当前位置:网站首页>Practice and Thinking on process memory
Practice and Thinking on process memory
2022-06-25 02:26:00 【Hua Weiyun】
Theoretical basis
Killing the virus , Apply security countermeasures , Static reverse application , Dynamic reverse application , The most important object is , Memory data of the application .
Virus killing fight : It is necessary to obtain the memory data of the killing object and compare it with the characteristics of the virus library .
Apply security countermeasures : You need to protect your own memory data from being transferred .
Static reverse application : Encountered application encryption protection , What's the use IDA I'll have a rest , At this time, it is very important to obtain the decrypted memory data .
Dynamic reverse application : use ollydbg Dynamic debugging applications are mainly used to debug the memory data released during operation .
Sum up : One of the problems with applications is memory data , Let's use code to get the of the application “ Air supremacy ”.
Effect display
What is shown below is , Read and operate , Running ClearData Memory data of the process .
The first part of the picture is the memory data correctly read , And write it into the newly created file , The file size is consistent with the original file of the process .
The second part of the picture is the working window , Shows some information about the read operation .
The third part of the picture shows , Running process information .
边栏推荐
- 当一个接口出现异常时候,你是如何分析异常的?
- Qt中使用QDomDocument操作XML文件
- jwt
- 元宇宙的生态圈
- 如何选择正规安全的外汇交易平台?
- 【STL源码剖析】STL六大组件功能与运用(目录)
- Android Internet of things application development (smart Park) - set sensor threshold dialog interface
- 一线城市软件测试工资——你拖后腿了吗
- js正则匹配数字、大小写字母、下划线、中线和点[通俗易懂]
- Post competition summary of kaggle patent matching competition
猜你喜欢

Exploring the mystery of C language program -- C language program compilation and preprocessing
![[STL source code analysis] configurator (to be supplemented)](/img/87/0ed1895e9cdb5327411c0c9cb0197f.png)
[STL source code analysis] configurator (to be supplemented)

当他们在私域里,掌握了分寸感

记一次beego通过go get命令后找不到bee.exe的坑

Can automate - 10k, can automate - 20K, do you understand automated testing?

3 years of testing experience. I don't even understand what I really need on my resume. I need 20K to open my mouth?

罗德与施瓦茨与中关村泛联院合作开展6G技术研究与早期验证

jwt

File system - basic knowledge of disk and detailed introduction to FAT32 file system

Experience of epidemic prevention and control, home office and online teaching | community essay solicitation
随机推荐
消息称一加将很快更新TWS耳塞、智能手表和手环产品线
Convert string array to list collection
3 years of testing experience. I don't even understand what I really need on my resume. I need 20K to open my mouth?
中信证券手机开户是靠谱的吗?安全吗
Smartctl opens the device and encounters permission denied problem troubleshooting process record
疫情防控,居家办公,网上授课之心得 | 社区征文
如何卸载cuda
Constant current circuit composed of 2 NPN triodes
Jetson Nano 从入门到实战(案例:Opencv配置、人脸检测、二维码检测)
Application of TSDB in civil aircraft industry
|How to analyze bugs? Professional summary and analysis
一线城市软件测试工资——你拖后腿了吗
华泰证券如何开户能做到万分之一?证券开户安全可靠吗
Are programmers from Huawei, Alibaba and other large manufacturers really easy to find?
It is said that Yijia will soon update the product line of TWS earplugs, smart watches and bracelets
vim的Dirvish中文文档
折叠屏将成国产手机分食苹果市场的重要武器
Intranet learning notes (7)
When an interface has an exception, how do you analyze the exception?
基本布局-QHBoxLayout类、QVBoxLayout类、QGridLayout类