http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Reversing&no=4 [º¹»ç]
dllÀ» Á¦ÀÛÇسõ°í À߸ø °Çµé¿©¼ ¼Ò½º¸¦ ³¯·Á¹ö·È³×¿ä..¤Ñ¤Ñ;;
ÀüÇüÀûÀÎ ¸®¹ö½ÌÀÇ ÀÌÀ¯ÀÔ´Ï´Ù..ÈìÈì..
Á¦°¡ ±Ùµ¥ FindWindow·Î ¾ÈƼµð¹ö±ëÀ» ÇسõÀº »óŶó(´ë·« invoke FindWindow, CTEXT(OllyDbg), 0 ¾î¼ÀÀ¸·Î ½À´Ï´Ù./)
ÄÑ¸é ¹Ù·Î ³¡³ª¹ö¸®³×¿ä.
dll¸®¹ö½ÌÀ» ÇÏ·Á´Âµ¥ (¾Æ´Ï, ÇØ¾ß Çϴµ¥.) ±âº»ÀûÀÎ FindWindow ¿ìȸÇÏ´Â Ç÷¯±×ÀÎÀ̳ª,
´Ù¸¥ ¾ÈƼµð¹ö±ëÀ» ¿ìȸÇÏ´Â Ç÷¯±×ÀÎÀ» ã°í ÀÖ½À´Ï´Ù. (¿Ã¸®µð¹ö°Å ¾²´Ï±î¿ä.)
¾î¶²°É ¾²´Â°Ô ÁÁÀ»Áö¿ä?
±×¸®°í dllÀ» ÀúÀåÇÏ·Á¸é ÀÏ¹Ý exeó·³ ¾ÊµÇ°í ¿Ö loaddll.exe·Î ÀúÀåÀÌ µÉ±î¿ä ¤Ñ¤Ñ;;
ÀÌ ¹æ¹ý ÇØ°á¹ýÁ»¿ä..;;
IDA·Î dllÀ» ¼öÁ¤ÇÏ°í dll·Î ÀúÀåÇÒ¼ö ¾øÀ»±î¿ä?
±×°É·Î asmÆÄÀÏÃßÃâÈÄ ¾î¼ÀºíÇÏ¸é ¿À·ù¸¸ Àܶ೪³×¿ä ¤»¤»¤»¤»¤»¤»
±×¹æ¹ýµµ ÀÖÀ¸¸é ¾Ë·ÁÁÖ¼ËÀ¸¸éÁÁ°Ù³×¿ä °¨»çÇÕ´Ï´Ù~ |
Hit : 6270 Date : 2010/12/21 08:34
|