¡¶Python³ÌÐòÉè¼Æ¡·Ï°ÌâÓë´ð°¸ ÏÂÔر¾ÎÄ

ÄÚÈÝ·¢²¼¸üÐÂʱ¼ä : 2025/4/4 7:59:12ÐÇÆÚÒ» ÏÂÃæÊÇÎÄÕµÄÈ«²¿ÄÚÈÝÇëÈÏÕæÔĶÁ¡£

µÚ16Õ ÄæÏò¹¤³ÌÓëÈí¼þ·ÖÎö

16.1 ÏÂÔØPEÎļþ¹æ·¶8.3°æ±¾£¬²¢³¢ÊÔÁ˽âPEÎļþ»ù±¾½á¹¹¡£ ´ð£ºÂÔ¡£

16.2 ÏÂÔز¢°²×°IDA ProÓëImmunity Debugger£¬²¢¼òµ¥Á˽âPEÎļþ·´»ã±àºÍµ÷ÊÔ²½Öè¡£

´ð£ºÂÔ¡£

16.3 °²×°²¢ÅäÖÃIDAPython²å¼þ£¬È»ºóÔËÐб¾ÕÂ16.2.1С½ÚµÄPython´úÂë¡£ ´ð£ºÂÔ¡£

16.4 ÔÚImmunity Debuggerµ÷ÊÔÆ÷ÖÐÔËÐб¾ÕÂ16.2.2С½ÚÖеĴúÂë¡£ ´ð£ºÂÔ¡£

16.5 ÐðÊöÈí¼þµ÷ÊԶϵãµÄ¸ÅÄî¡¢×÷Óü°Æä·ÖÀà¡£ ´ð£º

¶ÏµãÊÇ×î³£ÓõÄÈí¼þµ÷ÊÔ¼¼ÊõÖ®Ò»£¬Æä»ù±¾Ë¼ÏëÊÇÔÚijһ¸öλÖÃÉèÖÃÒ»¸ö¡°ÏÝÚ塱£¬µ±CPUÖ´Ðе½Õâ¸öλÖõÄʱºòÍ£Ö¹±»µ÷ÊԵijÌÐò²¢Öжϵ½µ÷ÊÔÆ÷ÖУ¬Èõ÷ÊÔÕß½øÐзÖÎöºÍµ÷ÊÔ£¬µ÷ÊÔÕß·ÖÎö½áÊøºó£¬¿ÉÒÔÈñ»µ÷ÊÔ³ÌÐò»Ö¸´Ö´ÐС£Í¨¹ýÉèÖöϵã¿ÉÒÔÔÝÍ£³ÌÐòÖ´ÐУ¬²¢¿ÉÒÔ¹Û²ìºÍ¼Ç¼ָÁîÐÅÏ¢¡¢±äÁ¿Öµ¡¢¶ÑÕ»²ÎÊýºÍÄÚ´æÊý¾Ý£¬»¹¿ÉÒÔÉîÈëÁ˽âºÍ°ÑÎÕ³ÌÐòÖ´ÐеÄÄÚ²¿Ô­ÀíºÍÏêϸ¹ý³Ì£¬¶Ïµã¶ÔÓÚÈí¼þµ÷ÊÔ¾ßÓÐÖØÒªµÄÒâÒåºÍ×÷Óá£

¶Ïµã¿ÉÒÔ·ÖΪÈí¼þ¶Ïµã¡¢Ó²¼þ¶ÏµãºÍÄÚ´æ¶ÏµãÈý´óÀà¡£ 1£©Èí¼þ¶Ïµã

Èí¼þ¶ÏµãÊÇÒ»¸öµ¥×Ö½ÚÖ¸ÁINT 3£¬×Ö½ÚÂëΪ0xCC£©£¬¿ÉÒÔÔÚ³ÌÐòÖÐÉèÖöà¸öÈí¼þ¶Ïµã£¬Ê¹µÃ³ÌÐòÖ´Ðе½¸Ã´¦Ê±Äܹ»ÔÝÍ£Ö´ÐУ¬²¢½«¿ØÖÆȨתÒƸøµ÷ÊÔÆ÷µÄ¶Ïµã´¦Àíº¯Êý¡£

µ±µ÷ÊÔÆ÷±»¸æÖªÔÚÄ¿±êµØÖ·ÉèÖÃÒ»¸ö¶Ïµã£¬ËüÊ×ÏȶÁÈ¡Ä¿±êµØÖ·µÄµÚÒ»¸ö×ֽڵIJÙ×÷Â룬Ȼºó±£´æÆðÀ´£¬Í¬Ê±°ÑµØÖ·´æ´¢ÔÚÄÚ²¿µÄÖжÏÁбíÖС£½Ó×Å£¬µ÷ÊÔÆ÷°ÑÒ»¸ö×Ö½Ú²Ù×÷Âë ¡°0xCC¡± дÈë¸Õ²ÅµÄµØÖ·¡£µ± CPU Ö´Ðе½¡°0xCC¡±²Ù×÷ÂëµÄʱºò¾Í»á´¥·¢Ò»¸ö ¡°INT 3¡±ÖжÏʼþ£¬´Ëʱµ÷ÊÔÆ÷¾ÍÄܲ¶×½µ½Õâ¸öʼþ¡£µ÷ÊÔÆ÷¼ÌÐøÅжÏÕâ¸ö·¢ÉúÖжÏʼþµÄµØÖ·(ͨ¹ýÖ¸ÁîÖ¸Õë¼Ä´æÆ÷EIP)ÊDz»ÊÇ×Ô¼ºÏÈÇ°ÉèÖöϵãµÄµØÖ·¡£Èç¹ûÔÚµ÷ÊÔÆ÷ÄÚ²¿µÄ¶ÏµãÁбíÖÐÕÒµ½ÁËÕâ¸öµØÖ·£¬¾Í½«ÉèÖöϵãÇ°´æ´¢ÆðÀ´µÄ²Ù×÷Âëд»Øµ½Ä¿±êµØÖ·£¬ÕâÑù½ø³Ì±»µ÷ÊÔÆ÷»Ö¸´ºó¾ÍÄÜÕý³£µÄÖ´ÐС£

2£©Ó²¼þ¶Ïµã

Ó²¼þ¶Ïµãͨ¹ýµ÷ÊԼĴæÆ÷ʵÏÖ£¬ÉèÖÃÔÚCPU¼¶±ðÉÏ£¬µ±ÐèÒªµ÷ÊÔij¸öÖ¸¶¨ÇøÓò¶øÓÖÎÞ·¨Ð޸ĸÃÇøÓòʱ£¬Ó²¼þ¶Ïµã·Ç³£ÓÐÓá£

Ò»¸öCPUÒ»°ã»áÓÐ8 ¸öµ÷ÊԼĴæÆ÷£¨DR0 ¼Ä´æÆ÷µ½DR7¼Ä´æÆ÷£©£¬ÓÃÓÚ¹ÜÀíÓ²¼þ¶Ïµã¡£ÆäÖе÷ÊԼĴæÆ÷DR0µ½µ÷ÊԼĴæÆ÷DR3´æ´¢Ó²¼þ¶ÏµãµØÖ·£¬Í¬Ò»Ê±¼äÄÚ×î¶àÖ»ÄÜÉèÖÃ4¸öÓ²¼þ¶Ïµã£»DR4ºÍDR5±£Áô£¬DR6ÊÇ״̬¼Ä´æÆ÷£¬ËµÃ÷±»¶Ïµã´¥·¢µÄµ÷ÊÔʼþµÄÀàÐÍ£»DR7±¾ÖÊÉÏÊÇÒ»¸öÓ²¼þ¶ÏµãµÄ¿ª¹Ø¼Ä´æÆ÷£¬Í¬Ê±Ò²´æ´¢Á˶ϵãµÄ²»Í¬ÀàÐÍ¡£Í¨¹ýÔÚDR7¼Ä´æÆ÷ÀïÉèÖò»Í¬±êÖ¾£¬Äܹ»´´½¨ÒÔϼ¸Öֶϵ㣺µ±Ìض¨µÄµØÖ·ÉÏÓÐÖ¸ÁîÖ´ÐеÄʱºòÖжϡ¢µ±Ìض¨µÄµØÖ·ÉÏÓÐÊý¾ÝдÈëµÄʱºò¡¢µ±Ìض¨µÄµØÖ·ÉÏÓÐÊý¾Ý¶Á»òÕß䵫²»Ö´ÐеÄʱºò¡£

Ó²¼þ¶ÏµãʹÓá°INT 1¡±ÊµÏÖ£¬¸ÃÖжϸºÔðÓ²¼þÖжϺͲ½½øʼþ¡£²½½øÊÇÖ¸¸ù¾ÝÔ¤¶¨µÄÁ÷³ÌÒ»ÌõÒ»ÌõµØÖ´ÐÐÖ¸ÁÿִÐÐÍêÒ»ÌõÖ¸ÁîºóÔÝÍ£ÏÂÀ´£¬´Ó¶ø¿ÉÒÔ¾«È·µØ¹Û²ì¹Ø¼ü´úÂë²¢¼àÊӼĴæÆ÷ºÍÄÚ´æÊý¾ÝµÄ±ä»¯¡£ÔÚCPUÿ´ÎÖ´ÐдúÂë֮ǰ£¬¶¼»áÏÈÈ·Èϵ±Ç°½«ÒªÖ´ÐдúÂëµÄµØÖ·ÊÇ·ñÊÇÓ²¼þ¶ÏµãµÄµØÖ·£¬Í¬Ê±Ò²ÒªÈ·ÈÏÊÇ·ñÓдúÂëÒª·ÃÎʱ»ÉèÖÃÁËÓ²¼þ¶ÏµãµÄÄÚ´æÇøÓò¡£Èç¹ûÈκδ¢´æÔÚDR0-DR3ÖеĵØÖ·ËùÖ¸ÏòµÄÇøÓò±»·ÃÎÊÁË£¬¾Í»á´¥·¢ ¡°INT 1¡±Öжϣ¬Í¬Ê±ÔÝÍ£CPU£»Èç¹û²»ÊÇÖжϵØÖ·ÔòCPUÖ´ÐиÃÐдúÂ룬µ½ÏÂÒ»ÐдúÂëʱ£¬CPU¼ÌÐøÖظ´ÉÏÃæµÄ¹ý³Ì¡£

3£©ÄÚ´æ¶Ïµã

ÄÚ´æ¶ÏµãÊÇͨ¹ýÐÞ¸ÄÄÚ´æÖÐÖ¸¶¨¿é»òÒ³µÄ·ÃÎÊȨÏÞÀ´ÊµÏֵġ£Í¨¹ý½«Ö¸¶¨ÄÚ´æ¿é»òÒ³µÄ·ÃÎÊȨÏÞÊôÐÔÉèÖÃΪÊܱ£»¤µÄ£¬ÔòÈκβ»·ûºÏ·ÃÎÊȨÏÞÔ¼ÊøµÄ²Ù×÷¶¼½«Ê§°Ü£¬²¢Å׳öÒì³££¬µ¼ÖÂCPUÔÝÍ£Ö´ÐУ¬Ê¹µÃµ÷ÊÔÆ÷¿ÉÒԲ鿴µ±Ç°Ö´ÐÐ״̬¡£

Ò»°ãÀ´Ëµ£¬Ã¿¸öÄÚ´æ¿é»òÒ³µÄ·ÃÎÊȨÏÞ¶¼ÓÉÈýÖÖ²»Í¬µÄ·ÃÎÊȨÏÞ×é³É£ºÊÇ·ñ¿ÉÖ´ÐС¢ÊÇ·ñ¿É¶Á¡¢ÊÇ·ñ¿Éд¡£Ã¿¸ö²Ù×÷ϵͳ¶¼ÌṩÁËÓÃÀ´²éѯºÍÐÞ¸ÄÄÚ´æÒ³·ÃÎÊȨÏ޵ĺ¯Êý£¬ÔÚWindows²Ù×÷ϵͳÖпÉÒÔʹÓÃVirtualProtect()º¯ÊýÀ´ÐÞ¸ÄÖ÷µ÷½ø³ÌÐéÄâµØÖ·¿Õ¼äÖÐÒÑÌá½»Ò³ÃæµÄ±£»¤ÊôÐÔ£¬Ê¹ÓÃVirtualProtectEx()º¯Êý¿ÉÒÔÐÞ¸ÄÆäËû½ø³ÌÐéÄâµØÖ·¿Õ¼äÒ³ÃæµÄ±£»¤ÊôÐÔ¡£

16.6 ÔËÐб¾ÕÂ16.4½ÚÖеĴúÂë²¢²é¿´ÔËÐнá¹û¡£ ´ð£ºÂÔ¡£

µÚ17Õ ¿Æѧ¼ÆËãÓë¿ÉÊÓ»¯

17.1 ÔËÐб¾ÕÂËùÓдúÂë²¢²é¿´ÔËÐнá¹û¡£ ´ð£ºÂÔ¡£

17.2 ʹÓÃPythonÄÚÖú¯Êýdir()²é¿´scipyÄ£¿éÖеĶÔÏóÓë·½·¨£¬²¢Ê¹ÓÃPythonÄÚÖú¯Êýhelp()²é¿´ÆäʹÓÃ˵Ã÷¡£ ´ð£ºÂÔ¡£