Pespin 1.33 bypass iat redirection
记得断在oep才跑脚本, 不然会报错只适用于PESpin v1.33//only for PESpin v1.33
//break on oep and run this script
var option
var shell
var addr
var first
var isenable
gmemi eip, MEMORYBASE
mov shell, $RESULT
mov option, shell
add option, 3887
add shell, 340
mov isenable, 0
bpmc
bphwc
bc
HRBreak:
sti
cmp , 00000000
jne HRBreak
mov first, esp
bprm option, 1
esto
bpmc
cmp eip, shell
jne err
sti
cmp , 0, 1
je next
mov , 0, 1
sub shell, 340
inc isenable
next:
gpa "CreateFileA", "kernel32.dll"
cmp $RESULT, 0
je err
mov addr, $RESULT
opcode addr
add addr, $RESULT_2
bp addr
esto
bc addr
mov addr, 0
gpa "LoadLibraryA", "kernel32.dll"
cmp $RESULT, 0
je err
mov addr, $RESULT
opcode addr
add addr, $RESULT_2
bp addr
esto
bc addr
cmp isenable, 0
je APIdisable
mov addr, 19de
add addr, shell
bphws addr, "x"
bphws first, "r"
loop:
esto
cmp eip, addr
jne err
cmp , C1, 1
jb loop
cmp , FA, 1
jg loop
sub , 80
jmp loop
APIdisable:
bphws first, "r"
esto
log "This target does not protect with API Redirection"
err:
bpmc
bphwc
bc
ret 收藏了~3Q~ 本帖最后由 ZeNiX 于 2011-8-25 15:03 编辑
脱壳毁一生,破解穷三代。。。
这签名,
太吓人了。
页:
[1]