好友
阅读权限10
听众
最后登录1970-1-1
|
script = session.create_script("""
const CreateProcessPtr = Module.getExportByName('Kernel32.dll','CreateProcessA');
const CreateProcess = new NativeFunction(CreateProcessPtr, 'bool', ['pointer','pointer','pointer','pointer','bool','int32','pointer','pointer','pointer','pointer']);
Interceptor.replace(CreateProcessPtr,new NativeCallback((lpApplicationName,lpCommandLine,lpProcessAttributes,lpThreadAttributes,bInheritHandles,dwCreationFlags,lpEnvironment,lpCurrentDirectory,lpStartupInfo,lpProcessInformation)=>{
const result = CreateProcess(lpApplicationName,lpCommandLine,lpProcessAttributes,lpThreadAttributes,bInheritHandles,dwCreationFlags,lpEnvironment,lpCurrentDirectory,lpStartupInfo,lpProcessInformation);
return result;
},'bool', ['pointer','pointer','pointer','pointer','bool','int32','pointer','pointer','pointer','pointer']));
""") |
|
发帖前要善用【论坛搜索】功能,那里可能会有你要找的答案或者已经有人发布过相同内容了,请勿重复发帖。 |
|
|
|
|