Slide 70
Slide 70 text
aaaddress1@chroot.org
老外寫了了 CE Script MSCRCBypass:
push eax
lea eax, [ecx]
cmp eax, 00401000
jb Normal
cmp eax, 00BFE000
ja Normal
push ebx
mov ebx, FakeDump
sub eax, 00401000
add eax, ebx
movzx ecx, byte ptr [eax]
pop ebx
pop eax
jmp Normal+04
Normal:
pop eax
movzx ecx, byte ptr [ecx]
mov edx, [ebp+14]
jmp 00A11487
00A11481:
jmp MSCRCBypass
nop
CreateThread(MSmemcpy)
MSmemcpy:
mov edi, FakeDump
mov esi, 00401000
mov ecx, 001FF400
repe movsd
ret
ccplz.net/threads/ems-v75-bypass-information.23009/