Get the App
SLTechnology News&Howtos  ›  Network Security  › 

The second session of ctf.360.cn, reverse part of the third question of writeup--

Shulou Source: shulou.com Published: 2022-06-01 04:02:33 10月06日 Update

Topic: see attachment

This problem is the quickest to solve, and the tip is very clear.

There was an error in the direct operation of exe. When OD was opened, it was found that the entry point was a jmp.

F8, tracked to the address after jmp, found the cause of the error in running the program.

In fact, this topic is to simulate the behavior of virus infecting exe, modifying file entry instructions, and inserting malicious code.

Patching is actually finding the code of the real entry function header and nop the previous instructions such as jmp. (it is also OK to modify OEP)

Attachment: http://down.51cto.com/data/2365126

Tags: Entry that is title code actual actually instruction attachment run fastest function reason address malicious file virus program behavior patch prompt Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Redmi Shulou Technology OPPO Reno Huawei MariaDB