MSVCRT:ROP - CN 修改ROP检测标志

本文深入解析了一个复杂的函数内部结构,通过一系列特定的指令序列展示了函数的工作原理。通过对不同指令的组合使用,揭示了函数如何实现其功能,并重点介绍了关键指令的作用。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >



 function getddd()
	{
	var kkkkk = unescape("\u0433\u77bf");
	kkkkk +=unescape("\u5ed5\u77be"); //xchg eax,esp retn
	
	kkkkk += unescape("\uf519\u77be")pop ecx,retn
	kkkkk += unescape("\u9ef8\u1009")10099EF8 check flag 1
	kkkkk += unescape("\uc047\u77be")//77BEC047 //MOV DWORD PTR DS:[ECX],EAX  MOV EAX,ESI  POP EDI  POP ESI POP EBP RETN


	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	
	kkkkk += unescape("\uf519\u77be")pop ecx,retn
	kkkkk += unescape("\u9ed0\u1009")10099Ed0 check flag 2
	kkkkk += unescape("\u1d16\u77bf")//pop eax,retn
	kkkkk += unescape("\u1d16\u77be")//fill
	kkkkk += unescape("\uc047\u77be")//77BEC047 //MOV DWORD PTR DS:[ECX],EAX  MOV EAX,ESI  POP EDI  POP ESI POP EBP RETN

	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\ubdf4\u77be")//pop ebp retn
	kkkkk += unescape("\ubdf4\u77be")//pop ebp retn
	kkkkk += unescape("\u3436\u77c2")//pop ebx retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\ucbf9\u77c1")//pop edx retn
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\ub1ad\u77c0")
	kkkkk += unescape("\ubdf4\u77be")
	kkkkk += unescape("\u7ae8\u77c1")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u80c1\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u67f0\u77c2")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\ubdf4\u77be")
	kkkkk += unescape("\ubdf4\u77be")
	kkkkk += unescape("\u3436\u77c2")
	kkkkk += unescape("\u406e\u883f")
	kkkkk += unescape("\u771c\u77c2")
	kkkkk += unescape("\u9f07\u77c2")
	kkkkk += unescape("\u5f07\u77c0")
	kkkkk += unescape("\u5f07\u77c0")
	kkkkk += unescape("\uded4\u77c1")
	kkkkk += unescape("\ucf92\u77c0")
	kkkkk += unescape("\u0c77\u77c2")
	kkkkk += unescape("\ub1ad\u77c0")
	kkkkk += unescape("\u05ac\u77c3")//oldprotect
	kkkkk += unescape("\u7ae8\u77c1")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u80c1\u77c0")
	kkkkk += unescape("\uaacc\u77bf")
	kkkkk += unescape("\uded4\u77c1")
	kkkkk += unescape("\u1131\u77be")
	kkkkk += unescape("\u67f0\u77c2")
	kkkkk += unescape("\u1025\u77c2");
			
	kkkkk += unescape("\u9090\u9090");	
	
	kkkkk += unescape("\u9090\u9090");	
	return kkkkk;
}


评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值