- UID
- 7428
注册时间2006-1-25
阅读权限40
最后登录1970-1-1
独步武林
 
TA的每日心情 | 奋斗 2025-1-2 00:02 |
---|
签到天数: 935 天 [LV.10]以坛为家III
|
脱UPX壳,方法知道,有脚本就偷下懒,好像别人都没发~
- /*
- EOP finder for upxshit 0.6 (snaker) & UPX
- It also works for a "standalone" UPX packed program
- Author : mimas
- */
- var x
- loop:
- findop eip, #E9??# // find jump to next loop
- mov x, $RESULT
- sub x, eip
- cmp x, 10 // (@jmp - eip) use to be 10,
- // we can handle different loop size this way
- ja stub
- go $RESULT
- sto
- jmp loop
- stub:
- // the terrific UPX OEP finder
- eob end
- sto
- mov x, esp
- bphws x, "r"
- run
- end:
- bphwc x
- sto
- ret
复制代码 |
|