Record of one PECompact 2.x-& amp; gt; Jeremy Collake shell Removal

Source: Internet
Author: User

A small software:


Show YesPECompact 2.x-> Jeremy CollakeI found an article on the internet saying thatESPThe law is shelled, so I tried it myself.

ODLoad:


F8One step:Push dword ptr fs: [0]HourESPChange0012FFC0

Right-click->Right-click the data window->Breakpoint->Hardware access-> DWORDNext hardware access breakpoint

F9Run:


Cancel hardware breakpoint, F8One step:


At this time, the jump is not implemented: Right-click--->Follow:


Then:F4ToPUSH EDIJump:


In this caseESPIs:0012FFC0 F8Single Step

InLea ebx, dword ptr ds: [EAX + 100012]Run the command again.ESPRecorded:


One stepJMP EAXAnd reachableOEP


UseODBuilt-in plug-ins can be shelled.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.