windowsÏµķ´µ÷ÊÔ¼¼Êõ

1. ½ø³Ì»·¾³¿é£¨PEB£©¼ì²â£ºPEBÖеÄBeingDebugged±êÖ¾£¨»òµÈЧµÄIsDebuggerPresentº¯Êý£©ÓÃÓÚ¼ì²éµ±Ç°½ø³ÌÊÇ·ñ´¦ÓÚµ÷ÊÔ״̬¡£ÔÚx86»·¾³ÏÂͨ¹ýFS:[0x30]»ñÈ¡PEBÖµ£¬ÔÚx64»·¾³...


Windows ÉÏ×îСµÄ¡¸HelloWorld.exe¡¹ÄÜÓжàС?

´Ófs:[0x30]£¨PEB£©ÖÐÈ¡kernelbase.dllµÄ»ùµØÖ·£¬È»ºóËÑË÷µ¼³ö±íµÃµ½GetProcAddressµÄµØÖ·£¬½ÓÏÂÀ´Ê¶ù¾ÍºÃ°ìÁË¡£ÕâÑù½ÚÊ¡µôÁ˵¼Èë±íµÄ¿Õ¼ä£¬½á...


mov eax,fs:[0x00000018]ÊÇʲôÒâ˼

mov ebx,fs:[0x18] ; get self pointer from TEB mov eax,fs:[0x30] ; get pointer to PEB / database mov [eax + 2], 0; being debugged typedef struct...


LVGLÒÆÖ²ÊÊÅäFATFS

LV_FS_MODE_WR = 0x02,LV_FS_CREATE_NEW = 0x04,LV_FS_CREATE_ALWAYS = 0x08,LV_FS_OPEN_ALWAYS = 0x10,LV_FS_OPEN_APPEND = 0x30,};2¡¢²»ÄܼÓÔØÍⲿͼ...


12V500w³µÔع¤ÆµÄæ±äÆ÷ÖÆ×÷ - °Ù¶È¾­Ñé

0x01,0x01,0x00,0x00,0x00,//10x00,0x01,0x03,0x00,0x00,0x00,//20x00,0x00,0x07,0x00,0x00,0x00,//


¼Ç¿ªÆôHDCP¹¦ÄܺóÎÞ·¨»Ö¸´³ö³§ÉèÖà - °Ù¶È¾­Ñé

writepages: jbd2_start: 8192 pages, ino 489; err -30[ 291.456866] EXT4-fs (mmcblk0p12): ext4_da_writepages: jbd2_start: 2048 pages, ino 489; err -30¡­¡­66 [ 370.412868] SysRq : Show Blocked State[ 370.416566] task PC stack pid father[ 370.421698] init D c0784b5c 0 1 0 0x00000000[ 370.427978] [] (__schedule+0x...


ubuntu·þÎñÆ÷¾­³£ËÀ»ú - ÔËά - CSDNÎÊ´ð

exit_to_user_mode_prepare+0x30/0xb0Jun 24 22:35:34 rw-Z790-UD kernel: [48497.051322] ? syscall_exit_to_user_mode+0x37/0x60...Jun 24 23:38:36 rw-Z790-UD kernel: [52279.029376] FS: 0000000000000000(0000) GS:ffff9cd43f680000(0000) knlGS:0000000000000000Jun 24...


ÄãÅöµ½¹ýµÄ×îÄѵ÷Ê﵀ Bug ÊÇʲôÑùµÄ?

ÈÆ¹ý£ºfs¶Î¼Ä´æÆ÷Æ«ÒÆ0x30h£¬ÓÃctrl+G¿ÉÒÔÕÒµ½PEB¡£µÚÒ»¸öfs:[30h]+2Ö¸ÏòÁËPEBµÄBeingDubgged£¬ÕâÊǼìÑé·´µ÷ÊÔµÄÒ»ÖÖ¼¼Êõ¡£BeingDubgged=...


shellcodeÔ­ÀíÊÇɶ?

//by shellcode gen v0.11.3 unsigned char SHELLCODE_RUNCALC[] = { 0x55, 0x64, 0x8B, 0x35, 0x30, 0x00, 0x00, 0x00, 0x...µ«ÊǵÚÒ»¶ÎIDA½«ÆäÊÓΪÁËÊý¾Ý¶Î£¬Ê¹Óÿì½Ý¼üCÀ´½øÐÐת»»»¹Ô­ºó¿ÉÒÔ·¢ÏÖ£¬ÆäÔÚµÚ¶þÐе÷ÓÃÁËsub_8F£¬ÁíÍ⻹Ҫ×¢Òâfs:[edx+30h],ÕâÊÇÒ»¸ö...


ascllÂëÓ¦Óóõ²½ - °Ù¶È¾­Ñé

33 0041 0x21 | A 65 0101 0x41 | a 97 0141 0x61 (stx)2 0002 0x02 | " 34 0042 0x22 | B 66 0102 0x42 | b 98 0142 0x...| Z 90 0132 0x5a | z 122 0172 0x7a (esc) 27 0033 0x1b | ; 59 0073 0x3b | [ 91 0133 0x5b | { 123 0173 0x7b (fs)...


Ïà¹ØËÑË÷

ÈÈÃÅËÑË÷