97, 2/5 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   rptprl123
   http://blog.naver.com/show3096
   ¸®¹ö½Ì °ü·ÃÇؼ­ ¼±¹è´Ôµé¿¡°Ô Áú¹®µå¸®°í ½ÍÀº°ÔÀִµ¥¿ä.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Reversing&no=76 [º¹»ç]


À©µµ¿ì 7 64bit ·Î ollyDbg 1.1 ¹öÀüÀ¸·Î
64bit ȣȯ Ç÷¯±×ÀÎ ¼³Ä¡ ÈÄ¿¡ ¸®¹ö½Ì °øºÎÇÏ°í Àִµ¥¿ä,

[¸®¹ö½Ì ÇÙ½É ¿ø¸®] ¶ó´Â Ã¥À¸·Î °øºÎ ÇÏ´øÁß

WIN API ÈÄÅ· ºÎºÐ¿¡¼­
notepad.exe ÀÇ writefile() API ÈÄÅ·Àε¥,
¸Þ¸ðÀåÀ» ollydbg ·Î ¿­¾î¼­ writefile API ÀÇ ½ÃÀۺκп¡
BP ¸¦ °É¾î³õÀº ÈÄ

¸Þ¸ðÀå¿¡ ±ÛÀ» ¾²°í ÀúÀåÀ» Çϸé writefile API() ºÎºÐ¿¡¼­
¸ØÃç¾ß Çϴµ¥ ¾È ¸ØÃß°í ÀüÇô ´Ù¸¥
ntdll.dll ¶óÀ̺귯¸®ÀÇ Áß°£¿¡¼­ ¸ØÃç¹ö¸®³×¿ä.
°Å±â¼­ F9 ¹øÀ¸·Î ¸î¹øÀÌ°í ½ÇÇàÀ» ½ÃÄѾßÁö ³Ñ¾î°¡°í

¿Ö ÀÌ·±Áö ¾Ë ¼ö ÀÖÀ»±î¿ä?

  Hit : 3004     Date : 2014/10/12 07:26



    
77   ¸®¹ö½º ¿£Áö´Ï¾î¸µÀÌ ¹¹¿¡¿ä?[3]     qkreoghks00
01/23 3970
76   ¸®¹ö½º ¿£Áö´Ï¾î¸µ ¹ÙÀ̺íÀ» Àдٰ¡ ±Ã±ÝÇÑ Á¡ÀÌ »ý°å´Âµ¥¿ä¤Ð![1]     tjswn7051
10/14 3469
75   ¸®¹ö½º ¿£Áö´Ï¾î¸µ °øºÎÇÏ·Á¸é[1]     °¨¿°¿À¸®
08/14 4163
74   ¸®¹ö½Ì¿¡ Á» ¹°¾îº¾´Ï´Ù[1]     ±×ÀúÁú¹®
01/19 4213
73   ¸®¹ö½ÌÇÏ´Ù°¡ JGE °ü·Ã Áú¹®     Z2ong2
10/09 2843
72   ¸®¹ö½ÌÀÇ·ÚÇÏ·ÁÇÕ´Ï´Ù[1]     eastgm
01/31 3571
71   ¸®¹ö½Ì-µð½º¾î¼Àºí¸®-µð¹ö°Å¿¡ ¹®ÀÇÁ»..     leonardo6
10/13 2532
70   ¸®¹ö½Ì,Å©·¢ ÀÇ·ÚÇÕ´Ï´Ù[2]     inx123
11/27 4269
69   ¸®¹ö½Ì, Å©·¢¹Ì ±îºÃ´õ´Ï¡¦ Ãæ°Ý[1]     creeper
12/01 4118
68   ¸®¹ö½Ì(¾î¼Àºí¸®¾î) ±âÃÊ Áú¹®Á» µå¸®°Ú½À´Ï´Ù[2]     skyclad1975
12/10 3264
67   ¸®¹ö½Ì ¿£Áö´Ï¾î¸µ °øºÎ??[3]     GaOnNuRI
04/30 4135
66   ¸®¹ö½Ì ¹®Á¦ Ǫ´Â Áß¿¡ ±Ã±ÝÇÑ Á¡ÀÌ ÀÖ½À´Ï´Ù.[5]     ansuz0710
08/10 3237
65   ¸®¹ö½Ì °øºÎ µµÁß...[1]     whitetie
06/05 3117
  ¸®¹ö½Ì °ü·ÃÇؼ­ ¼±¹è´Ôµé¿¡°Ô Áú¹®µå¸®°í ½ÍÀº°ÔÀִµ¥¿ä.     rptprl123
10/12 3003
63   ¸®¹ö½Ì __security_cookie[3]     healer
07/17 3596
62   ¸®¹ö½Ì Çٽɿø¸®¸¦ °øºÎÇÏ´Ù°¡ ¸·Çû½À´Ï´Ù.     aaasss445
06/12 2125
61   ¸®¹ö½Ì ÇÏ·Á¸é À©µµ¿ì ÇÁ·Î±×·¡¹Öµµ ¹è¿ö¾ß Çϳª¿ä?[2]     cji2
05/20 4096
60   ¸®¹ö½Ì ÀÔ¹®ÇÏ°í ½Í¾î¼­ Áú¹®µå¸³´Ï´Ù.[2]     shdac
09/27 3991
59   ¸®¹ö½Ì ÀÔ¹®ÀÚÀÔ´Ï´Ù     shdac
10/12 2753
58   ¸®¹ö½Ì Ãʺ¸ÀÔ´Ï´Ù. IDA¿¡ ´ëÇÑ Áú¹®ÀÖ½À´Ï´Ù.[3]     shdac
10/29 3786
[1] 2 [3][4][5]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org