 64, 4, 137, 92, 136, 8, 57, 238, 114, 150, 139, 68, 36, 8, 139, 64, 4, 93, 201, 194, 16, 0 })返回 (0 )|
| 签名寻找_字节集 | 整数型 | | |
| 数据 | 字节集 | | | | 签名 | 文本型 | | | | 返回偏移数组 | 整数型 | | | | 置入代码 ({ 139, 125, 12, 139, 55, 49, 219, 137, 241, 133, 246, 15, 132, 8, 1, 0, 0, 138, 1, 65, 60, 32, 116, 249, 67, 132, 192, 117, 244, 131, 251, 1, 15, 134, 243, 0, 0, 0, 247, 195, 1, 0, 0, 0, 15, 132, 231, 0, 0, 0, 41, 241, 131, 193, 7, 131, 225, 252, 41, 204, 137, 231, 138, 6, 70, 60, 32, 116, 249, 136, 7, 71, 132, 192, 117, 242, 198, 7, 0, 137, 230, 139, 77, 8, 131, 235, 1, 139, 9, 209, 235, 133, 201, 15, 132, 182, 0, 0, 0, 139, 65, 4, 131, 193, 8, 133, 192, 15, 132, 168, 0, 0, 0, 49, 210, 247, 243, 141, 80, 1, 137, 216, 131, 195, 7, 131, 227, 252, 41, 220, 137, 231, 80, 131, 192, 3, 255, 12, 36, 193, 232, 2, 80, 87, 86, 82, 81, 137, 85, 252, 232, 55, 0, 0, 0, 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 0, 0, 0, 0, 0, 0, 0, 10, 11, 12, 13, 14, 15, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 10, 11, 12, 13, 14, 15, 90, 49, 201, 131, 234, 48, 102, 139, 4, 14, 65, 102, 133, 192, 116, 43, 102, 61, 63, 63, 116, 27, 136, 199, 193, 232, 8, 138, 28, 16, 136, 248, 138, 60, 16, 198, 6, 255, 192, 231, 4, 70, 8, 223, 136, 63, 71, 235, 213, 198, 6, 0, 198, 7, 0, 70, 71, 235, 203, 199, 6, 0, 0, 0, 0, 199, 7, 0, 0, 0, 0 })重定义数组 (返回偏移数组, 假, i )置入代码 ({ 199, 64, 4, 0, 0, 0, 0, 85, 137, 68, 36, 8, 131, 125, 252, 0, 116, 115, 139, 116, 36, 4, 139, 110, 252, 1, 245, 139, 92, 36, 12, 139, 124, 36, 16, 139, 27, 139, 63, 139, 6, 70, 33, 216, 49, 248, 116, 6, 57, 238, 114, 243, 235, 79, 139, 76, 36, 20, 73, 116, 43, 139, 92, 36, 12, 139, 124, 36, 16, 141, 86, 3, 131, 195, 4, 131, 199, 4, 139, 2, 131, 194, 4, 35, 3, 131, 195, 4, 51, 7, 117, 191, 141, 127, 4, 73, 116, 6, 57, 234, 114, 232, 235, 29, 141, 94, 255, 139, 68, 36, 8, 3, 116, 36, 24, 139, 72, 4, 43, 92, 36, 4, 255, 64, 4, 137, 92, 136, 8, 57, 238, 114, 150, 139, 68, 36, 8, 139, 64, 4, 93, 201, 194, 12, 0 })返回 (0 ) |