ã©ããå®è¡ã§ããããã. http://www.artonx.org/diary/20091020.html#p01 ã¸ãã¼!
ã©ããå®è¡ã§ããããã. http://www.artonx.org/diary/20091020.html#p01 ã¸ãã¼!
ATOKãã¤ã¬ã¯ãã§ASããµãã¼ããããªãããç¡è¦ãããªãã¦ããã®ã¯ãå®ã®æã¡è ãã«ãç¨ãããã£ã¦ãã®ã§ãä½ãä½ã£ã¦ã¿ããã¨ã«ããã ããããä½ãããã«ã¯èª°ã¨ããã¶ã£ã¦ãªãã¦ãããããã§ãªããããªãã®ãä½ããããå°ä¸æéææ¡ã«è½ã£ã¦ã¿ãã¨ããããx86ã¢ã»ã³ãã©ãã¨ãããã¼ã¯ã¼ããæãæµ®ããã ã ãããä»æ±ãã¦ããã®ã¯ãã£ã¨ããã ãããã§ãããã x86ã¢ã»ã³ãã©ã¨è¨ãã°ãMicrosoftã®MASMããBorlandã®TASMããªã¼ãã³ã½ã¼ã¹ããã¸ã§ã¯ãã®NASMãGNUã®GAS辺ããæåã ã¨æããããã¤ããå¼ã³åºãã¦ãåºåãunpackãã¦ããããã ãã©ãã¹ã¯ãªããã§ãããªã100% Pure Rubyã§è¡ãããã¨ããã ã æ¤ç´¢ãµã¤ãã§èª¿ã¹ã¦ã¿ãã¨ãMetasploitã¨é¢é£æ·±ãããã¸ã§ã¯ãã«Metasmã¨ãããã®ããã£ã¦ãRubyã§ã¢ã»ã³ãã©ã»éã¢ã»ã³ãã©ã»ãªã³ã«ã»Cã³ã³ãã¤ã©ã»ãã
kosaki ããããã³ã¡ã³ããããã ãã¾ããï¼ >> å£ãã¡ããããªãã®ã ebx, esi, edi, ebpã¨ã»ã°ã¡ã³ãã¬ã¸ã¹ã¿ ã¡ãªã¿ã«ãå£ãã¡ããããªãã¬ã¸ã¹ã¿ã調ã¹ããã¡ã°ãããæ¹æ³ã¯setjmpã®ã½ã¼ã¹ãèªããã¨ã CPUã«ãããããããã¡ããããªãã¬ã¸ã¹ã¿ã¯ä¿åãã¦ããããã®ã§ãä¸æ £ããªCPUã®æã¯åèã«ãªãã¾ãã ãªãã»ã©ï¼ã¨ããããã§ï¼ãã£ãã glibc-2.4 ã®ã½ã¼ã¹ãè½ã¨ãã¦ãã¦ï¼ã¨ãããã glibc-2.4\sysdeps\i386\setjmp.S ãéãã¦ã¿ãï¼ /* Save registers. */ movl %ebx, (JB_BX*4)(%eax) movl %esi, (JB_SI*4)(%eax) movl %edi, (JB_DI*4)(%eax) /* ã¹ã¿ãã¯ãã¤ã³ã¿ä¿å */ leal JMPBUF(%esp), %ecx /* S
ãã«ã¼ãã«ã¢ã¼ãã¸ç§»è¡ããæ¹æ³ã WindowsNT/2000 int 2E(å²è¾¼ã¿ã²ã¼ã) WindowsXP/2003(x86ç) sysenter WindowsXP/2003(x64ç) syscall Windows95/98/Me call(ã³ã¼ã«ã²ã¼ã) int 2E(å²è¾¼ã¿ã²ã¼ã)ã¨call(ã³ã¼ã«ã²ã¼ã)ã¯32ãããä¸ä»£ã®æåã®CPUã§ãã386ããå©ç¨å¯è½ãªæ¹æ³ã§ãã(æ£ç¢ºã«ã¯ãããã¯ãã¢ã¼ããå°å ¥ããã286(16ãããCPU)ããã§ããã) ããã«å¯¾ããsysenterã¯ã¤ã³ãã«ãPentiumIIã§å°å ¥ããå½ä»¤ã syscallã¯AMDã(ããã)K6ã§å°å ¥ããå½ä»¤ã§ãã ãªãsyscallã¯EM64Tã§ãå©ç¨å¯è½ã§ãã é度æ¯è¼ ãããã®æ¹æ³ã§é度ã«ã©ã®ç¨åº¦ã®å·®ãããã®ãããã¹ããã¦ã¿ã¾ãã 以ä¸ã®ããã°ã©ã ã使ãã¾ãã ãsyscall.cã // ã«ã¼ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}