学习目标:
分析解密存放物品CALL缓冲区结构
一、分析物品存放功能:一次存放N个物品
+12 //8byte 来源于 物品对象+4C
+1A //存放的物品数量
+2A //12字节 可能是物品ID
+32 //8byte 来源于 物品对象+4C
+3A //物品数量上限 2字节
+43 //物品在背包里的下标
//存放指令 //买出 存 取
//物品ID 告诉服务器 我要存放是什么物品
//物品数量
BYTE nbData[0x90]={
0x00,0x00,0x94,0x00,0x84,0x00,0x01,0x00,0x00,0x00,0x03,0x00,0x00,0x00,0x2B,0x0C,
0x17,0x24,0x6A,0xCA,0x9A,0x3B,0x00,0x00,0x00,0x00,0x03,0x00,0x00,0x00,0x00,0x00,
0x00,0x00,0xAA,0xE2,0x99,0x00,0x00,0x00,0x00,0x00,0xB7,0xBC,0x14,0x40,0x1A,0x41,
0xED,0x19,0x6A,0xCA,0x9A,0x3B,0x00,0x00,0x00,0x00,0x7A,0x01,0x00,0x00,0x00,0x00,
0x00,0x00,0x01,0x0B,0x00,0x00,0x01,0x00,0x4F,0x90,0x00,0x00,0x00,0x00,0x00,0x00,
0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
0x00,0xAB,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x27,0x3A,0x00,0x00,
0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x0F,0x1C,0x28,
分析解密存放物品CALL缓冲区结构
一、分析物品存放功能:一次存放N个物品
+12 //8byte 来源于 物品对象+4C
+1A //存放的物品数量
+2A //12字节 可能是物品ID
+32 //8byte 来源于 物品对象+4C
+3A //物品数量上限 2字节
+43 //物品在背包里的下标
//存放指令 //买出 存 取
//物品ID 告诉服务器 我要存放是什么物品
//物品数量
BYTE nbData[0x90]={
0x00,0x00,0x94,0x00,0x84,0x00,0x01,0x00,0x00,0x00,0x03,0x00,0x00,0x00,0x2B,0x0C,
0x17,0x24,0x6A,0xCA,0x9A,0x3B,0x00,0x00,0x00,0x00,0x03,0x00,0x00,0x00,0x00,0x00,
0x00,0x00,0xAA,0xE2,0x99,0x00,0x00,0x00,0x00,0x00,0xB7,0xBC,0x14,0x40,0x1A,0x41,
0xED,0x19,0x6A,0xCA,0x9A,0x3B,0x00,0x00,0x00,0x00,0x7A,0x01,0x00,0x00,0x00,0x00,
0x00,0x00,0x01,0x0B,0x00,0x00,0x01,0x00,0x4F,0x90,0x00,0x00,0x00,0x00,0x00,0x00,
0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
0x00,0xAB,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x27,0x3A,0x00,0x00,
0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x0F,0x1C,0x28,

本文深入探讨了游戏外挂技术中关于存放物品的CALL缓冲区结构的逆向分析。通过研究存放指令、物品ID、数量等关键数据,揭示了存放物品功能的实现细节。同时,展示了代码示例,揭示了如何使用汇编进行存取操作。
最低0.47元/天 解锁文章
1万+

被折叠的 条评论
为什么被折叠?



