ESP's law shelling shelling --NsPack3.x

First, conduct inspections of shell, NsPack

 

 The program dragged x64dbg

Program entrance iconic push

 

 F8 single step, esp found that only register changes

 

 Right in the memory window viewing on esp, lower hardware breakpoints

 

 F9 to run the program, the program off after a pop.

 

 F7 single step using two subsequent entry into the program, oep

 

 Use shelling comes scylla

Fill in the correct OEP, IAT automatically find and acquire library, dump out a program to import, and then repair it. OEP position can be the next breakpoint, the next convenient time debugging

 

 After the check program shell shelling

 

 

Shelling success

Guess you like

Origin www.cnblogs.com/hongren/p/12633232.html