Network Security Internet Technology Development Database Servers Mobile Phone Android Software Apple Software Computer Software News IT Information

In addition to Weibo, there is also WeChat

Please pay attention

WeChat public account

Shulou

The second session of ctf.360.cn, reverse part of the third question of writeup--

2025-01-15 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > Network Security >

Share

Shulou(Shulou.com)06/01 Report--

Topic: see attachment

This problem is the quickest to solve, and the tip is very clear.

There was an error in the direct operation of exe. When OD was opened, it was found that the entry point was a jmp.

F8, tracked to the address after jmp, found the cause of the error in running the program.

In fact, this topic is to simulate the behavior of virus infecting exe, modifying file entry instructions, and inserting malicious code.

Patching is actually finding the code of the real entry function header and nop the previous instructions such as jmp. (it is also OK to modify OEP)

Attachment: http://down.51cto.com/data/2365126

Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.

Views: 0

*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.

Share To

Network Security

Wechat

© 2024 shulou.com SLNews company. All rights reserved.

12
Report