MSVCRT:ROP - CN 修改ROP檢測標誌



 function getddd()
	{
	var kkkkk = unescape("\u0433\u77bf");
	kkkkk +=unescape("\u5ed5\u77be"); //xchg eax,esp retn
	
	kkkkk += unescape("\uf519\u77be")////pop ecx,retn
	kkkkk += unescape("\u9ef8\u1009")////10099EF8 check flag 1
	kkkkk += unescape("\uc047\u77be")//77BEC047 //MOV DWORD PTR DS:[ECX],EAX  MOV EAX,ESI  POP EDI  POP ESI POP EBP RETN


	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	
	kkkkk += unescape("\uf519\u77be")////pop ecx,retn
	kkkkk += unescape("\u9ed0\u1009")////10099Ed0 check flag 2
	kkkkk += unescape("\u1d16\u77bf")//pop eax,retn
	kkkkk += unescape("\u1d16\u77be")//fill
	kkkkk += unescape("\uc047\u77be")//77BEC047 //MOV DWORD PTR DS:[ECX],EAX  MOV EAX,ESI  POP EDI  POP ESI POP EBP RETN

	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\ubdf4\u77be")//pop ebp retn
	kkkkk += unescape("\ubdf4\u77be")//pop ebp retn
	kkkkk += unescape("\u3436\u77c2")//pop ebx retn
	kkkkk += unescape("\u9f92\u77c0")//retn
	kkkkk += unescape("\ucbf9\u77c1")//pop edx retn
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\ub1ad\u77c0")
	kkkkk += unescape("\ubdf4\u77be")
	kkkkk += unescape("\u7ae8\u77c1")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u80c1\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u67f0\u77c2")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\ubdf4\u77be")
	kkkkk += unescape("\ubdf4\u77be")
	kkkkk += unescape("\u3436\u77c2")
	kkkkk += unescape("\u406e\u883f")
	kkkkk += unescape("\u771c\u77c2")
	kkkkk += unescape("\u9f07\u77c2")
	kkkkk += unescape("\u5f07\u77c0")
	kkkkk += unescape("\u5f07\u77c0")
	kkkkk += unescape("\uded4\u77c1")
	kkkkk += unescape("\ucf92\u77c0")
	kkkkk += unescape("\u0c77\u77c2")
	kkkkk += unescape("\ub1ad\u77c0")
	kkkkk += unescape("\u05ac\u77c3")//oldprotect
	kkkkk += unescape("\u7ae8\u77c1")
	kkkkk += unescape("\u9f92\u77c0")
	kkkkk += unescape("\u80c1\u77c0")
	kkkkk += unescape("\uaacc\u77bf")
	kkkkk += unescape("\uded4\u77c1")
	kkkkk += unescape("\u1131\u77be")
	kkkkk += unescape("\u67f0\u77c2")
	kkkkk += unescape("\u1025\u77c2");
			
	kkkkk += unescape("\u9090\u9090");	
	
	kkkkk += unescape("\u9090\u9090");	
	return kkkkk;
}


發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章