在(zài )找(zhǎo )到IAT之(zhī )后(hòu ),我(wǒ )们只需在其中遍(biàn )历,找到(dào )我(wǒ )们需要的API地址,然后用我们自己的函数地址去覆(fù )盖(gài )它,下面(miàn )给出(chū )一(yī )段(duàn )对应(yīng )的源(yuán )码(mǎ ) procedure RedirectApiCall var ImportDescPIMAGE_IMPORT_DESCRIPTOR FirstThunkPIMAGE_THUNK_DATA32 szDWORD
Copyright © 2008-2018