天天看點

windbg 腳本簡單入門

.dvalloc /b 0x79990000 30
 ew 0x79990000 0xc033
 ed 0x79990002 0x00001cc2
 bp kernel32!CreateFileW "
 as /mu ${/v:filename} poi(esp+4);
 .block{
     .if ($sicmp(\"${filename}\", \"c:\\1.txt\") == 0){
         .echo \"open 1.txt\";
         r eip=0x79990000
     }
 }
 ad ${/v:filename};
 gc;
 "      

繼續閱讀