- 1、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。。
- 2、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 3、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
- 4、该文档为VIP文档,如果想要下载,成为VIP会员后,下载免费。
- 5、成为VIP后,下载本文档将扣除1次下载权益。下载后,不支持退款、换文档。如有疑问请联系我们。
- 6、成为VIP后,您将拥有八大权益,权益包括:VIP文档下载权益、阅读免打扰、文档格式转换、高级专利检索、专属身份标志、高级客服、多端互通、版权登记。
- 7、VIP文档为合作方或网友上传,每下载1次, 网站将根据用户上传文档的质量评分、类型等,对文档贡献者给予高额补贴、流量扶持。如果你也想贡献VIP文档。上传文档
查看更多
delphi实现无导入表程序(Delphi implements an imported table program)
delphi实现无导入表程序(Delphi implements an imported table program)
The premise is that you already have a certain knowledge of PE Virus
Well, first of all, there is no import table procedures of the basic components
1.GetkernelBase (base for kernel32.dll)
Since we are programs without import tables, all API functions are done by memory search,
You already know that EXE is loaded into memory, and ESP saves the ExitThread function address
The ExitThread function is in the kernel32.dll module, so it is loaded when it proves that the EXE is loaded
The kernel32.dll module, so our work is to determine the kernel32.dll base address.
Here I use the method of PEB to obtain the kernel32.dll address of the base (simple.. Delphi debugging this program is very troublesome ~ so use this.. )
Code: --------------------------------------------------------------------------------
ASM
MOV, eax, fs:$30
MOV, eax, [eax + $0c]
MOV, ESI, [eax + $1c]
Lodsd
Mov eax, the base [eax+$08] / / eax is saved when the k32.
End;
--------------------------------------------------------------------------------
Get to the rest of the base is required to determine the two important functions we need.
The two functions of GetProcAddress and LoadLibraryA - with these two functions, we can
Get any of the functions we need..
2. build the GetProcAddress function
Above we have access to the k32 address - but the problem is that we have to finish our program needs some other functions
First, we review the API search functions written by our predecessors in order to reduce program size and protect the program itself
They basically use the hash value to search the modules import table so that we can build a API search ourselves
Function. Direct paste code is good ~ in fact, Delphi version of the API search function, many predecessors have written
Aming, Lao Wang, liumazi, and so on ~!
Code: --------------------------------------------------------------------------------
FUNCTION GetProcAddress (Module:Cardinal; ProcessC
您可能关注的文档
- 2011年4月党员思想汇报学习胡主席清华大学讲话(Party members' ideological report in April 2011 study President Hu Jintao's speech at Tsinghua University).doc
- 2011年4月管理会计一(April 2011 management accounting).doc
- 2011年4月自考真题管理会计(Self Zhenti April 2011 management accounting).doc
- 2011年5月中物联物流师考点估计(简体)、(In May 2011, China Federation of logistics and logistics division point estimate (simplified),).doc
- 2011年个人年终工作总结暨2012年工作计划(Personal year-end work summary in 2011 and work plan for 2012).doc
- 2011年中考《数学》冲刺试题及答案(2011 mid-term exam Mathematics sprint questions and answers).doc
- 2011cpa注册会计师审计《经典题解》勘误完整终结版(2011cpa CPA classic errata complete version of the end solution).doc
- 2011年中考语文试题集锦(A collection of Chinese examination questions in 2011).doc
- 2011年党课讲稿(2011 lectures notes).doc
- 2011年中考化学图像型计算题专题复习(Special review of chemistry image type calculation questions in middle school entrance examination in 2011).doc
- dna提取中实验试剂作用原理(The principle of experimental reagent in DNA extraction).doc
- dns服务器的搭建(DNS server build).doc
- cet4必考100单词(CET4 compulsory 100 words).doc
- df和du 命令详解 df命令详细用法(The DF and Du commands explain the DF command in detail).doc
- dos运行指令(DOS operating instructions).doc
- dota imba 命令(bit imba 命令).doc
- dota、真三通用改键v1.1 dota改建(DOTA, true three GM change key, v1.1, dota alterations).doc
- dos 入门基础知识(Two 入门基础知识).doc
- debug卡(debug卡).doc
- e-prime使用简要说明(中文)(Brief description of E-Prime usage (in Chinese)).doc
最近下载
- 2025金风变流器2.0MW故障代码手册V4.docx VIP
- 神经系统疾病病人的护理—颅内压增高与脑疝病人的护理.ppt
- VW 75205_DE 扭线 标准要求.pdf VIP
- 临时占道施工方案及安全措施.docx VIP
- 2024年软件资格考试系统集成项目管理工程师(中级)(基础知识、应用技术)合卷试卷与参考答案.docx VIP
- 纪委遴选笔试题及答案.doc VIP
- 内蒙古新街台格庙矿区新街二井及选煤厂水土保持方案.pdf VIP
- 2026国家公务员考试《申论》三色笔记.pdf VIP
- 2025年版《中华人民共和国药典》修订内容解读与实施指南.pptx VIP
- 货物仓储监管三方合同协议书范本模板.doc VIP
文档评论(0)