{"id":1455,"date":"2011-01-13T13:54:00","date_gmt":"2011-01-13T05:54:00","guid":{"rendered":""},"modified":"2011-01-13T13:54:00","modified_gmt":"2011-01-13T05:54:00","slug":"","status":"publish","type":"post","link":"https:\/\/kyle.ai\/blog\/1455.html","title":{"rendered":"\u5b9d\u5b9d\u53d6\u540d\u8f6f\u4ef6V17.0\u7834\u89e3\u7b14\u8bb0"},"content":{"rendered":"<p><html><head><meta http-equiv=\"Content-Type\" content=\"text\/html; charset=utf-8\" \/><title>\u5b9d\u5b9d\u53d6\u540d\u8f6f\u4ef6V17.0\u7834\u89e3\u7b14\u8bb0<\/title><\/head><body><\/p>\n<h1 style=\"display:none\">\u5b9d\u5b9d\u53d6\u540d\u8f6f\u4ef6V17.0\u7834\u89e3\u7b14\u8bb0<\/h1>\n<div>\n<p><span style=\"FONT-SIZE: 14px\">\u9996\u5148\u8131\u58f3\u3002ASPack\u7684\u58f3\uff0cVC++\u7f16\u5199\u7684\u7a0b\u5e8f\u3002<\/span><br \/><span style=\"FONT-SIZE: 14px\">\u8fd0\u884c\u540e\u5982\u56fe\uff1a<\/span><br \/><span style=\"FONT-SIZE: 14px\">&nbsp;<\/span><span><img loading=\"lazy\" decoding=\"async\" class=\"blogimg\" src=\".\/wp-content\/uploads\/hibaidu\/b2460c091ac80c8162d986af.jpg\" width=\"721\" height=\"508\" small=\"0\"><\/span><br \/><span style=\"FONT-SIZE: 14px\">\u6807\u9898\u6709\u6587\u5b57\u201c\u8bd5\u7528\u7248\u201d\uff0c\u4e8e\u662f\u6211\u4eec\u67e5\u627e\u5b57\u7b26\u4e32\uff0c\u5728\u6240\u6709\u51fa\u73b0\u201c\u8bd5\u7528\u7248\u201d\u7684\u5730\u65b9\u4e0b\u65ad\u70b9\uff0c\u7136\u540e\u8fd0\u884cOD\uff0c\u65ad\u5728\u8fd9\u91cc\uff1a<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">004686D9&nbsp;&nbsp; .&nbsp; 895D B8&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV DWORD PTR SS:[EBP-48],EBX<\/span><br \/><span style=\"FONT-SIZE: 14px\">004686DC&nbsp;&nbsp; .&nbsp; 68 26275F00&nbsp;&nbsp; PUSH Unpacked.005F2726&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ; \/ (\u8bd5\u7528\u7248)<\/span><br \/><span style=\"FONT-SIZE: 14px\">004686E1&nbsp;&nbsp; .&nbsp; 8B5D B8&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV EBX,DWORD PTR SS:[EBP-48]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ; |<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u7136\u540e\u62c9\u5230\u6bb5\u9996\uff0c\u4e0b\u65ad\uff0c\u91cd\u65b0\u6765\u8ddf\u4e00\u4e0b\u3002\u65ad\u9996\u4f4d\u7f6e\u4e3a\uff1a<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">004681F7&nbsp;&nbsp; $&nbsp; 55&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; PUSH EBP<\/span><br \/><span style=\"FONT-SIZE: 14px\">004681F8&nbsp;&nbsp; .&nbsp; 8BEC&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV EBP,ESP<\/span><br \/><span style=\"FONT-SIZE: 14px\">004681FA&nbsp;&nbsp; .&nbsp; 81EC 58000000 SUB ESP,58<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u5355\u6b65\u8d70\u6765\u5230\u5173\u952e\u4ee3\u7801\u5904\uff1a<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">0046834D&nbsp;&nbsp; .&nbsp; 83C4 18&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ADD ESP,18<\/span><br \/><span style=\"FONT-SIZE: 14px\">00468350&nbsp;&nbsp; .&nbsp; E8 4193F9FF&nbsp;&nbsp; CALL Unpacked.00401696&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u5173\u952eCALL<\/span><br \/><span style=\"FONT-SIZE: 14px\">00468355&nbsp;&nbsp; .&nbsp; 85C0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TEST EAX,EAX<\/span><br \/><span style=\"FONT-SIZE: 14px\">00468357&nbsp;&nbsp; .&nbsp; 0F84 6A030000 JE Unpacked.004686C7&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u5173\u952e\u8df3\uff0c\u8df3\u4e86\u5c31\u51fa\u9519\uff0cEAX\u8981\u4e3a1\u624d\u6ce8\u518c\u6210\u529f<\/span><br \/><span style=\"FONT-SIZE: 14px\">0046835D&nbsp;&nbsp; .&nbsp; C705 4C938C00&gt;MOV DWORD PTR DS:[8C934C],1<\/span><br \/><span style=\"FONT-SIZE: 14px\">00468367&nbsp;&nbsp; .&nbsp; 8B1D 2C928C00 MOV EBX,DWORD PTR DS:[8C922C]<\/span><br \/><span style=\"FONT-SIZE: 14px\">0046836D&nbsp;&nbsp; .&nbsp; 895D BC&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV DWORD PTR SS:[EBP-44],EBX<\/span><br \/><span style=\"FONT-SIZE: 14px\">00468370&nbsp;&nbsp; .&nbsp; 8B1D 2C928C00 MOV EBX,DWORD PTR DS:[8C922C]<\/span><br \/><span style=\"FONT-SIZE: 14px\">00468376&nbsp;&nbsp; .&nbsp; 83C3 08&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ADD EBX,8<\/span><br \/><span style=\"FONT-SIZE: 14px\">00468379&nbsp;&nbsp; .&nbsp; 895D B8&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV DWORD PTR SS:[EBP-48],EBX<\/span><br \/><span style=\"FONT-SIZE: 14px\">0046837C&nbsp;&nbsp; .&nbsp; 68 46275E00&nbsp;&nbsp; PUSH Unpacked.005E2746&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ; \/ (\u5df2\u6ce8\u518c)<\/span><br \/><span style=\"FONT-SIZE: 14px\">00468381&nbsp;&nbsp; .&nbsp; 8B5D B8&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV EBX,DWORD PTR SS:[EBP-48]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ; |<\/span><br \/><span style=\"FONT-SIZE: 14px\">00468384&nbsp;&nbsp; .&nbsp; FF33&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; PUSH DWORD PTR DS:[EBX]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ; |Arg3<\/span><br \/><span style=\"FONT-SIZE: 14px\">00468386&nbsp;&nbsp; .&nbsp; 68 D6265E00&nbsp;&nbsp; PUSH Unpacked.005E26D6&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ; | v<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u597d\uff0c\u6211\u4eec\u76f4\u63a5\u5728\u5173\u952eCALL\u5904\u4e0b\u597d\u65ad\uff0c\u91cd\u65b0\u6765\u8fc7\uff0c\u8fdb\u5165CALL\u770b\u770b\u3002\u5728CALL\u7684\u6700\u540e\u51e0\u53e5\u5206\u6790\u4e86\u4e00\u4e0b\uff1a<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">00401735&nbsp; |.&nbsp; 50&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; PUSH EAX<\/span><br \/><span style=\"FONT-SIZE: 14px\">00401736&nbsp; |.&nbsp; E8 950B0000&nbsp;&nbsp; CALL Unpacked.004022D0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u7531\u4e0b\u9762\u5206\u6790\u5f97\u8fd9\u91cc\u4e3a\u5173\u952e\u7b97\u6cd5CALL<\/span><br \/><span style=\"FONT-SIZE: 14px\">0040173B&nbsp; |.&nbsp; 8945 EC&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV DWORD PTR SS:[EBP-14],EAX&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u8fd9\u91ccEAX\u7ed9EBP-14<\/span><br \/><span style=\"FONT-SIZE: 14px\">0040173E&nbsp; |.&nbsp; 8B5D F0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV EBX,DWORD PTR SS:[EBP-10]<\/span><br \/><span style=\"FONT-SIZE: 14px\">00401741&nbsp; |.&nbsp; 85DB&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TEST EBX,EBX<\/span><br \/><span style=\"FONT-SIZE: 14px\">00401743&nbsp; |.&nbsp; 74 09&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; JE SHORT Unpacked.0040174E<\/span><br \/><span style=\"FONT-SIZE: 14px\">00401745&nbsp; |.&nbsp; 53&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; PUSH EBX<\/span><br \/><span style=\"FONT-SIZE: 14px\">00401746&nbsp; |.&nbsp; E8 76A60B00&nbsp;&nbsp; CALL Unpacked.004BBDC1<\/span><br \/><span style=\"FONT-SIZE: 14px\">0040174B&nbsp; |.&nbsp; 83C4 04&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ADD ESP,4<\/span><br \/><span style=\"FONT-SIZE: 14px\">0040174E&nbsp; |&gt;&nbsp; 8B45 EC&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV EAX,DWORD PTR SS:[EBP-14]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u8fd9\u91ccEBP-14\u7ed9EAX<\/span><br \/><span style=\"FONT-SIZE: 14px\">00401751&nbsp; |.&nbsp; E9 00000000&nbsp;&nbsp; JMP Unpacked.00401756<\/span><br \/><span style=\"FONT-SIZE: 14px\">00401756&nbsp; |&gt;&nbsp; 8BE5&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV ESP,EBP<\/span><br \/><span style=\"FONT-SIZE: 14px\">00401758&nbsp; |.&nbsp; 5D&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; POP EBP<\/span><br \/><span style=\"FONT-SIZE: 14px\">00401759&nbsp; \\.&nbsp; C3&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; RETN<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u8fd9\u91cc\u8981\u8ba9EAX\u6700\u540e\u4e3a1\u624d\u80fd\u6ce8\u518c\u6210\u529f\u3002\u89c2\u5bdf\u6700\u540e\u7684\u4ee3\u7801\uff0c\u53d1\u73b0\u6700\u540e\u51b3\u5b9aEAX\u503c\u7684\u662f\u8fd9\u91cc\u201c00401736&nbsp; |.&nbsp; E8 950B0000&nbsp;&nbsp; CALL Unpacked.004022D0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u7531\u4e0b\u9762\u5206\u6790\u5f97\u8fd9\u91cc\u4e3a\u5173\u952e\u7b97\u6cd5CALL<\/span><br \/><span style=\"FONT-SIZE: 14px\">\u201d\uff0c\u7136\u540e\u6211\u4eec\u8fdb\u53bb\u770b\u770b\u3002<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u8fd9\u4e2a\u201c004022D0\u201d\u5730\u5740\u7684\u7b97\u6cd5CALL\u4ee3\u7801\u76f8\u5f53\u957f\uff0c\u6211\u521a\u5f00\u59cb\u8ddf\u7684\u65f6\u5019\u5c31\u8ddf\u5f97\u4e0d\u8010\u70e6\u4e86\u3002<\/span><br \/><span style=\"FONT-SIZE: 14px\">\u7ec8\u4e8e\u6211\u4eec\u627e\u5230\u4e86\u6bb5\u5c3e\u5904\uff1a<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">00404142&nbsp;&nbsp; &gt; \\8B5D C4&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV EBX,DWORD PTR SS:[EBP-3C]<\/span><br \/><span style=\"FONT-SIZE: 14px\">00404145&nbsp;&nbsp; .&nbsp; 85DB&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TEST EBX,EBX<\/span><br \/><span style=\"FONT-SIZE: 14px\">00404147&nbsp;&nbsp; .&nbsp; 74 09&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; JE SHORT Unpacked.00404152<\/span><br \/><span style=\"FONT-SIZE: 14px\">00404149&nbsp;&nbsp; .&nbsp; 53&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; PUSH EBX<\/span><br \/><span style=\"FONT-SIZE: 14px\">0040414A&nbsp;&nbsp; .&nbsp; E8 727C0B00&nbsp;&nbsp; CALL Unpacked.004BBDC1<\/span><br \/><span style=\"FONT-SIZE: 14px\">0040414F&nbsp;&nbsp; .&nbsp; 83C4 04&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ADD ESP,4&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; ESP\u8d4b\u4e3a4<\/span><br \/><span style=\"FONT-SIZE: 14px\">00404152&nbsp;&nbsp; &gt;&nbsp; 58&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; POP EAX<\/span><br \/><span style=\"FONT-SIZE: 14px\">00404153&nbsp;&nbsp; .&nbsp; 8BE5&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV ESP,EBP&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u53c8\u628aEBP\u7ed9ESP\uff0c\u6545\u4e0a\u9762\u90a3\u4e2aESP=4\u6ca1\u7528<\/span><br \/><span style=\"FONT-SIZE: 14px\">00404155&nbsp;&nbsp; .&nbsp; 5D&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; POP EBP<\/span><br \/><span style=\"FONT-SIZE: 14px\">00404156&nbsp;&nbsp; .&nbsp; C2 0800&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; RETN 8<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u5206\u6790\u540e\u5c31\u628a<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">0040414F&nbsp;&nbsp; .&nbsp; 83C4 04&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ADD ESP,4&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; ESP\u8d4b\u4e3a4<\/span><br \/><span style=\"FONT-SIZE: 14px\">00404152&nbsp;&nbsp; &gt;&nbsp; 58&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; POP EAX<\/span><br \/><span style=\"FONT-SIZE: 14px\">00404153&nbsp;&nbsp; .&nbsp; 8BE5&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV ESP,EBP&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u53c8\u628aEBP\u7ed9ESP\uff0c\u6545\u4e0a\u9762\u90a3\u4e2aESP=4\u6ca1\u7528<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u76f4\u63a5\u6539\u6210\uff1a<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">0040414F&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; B8 01000000&nbsp;&nbsp; MOV EAX,1&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u76f4\u63a5\u8ba9EAX\u4e3a1<\/span><br \/><span style=\"FONT-SIZE: 14px\">00404154&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 90&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; NOP<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u540e\u9762\u624d\u53d1\u73b0\uff0c\u8fd9\u6837\u6539\u662f\u4e0d\u884c\u7684\uff0c\u7a0b\u5e8f\u8fd0\u884c\u540e\u5c31\u4f1a\u51fa\u9519\u3002<\/span><br \/><span style=\"FONT-SIZE: 14px\">\u7136\u540e\u6211\u53c8\u5c1d\u8bd5\u5728\u7b97\u6cd5CALL\u91cc\u9762\u6539\u4ee3\u7801\uff0c\u7ed3\u679c\u90fd\u4e0d\u884c\uff0c\u4e0d\u7ba1\u6539\u54ea\u90fd\u4f1a\u4f7f\u7a0b\u5e8f\u51fa\u9519\u3002<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u90a3\u5c31\u4e0d\u6539\u7b97\u6cd5CALL\u4e86\u5427\uff0c\u76f4\u63a5\u6539\u5173\u952eCALL\u91cc\u9762\u3002<\/span><br \/><span style=\"FONT-SIZE: 14px\">&nbsp;<\/span><span><img loading=\"lazy\" decoding=\"async\" class=\"blogimg\" src=\".\/wp-content\/uploads\/hibaidu\/11d184120a616480f7039eb1.jpg\" width=\"726\" height=\"245\" small=\"0\"><\/span><br \/><span style=\"FONT-SIZE: 14px\">\u8fd9\u6837\u6539\u4e86\u4e4b\u540e\uff0c\u7a0b\u5e8f\u7684\u7b2c\u4e00\u6b21\u542f\u52a8\u9a8c\u8bc1\u5c31OK\u4e86\uff0c\u6807\u9898\u5df2\u7ecf\u663e\u793a\u4e3a\u201c\u5df2\u6ce8\u518c\u201d\uff0c\u4f46\u662f\u70b9\u51fb\u201c\u6ce8\u518c\u201d\u548c\u5176\u5b83\u7684\u529f\u80fd\u6309\u94ae\u540e\uff0c\u7a0b\u5e8f\u4f9d\u7136\u4f1a\u51fa\u9519\u3002<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u540e\u6765\u5206\u6790\u4e86\u4e00\u665a\u4e0a\uff0c\u7b2c\u4e8c\u5929\u65e9\u4e0a\u624d\u641e\u51fa\u6765\u3002\u539f\u6765\u8fd9\u4e2a\u8f6f\u4ef6\u6709\u70b9\u53d8\u6001\uff0c\u5b83\u7684\u6bcf\u4e00\u5904\u90fd\u4f1a\u6709\u9a8c\u8bc1\u6ce8\u518c\u7684\u4ee3\u7801\u3002\u6bcf\u4e00\u6b21\u90fd\u91cd\u65b0\u9a8c\u8bc1\uff0c\u800c\u4e14\u8fd8\u4e0d\u662f\u8c03\u7528\u540c\u4e00\u4e2a\u5730\u5740\u7684\u51fd\u6570\u8fdb\u884c\u9a8c\u8bc1\u3002<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u4f46\u662f\u6700\u7ec8\u90fd\u662f\u8c03\u7528\u4e86\u7b97\u6cd5CALL\uff0c\u5173\u952e\u4e0d\u4e00\u6837\u3002\u4e8e\u662f\u6211\u4eec\u9009\u4e2d\u7b97\u6cd5CALL\uff0c\u53f3\u952e-&gt;\u67e5\u627e\u53c2\u8003-&gt;\u8c03\u7528\u76ee\u7684\u5730\u5740\u3002\u5728\u6bcf\u4e00\u5904\u8c03\u7528\u5730\u65b9\u90fd\u4e0b\u65ad\u70b9\u3002\u5728\u641c\u7d22\u51fa\u6765\u7684\u7ed3\u679c\u4e2d\u53f3\u952e-&gt;\u5728\u6bcf\u4e2a\u547d\u4ee4\u4e0a\u8bbe\u7f6e\u65ad\u70b9\u3002<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u8fd9\u65f6\uff0c\u8fd0\u884c\u8d77\u6765\u3002\u7a0b\u5e8f\u8fd0\u884c\u540e\u4f1a\u518d\u6b21\u8c03\u7528\u8fd9\u4e2aCALL\u4ee5\u786e\u5b9a\u662f\u5426\u6ce8\u518c\uff0c\u5982\u679c\u6ca1\u6ce8\u518c\u5c31\u5f39\u51fa\u6ce8\u518c\u6846\u3002\u8fd9\u4e2a\u9a8c\u8bc1\u6211\u4eec\u6682\u65f6\u4e0d\u7ba1\uff0c\u76f4\u63a5F9\u8fd0\u884c\u3002\u5f53\u7a0b\u5e8f\u5b8c\u5168\u8fd0\u884c\u8d77\u6765\u540e\uff0c\u6211\u4eec\u70b9\u51fb\u201c\u751f\u6210\u201d\u6309\u94ae\uff0c\u65ad\u4e0b\u6765\u540e\uff0c\u6267\u884c\u5230\u8fd4\u56de\uff0c\u6765\u5230\u5982\u4e0b\u4ee3\u7801\uff1a<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">0048B9AE&nbsp; |&gt; \\E8 E35CF7FF&nbsp;&nbsp; CALL Unpacked.00401696&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u5173\u952eCALL<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048B9B3&nbsp; |.&nbsp; 85C0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TEST EAX,EAX<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048B9B5&nbsp; |.&nbsp; 0F84 17000000 JE Unpacked.0048B9D2<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048B9BB&nbsp; |.&nbsp; E8 34D5F9FF&nbsp;&nbsp; CALL Unpacked.00428EF4&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u5173\u952eCALL<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048B9C0&nbsp; |.&nbsp; 8945 F8&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV DWORD PTR SS:[EBP-8],EAX<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048B9C3&nbsp; |.&nbsp; 837D F8 00&nbsp;&nbsp;&nbsp; CMP DWORD PTR SS:[EBP-8],0<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048B9C7&nbsp; |.&nbsp; 0F85 05000000 JNZ Unpacked.0048B9D2<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048B9CD&nbsp; |.&nbsp; E8 D755FFFF&nbsp;&nbsp; CALL Unpacked.00480FA9<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048B9D2&nbsp; |&gt;&nbsp; E8 BF5CF7FF&nbsp;&nbsp; CALL Unpacked.00401696&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u5173\u952eCALL<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048B9D7&nbsp; |.&nbsp; 85C0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TEST EAX,EAX<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048B9D9&nbsp; |.&nbsp; 0F84 17000000 JE Unpacked.0048B9F6<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048B9DF&nbsp; |.&nbsp; E8 B3D5F8FF&nbsp;&nbsp; CALL Unpacked.00418F97&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u5173\u952eCALL<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048B9E4&nbsp; |.&nbsp; 8945 F8&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV DWORD PTR SS:[EBP-8],EAX<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048B9E7&nbsp; |.&nbsp; 837D F8 00&nbsp;&nbsp;&nbsp; CMP DWORD PTR SS:[EBP-8],0<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048B9EB&nbsp; |.&nbsp; 0F85 05000000 JNZ Unpacked.0048B9F6<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048B9F1&nbsp; |.&nbsp; E8 846CFAFF&nbsp;&nbsp; CALL Unpacked.0043267A<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048B9F6&nbsp; |&gt;&nbsp; E8 9B5CF7FF&nbsp;&nbsp; CALL Unpacked.00401696&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u5173\u952eCALL<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048B9FB&nbsp; |.&nbsp; 85C0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TEST EAX,EAX<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048B9FD&nbsp; |.&nbsp; 0F84 17000000 JE Unpacked.0048BA1A<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048BA03&nbsp; |.&nbsp; E8 85D0FCFF&nbsp;&nbsp; CALL Unpacked.00458A8D&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u5173\u952eCALL<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048BA08&nbsp; |.&nbsp; 8945 F8&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV DWORD PTR SS:[EBP-8],EAX<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048BA0B&nbsp; |.&nbsp; 837D F8 00&nbsp;&nbsp;&nbsp; CMP DWORD PTR SS:[EBP-8],0<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048BA0F&nbsp; |.&nbsp; 0F85 05000000 JNZ Unpacked.0048BA1A<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048BA15&nbsp; |.&nbsp; E8 F619FDFF&nbsp;&nbsp; CALL Unpacked.0045D410&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u5173\u952eCALL<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048BA1A&nbsp; |&gt;&nbsp; E8 775CF7FF&nbsp;&nbsp; CALL Unpacked.00401696<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048BA1F&nbsp; |.&nbsp; 85C0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TEST EAX,EAX<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048BA21&nbsp; |.&nbsp; 0F84 17000000 JE Unpacked.0048BA3E<\/span><br \/><span style=\"FONT-SIZE: 14px\">0048BA27&nbsp; |.&nbsp; E8 3711FBFF&nbsp;&nbsp; CALL Unpacked.0043CB63<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u53d1\u73b0\u8fd9\u91cc\u4e00\u53e3\u6c14\u7a0b\u5e8f\u8c03\u7528\u4e86\u597d\u591a\u6b21\u9a8c\u8bc1\u6ce8\u518c\u7684\u7b97\u6cd5CALL\uff0c\u6bcf\u6b21\u5173\u952eCALL\u7684\u5730\u5740\u90fd\u4e0d\u4e00\u6837\uff0c\u4f46\u90fd\u662f\u8c03\u7528\u4e86\u7b97\u6cd5CALL\u3002<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u4e0d\u7ba1\u5b83\uff0c\u76f4\u63a5\u8fd0\u884c\uff0c\u65ad\u4e0b\u540e\uff0c\u8fd4\u56de\uff0c\u518d\u8fd0\u884c\uff0c\u4e00\u76f4\u6765\u5230\u5982\u4e0b\u4ee3\u7801\uff1a<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">0047BE6C&nbsp; |.&nbsp; E8 2558F8FF&nbsp;&nbsp; CALL Unpacked.00401696&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u5173\u952eCALL<\/span><br \/><span style=\"FONT-SIZE: 14px\">0047BE71&nbsp; |.&nbsp; 85C0&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; TEST EAX,EAX<\/span><br \/><span style=\"FONT-SIZE: 14px\">0047BE73&nbsp; |.&nbsp; 0F84 DF1E0000 JE Unpacked.0047DD58&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u672a\u6ce8\u518c\u5c31\u8df3<\/span><br \/><span style=\"FONT-SIZE: 14px\">0047BE79&nbsp; |.&nbsp; E8 FEFBFDFF&nbsp;&nbsp; CALL Unpacked.0045BA7C<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u8fd9\u91cc\u7684JE\u4e0d\u80fd\u8ba9\u5b83\u8df3\u3002<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u540c\u7406\uff0c\u4e0b\u9762\u8fd9\u4e2a\u4e5f\u4e0d\u80fd\u8ba9\u5b83\u8df3\uff1a<\/span><br \/><span style=\"FONT-SIZE: 14px\">0047BEAB&nbsp; |.&nbsp; 3BC8&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; CMP ECX,EAX<\/span><br \/><span style=\"FONT-SIZE: 14px\">0047BEAD&nbsp; |.&nbsp; 0F8F 9D1E0000 JG Unpacked.0047DD50&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u4e0d\u80fd\u8df3<\/span><br \/><span style=\"FONT-SIZE: 14px\">0047BEB3&nbsp; |.&nbsp; 68 00000000&nbsp;&nbsp; PUSH 0<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u4e00\u76f4\u6267\u884c\u5230\u8fd9\u91cc\uff0c\u8fd9\u91cc\u6709\u975e\u5e38\u591a\u7684\u9a8c\u8bc1CALL\u4e0e\u8df3\uff0c\u975e\u5e38\u591a\u3002\u591a\u4ece\u6765\u6ca1\u6709\u5355\u6b65\u8d70\u5b8c\u8fc7\u3002<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">&nbsp;<\/span><span><img loading=\"lazy\" decoding=\"async\" class=\"blogimg\" src=\".\/wp-content\/uploads\/hibaidu\/2118b230852e32f85edf0eb9.jpg\" width=\"902\" height=\"576\" small=\"0\"><\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u5206\u6790\u5230\u8fd9\u91cc\uff0c\u5c31\u77e5\u9053\u8fd9\u4e2a\u8f6f\u4ef6\u6709\u975e\u5e38\u591a\u4e2a\uff0c\u81f3\u5c11\u6709\u4e00\u767e\u591a\u4e2a\u91cd\u590d\u9a8c\u8bc1\u6ce8\u518c\u7684\u5730\u5740\uff0c\u6bcf\u4e2a\u9a8c\u8bc1\u7684CALL\u90fd\u4f1a\u8c03\u7528\u7b97\u6cd5CALL\uff0c\u7b97\u6cd5CALL\u6211\u4eec\u4e0d\u80fd\u6539\uff0c\u6539\u4e86\u7a0b\u5e8f\u5c31\u4e0d\u80fd\u8fd0\u884c\u3002\u4e8e\u662f\u6211\u4eec\u5f97\u5728\u6bcf\u4e00\u4e2a\u5173\u952eCALL\u91cc\u9762\u6539\uff0c\u4e0b\u9762\u662f\u4e00\u4e2a\u5173\u952eCALL\u7684\u6539\u6cd5\u3002<\/span><br \/><span style=\"FONT-SIZE: 14px\">&nbsp;<\/span><span><img loading=\"lazy\" decoding=\"async\" class=\"blogimg\" src=\".\/wp-content\/uploads\/hibaidu\/013c4491b54875dda977a4be.jpg\" width=\"682\" height=\"229\" small=\"0\"><\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u7531\u4e8e\u6240\u6709\u7684\u5173\u952eCALL\u7ed3\u6784\u7c7b\u4f3c\uff0c\u4e8e\u662f\u6211\u4eec\u53ef\u4ee5\u67e5\u627e\u6240\u6709\u8981\u6539\u7684\u5730\u65b9 \uff0cCtrl+B\uff0c\u8f93\u5165\u4e8c\u8fdb\u5236\u201c8B 45 EC E9\u201d\u4e5f\u5c31\u662f<\/span><br \/><span style=\"FONT-SIZE: 14px\">0047E4CF&nbsp; |&gt; \\8B45 EC&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV EAX,DWORD PTR SS:[EBP-14]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ;&nbsp; \u628a\u8fd9\u91ccNOP\u6389<\/span><br \/><span style=\"FONT-SIZE: 14px\">0047E4D2&nbsp; |.&nbsp; E9 00000000&nbsp;&nbsp; JMP Unpacked.0047E4D7<\/span><br \/><span style=\"FONT-SIZE: 14px\">\u8fd9\u4e24\u53e5\u4ee3\u7801\u3002<\/span><br \/><span style=\"FONT-SIZE: 14px\">\u627e\u5230\u4e00\u4e2a\u5730\u65b9\u662f\u8fd9\u79cd\u7ed3\u6784\u7684\uff0c\u5c31\u628aMOV\u8bed\u53e5NOP\u6389\uff0c\u627e\u5b8c\u540e\u518dCtrl+L\u7ee7\u7eed\u627e\u3002\u8fd9\u662f\u4e2a\u4f53\u529b\u6d3b\uff0c\u56e0\u4e3a\u6709\u76f8\u5f53\u591a\u7684\u8fd9\u4e2a\u8981\u6539\u3002<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u8fd9\u91cc\u6539\u5b8c\u540e\uff0c\u518d\u8fd0\u884c\uff0c\u6765\u5230\u6709\u975e\u5e38\u591a\u7684\u5173\u952eCALL\u4e0eJNZ\u8bed\u53e5\u7684\u90a3\u4e2a\u5730\u65b9\uff0c\u518d\u5355\u6b65\uff0c\u770b\u662f\u4e0d\u662f\u6bcf\u4e2a\u8bed\u53e5\u90fd\u6539\u6b63\u786e\u4e86\uff0c\u8fd9\u65f6\u4f1a\u53d1\u73b0\u6709\u7684CALL\u5e76\u6ca1\u6709\u4fee\u6539\u5230\uff0c\u8fd9\u662f\u56e0\u4e3a\u5b83\u4e0e\u6211\u4eec\u4e0a\u9762\u67e5\u627e\u7684\u7ed3\u6784\u6709\u70b9\u4e0d\u540c\uff0c\u5b83\u7684\u7ed3\u6784\u4e3a\uff1a<\/span><br \/><span style=\"FONT-SIZE: 14px\">&nbsp;<\/span><span><img loading=\"lazy\" decoding=\"async\" class=\"blogimg\" src=\".\/wp-content\/uploads\/hibaidu\/ee739c59325ab58e9c820486.jpg\" width=\"822\" height=\"394\" small=\"0\"><\/span><br \/><span style=\"FONT-SIZE: 14px\">\u6211\u4eec\u518d\u901a\u8fc7\u641c\u7d22\u6765\u627e\u76f8\u5e94\u7684\u6240\u6709\u7c7b\u4f3c\u7684\u7ed3\u6784\uff0c\u641c\u7d22\u201c8B 45 F4 E9\u201d\uff0c\u627e\u5230\u6240\u6709\u7684MOV \u5e76NOP\u6389\u3002<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u8fd9\u6837\u5b8c\u6210\u540e\uff0c\u5c31\u8fbe\u5230\u5b8c\u7f8e\u7834\u89e3\u4e86\u3002<\/span><\/p>\n<p><span style=\"COLOR: #ff0000; FONT-SIZE: 14px\">\u603b\u7ed3\uff1a\u67e5\u627e\u201c8B 45 F4 E9\u201d\u4e0e\u201c8B 45 EC E9\u201d\uff0c\u627e\u5230\u6240\u6709\u50cf\uff1a<\/span><\/p>\n<p><span style=\"COLOR: #ff0000; FONT-SIZE: 14px\">00437F4A&nbsp; |&gt; \\8B45 F4&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV EAX,DWORD PTR SS:[EBP-C]<\/span><br \/><span style=\"COLOR: #ff0000; FONT-SIZE: 14px\">00437F4D&nbsp; |.&nbsp; E9 00000000&nbsp;&nbsp; JMP Unpacked.00437F52<\/span><br \/><span style=\"COLOR: #ff0000; FONT-SIZE: 14px\">00437F52&nbsp; |&gt;&nbsp; 8BE5&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV ESP,EBP<\/span><br \/><span style=\"COLOR: #ff0000; FONT-SIZE: 14px\">00437F54&nbsp; |.&nbsp; 5D&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; POP EBP<\/span><br \/><span style=\"COLOR: #ff0000; FONT-SIZE: 14px\">00437F55&nbsp; \\.&nbsp; C3&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; RETN<\/span><\/p>\n<p><span style=\"COLOR: #ff0000; FONT-SIZE: 14px\">\u8fd9\u79cd\u7ed3\u6784\u7684\u5730\u65b9\uff0cNOP\u6389MOV\u7ed9EAX\u8d4b\u503c\u7684\u5730\u65b9\u5c31OK\u4e86\u3002<\/span><br \/><span style=\"FONT-SIZE: 14px\">&nbsp;<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u81f3\u4e8e\u7a0b\u5e8f\u4f1a\u5f39\u51fa\u7f51\u7ad9\u7684\u95ee\u9898\uff0c\u4e0b\u65ad\u70b9\u201cbp ShellExecuteA\u201d\uff0cNOP\u6389\u51fd\u6570\u8c03\u7528\u5c31OK\u4e86\u3002<\/span><\/p>\n<p><span style=\"FONT-SIZE: 14px\">\u7834\u89e3\u540e\u7684\u7a0b\u5e8f\u56fe\uff1a<\/span><\/p>\n<p><span><img loading=\"lazy\" decoding=\"async\" class=\"blogimg\" border=\"0\" src=\".\/wp-content\/uploads\/hibaidu\/95c8eeff4eaaba615d60087a.jpg\" width=\"718\" height=\"508\" small=\"0\"><\/span><\/p>\n<p><span>\u201c\u751f\u6210\u201d\u6309\u94ae\u7684\u4e8b\u4ef6\u5730\u5740\u4e3a\uff1a<\/span><\/p>\n<p>0048B1A2&nbsp; \/.&nbsp; 55&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; PUSH EBP<br \/>0048B1A3&nbsp; |.&nbsp; 8BEC&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; MOV EBP,ESP<\/p>\n<\/div>\n<p><\/body><\/html><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u5b9d\u5b9d\u53d6\u540d\u8f6f\u4ef6V17.0\u7834\u89e3\u7b14\u8bb0 \u5b9d\u5b9d\u53d6\u540d\u8f6f\u4ef6V17.0\u7834\u89e3\u7b14\u8bb0 \u9996\u5148\u8131\u58f3\u3002ASPack\u7684\u58f3\uff0cVC++\u7f16\u5199\u7684\u7a0b\u5e8f [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-1455","post","type-post","status-publish","format-standard","hentry","category-diary"],"_links":{"self":[{"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/posts\/1455","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/comments?post=1455"}],"version-history":[{"count":0,"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/posts\/1455\/revisions"}],"wp:attachment":[{"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/media?parent=1455"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/categories?post=1455"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/tags?post=1455"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}