当前位置:网站首页>Practice and Thinking on process memory
Practice and Thinking on process memory
2022-06-25 02:26:00 【Hua Weiyun】
Theoretical basis
Killing the virus , Apply security countermeasures , Static reverse application , Dynamic reverse application , The most important object is , Memory data of the application .
Virus killing fight : It is necessary to obtain the memory data of the killing object and compare it with the characteristics of the virus library .
Apply security countermeasures : You need to protect your own memory data from being transferred .
Static reverse application : Encountered application encryption protection , What's the use IDA I'll have a rest , At this time, it is very important to obtain the decrypted memory data .
Dynamic reverse application : use ollydbg Dynamic debugging applications are mainly used to debug the memory data released during operation .
Sum up : One of the problems with applications is memory data , Let's use code to get the of the application “ Air supremacy ”.
Effect display
What is shown below is , Read and operate , Running ClearData Memory data of the process .
The first part of the picture is the memory data correctly read , And write it into the newly created file , The file size is consistent with the original file of the process .
The second part of the picture is the working window , Shows some information about the read operation .
The third part of the picture shows , Running process information .
边栏推荐
- Constant current circuit composed of 2 NPN triodes
- Smartctl opens the device and encounters permission denied problem troubleshooting process record
- ProcessOn制作ER过程(自定义)
- 常用的软件测试工具清单,请查收。
- Taishan Office Technology Lecture: a simple study of Chinese punctuation in vertical arrangement
- 如何通过EasyCVR接口监测日志观察平台拉流情况?
- What are the reasons for the abnormal playback of the online channel of the channel accessed by easycvr national standard protocol?
- 软件测试人员的7个等级,据说只有1%的人能做到级别7
- Intranet learning notes (7)
- 【移动端】手机界面的设计尺寸
猜你喜欢

华为、阿里等大厂程序员真的好找对象吗?

保险APP适老化服务评测分析2022第06期

qt打包exe文件,解决“无法定位程序输入点_ZdaPvj于动态链接库Qt5Cored.dll”

The role of software security testing, how to find a software security testing company to issue a report?

I've been doing software testing for two years. I'd like to give some advice to girls who are still hesitating

Redis

【STL源码剖析】STL六大组件功能与运用(目录)

【Proteus仿真】Arduino UNO+数码管显示4x4键盘矩阵按键

Talking about the advantages of flying book in development work | community essay solicitation

元宇宙的生态圈
随机推荐
多模态情感识别_多模态融合的情感识别研究「建议收藏」
[STL source code analysis] configurator (to be supplemented)
Taishan Office Technology Lecture: a simple study of Chinese punctuation in vertical arrangement
云原生数据库VS传统数据库
基本布局-QHBoxLayout类、QVBoxLayout类、QGridLayout类
把 Oracle 数据库从 Windows 系统迁移到 Linux Oracle Rac 集群环境(2)——将数据库转换为集群模式
转行软件测试2年了,给还在犹豫的女生一点建议
都2022年了,你还不了解什么是性能测试?
商城项目 pc----商品详情页
Sumati gamefi ecological overview, element design in the magical world
Software testing salary in first tier cities - are you dragging your feet
Is it out of reach to enter Ali as a tester? Here may be the answer you want
June 24, 2022: golang multiple choice question, what does the following golang code output? A:1; B:3; C:4; D: Compilation failed. package main import ( “f
yarn : 无法加载文件 C:\Users\xxx\AppData\Roaming\npm\yarn.ps1,因为在此系统上禁止运行脚本
内网学习笔记(6)
内网学习笔记(5)
Once beego failed to find bee after passing the go get command Exe's pit
把 Oracle 数据库从 Windows 系统迁移到 Linux Oracle Rac 集群环境(4)—— 修改 oracle11g rac 集群的 scanIP
Uncaught Error: [About] is not a <Route> component. All component children of <Routes> must be a <Ro
内网学习笔记(7)