PersonalCorpus °æ (¾«»ªÇø)
·¢ÐÅÈË: CF (ÍøÊÂËæ·ç), ÐÅÇø: Hacker
±ê Ìâ: tKCµÄÆƽâ½Ì³Ì£¨¶þ£©
·¢ÐÅÕ¾: ¹þ¹¤´ó×϶¡Ïã (2000Äê09ÔÂ18ÈÕ09:49:35 ÐÇÆÚÒ»), Õ¾ÄÚÐżþ
http://sunbirdsoftware.abc.yesite.com
àË£¬»¨»¨¹«×ÓÃÇ£¨SB£ºÕâËãʲôÕкôѽ£©£¡
ÏÖÔÚÓֻص½ÎÒµÄÆƽâ½Ì³Ì£¬Õâ´ÎÎÒ½«½ÌÄãÈçºÎÈ¥³ýNAGS£¨Ìáʾע²á´°¿Ú£©ºÍÈçºÎʹÓÃ
W32DasmµÄµ÷ÊÔģʽ£¨Debugger Mode£©£¬ÕæµÄºÜ¼òµ¥ßÏ£¡
±§Ç¸ÓкܶàÓï·¨´íÎó£¬ÎÒÏ£ÍûÄãÄܹ»¿´µÃ¶®£¡:-)
ÎÒÃÇ¿ªÊ¼°É£¡
¹¤¾ßÈí¼þ£º
ÄãÐèÒªÒÔÏµĹ¤¾ßÈí¼þ£¨ÎÒʹÓÃÕâЩ¹¤¾ßÈí¼þ£¬ÎÒ¼ÙÉèÄãÒ²½«Ê¹ÓÃËüÃÇ£©£º
W32Dasm 8.9»ò¸ü¸ßµÄ°æ±¾
Hacker's View 5.60
Norton Commander»òWindows Commander£¨ÎÒ½«ÔÚºóÃæ½âÊÍΪʲôʹÓÃËü£©
µ±ÄãÏòÈκÎCrackerÇóÖúʱ£¬ËûÃǶ¼»áÀÖÓÚÌṩÄãÕâЩ¹¤¾ßÈí¼þ:-)
Ŀ¼£º
1)a.ÈçºÎÈ¥³ýPrivate EXE 2.0aµÄNAGs£¨Ê¹ÓÃW32DasmµÄµ÷ÊÔģʽ£©
b.ÈçºÎÈ¥³ýPrivate EXE 2.0aµÄNAGs£¨²»Ê¹ÓÃW32Dasm£¡£¡£©
2)a.ÈçºÎÈ¥³ýLView Pro 1.C/32µÄNAGs£¨Ê¹ÓÃW32DasmµÄµ÷ÊÔģʽ£©
b.ÈçºÎÆƽâLView Pro 1.C/32£¨ÊäÈëÈÎÒâÐòÁкţ©
£¨ÓÉÓÚÒ»¶Îʱ¼äûÓÐ裬Äò»µ½×îа汾µÄ¹²ÏíÈí¼þ£¬ËùÒÔÎÒʹÓÃÕâЩ¾É³ÌÐòÀ´×÷ʾ·¶¡££©
µÚÒ»²¿·Ö£¨a£©£ºÈ¥³ýPrivate EXE 2.0aµÄNAGs£¨Ê¹ÓÃW32Dasm£©
1. ÔËÐÐPEXE32.EXE
2. ÏÖÔÚÄã¿´µ½ÁËÁîÈËÑá¶ñµÄNAGsÆÁÄ»£¬ÄãÏ£Íû°ÑËü³ýÈ¥£¬¶Ô²»¶Ô£¿:-)
3. ºÃ£¬Í˳ö³ÌÐò
4. ÔËÐÐNorton Commander£¬½øÈëPrivateEXE·¾¶
5. ½«PEXE32.EXE¸´ÖÆΪPEXE32.EXX£¨Áô×÷±¸·Ý£©£¬½«PEXE32.EXE¸´ÖÆΪ1.EXE£¨¸øW32Dasm
Óã©
6. ÔËÐÐW32Dasm£¬·´±àÒë1.EXE
7. µ±·´±àÒëÍê³Éºó£¬µ¥»÷Debug|Load Process£¨»ò°´CTRL-L£©
8. µÈºòµ÷ÊÔģʽµ÷ÈëËùÓеÄDLL's£¨¶¯Ì¬Á´½Ó¿â£©
9. ºÃ£¬ÏÖÔÚÄãÔÚ"debug"´°¿Ú£¬ÄãÓ¦¸Ã¿´µ½¹âÌõÍ£ÔÚ£º
:004074B0 mov eax, dword ptr fs: [00000000]
:004074B6 push ebp
...
...
10. Õâ¾ÍÊdzÌÐòµÄÈë¿Ú£¨Program Entry Point£©¡£ºÃ£¬×¼±¸ÔËÐÐPrivate EXE£¬µ¥»÷RUN£¨
»ò°´F9£©¡£Ä㽫¿´µ½NAGsÆÁÄ»£¬ÏÖÔÚÄãÏëÖªµÀNAGs½ø³Ì£¨processes£©ÔÚÄĶù¡£µ¥»÷Step
Into£¨»ò°´F7£©¡£°¡£¡ÏÖÔÚÄã¿´µ½ÁËÈçÏÂÄÚÈÝ£º
:00405C21 call USER32.DialogBoxParamA
:00405C27 pop ebp
...
...
11. µ¥»÷Terminate¹Ø±Õµ÷ÊÔģʽºÍPrivate.EXE´°¿Ú
12. ÄãÓ¦¸Ã»Øµ½W32Dasm²¢¿´µ½ÈçÏÂÄÚÈÝ£º
:00405C21 FF1590664100 Call dword ptr [00416690]
:00405C27 5D pop ebp
:00405C28 C3 ret
...
13. ºÃ£¬ÏÖÔÚÄãÐèÒª²éÕÒÊÇ´ÓÄÄÀ↑ʼ´¦Àí¶Ô»°¿ò£¨dialogs£©µÄ¡£°´ÉϼýÍ·Ö±µ½ÄãÕÒµ½£º
:00405BFC CC int 03
:00405BFD CC int 03
:00405BFE CC int 03
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:00401064 (U)
|
:00405BFF 55 push ebp
:00405C00 8B442414 mov eax, dword ptr [esp+14]
...
14. ÕâЩ"CC"£¨int 03£©¾ÍÊÇ´¦Àí¶Ô»°¿òµÄ¿ªÊ¼¡£È·¶¨À¶ÂÌÉ«¹âÌõ´¦ÓÚ£º00405BFF 55´¦£¬
°´ebp£¬Äã»áÔÚÆÁÄ»ÏÂÃæ¿´µ½ÏóÕâÑùµÄÆ«ÒƵØÖ·@Offset 00004FFFh¡£ÄǾÍÊÇÄã¿ÉÒÔÔÚ
PEXE32.EXE´ò²¹¶¡µÄµØ·½
15. »Øµ½Norton Commander£¬ÔËÐÐHIEW PEXE32.EXE£¬°´F4Ñ¡ÔñDecodeģʽ£¨ASM£©£¬°´F5Êä
Èë4FFF£¬Äã»á¿´µ½£º
00005BFF: 55 push ebp
00005C00: 8B442414 mov eax,[esp][00014]
00005C04: 8BEC mov ebp,esp
00005C06: 85C0 test eax,eax
£¨¼Çס£¬ÏÖÔÚÎÒʹµÄÊÇHIEW5.60£¬Ëü»áÏÔʾºÍÄ㲻ͬµÄÆ«ÒƵØÖ·£¬Õâ¸ö°æ±¾°ô¼«ÁË£¬È¥
ÕÒËü£¡£¡£©
16. Õâ¾ÍÊÇÄã¿ÉÒÔ¸ü¸Ä×ֽڵĵط½£¬°´F3ÊäÈëC3£¬°´F9¸üÐÂPEXE32.EXE¡£µ±Äã°´F3ÊäÈëC3ºó
£¬Äã»á¿´µ½£º
00004FFF: C3 retn
00005000: 8B442414 mov eax,[esp][00014]
00005004: 8BEC mov ebp,esp
00005006: 85C0 test eax,eax
£¨×¢ÒâÆ«ÒƵØÖ·£©
17. ΪʲôÊÇ"C3"£¿°¡£¬µ±³ÌÐòÔËÐе½C3´¦£¨retn£©£¬Ëü²»»áÈ¥´¦Àí¶Ô»°¿ò£¬ÒòΪÄã¸æËßËü
·µ»Ø°É£¡
18. ÏÖÔÚÔËÐÐPEXE32.EXE£¬Ä㻹¿´µ½NAGsÆÁÄ»Âð£¿àÅ£¡£¡ÄãÒѾÆƽâÁËPrivate EXE 2.0a£¡
£¡
˳±ã˵һ¾ä£ºÕâ²¢²»ÊÇ100£¥µÄÆƽ⣨Èƹý¿ÚÁî±£»¤£©£¬ÎÒ½ö½öÊÇÏòÄãչʾÈçºÎÈ¥³ýNAGs£¬
¼ÇµÃÂð£¿:-)
µÚÒ»²¿·Ö£¨b£©£ºÈ¥³ýPrivate EXE 2.0aµÄNAGs£¨²»ÓÃW32Dasm£©
£¨ÕâÖÖ·½·¨¶à¿ìºÃÊ¡£©
1. ÔËÐÐPEXE32.EXE
2. ÏÖÔÚÄã¿´µ½ÁËÁîÈËÑá¶ñµÄNAGsÆÁÄ»£¬ÄãÏ£Íû°ÑËü³ýÈ¥£¬¶Ô²»¶Ô£¿:-)
3. ºÃ£¬Í˳ö³ÌÐò
4. ÔËÐÐNorton Commander£¬½øÈëPrivateEXE·¾¶
5. ½«PEXE32.EXE¸´ÖÆΪPEXE32.EXX£¨Áô×÷±¸·Ý£©£¬ÔËÐÐHIEW PEXE32.EXE
6. °´F4Ñ¡Ôñ16½øÖÆģʽ£¨HEX Mode£©£¬ÏÖÔÚÄã»á¿´µ½PEXE32.EXEµÄ16½øÖÆ´úÂ룬²»ÒªÏŵÃ
Äò¿ã×ÓßÏ£¡:-)
7. »¹¼ÇµÃÔÚNAGsÆÁÄ»³öÏÖµÄ×Ö·ûÂ𣿰¡£¬ÔÚÔËÐÐPEXE32.EXEʱÄãÓ¦¸ÃдÏÂÕâЩ×Ö·û¡£Ïó
"PrivateEXE is NOT a free software. It is commercial¡"»ò"Ok, I agree¡"µÈµÈ¡£
8. °´F7ËÑË÷£¬ÊäÈë"agree"£¨ÔÚASCIIÇøÓò£©¡£ÕÒµ½ÁËÂ𣿺㬼ÇסPEXE32.EXEÊÇ32λ³ÌÐò
£¬ËùÒÔÔÚÿ¸ö×Ö·û¼äÐèÒªÊäÈë×Ö·û´®"00"£¬Ïó"a g r e e"£¨²»ÊÇ¿Õ¸ñ£¡£©
9. Ôٴΰ´F7£¬ÊäÈë"a"£¨ÔÚASCIIÇøÓò£©£¬°´Ï¼ýÍ·ÊäÈë"00"£¨ÔÚHEXÇøÓò£©£¬°´ÉϼýÍ·£¬Êä
Èë"g"£¬°´Ï¼ýÍ·£¬"00"£¬ÉϼýÍ·£¬"r"£¬Ï¼ýÍ·£¬"00"£¬ÉϼýÍ·£¬"e"£¬Ï¼ýÍ·"00"£¬Éϼý
Í·£¬"e"¡£Äã»á¿´µ½£º
ÉÍ[F2:Forward /F4:Full ]ÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ...
?ASCII: a g r e e°°°°°°°°°°? ...
? ...
? Hex: 61 00 67 00 72 00 65 00 65 °°°°°°°°...
ÈÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ...
10. ºÃ£¬°´»Ø³µÑ°ÕÒÕâ¸ö×Ö·û´®£¬Äã»á¿´µ½£º
.00019300: 00 00 F0 00-14 01 00 00-00 00 41 00-62 00 6F 00 ?__ A b
o
.00019310: 75 00 74 00-20 00 50 00-72 00 69 00-76 00 61 00 u t P r i v
a
.00019320: 74 00 65 00-45 00 58 00-45 00 00 00-08 00 4D 00 t e E X E M
.00019330: 53 00 20 00-53 00 61 00-6E 00 73 00-20 00 53 00 S S a n s
S
.00019340: 65 00 72 00-69 00 66 00-00 00 00 00-01 00 01 50 e r i f _
_P
.00019350: 00 00 00 00-19 00 EA 00-5A 00 0E 00-01 00 FF FF _ ?Z _
??
.00019360: 80 00 26 00-4F 00 6B 00-2C 00 20 00-49 00 20 00 € & O k , I
.00019370: 61 00 67 00-72 00 65 00-65 00 00 00-00 00 00 00 a g r e e
.00019380: 00 00 01 50-00 00 00 00-7B 00 EA 00-5A 00 0E 00 _P { ?Z
.00019390: 65 00 FF FF-80 00 4F 00-72 00 64 00-65 00 72 00 e ??€ O r d e
r
.000193A0: 69 00 6E 00-67 00 20 00-26 00 49 00-6E 00 66 00 i n g & I n
f
11. ÄÇЩ"Ok, I agree"¡¢" Ordering"µÈÊÇ°´Å¥£¬ÏÖÔÚÏòÏÂÖ±µ½£º
.00019420: 81 00 02 50-00 00 00 00-11 00 9E 00-CC 00 21 00 ?_P _ ??!
.00019430: FF FF FF FF-82 00 50 00-72 00 69 00-76 00 61 00 ????~ P r i v
a
.00019440: 74 00 65 00-45 00 58 00-45 00 20 00-69 00 73 00 t e E X E i
s
.00019450: 20 00 4E 00-4F 00 54 00-20 00 61 00-20 00 66 00 N O T a
f
.00019460: 72 00 65 00-65 00 20 00-73 00 6F 00-66 00 74 00 r e e s o f
t
.00019470: 77 00 61 00-72 00 65 00-2E 00 20 00-49 00 74 00 w a r e . I
t
.00019480: 20 00 69 00-73 00 20 00-63 00 6F 00-6D 00 6D 00 i s c o m
m
.00019490: 65 00 72 00-63 00 69 00-61 00 6C 00-20 00 70 00 e r c i a l
p
12. ×¢Òâ¾ÍÔÚ×Ö·û´®"PrivateEXE is NOT a.."Ç°ÃæµÄ"FF FF FF FF 82"£¬ÄǾÍÊDzúÉú¶Ô»°
¿òµÄµØ·½£¬¼ÇסֻÓÐ4¸ö"FF"ºÍ1¸ö"82"¿ÉÒԸı䣡ÏÖÔÚÓ÷½Ïò¼ü½«¹â±êÒƶ¯µ½"82"´¦£¬ÔÚÆÁ
Ä»ÉÏÄã»á¿´µ½"19434"£¬ÏÖÔÚ°´F3²¢½«"82"¸ÃΪ"7E"£¬¿´ÆÁÄ»£¬ÄãÓ¦¸ÃÔÚÆ«ÒƵØÖ·14A34¡£Õâ
¾ÍÊÇÄã¿ÉÒÔ¸ü¸ÄµÄµØ·½¡£°´F9¸üÐÂPEXE32.EXE¡£
13. ¼ÇסÄãÖ»ÓÐ4¸ö"FF"ºÍ1¸ö"82"¿ÉÒԸĶ¯£¬·ñÔòÄãÖ»ºÃÃHÄã×Ô¼ºµÄƨÑÛ¶ùÁË£¨SB£ººÃ´ÖË×
ѽ£©¡£ÏÖÔÚµ±Ä㽫"82"¸ÄΪ"7E"ºó£¬Ëü½«²»ÔÙ²úÉú¶Ô»°¿ò¡£Í˳öHIEW²¢ÔËÐÐPEXE32.EXE¡£
14. »¹ÓÐNAGsÆÁÄ»Âð£¿àÅ£¡£¡ÄãÒѾÆƽâÁËPrivate EXE 2.0a£¡£¡
µÚ¶þ²¿·Ö£¨a£©£ºÈ¥³ýLView Pro 1.C/32µÄNAGs£¨Ê¹ÓÃW32Dasm£©
1. ÔËÐÐLVIEWPRO.EXE
2. ÏÖÔÚÄã¿´µ½ÁËÁîÈËÑá¶ñµÄNAGsÆÁÄ»£¬ÄãÏ£Íû°ÑËü³ýÈ¥£¬¶Ô²»¶Ô£¿:-)
3. ºÃ£¬Í˳ö³ÌÐò
4. ÔËÐÐNorton Commander£¬½øÈëLView Pro·¾¶
5. ½«LVIEWPRO.EXE¸´ÖÆΪLVIEWPRO.EXX£¨Áô×÷±¸·Ý£©£¬½«LVIEWPRO.EXE¸´ÖÆΪ1.EXE£¨¸ø
W32DasmÓã©
6. ÔËÐÐW32Dasm£¬·´±àÒë1.EXE
7. µ±·´±àÒëÍê³Éºó£¬µ¥»÷Debug|Load Process£¨»ò°´CTRL-L£©
8. µÈºòµ÷ÊÔģʽµ÷ÈëËùÓеÄDLL's£¨¶¯Ì¬Á´½Ó¿â£©
9. ºÃ£¬ÏÖÔÚÄãÔÚ"debug"´°¿Ú£¬ÄãÓ¦¸Ã¿´µ½¹âÌõÍ£ÔÚ£º
:00450236 mov eax, dword ptr fs: [00000000]
:0045023C push ebp
...
...
10. Õâ¾ÍÊdzÌÐòµÄÈë¿Ú£¨Program Entry Point£©¡£ºÃ£¬×¼±¸ÔËÐÐLView PRO£¬µ¥»÷RUN£¨»ò
°´F9£©¡£Ä㽫¿´µ½NAGsÆÁÄ»£¬ÏÖÔÚÄãÏëÖªµÀNAGs½ø³Ì£¨processes£©ÔÚÄĶù¡£µ¥»÷Step
Into£¨»ò°´F7£©¡£°¡£¡ÏÖÔÚÄã¿´µ½ÁËÈçÏÂÄÚÈÝ£º
:004324F1 cmp eax, FFFFFFFF
:004324F4 jne 00432508
...
...
11. µ¥»÷Terminate¹Ø±Õµ÷ÊÔģʽºÍLView Pro´°¿Ú
12. ÄãÓ¦¸Ã»Øµ½W32Dasm²¢¿´µ½ÈçÏÂÄÚÈÝ£º
:004324F1 83F8FF cmp eax, FFFFFFFF
:004324F4 7512 jne 00432508
...
13. ºÃ£¬ÏÖÔÚÄãÐèÒª²éÕÒÊÇ´ÓÄÄÀ↑ʼ´¦Àí¶Ô»°¿ò£¨dialogs£©µÄ¡£°´ÉϼýÍ·Ö±µ½ÄãÕÒµ½£º
:004323ED CC int 03
:004323EE CC int 03
:004323EF CC int 03
* Referenced by a CALL at Address:
|:00407EEC
|
:004323F0 83EC78 sub esp, 00000078
:004323F3 56 push esi
...
14. ÕâЩ"CC"£¨int 03£©¾ÍÊÇ´¦Àí¶Ô»°¿òµÄ¿ªÊ¼¡£È·¶¨À¶ÂÌÉ«¹âÌõ´¦ÓÚ:004323F0 83EC78
sub esp, 00000078´¦£¬Äã»áÔÚÆÁÄ»ÏÂÃæ¿´µ½ÏóÕâÑùµÄÆ«ÒƵØÖ·@Offset
000317F0h¡£ÄǾÍÊÇÄã¿ÉÒÔÔÚLVIEWPRO.EXE´ò²¹¶¡µÄµØ·½
15. »Øµ½Norton Commander£¬ÔËÐÐHIEW LVIEWPRO.EXE£¬°´F4Ñ¡ÔñDecodeģʽ£¨ASM£©£¬°´
F5ÊäÈë317F0£¬Äã»á¿´µ½£º
.000323F0: 83EC78 sub esp,078 ;"x"
.000323F3: 56 push esi
.000323F4: 8BB42480000000 mov esi,[esp][000000080]
.000323FB: 85F6 test esi,esi
£¨¼Çס£¬ÏÖÔÚÎÒʹµÄÊÇHIEW5.60£¬Ëü»áÏÔʾºÍÄ㲻ͬµÄÆ«ÒƵØÖ·£¬Õâ¸ö°æ±¾°ô¼«ÁË£¬È¥
ÕÒËü£¡£¡£©
16. Õâ¾ÍÊÇÄã¿ÉÒÔ¸ü¸Ä×ֽڵĵط½£¬°´F3ÊäÈëC3£¬°´F9¸üÐÂLVIEWPRO.EXE¡£µ±Äã°´F3ÊäÈë
C3ºó£¬Äã»á¿´µ½£º
000317F0: C3 retn
000317F1: EC in al,dx
000317F2: 7856 js 00003184A
000317F4: 8BB42480000000 mov esi,[esp][000000080]
000317FB: 85F6 test esi,esi
£¨×¢ÒâÆ«ÒƵØÖ·£©
17. ΪʲôÊÇ"C3"£¿°¡£¬µ±³ÌÐòÔËÐе½C3´¦£¨retn£©£¬Ëü²»»áÈ¥´¦Àí¶Ô»°¿ò£¬ÒòΪÄã¸æËßËü
·µ»Ø°É£¡
18. ÏÖÔÚÔËÐÐLVIEWPRO.EXE£¬Ä㻹¿´µ½NAGsÆÁÄ»Âð£¿àÅ£¡£¡ÄãÒѾÆƽâÁËLView Pro 1.
C/32£¡£¡
ÕâÀﻹÓÐÁíÍâÒ»¸ö°ì·¨È¥³ýNAGsÆÁÄ»£¬ÏëÊÔÊÔÂ𣿺㬷µ»Ø1.Ö´Ðе½15.£¬½Ó×Å×÷£º
19. ÏÖÔÚÄãÔÚÆ«ÒƵØÖ·317F0´¦£¬ÄãÏë¿´¿´ÊÇ˵÷ÓÃÕâ¸ö¹ý³ÌµÄ¡£°´F6Ñ¡ÔñRefer£¨Ëü½«ÕÒµ½
µ±Ç°Î»Öõĵ÷Óô¦£©£¬Äã»á¿´µ½£º
.00007EEC: E8FFA40200 call .0000323F0 ---------- (6)
.00007EF1: 83C404 add esp,004
.00007EF4: 33C0 xor eax,eax
.00007EF6: E9320D0000 jmp .000008C2D ---------- (7)
20. °¡£¬ÏÖÔÚÄãÖªµÀÊÇ˵÷ÓõĶԻ°¿ò¹ý³Ì¡£°´F3ÊäÈë"9090909090"£¬°´F9¸üÐÂLVIEWPRO.
EXE£¬µ±Äã°´F3ÊäÈë"9090909090"ºó£¬Äã»á¿´µ½£º
000072EC: 90 nop
000072ED: 90 nop
000072EE: 90 nop
000072EF: 90 nop
000072F0: 90 nop
000072F1: 83C404 add esp,004
000072F4: 33C0 xor eax,eax
21. ÄÇЩ"9090909090"ʹµÃ³ÌÐò²»ÔÙµ÷ÓöԻ°¿ò¹ý³Ì¡£ÏÖÔÚÔËÐÐLVIEWPRO.EXE£¬Ä㻹¿´µ½
NAGsÆÁÄ»Âð£¿àÅ£¡£¡ÄãÒѾÆƽâÁËLView Pro 1.C/32£¡£¡
µÚ¶þ²¿·Ö£¨b£©£ºÈçºÎÆƽâLView Pro 1.C/32£¨ÊäÈëÈÎÒâÐòÁкţ©
1. ÔËÐÐLVIEWPRO.EXE
2. µ¥»÷Registration£¬½Ó×ÅI'll Register...£¬ÔÚName´¦ÊäÈë"TKC/PC '97"£¬ÔÚID#´¦ÊäÈë
"12345"
3. Ä㽫¿´µ½´íÎóÐÅÏ¢£¨ÄãÐèҪдÏÂÕâЩÐÅÏ¢£©£¬Í˳öÈí¼þ
4. ÔËÐÐNorton Commander£¬½øÈëLVP·¾¶
5. ½«LVIEWPRO.EXE¸´ÖÆΪLVIEWPRO.EXX£¨Áô×÷±¸·Ý£©£¬½«LVIEWPRO.EXE¸´ÖÆΪ1.EXE£¨¸ø
W32DasmÓã©
6. ÔËÐÐW32Dasm£¬·´±àÒë1.EXE
7. µ±·´±àÒëÍê³Éºó£¬µ¥»÷STRING DATA REFERENCE£¬ÏòÏÂÑ°ÕÒ×Ö·û´®"User name and ID
numbers do not..."£¨ÄãÓ¦¸Ã¼ÇµÃ³ö´íÐÅÏ¢µÄ£©£¬Ë«»÷Ëü
8. ¹Ø±ÕSDR´°¿Ú£¬Äã»á¿´µ½£º
* Possible StringData Ref from Data Obj -> "User name and ID numbers..
-> "match, please verify if..
:0041ED7D 68188F4600 push 00468F18
:0041ED82 56 push esi
9. ºÃ£¬ÏÖÔÚÄã±ØÐëÑ°ÕÒÔÚ³ö´íÐÅϢǰµÄ×îºóÒ»¸ö±È½ÏÓï¾ä£¬ÀýÈçCMP¡¢JNE¡¢JE¡¢TESTµÈµÈ
£¬°´ÉϼýÍ·Ö±µ½ÄãÕÒµ½£º
:0041ED7B 751A jne 0041ED97
* Possible StringData Ref from Data Obj -> "User name and ID numbers..
-> "match, please verify if..
...
10. ºÃ£¬ÄãÖªµÀµ±ÊäÈëÁË´íÎóµÄ×¢²áÂëºó»áÌøתµ½ÄÄÀïÁË¡£ÏÖÔÚÄãÏë¿´¿´Èç¹û°Ñ"jne"¸ÄΪ
"je"»áÔõôÑù£¿È·¶¨ÂÌÉ«¹âÌõÔÚ:0041ED7B 751A jne 0041ED97ÉÏ£¬Äã»áÔÚÆÁÄ»ÏÂÃæ¿´µ½Ïó
ÕâÑùµÄÆ«ÒƵØÖ·@Offset 0001E17Bh£¬ÄǾÍÊÇÄã¿ÉÒÔÔÚLVIEWPRO.EXE´ò²¹¶¡µÄµØ·½
11. »Øµ½Norton Commander£¬ÔËÐÐHIEW LVIEWPRO.EXE£¬°´F4Ñ¡ÔñDecodeģʽ£¨ASM£©£¬°´
F5ÊäÈë1E17B£¬Äã»á¿´µ½£º
.0001ED7B: 751A jne .00001ED97 ---------- (1)
.0001ED7D: 68188F4600 push 000468F18
.0001ED82: 56 push esi
12. Õâ¾ÍÊÇÄã¿ÉÒÔ¸ü¸Ä×ֽڵĵط½£¬°´F3ÊäÈë74£¬°´F9¸üÐÂLVIEWPRO.EXE£¬È»ºóÍ˳öHIEW
13. ÔËÐÐLVIEWPRO.EXEËæ±ãÊäÈë×¢²áÂ룬ÇÆ£¡ÄãÒѾÆƽâÁËLVP 1.C/32£¡£¡Ð¡ÐÄ£¡µ±ÄãÊäÈë
ÁËÕæÕýµÄ×¢²áÂëºó»áÔõôÑù£¿Ëü½«Ìøתµ½´íÎóÐÅÏ¢¶Ô»°¿ò£¡Ôõô°ì£¿
14. ÔÙ´ÎÔËÐÐHIEW LVIEWPRO.EXE£¬°´F4Ñ¡ÔñDecode¡¢°´F5ÊäÈë1E17B¡¢°´F3ÊäÈëEB¡¢°´F9¡£
Ëü½«²»ÔÙÌøתµ½´íÎó¶Ô»°¿ò£¡
ÏÖÔÚ¹»ÁË°É¡£ÎÒÏ£ÍûÄãÃǵõ½µÄ±ÈÎÒ×öµÄ¶à£¡:-)
ÎÒÏ´ν«ÔÚ½²½âSoft-ICE 3.0µÄ½Ì³Ì£¨Èý£©ºÍ´ó¼Ò¼ûÃæ¡£
The Keyboard Caper
PhRoZeN CReW '94 - '97µÄ´´Á¢ÈË
1997Äê6ÔÂ8ÈÕ
--
ÔÙ²»Ñ§Ï°£¬Äã¾ÍÒª......
¡ù À´Ô´:¡¤¹þ¹¤´ó×϶¡Ïã bbs.hit.edu.cn¡¤[FROM: 202.118.227.121]
Powered by KBS BBS 2.0 (http://dev.kcn.cn)
Ò³ÃæÖ´ÐÐʱ¼ä£º213.641ºÁÃë