fs 0x30
windowsÏµķ´µ÷ÊÔ¼¼Êõ
1. ½ø³Ì»·¾³¿é£¨PEB£©¼ì²â£ºPEBÖеÄBeingDebugged±êÖ¾£¨»òµÈЧµÄIsDebuggerPresentº¯Êý£©ÓÃÓÚ¼ì²éµ±Ç°½ø³ÌÊÇ·ñ´¦ÓÚµ÷ÊÔ״̬¡£ÔÚx86»·¾³ÏÂͨ¹ýFS:[0x30]»ñÈ¡PEBÖµ£¬ÔÚx64»·¾³...
Windows ÉÏ×îСµÄ¡¸HelloWorld.exe¡¹ÄÜÓжàС?
´Ófs:[0x30]£¨PEB£©ÖÐÈ¡kernelbase.dllµÄ»ùµØÖ·£¬È»ºóËÑË÷µ¼³ö±íµÃµ½GetProcAddressµÄµØÖ·£¬½ÓÏÂÀ´Ê¶ù¾ÍºÃ°ìÁË¡£ÕâÑù½ÚÊ¡µôÁ˵¼Èë±íµÄ¿Õ¼ä£¬½á...
mov eax,fs:[0x00000018]ÊÇʲôÒâ˼
mov ebx,fs:[0x18] ; get self pointer from TEB mov eax,fs:[0x30] ; get pointer to PEB / database mov [eax + 2], 0; being debugged typedef struct...
LVGLÒÆÖ²ÊÊÅäFATFS
LV_FS_MODE_WR = 0x02,LV_FS_CREATE_NEW = 0x04,LV_FS_CREATE_ALWAYS = 0x08,LV_FS_OPEN_ALWAYS = 0x10,LV_FS_OPEN_APPEND = 0x30,};2¡¢²»ÄܼÓÔØÍⲿͼ...
12V500w³µÔع¤ÆµÄæ±äÆ÷ÖÆ×÷ - °Ù¶È¾Ñé
0x01,0x01,0x00,0x00,0x00,//10x00,0x01,0x03,0x00,0x00,0x00,//20x00,0x00,0x07,0x00,0x00,0x00,//
¼Ç¿ªÆôHDCP¹¦ÄܺóÎÞ·¨»Ö¸´³ö³§ÉèÖà - °Ù¶È¾Ñé
writepages: jbd2_start: 8192 pages, ino 489; err -30[ 291.456866] EXT4-fs (mmcblk0p12): ext4_da_writepages: jbd2_start: 2048 pages, ino 489; err -30¡¡66 [ 370.412868] SysRq : Show Blocked State[ 370.416566] task PC stack pid father[ 370.421698] init D c0784b5c 0 1 0 0x00000000[ 370.427978] [] (__schedule+0x...
ubuntu·þÎñÆ÷¾³£ËÀ»ú - ÔËά - CSDNÎÊ´ð
exit_to_user_mode_prepare+0x30/0xb0Jun 24 22:35:34 rw-Z790-UD kernel: [48497.051322] ? syscall_exit_to_user_mode+0x37/0x60...Jun 24 23:38:36 rw-Z790-UD kernel: [52279.029376] FS: 0000000000000000(0000) GS:ffff9cd43f680000(0000) knlGS:0000000000000000Jun 24...
ÄãÅöµ½¹ýµÄ×îÄѵ÷Ê﵀ Bug ÊÇʲôÑùµÄ?
ÈÆ¹ý£ºfs¶Î¼Ä´æÆ÷Æ«ÒÆ0x30h£¬ÓÃctrl+G¿ÉÒÔÕÒµ½PEB¡£µÚÒ»¸öfs:[30h]+2Ö¸ÏòÁËPEBµÄBeingDubgged£¬ÕâÊǼìÑé·´µ÷ÊÔµÄÒ»ÖÖ¼¼Êõ¡£BeingDubgged=...
shellcodeÔÀíÊÇɶ?
//by shellcode gen v0.11.3 unsigned char SHELLCODE_RUNCALC[] = { 0x55, 0x64, 0x8B, 0x35, 0x30, 0x00, 0x00, 0x00, 0x...µ«ÊǵÚÒ»¶ÎIDA½«ÆäÊÓΪÁËÊý¾Ý¶Î£¬Ê¹Óÿì½Ý¼üCÀ´½øÐÐת»»»¹Ôºó¿ÉÒÔ·¢ÏÖ£¬ÆäÔÚµÚ¶þÐе÷ÓÃÁËsub_8F£¬ÁíÍ⻹ҪעÒâfs:[edx+30h],ÕâÊÇÒ»¸ö...
ascllÂëÓ¦Óóõ²½ - °Ù¶È¾Ñé
33 0041 0x21 | A 65 0101 0x41 | a 97 0141 0x61 (stx)2 0002 0x02 | " 34 0042 0x22 | B 66 0102 0x42 | b 98 0142 0x...| Z 90 0132 0x5a | z 122 0172 0x7a (esc) 27 0033 0x1b | ; 59 0073 0x3b | [ 91 0133 0x5b | { 123 0173 0x7b (fs)...