relost's blog
  • 首页
  • 归档
  • 分类
  • 标签
  • 关于
  • 友链

第五届“鹏城杯”初赛 Reverse-MDriver wp

驱动分析驱动被vmp保护,因此首先需要dump驱动以完成脱壳,对KeRevertToUserAffinityThread下断点后dump驱动程序并分别修复SectionAlignment,SizeOfHeaders,PointerToRawData以便其能被ida识别。 入口点逻辑脱完壳后首先定位 security_init_cookie找真正的驱动入口点 这里直接用特征码 48 8B 05 ??
2025-12-22
Ctf-writeups
#CTF #Reverse

test

2024-09-29
Ctf writeups
#原创

Hello World

Welcome to Hexo! This is your very first post. Check documentation for more info. If you get any problems when using Hexo, you can find the answer in troubleshooting or you can ask me on GitHub. Quick
2024-09-29

搜索

Hexo Fluid