-
Notifications
You must be signed in to change notification settings - Fork 0
/
index.html
205 lines (174 loc) · 17.7 KB
/
index.html
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
<!DOCTYPE html><html lang="zh-CN" data-theme="light"><head><meta charset="UTF-8"><meta http-equiv="X-UA-Compatible" content="IE=edge"><meta name="viewport" content="width=device-width, initial-scale=1.0,viewport-fit=cover"><title>HD-Blog - Coding</title><meta name="author" content="HD"><meta name="copyright" content="HD"><meta name="format-detection" content="telephone=no"><meta name="theme-color" content="#ffffff"><meta name="description" content="这是我的网站,用来记录学习和有趣的事">
<meta property="og:type" content="website">
<meta property="og:title" content="HD-Blog">
<meta property="og:url" content="https://huadongblog.top/index.html">
<meta property="og:site_name" content="HD-Blog">
<meta property="og:description" content="这是我的网站,用来记录学习和有趣的事">
<meta property="og:locale" content="zh_CN">
<meta property="og:image" content="https://hdblog-image.oss-cn-nanjing.aliyuncs.com/image/3B8E772D51765C282A3959BF9EFBED3D.jpg">
<meta property="article:author" content="HD">
<meta name="twitter:card" content="summary">
<meta name="twitter:image" content="https://hdblog-image.oss-cn-nanjing.aliyuncs.com/image/3B8E772D51765C282A3959BF9EFBED3D.jpg"><link rel="shortcut icon" href="/img/favicon.png"><link rel="canonical" href="https://huadongblog.top/index.html"><link rel="preconnect" href="//cdn.jsdelivr.net"/><link rel="preconnect" href="//busuanzi.ibruce.info"/><link rel="stylesheet" href="/css/index.css"><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/@fortawesome/fontawesome-free/css/all.min.css" media="print" onload="this.media='all'"><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/@fancyapps/ui/dist/fancybox/fancybox.min.css" media="print" onload="this.media='all'"><script>const GLOBAL_CONFIG = {
root: '/',
algolia: undefined,
localSearch: undefined,
translate: undefined,
noticeOutdate: undefined,
highlight: {"plugin":"highlighjs","highlightCopy":true,"highlightLang":true,"highlightHeightLimit":false},
copy: {
success: '复制成功',
error: '复制错误',
noSupport: '浏览器不支持'
},
relativeDate: {
homepage: false,
post: false
},
runtime: '',
dateSuffix: {
just: '刚刚',
min: '分钟前',
hour: '小时前',
day: '天前',
month: '个月前'
},
copyright: undefined,
lightbox: 'fancybox',
Snackbar: undefined,
source: {
justifiedGallery: {
js: 'https://cdn.jsdelivr.net/npm/flickr-justified-gallery/dist/fjGallery.min.js',
css: 'https://cdn.jsdelivr.net/npm/flickr-justified-gallery/dist/fjGallery.min.css'
}
},
isPhotoFigcaption: false,
islazyload: false,
isAnchor: false,
percent: {
toc: true,
rightside: false,
},
autoDarkmode: false
}</script><script id="config-diff">var GLOBAL_CONFIG_SITE = {
title: 'HD-Blog',
isPost: false,
isHome: true,
isHighlightShrink: false,
isToc: false,
postUpdate: '2024-09-17 21:59:31'
}</script><noscript><style type="text/css">
#nav {
opacity: 1
}
.justified-gallery img {
opacity: 1
}
#recent-posts time,
#post-meta time {
display: inline !important
}
</style></noscript><script>(win=>{
win.saveToLocal = {
set: function setWithExpiry(key, value, ttl) {
if (ttl === 0) return
const now = new Date()
const expiryDay = ttl * 86400000
const item = {
value: value,
expiry: now.getTime() + expiryDay,
}
localStorage.setItem(key, JSON.stringify(item))
},
get: function getWithExpiry(key) {
const itemStr = localStorage.getItem(key)
if (!itemStr) {
return undefined
}
const item = JSON.parse(itemStr)
const now = new Date()
if (now.getTime() > item.expiry) {
localStorage.removeItem(key)
return undefined
}
return item.value
}
}
win.getScript = url => new Promise((resolve, reject) => {
const script = document.createElement('script')
script.src = url
script.async = true
script.onerror = reject
script.onload = script.onreadystatechange = function() {
const loadState = this.readyState
if (loadState && loadState !== 'loaded' && loadState !== 'complete') return
script.onload = script.onreadystatechange = null
resolve()
}
document.head.appendChild(script)
})
win.getCSS = (url,id = false) => new Promise((resolve, reject) => {
const link = document.createElement('link')
link.rel = 'stylesheet'
link.href = url
if (id) link.id = id
link.onerror = reject
link.onload = link.onreadystatechange = function() {
const loadState = this.readyState
if (loadState && loadState !== 'loaded' && loadState !== 'complete') return
link.onload = link.onreadystatechange = null
resolve()
}
document.head.appendChild(link)
})
win.activateDarkMode = function () {
document.documentElement.setAttribute('data-theme', 'dark')
if (document.querySelector('meta[name="theme-color"]') !== null) {
document.querySelector('meta[name="theme-color"]').setAttribute('content', '#0d0d0d')
}
}
win.activateLightMode = function () {
document.documentElement.setAttribute('data-theme', 'light')
if (document.querySelector('meta[name="theme-color"]') !== null) {
document.querySelector('meta[name="theme-color"]').setAttribute('content', '#ffffff')
}
}
const t = saveToLocal.get('theme')
if (t === 'dark') activateDarkMode()
else if (t === 'light') activateLightMode()
const asideStatus = saveToLocal.get('aside-status')
if (asideStatus !== undefined) {
if (asideStatus === 'hide') {
document.documentElement.classList.add('hide-aside')
} else {
document.documentElement.classList.remove('hide-aside')
}
}
const detectApple = () => {
if(/iPad|iPhone|iPod|Macintosh/.test(navigator.userAgent)){
document.documentElement.classList.add('apple')
}
}
detectApple()
})(window)</script><meta name="generator" content="Hexo 6.3.0"></head><body><div id="sidebar"><div id="menu-mask"></div><div id="sidebar-menus"><div class="avatar-img is-center"><img src="https://hdblog-image.oss-cn-nanjing.aliyuncs.com/image/3B8E772D51765C282A3959BF9EFBED3D.jpg" onerror="onerror=null;src='/img/friend_404.gif'" alt="avatar"/></div><div class="sidebar-site-data site-data is-center"><a href="/archives/"><div class="headline">文章</div><div class="length-num">2</div></a><a href="/tags/"><div class="headline">标签</div><div class="length-num">2</div></a><a href="/categories/"><div class="headline">分类</div><div class="length-num">2</div></a></div><hr class="custom-hr"/><div class="menus_items"><div class="menus_item"><a class="site-page" href="/"><i class="fa-fw fas fa-home"></i><span> Home</span></a></div><div class="menus_item"><a class="site-page" href="/archives/"><i class="fa-fw fas fa-archive"></i><span> Archives</span></a></div><div class="menus_item"><a class="site-page" href="/tags/"><i class="fa-fw fas fa-tags"></i><span> Tags</span></a></div></div></div></div><div class="page" id="body-wrap"><header class="full_page" id="page-header" style="background-image: url('https://hdblog-image.oss-cn-nanjing.aliyuncs.com/image/wallpaper.jpeg')"><nav id="nav"><span id="blog-info"><a href="/" title="HD-Blog"><span class="site-name">HD-Blog</span></a></span><div id="menus"><div class="menus_items"><div class="menus_item"><a class="site-page" href="/"><i class="fa-fw fas fa-home"></i><span> Home</span></a></div><div class="menus_item"><a class="site-page" href="/archives/"><i class="fa-fw fas fa-archive"></i><span> Archives</span></a></div><div class="menus_item"><a class="site-page" href="/tags/"><i class="fa-fw fas fa-tags"></i><span> Tags</span></a></div></div><div id="toggle-menu"><a class="site-page" href="javascript:void(0);"><i class="fas fa-bars fa-fw"></i></a></div></div></nav><div id="site-info"><h1 id="site-title">HD-Blog</h1><div id="site_social_icons"><a class="social-icon" href="https://huadong1120.github.io" target="_blank" title="Github"><i class="fab fa-github" style="color: #24292e;"></i></a><a class="social-icon" href="mailto:[email protected]" target="_blank" title="Email"><i class="fas fa-envelope" style="color: #4a7dbe;"></i></a></div></div><div id="scroll-down"><i class="fas fa-angle-down scroll-down-effects"></i></div></header><main class="layout" id="content-inner"><div class="recent-posts" id="recent-posts"><div class="recent-post-item"><div class="post_cover right"><a href="/2023/08/23/%E5%88%9D%E5%A7%8B%E9%80%86%E5%90%91%E6%8A%80%E6%9C%AF-%E7%BA%BF%E7%A8%8B%E6%B3%A8%E5%85%A5/" title="初识逆向技术--线程注入"><img class="post-bg" src="https://hdblog-image.oss-cn-nanjing.aliyuncs.com/image/2W.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="初识逆向技术--线程注入"></a></div><div class="recent-post-info"><a class="article-title" href="/2023/08/23/%E5%88%9D%E5%A7%8B%E9%80%86%E5%90%91%E6%8A%80%E6%9C%AF-%E7%BA%BF%E7%A8%8B%E6%B3%A8%E5%85%A5/" title="初识逆向技术--线程注入">初识逆向技术--线程注入</a><div class="article-meta-wrap"><span class="post-meta-date"><i class="far fa-calendar-alt"></i><span class="article-meta-label">发表于</span><time datetime="2023-08-23T11:46:39.000Z" title="发表于 2023-08-23 19:46:39">2023-08-23</time></span><span class="article-meta"><span class="article-meta-separator">|</span><i class="fas fa-inbox"></i><a class="article-meta__categories" href="/categories/%E9%80%86%E5%90%91/">逆向</a></span></div><div class="content">逆向之远程线程注入
Method
CreateRemoteThread()
Windows中的函数,用于在其他进程中创建一个新的线程,让该线程在其他进程中运行。
NtCreateThreadEx()
使用系统调用在目标进程直接创建线程,提供更高级的线程创建功能
QueueUserAPC()
向目标进程内核对象队列中加入需要运行的用户空间异步过程调用(APC),被线程从APC队列中取出并执行
SetWindowsHookEx()
Windows中的函数,运行应用程序注入到其它应用程序的消息循环中,监控或处理这些应用程序收到的消息
RtlCreateUserThread()
来自NTDLL的函数,主要用户底层或者驱动中,支持更多安全参数,可以运行在更高版本和CreateRemoteThread类似
SetThreadContext()
Windows中的函数,允许设置一个线程的cpu上下文
Reflective DLL
反射式注入,不需要建立远程线程来加载dll,直接复制dll到目标进程空闲内存区域中。
本文主要讨论第一个函数,简单入门,让我们先看看 ...</div></div></div><div class="recent-post-item"><div class="post_cover right"><a href="/2023/08/20/C-%E4%B8%AD%E7%9A%84Asio%E5%BA%93/" title="C++著名库Boost.asio"><img class="post-bg" src="https://hdblog-image.oss-cn-nanjing.aliyuncs.com/image/asio.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="C++著名库Boost.asio"></a></div><div class="recent-post-info"><a class="article-title" href="/2023/08/20/C-%E4%B8%AD%E7%9A%84Asio%E5%BA%93/" title="C++著名库Boost.asio">C++著名库Boost.asio</a><div class="article-meta-wrap"><span class="post-meta-date"><i class="far fa-calendar-alt"></i><span class="article-meta-label">发表于</span><time datetime="2023-08-20T10:22:07.000Z" title="发表于 2023-08-20 18:22:07">2023-08-20</time></span><span class="article-meta"><span class="article-meta-separator">|</span><i class="fas fa-inbox"></i><a class="article-meta__categories" href="/categories/C/">C++</a></span></div><div class="content"></div></div></div><nav id="pagination"><div class="pagination"><span class="page-number current">1</span></div></nav></div><div class="aside-content" id="aside-content"><div class="card-widget card-info"><div class="is-center"><div class="avatar-img"><img src="https://hdblog-image.oss-cn-nanjing.aliyuncs.com/image/3B8E772D51765C282A3959BF9EFBED3D.jpg" onerror="this.onerror=null;this.src='/img/friend_404.gif'" alt="avatar"/></div><div class="author-info__name">HD</div><div class="author-info__description">这是我的网站,用来记录学习和有趣的事</div></div><div class="card-info-data site-data is-center"><a href="/archives/"><div class="headline">文章</div><div class="length-num">2</div></a><a href="/tags/"><div class="headline">标签</div><div class="length-num">2</div></a><a href="/categories/"><div class="headline">分类</div><div class="length-num">2</div></a></div><a id="card-info-btn" target="_blank" rel="noopener" href="https://huadong1120.github.io/"><i class="fab fa-github"></i><span>Follow Me</span></a><div class="card-info-social-icons is-center"><a class="social-icon" href="https://huadong1120.github.io" target="_blank" title="Github"><i class="fab fa-github" style="color: #24292e;"></i></a><a class="social-icon" href="mailto:[email protected]" target="_blank" title="Email"><i class="fas fa-envelope" style="color: #4a7dbe;"></i></a></div></div><div class="card-widget card-announcement"><div class="item-headline"><i class="fas fa-bullhorn fa-shake"></i><span>公告</span></div><div class="announcement_content">This is my Blog</div></div><div class="sticky_layout"><div class="card-widget card-recent-post"><div class="item-headline"><i class="fas fa-history"></i><span>最新文章</span></div><div class="aside-list"><div class="aside-list-item"><a class="thumbnail" href="/2023/08/23/%E5%88%9D%E5%A7%8B%E9%80%86%E5%90%91%E6%8A%80%E6%9C%AF-%E7%BA%BF%E7%A8%8B%E6%B3%A8%E5%85%A5/" title="初识逆向技术--线程注入"><img src="https://hdblog-image.oss-cn-nanjing.aliyuncs.com/image/2W.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="初识逆向技术--线程注入"/></a><div class="content"><a class="title" href="/2023/08/23/%E5%88%9D%E5%A7%8B%E9%80%86%E5%90%91%E6%8A%80%E6%9C%AF-%E7%BA%BF%E7%A8%8B%E6%B3%A8%E5%85%A5/" title="初识逆向技术--线程注入">初识逆向技术--线程注入</a><time datetime="2023-08-23T11:46:39.000Z" title="发表于 2023-08-23 19:46:39">2023-08-23</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2023/08/20/C-%E4%B8%AD%E7%9A%84Asio%E5%BA%93/" title="C++著名库Boost.asio"><img src="https://hdblog-image.oss-cn-nanjing.aliyuncs.com/image/asio.png" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="C++著名库Boost.asio"/></a><div class="content"><a class="title" href="/2023/08/20/C-%E4%B8%AD%E7%9A%84Asio%E5%BA%93/" title="C++著名库Boost.asio">C++著名库Boost.asio</a><time datetime="2023-08-20T10:22:07.000Z" title="发表于 2023-08-20 18:22:07">2023-08-20</time></div></div></div></div><div class="card-widget card-categories"><div class="item-headline">
<i class="fas fa-folder-open"></i>
<span>分类</span>
</div>
<ul class="card-category-list" id="aside-cat-list">
<li class="card-category-list-item "><a class="card-category-list-link" href="/categories/C/"><span class="card-category-list-name">C++</span><span class="card-category-list-count">1</span></a></li><li class="card-category-list-item "><a class="card-category-list-link" href="/categories/%E9%80%86%E5%90%91/"><span class="card-category-list-name">逆向</span><span class="card-category-list-count">1</span></a></li>
</ul></div><div class="card-widget card-tags"><div class="item-headline"><i class="fas fa-tags"></i><span>标签</span></div><div class="card-tag-cloud"><a href="/tags/Asio/" style="font-size: 1.15em; color: rgb(170, 124, 172)">Asio</a><a href="/tags/%E9%80%86%E5%90%91/" style="font-size: 1.15em; color: rgb(144, 33, 81)">逆向</a></div></div><div class="card-widget card-archives"><div class="item-headline"><i class="fas fa-archive"></i><span>归档</span></div><ul class="card-archive-list"><li class="card-archive-list-item"><a class="card-archive-list-link" href="/archives/2023/08/"><span class="card-archive-list-date">八月 2023</span><span class="card-archive-list-count">2</span></a></li></ul></div><div class="card-widget card-webinfo"><div class="item-headline"><i class="fas fa-chart-line"></i><span>网站资讯</span></div><div class="webinfo"><div class="webinfo-item"><div class="item-name">文章数目 :</div><div class="item-count">2</div></div><div class="webinfo-item"><div class="item-name">本站访客数 :</div><div class="item-count" id="busuanzi_value_site_uv"><i class="fa-solid fa-spinner fa-spin"></i></div></div><div class="webinfo-item"><div class="item-name">本站总访问量 :</div><div class="item-count" id="busuanzi_value_site_pv"><i class="fa-solid fa-spinner fa-spin"></i></div></div><div class="webinfo-item"><div class="item-name">最后更新时间 :</div><div class="item-count" id="last-push-date" data-lastPushDate="2024-09-17T13:59:31.001Z"><i class="fa-solid fa-spinner fa-spin"></i></div></div></div></div></div></div></main><footer id="footer"><div id="footer-wrap"></div></footer></div><div id="rightside"><div id="rightside-config-hide"><button id="darkmode" type="button" title="浅色和深色模式转换"><i class="fas fa-adjust"></i></button><button id="hide-aside-btn" type="button" title="单栏和双栏切换"><i class="fas fa-arrows-alt-h"></i></button></div><div id="rightside-config-show"><button id="rightside_config" type="button" title="设置"><i class="fas fa-cog fa-spin"></i></button><button id="go-up" type="button" title="回到顶部"><span class="scroll-percent"></span><i class="fas fa-arrow-up"></i></button></div></div><div><script src="/js/utils.js"></script><script src="/js/main.js"></script><script src="https://cdn.jsdelivr.net/npm/@fancyapps/ui/dist/fancybox/fancybox.umd.min.js"></script><div class="js-pjax"></div><script async data-pjax src="//busuanzi.ibruce.info/busuanzi/2.3/busuanzi.pure.mini.js"></script></div></body></html>