Windows 逆向-模拟 CE 搜索功能

Oyst3r 于 2024-01-13 发布

这篇文章就直接上代码了,就是给大家展示一下海哥上课说的搜索数据的功能,现在这个搜索只是建了一个数组去模拟数据的存储,真实的搜索数据会在后面学了 PE 有个具体的项目

废话不多说,上代码,其实我觉得这个代码没多难,但就是海哥说的那样,指针很灵活,谁说 int 的指针只能指向 int 型的数据,理解了这点那么这个代码就能很快写出来,理解不了就可能要想半天了

char data[100] = {
	0x00,0x01,0x02,0x03,0x04,0x05,0x06,0x07,0x07,0x09,
	0x00,0x20,0x10,0x03,0x03,0x0C,0x00,0x00,0x44,0x00,
	0x00,0x33,0x00,0x47,0x0C,0x0E,0x00,0x0D,0x00,0x11,
	0x00,0x00,0x00,0x02,0x64,0x00,0x00,0x00,0xAA,0x00,
	0x00,0x00,0x64,0x10,0x00,0x00,0x00,0x00,0x00,0x00,
	0x00,0x00,0x02,0x00,0x74,0x0F,0x41,0x00,0x00,0x00,
	0x01,0x00,0x00,0x00,0x05,0x00,0x00,0x00,0x0A,0x00,
	0x00,0x02,0x74,0x0F,0x41,0x00,0x06,0x08,0x00,0x00,
	0x00,0x00,0x00,0x64,0x00,0x0F,0x00,0x05,0x0D,0x00,
	0x00,0x00,0x23,0x00,0x00,0x64,0x00,0x00,0x64,0x00
};

void Search_int()
{
	int i = 0;
	for(i ;i < 97;i++){

		int* p = (int*)&data[i];
		if(*p == 0x64 ){

			printf("%x\n",p);
		}
	}
}

哈哈哈哈哈水一篇,海哥的课好好听哈