当前位置:网站首页>Practice and Thinking on process memory
Practice and Thinking on process memory
2022-06-25 02:26:00 【Hua Weiyun】
Theoretical basis
Killing the virus , Apply security countermeasures , Static reverse application , Dynamic reverse application , The most important object is , Memory data of the application .
Virus killing fight : It is necessary to obtain the memory data of the killing object and compare it with the characteristics of the virus library .
Apply security countermeasures : You need to protect your own memory data from being transferred .
Static reverse application : Encountered application encryption protection , What's the use IDA I'll have a rest , At this time, it is very important to obtain the decrypted memory data .
Dynamic reverse application : use ollydbg Dynamic debugging applications are mainly used to debug the memory data released during operation .
Sum up : One of the problems with applications is memory data , Let's use code to get the of the application “ Air supremacy ”.
Effect display
What is shown below is , Read and operate , Running ClearData Memory data of the process .
The first part of the picture is the memory data correctly read , And write it into the newly created file , The file size is consistent with the original file of the process .
The second part of the picture is the working window , Shows some information about the read operation .
The third part of the picture shows , Running process information .
边栏推荐
- [live review] battle code pioneer phase 7: how third-party application developers contribute to open source
- Sumati gamefi ecological overview, element design in the magical world
- 消息称一加将很快更新TWS耳塞、智能手表和手环产品线
- 计算机三级(数据库)备考题目知识点总结
- 保险APP适老化服务评测分析2022第06期
- 会自动化—10K,能做自动化—20K,你搞懂自动化测试没有?
- 探索C语言程序奥秘——C语言程序编译与预处理
- 3年测试经验,连简历上真正需要什么都没搞明白,张口就要20k?
- 实战攻防演练中的四大特点
- 商城项目 pc----商品详情页
猜你喜欢

探索C语言程序奥秘——C语言程序编译与预处理

How to quickly familiarize yourself with the code when you join a new company?

Please run IDA with elevated permissons for local debugging.

What is the reason for the disconnection of video playback due to the EHOME protocol access of easycvr platform?

jwt

软件测试人员的7个等级,据说只有1%的人能做到级别7

Use of hashcat

【直播回顾】战码先锋第七期:三方应用开发者如何为开源做贡献

1-6搭建Win7虚拟机环境

内网学习笔记(7)
随机推荐
产业互联网的概念里有「互联网」字眼,但却是一个和互联网并不关联的存在
Is the compass reliable? Is it safe to open a securities account?
It's 2022, and you still don't know what performance testing is?
【直播回顾】战码先锋第七期:三方应用开发者如何为开源做贡献
一线城市软件测试工资——你拖后腿了吗
The ecosystem of the yuan universe
当人们用互联网式的思维和视角来看待产业互联网的时候,其实已陷入到了死胡同
计网 | 【四 网络层】知识点及例题
[analysis of STL source code] functions and applications of six STL components (directory)
Beescms website penetration test and repair comments "suggestions collection"
云原生数据库VS传统数据库
02 common codes for Epicor secondary development
I've been doing software testing for two years. I'd like to give some advice to girls who are still hesitating
高速缓存Cache详解(西电考研向)
多模态情感识别_多模态融合的情感识别研究「建议收藏」
内网学习笔记(5)
yarn : 无法加载文件 C:\Users\xxx\AppData\Roaming\npm\yarn.ps1,因为在此系统上禁止运行脚本
Kaggle 专利匹配比赛赛后总结
1-6搭建Win7虚拟机环境
How to quickly familiarize yourself with the code when you join a new company?