国产探花免费观看_亚洲丰满少妇自慰呻吟_97日韩有码在线_资源在线日韩欧美_一区二区精品毛片,辰东完美世界有声小说,欢乐颂第一季,yy玄幻小说排行榜完本

首頁 > 學院 > 開發設計 > 正文

Crackme 20

2019-11-08 02:46:42
字體:
來源:轉載
供稿:網友

首先用PEID檢測一下 這里寫圖片描述 有殼wwPack32 經典殼,現在接觸的帶殼程序不多,上次直接脫殼軟件搞定,這次跟著教程手動搞了一下 首先單步調試找到跨段跳轉 這里寫圖片描述 跳入之后下斷點(一般跳入之后就是程序開始的地方),但里面的沒有反匯編代碼,看著比較難受。 這里寫圖片描述 首先脫殼 這里寫圖片描述 脫殼之后打不開,我看有的題解上脫殼后可以打開···· 利用PEID查看什么程序編寫 這里寫圖片描述 利用dede反編譯沒有什么成果,直接利用IDR分析Delphi

Unit1::TForm1.Button1Click 0044A2E8 push ebp 0044A2E9 mov ebp,esp 0044A2EB xor ecx,ecx 0044A2ED push ecx 0044A2EE push ecx 0044A2EF push ecx 0044A2F0 push ecx 0044A2F1 push ebx 0044A2F2 push esi 0044A2F3 mov ebx,eax 0044A2F5 xor eax,eax 0044A2F7 push ebp 0044A2F8 push 44A3E4 0044A2FD push dWord ptr fs:[eax] 0044A300 mov dword ptr fs:[eax],esp 0044A303 lea edx,[ebp-4] 0044A306 mov eax,dword ptr [ebx+2C8]; TForm1.Edit2:TEdit 0044A30C call TControl.GetText 0044A311 mov eax,dword ptr [ebp-4] 0044A314 call StrToInt 0044A319 mov esi,eax 0044A31B mov eax,dword ptr [ebp-4] 0044A31E call StrToInt64 0044A323 push edx 0044A324 push eax 0044A325 mov eax,esi 0044A327 cdq 0044A328 add eax,dword ptr [esp] 0044A32B adc edx,dword ptr [esp+4] 0044A32F add esp,8 0044A332 push edx 0044A333 push eax 0044A334 mov eax,esi 0044A336 cdq 0044A337 add eax,dword ptr [esp] 0044A33A adc edx,dword ptr [esp+4] 0044A33E add esp,8 0044A341 push edx 0044A342 push eax 0044A343 lea edx,[ebp-8] 0044A346 mov eax,6 0044A34B call IntToHex 0044A350 mov edx,dword ptr [ebp-8] 0044A353 mov eax,dword ptr [ebx+2CC]; TForm1.Edit3:TEdit 0044A359 call TControl.SetText 0044A35E lea edx,[ebp-0C] 0044A361 mov eax,dword ptr [ebx+2CC]; TForm1.Edit3:TEdit 0044A367 call TControl.GetText 0044A36C mov eax,dword ptr [ebp-0C] 0044A36F push eax 0044A370 lea edx,[ebp-10] 0044A373 mov eax,dword ptr [ebx+2F0]; TForm1.Label1:TLabel 0044A379 call TControl.GetText 0044A37E mov edx,dword ptr [ebp-10] 0044A381 pop eax 0044A382 call @LStrCmp>0044A387 jne 0044A398 0044A389 mov dl,1 0044A38B mov eax,dword ptr [ebx+2FC]; TForm1.Label2:TLabel 0044A391 call TControl.SetVisible>0044A396 jmp 0044A3A9 0044A398 mov eax,dword ptr [ebx+2D4]; TForm1.Label6:TLabel 0044A39E mov edx,dword ptr [eax+34]; TLabel.Top:Integer 0044A3A1 sub edx,0A 0044A3A4 call TControl.SetTop 0044A3A9 mov eax,dword ptr [ebx+2D4]; TForm1.Label6:TLabel 0044A3AF cmp dword ptr [eax+34],32; TLabel.Top:Integer>0044A3B3 jge 0044A3BC 0044A3B5 mov eax,ebx 0044A3B7 call TCustomForm.Close 0044A3BC xor eax,eax 0044A3BE pop edx 0044A3BF pop ecx 0044A3C0 pop ecx 0044A3C1 mov dword ptr fs:[eax],edx 0044A3C4 push 44A3EB 0044A3C9 lea eax,[ebp-10] 0044A3CC mov edx,2 0044A3D1 call @LStrArrayClr 0044A3D6 lea eax,[ebp-8] 0044A3D9 mov edx,2 0044A3DE call @LStrArrayClr 0044A3E3 ret<0044A3E4 jmp @HandleFinally<0044A3E9 jmp 0044A3C9 0044A3EB pop esi 0044A3EC pop ebx 0044A3ED mov esp,ebp 0044A3EF pop ebp 0044A3F0 ret

分析算法

0044A30C |. E8 FBA0FDFF CALL 3.0042440C ; name string0044A311 |. 8B45 FC MOV EAX,[LOCAL.1]0044A314 |. E8 EFD6FBFF CALL 3.00407A08 ; strtoint0044A319 |. 8BF0 MOV ESI,EAX0044A31B |. 8B45 FC MOV EAX,[LOCAL.1]0044A31E |. E8 5DD7FBFF CALL 3.00407A800044A323 |. 52 PUSH EDX0044A324 |. 50 PUSH EAX0044A325 |. 8BC6 MOV EAX,ESI0044A327 |. 99 CDQ0044A328 |. 030424 ADD EAX,DWORD PTR SS:[ESP] ; 0x7b + 0x7b0044A32B |. 135424 04 ADC EDX,DWORD PTR SS:[ESP+4]0044A32F |. 83C4 08 ADD ESP,80044A332 |. 52 PUSH EDX0044A333 |. 50 PUSH EAX0044A334 |. 8BC6 MOV EAX,ESI0044A336 |. 99 CDQ0044A337 |. 030424 ADD EAX,DWORD PTR SS:[ESP] ; 0x7b + 0xf60044A33A |. 135424 04 ADC EDX,DWORD PTR SS:[ESP+4]0044A33E |. 83C4 08 ADD ESP,80044A341 |. 52 PUSH EDX ; /Arg20044A342 |. 50 PUSH EAX ; |Arg10044A343 |. 8D55 F8 LEA EDX,[LOCAL.2] ; |0044A346 |. B8 06000000 MOV EAX,6 ; |0044A34B |. E8 78D6FBFF CALL 3.004079C8 ; /int to hex0044A350 |. 8B55 F8 MOV EDX,[LOCAL.2]0044A353 |. 8B83 CC020000 MOV EAX,DWORD PTR DS:[EBX+2CC]0044A359 |. E8 DEA0FDFF CALL 3.0042443C0044A35E |. 8D55 F4 LEA EDX,[LOCAL.3]0044A361 |. 8B83 CC020000 MOV EAX,DWORD PTR DS:[EBX+2CC]0044A367 |. E8 A0A0FDFF CALL 3.0042440C0044A36C |. 8B45 F4 MOV EAX,[LOCAL.3]0044A36F |. 50 PUSH EAX0044A370 |. 8D55 F0 LEA EDX,[LOCAL.4]0044A373 |. 8B83 F0020000 MOV EAX,DWORD PTR DS:[EBX+2F0]0044A379 |. E8 8EA0FDFF CALL 3.0042440C0044A37E |. 8B55 F0 MOV EDX,[LOCAL.4]0044A381 |. 58 POP EAX0044A382 >|. E8 6198FBFF CALL 3.00403BE8 ; strcmp

寫出注冊機

s = '0x3e74984b'PRint int(s,16)/3

這里寫圖片描述


發表評論 共有條評論
用戶名: 密碼:
驗證碼: 匿名發表
主站蜘蛛池模板: 正蓝旗| 梅州市| 土默特左旗| 轮台县| 靖边县| 宜章县| 故城县| 封丘县| 新津县| 锡林郭勒盟| 克什克腾旗| 九江县| 永寿县| 上林县| 贵德县| 邵东县| 孙吴县| 黄浦区| 吴桥县| 汉源县| 柳林县| 南安市| 久治县| 东乌珠穆沁旗| 甘谷县| 闽清县| 玉林市| 宣威市| 丰宁| 江阴市| 江北区| 巫溪县| 万年县| 鸡西市| 克东县| 云浮市| 佛坪县| 丽江市| 陵水| 富平县| 太白县|