摘要: windbg 调试进程。0:001> dg @fsP Si Gr Pr LoSel Base Limit Type l ze an es ng Flags---- -------- -------- ---------- - -- -- -- -- --------0038 7ffde000 00000fff Data RW Ac 3 Bg By P Nl 000004f3 <--------------7ffde0000:001> r $teb$teb=7ffde000 <--------------fs:[0x30] 就是 PEB结构的指针.继续分析怎么得出 0x3 阅读全文
posted @ 2012-12-05 04:38 Red Cat 阅读(1700) 评论(0) 推荐(0) 编辑

Copyright © 2022 LyShark Powered by .NET 6 on Kubernetes
Theme - LyTheme 1.0