2023-04-27 10:48:45
27 04 2023
摘要:

脚本文件memmove.txt

as /mu ${/v:tn2} esi;
.block
{
.if( $sicmp(@"${tn2}","NTDLL") == 0 ){.echo find; ad ${/v:tn2};}.else{.echo no;ad ${/v:tn2};gc}
}

 

//使用条件断点

bp ntdll!memmove+0xe "$><c:\\memove.txt"

 

延伸阅读
  1. 上一篇:JDK
  2. 下一篇:Nginx
发表评论