冰楓論壇

標題: TwMS v222.2 技能注入Call分析 [打印本頁]

作者: yutsaihsieh    時間: 2020-2-6 15:57
標題: TwMS v222.2 技能注入Call分析
  1. //TwMS v222.2 技能注入Call分析
  2. Alloc(temp,128) //temp:[ebp-14]
  3. Label(Label1)
  4. Alloc(switch,4)

  5. switch:
  6. dd 0
  7. temp:
  8. db 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00

  9. Main:
  10. mov dword ptr [temp+08],00000000
  11. mov dword ptr [temp+10],00000000
  12. cmp [switch],01
  13. jne originalcode
  14. mov [switch],00
  15. pushad
  16. //------------------------------------
  17. mov edi,[03DD1540]
  18. mov ecx,[03DCF228]
  19. lea eax,[temp]
  20. push eax
  21. call 02A01D90
  22. cmp dword ptr [temp+04],00
  23. mov eax,[eax+04]
  24. mov [temp+08],eax
  25. je Label1
  26. push 00
  27. lea ecx,[temp]
  28. call 0047F170
  29. mov [temp+04],00000000
  30. //------------------------------------
  31. Label1:
  32. mov dword ptr [edi+00016660],技能代碼
  33. //------------------------------------
  34. mov ecx,[03DCF220]
  35. lea eax,[temp+10]
  36. push 01
  37. push 00
  38. push 00
  39. push 00
  40. push eax
  41. push [edi+00016660]
  42. mov [temp+10],00000000
  43. push [temp+08]
  44. call 0084ECF0
  45. //------------------------------------
  46. push 00
  47. push 00
  48. push 00
  49. push 00
  50. push 00
  51. push 00
  52. push 00
  53. push 00
  54. push 00
  55. push 00
  56. push 00
  57. push 00
  58. push 00
  59. push 00
  60. push 00
  61. push 00
  62. push 00
  63. push eax
  64. push [temp+10]
  65. mov ecx,edi
  66. call 02657970
  67. mov dword ptr [edi+00016660],00000000
  68. //------------------------------------
  69. popad
複製代碼
懂得用法的歡迎使用
作者: 唔係車大炮    時間: 2020-3-23 09:58
不明覺厲,哈哈




歡迎光臨 冰楓論壇 (https://bingfong.com/) Powered by 冰楓