在找(zhǎo )到IAT之(zhī )后,我们只(zhī )需在其(qí )中(zhōng )遍历(lì ),找到(dào )我们需(xū )要的(de )API地址,然(rán )后用我们自己(jǐ )的函数地址(zhǐ )去覆(fù )盖(gài )它(tā ),下面给出一段对(duì )应(yīng )的源码 procedure RedirectApiCall var ImportDescPIMAGE_IMPORT_DESCRIPTOR FirstThunkPIMAGE_THUNK_DATA32 szDWORD
Copyright © 2008-2018