﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>BlogJava-VIRGIN FOREST OF JAVA-文章分类-ASM-MACRO</title><link>http://www.blogjava.net/RR00/category/31982.html</link><description>不要埋头苦干，要学习，学习，再学习。。。。。
&lt;br&gt;
powered  by &lt;font color='orange'&gt;R.Zeus&lt;/font&gt;</description><language>zh-cn</language><lastBuildDate>Mon, 11 Aug 2008 23:56:44 GMT</lastBuildDate><pubDate>Mon, 11 Aug 2008 23:56:44 GMT</pubDate><ttl>60</ttl><item><title>Exploit code</title><link>http://www.blogjava.net/RR00/articles/220137.html</link><dc:creator>R.Zeus</dc:creator><author>R.Zeus</author><pubDate>Tue, 05 Aug 2008 05:10:00 GMT</pubDate><guid>http://www.blogjava.net/RR00/articles/220137.html</guid><wfw:comment>http://www.blogjava.net/RR00/comments/220137.html</wfw:comment><comments>http://www.blogjava.net/RR00/articles/220137.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/RR00/comments/commentRss/220137.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/RR00/services/trackbacks/220137.html</trackback:ping><description><![CDATA[1.the stack address and new buffer address is automatic, so they can't be used them in code.<br />
we should use <span style="color: red;">registers </span>which store the useful information in code.<br />
<br />
jmp eax,ecx,esi,edi...<br />
<br />
lea ebp,dowrd ptr[esp+XX] to restore stack.<br />
<br />
mov ecx,0040xxx<br />
jmp ecx<br />
<br />
the same as:<br />
push 0040xxx<br />
ret<br />
<br />
<br />
mov [0040xx],xxx<br />
<br />
<br />
<img src ="http://www.blogjava.net/RR00/aggbug/220137.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/RR00/" target="_blank">R.Zeus</a> 2008-08-05 13:10 <a href="http://www.blogjava.net/RR00/articles/220137.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>crack process</title><link>http://www.blogjava.net/RR00/articles/219088.html</link><dc:creator>R.Zeus</dc:creator><author>R.Zeus</author><pubDate>Thu, 31 Jul 2008 08:26:00 GMT</pubDate><guid>http://www.blogjava.net/RR00/articles/219088.html</guid><wfw:comment>http://www.blogjava.net/RR00/comments/219088.html</wfw:comment><comments>http://www.blogjava.net/RR00/articles/219088.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/RR00/comments/commentRss/219088.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/RR00/services/trackbacks/219088.html</trackback:ping><description><![CDATA[1.find key word:<br />
MessageBox<br />
getDlgText<br />
getWindowText<br />
<br />
2.search inputed strings in memory.<br />
<br />
3.button track.<br />
<br />
<img src ="http://www.blogjava.net/RR00/aggbug/219088.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/RR00/" target="_blank">R.Zeus</a> 2008-07-31 16:26 <a href="http://www.blogjava.net/RR00/articles/219088.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>ida</title><link>http://www.blogjava.net/RR00/articles/218069.html</link><dc:creator>R.Zeus</dc:creator><author>R.Zeus</author><pubDate>Mon, 28 Jul 2008 07:04:00 GMT</pubDate><guid>http://www.blogjava.net/RR00/articles/218069.html</guid><wfw:comment>http://www.blogjava.net/RR00/comments/218069.html</wfw:comment><comments>http://www.blogjava.net/RR00/articles/218069.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/RR00/comments/commentRss/218069.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/RR00/services/trackbacks/218069.html</trackback:ping><description><![CDATA[ida some times will add binary char at the end of the file,take attention!<br />
use stud_pe to view what is it ida adds.<br />
<br />
the sys's entry is gsEntry??what is that ?<br />
<br />
<img src ="http://www.blogjava.net/RR00/aggbug/218069.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/RR00/" target="_blank">R.Zeus</a> 2008-07-28 15:04 <a href="http://www.blogjava.net/RR00/articles/218069.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title> SoftICE  ollydbg hot key</title><link>http://www.blogjava.net/RR00/articles/217158.html</link><dc:creator>R.Zeus</dc:creator><author>R.Zeus</author><pubDate>Thu, 24 Jul 2008 04:52:00 GMT</pubDate><guid>http://www.blogjava.net/RR00/articles/217158.html</guid><wfw:comment>http://www.blogjava.net/RR00/comments/217158.html</wfw:comment><comments>http://www.blogjava.net/RR00/articles/217158.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/RR00/comments/commentRss/217158.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/RR00/services/trackbacks/217158.html</trackback:ping><description><![CDATA[F2：设置断点，只要在光标定位的位置（上图中灰色条）按F2键即可，再按一次F2键则会删除断点。（相当于&nbsp;SoftICE&nbsp;中的&nbsp;F9）<br />
<br />
F8：单步步过。每按一次这个键执行一条反汇编窗口中的一条指令，遇到&nbsp;CALL&nbsp;等子程序不进入其代码。（相当于&nbsp;SoftICE&nbsp;中的&nbsp;F10）<br />
<br />
F7：单步步入。功能同单步步过(F8)类似，区别是遇到&nbsp;CALL&nbsp;等子程序时会进入其中，进入后首先会停留在子程序的第一条指令上。（相当于&nbsp;SoftICE&nbsp;中的&nbsp;F8）<br />
<br />
F4：运行到选定位置。作用就是直接运行到光标所在位置处暂停。（相当于&nbsp;SoftICE&nbsp;中的&nbsp;F7）<br />
<br />
F9：运行。按下这个键如果没有设置相应断点的话，被调试的程序将直接开始运行。（相当于&nbsp;SoftICE&nbsp;中的&nbsp;F5）<br />
<br />
CTR+F9：执行到返回。此命令在执行到一个&nbsp;ret&nbsp;(返回指令)指令时暂停，常用于从系统领空返回到我们调试的程序领空。（相当于&nbsp;SoftICE&nbsp;中的&nbsp;F12）<br />
<br />
ALT+F9：执行到用户代码。可用于从系统领空快速返回到我们调试的程序领空。（相当于&nbsp;SoftICE&nbsp;中的&nbsp;F11）
<img src ="http://www.blogjava.net/RR00/aggbug/217158.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/RR00/" target="_blank">R.Zeus</a> 2008-07-24 12:52 <a href="http://www.blogjava.net/RR00/articles/217158.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>pushz "hello.txt"</title><link>http://www.blogjava.net/RR00/articles/206125.html</link><dc:creator>R.Zeus</dc:creator><author>R.Zeus</author><pubDate>Thu, 05 Jun 2008 10:16:00 GMT</pubDate><guid>http://www.blogjava.net/RR00/articles/206125.html</guid><wfw:comment>http://www.blogjava.net/RR00/comments/206125.html</wfw:comment><comments>http://www.blogjava.net/RR00/articles/206125.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.blogjava.net/RR00/comments/commentRss/206125.html</wfw:commentRss><trackback:ping>http://www.blogjava.net/RR00/services/trackbacks/206125.html</trackback:ping><description><![CDATA[pushz&nbsp;&nbsp; &nbsp;macro szText:VARARG<br />
&nbsp;&nbsp; &nbsp;local&nbsp;&nbsp; &nbsp;nexti<br />
&nbsp;&nbsp;<span style="color: red;"> &nbsp;call&nbsp;&nbsp; &nbsp;nexti<br />
&nbsp;&nbsp; &nbsp;db szText,00h </span><br />
nexti:<br />
endm<br />
<br />
//db szText,00h the "<span style="color: red;">db</span>" directive will make the "<span style="color: red;">szText</span>" as opcode next to the "<span style="color: red;">call&nbsp;&nbsp; &nbsp;nexti<span style="color: #040000;">" when expand the macro.<br />
&nbsp;after invoke this macro,the esp will point to the szText opcode because of the call mechanism.<br />
<br />
call = put eip+1 to esp,jump to call method.<br />
<br />
usage: <span style="color: #0c2b88;">pushz "hello.txt"</span><br />
<br />
//dw is the same as db,but I don't know what is the dd do.<br />
<br />
</span></span>
<img src ="http://www.blogjava.net/RR00/aggbug/206125.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.blogjava.net/RR00/" target="_blank">R.Zeus</a> 2008-06-05 18:16 <a href="http://www.blogjava.net/RR00/articles/206125.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item></channel></rss>