13.07.2015 Views

The art of cracking - Tutoriali

The art of cracking - Tutoriali

The art of cracking - Tutoriali

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

77F79B52 |. 8D09 LEA ECX,DWORD PTR DS:[ECX]77F79B54 |> 53PUSH EBX77F79B55 |. 56PUSH ESI77F79B56 |. 57PUSH EDI77F79B57 |. 33C0XOR EAX,EAX77F79B59 |. 33DB XOR EBX,EBX77F79B5B |. 33F6XOR ESI,ESI77F79B5D |. 33FFXOR EDI,EDI77F79B5F |. FF7424 20 PUSH DWORD PTR SS:[ESP+20] ; /Arg577F79B63 |. FF7424 20 PUSH DWORD PTR SS:[ESP+20] ; |Arg477F79B67 |. FF7424 20 PUSH DWORD PTR SS:[ESP+20] ; |Arg377F79B6B |. FF7424 20 PUSH DWORD PTR SS:[ESP+20] ; |Arg277F79B6F |. FF7424 20 PUSH DWORD PTR SS:[ESP+20] ; |Arg177F79B73 |. E8 06000000 CALL ntdll.77F79B7E ; \ntdll.77F79B7E77F79B78 |. 5FPOP EDI77F79B79 |. 5EPOP ESI77F79B7A |. 5BPOP EBX77F79B7B \. C2 1400 RET 14....77F79BA2 |. FFD1 CALL ECX77F79BA4 |. 64:8B25 00000> MOV ESP,DWORD PTR FS:[0]77F79BAB |. 64:8F05 00000> POP DWORD PTR FS:[0]77F79BB2 |. 8BE5 MOV ESP,EBP77F79BB4 |. 5DPOP EBP77F79BB5 \. C2 1400 RET 14Sada cemo se kretati sa F8 preko svih ostalih ASM komandi sem CALLova ukoje cemo ulaziti sa F7. Zadnji CALL u koji cemo ovde uci je CALL ECX poslecega stizemo ovde:00882FBE 8B6424 0800882FC2 EB 0C00882FC4 2BD200882FC6 64:FF32MOV ESP,DWORD PTR SS:[ESP+8]JMP SHORT 00882FD0SUB EDX,EDXPUSH DWORD PTR FS:[EDX]ovde se ne desava nista bitno po odpakivanje pa cemo sa F8 ici kroz kod svedok ne dodjemo do skoka koji bi nas vratio daleko gore u kod. Taj skok senalazi ovde:0088307D /E3 03 JECXZ SHORT 008830820088307F |59POP ECX00883080 ^|EB C8 JMP SHORT 0088304A

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!