iczelion tut29[4]

[入库:2005年8月19日] [更新:2007年3月24日]

本文简介:选择自 jimgreen 的 blog

.......

it still calls getthreadcontext to obtain the current value of eip but instead of overwriting the "jmp $" instruction, it increments the value of regeip by 2 to "skip over" the instruction. the result is that when the debuggee regains control , it resumes execution at the next instruction after "jmp $".

本文关键:iczelion asm
  相关方案
Google
 

本站最佳浏览方式为 分辨率 1024x768 IE 6.0(或更高版本的 IE浏览器)

go top