<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SoftRCE.net &#187; 乾坤挪移（RCE）</title>
	<atom:link href="http://www.softrce.net/archives/category/rce/feed" rel="self" type="application/rss+xml" />
	<link>http://www.softrce.net</link>
	<description>Software Reverse Code Engineering</description>
	<lastBuildDate>Tue, 13 Sep 2011 06:58:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>静态分析驱动的一点技巧</title>
		<link>http://www.softrce.net/archives/140</link>
		<comments>http://www.softrce.net/archives/140#comments</comments>
		<pubDate>Sat, 16 May 2009 09:12:36 +0000</pubDate>
		<dc:creator>dge</dc:creator>
				<category><![CDATA[乾坤挪移（RCE）]]></category>
		<category><![CDATA[逆向技巧]]></category>

		<guid isPermaLink="false">http://www.softrce.net/?p=140</guid>
		<description><![CDATA[习惯了OD和IDA的组合，也懒的装内核调试器了，好在需要分析驱动的时候特别少，而且只用IDA就可以玩的转。
最近在整驱动的过程中积累了点技巧，把他们记录下来，以慰同菜。]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;">author:dge</p>
<p style="text-align: left;">习惯了OD和IDA的组合，也懒的装内核调试器了，好在需要分析驱动的时候特别少，而且只用IDA就可以玩的转。</p>
<p style="text-align: left;">最近在整驱动的过程中积累了点技巧，把他们记录下来，以慰同菜。</p>
<p><span id="more-140"></span></p>
<p style="text-align: left;">Q:许多软件隐藏了驱动,如何找到它们?<br />
A:其实很简单，隐藏文件肯定是驱动干的，不让驱动的加载，再牛B的隐藏也废了，用SSM拦截驱动的加载是个不错的选择。</p>
<p style="text-align: left;">Q:如何提高驱动代码可读性?<br />
A:驱动中对IRP，DEVICE_OBJECT，DRIVER_OBJECT和IO_STACK_LOCATION的操作很多，所以把这些结构添加进来，然后把对这些结构的操作进行标识。</p>
<p style="text-align: left;">Q:如何完成驱动代码的准确定位?<br />
A:一般的驱动都是用DeviceIoControl给驱动发送IRP_MJ_DEVICE_CONTROL类型的IRP来调用驱动中的代码，在驱动中一般先对<br />
IRP_MJ_DEVICE_CONTROL进行处理，然后再细化到处理相应IOCTL的代码，这个IOCTL又是DeviceIoControl的一个参数，所以通过监视DeviceIoControl就可以完成代码的精确定位。</p>
<p style="text-align: left;">Q:如何来获取这个IOCTL?<br />
A:(1):可以通过调试器对DeviceIoControl下断，不过一般得应付很多反调试，感觉很笨拙。<br />
(2):可以写个监视DeviceIoControl的程序，然后把IOCTL作为日志实时的输出。如果我们想分析软件的某个功能，只要运行软件的某个功能,然后
</p>
<p style="text-align: left;">在日志中找到IOCTL，再在驱动代码中搜索它，就可以完成准确定位了，这个方式感觉比较好，它饶过了反调试。</p>
<p style="text-align: left;">Q:如何实现监视?<br />
A:其实就是改变DeviceIoControl的流程，inline hook就可以。</p>
<p style="text-align: left;">Q:还需要什么?<br />
A:一点兴趣，一些体力。</p>
<hr /><h2>Comments</h2><ul><li><a href="http://www.softrce.net/archives/140">2009年05月26日</a>, mj0011 writes: 真技巧啊真技巧</li><li><a href="http://www.softrce.net/archives/140">2009年06月1日</a>, lammer writes: Q:还需要什么?
A:一点兴趣，一些体力。

这个是最重要的·！赞</li></ul><hr /><small>Copyright &copy; 2008<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. If this content is not in your news reader, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint:<br /> 8e761b2ea8edc3ca311452b020051837)</small><h3  class="related_post_title">随机日志</h3><ul class="related_post"><li>2008年09月30日 -- <a href="http://www.softrce.net/archives/10" title="[国庆礼]Exploiting Windows Device Drivers译文版">[国庆礼]Exploiting Windows Device Drivers译文版</a></li><li>2008年10月9日 -- <a href="http://www.softrce.net/archives/11" title="About the SMM rootkit">About the SMM rootkit</a></li><li>2010年05月7日 -- <a href="http://www.softrce.net/archives/310" title="IoRegisterDriverReinitialization 和IoRegisterBootDriverReinitialization">IoRegisterDriverReinitialization 和IoRegisterBootDriverReinitialization</a></li><li>2010年03月1日 -- <a href="http://www.softrce.net/archives/288" title="Steve Jobs在斯坦福大学毕业典礼上的演讲">Steve Jobs在斯坦福大学毕业典礼上的演讲</a></li><li>2009年05月1日 -- <a href="http://www.softrce.net/archives/114" title="Symbian S60 3rd Reverse CrAcKiNg Tutorial">Symbian S60 3rd Reverse CrAcKiNg Tutorial</a></li><li>2008年10月22日 -- <a href="http://www.softrce.net/archives/16" title="绕过主动防御的代码注入方法一点思考">绕过主动防御的代码注入方法一点思考</a></li><li>2009年05月15日 -- <a href="http://www.softrce.net/archives/136" title="ActiveX 控件组件的Fuzz和利用">ActiveX 控件组件的Fuzz和利用</a></li><li>2008年10月15日 -- <a href="http://www.softrce.net/archives/12" title="About Handling Nmi">About Handling Nmi</a></li><li>2008年11月16日 -- <a href="http://www.softrce.net/archives/19" title="[转载]在英特尔软件网络博客上看到的">[转载]在英特尔软件网络博客上看到的</a></li><li>2009年04月26日 -- <a href="http://www.softrce.net/archives/1" title="SoftRCE再次回归上线">SoftRCE再次回归上线</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.softrce.net/archives/140/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Symbian S60 3rd Reverse CrAcKiNg Tutorial</title>
		<link>http://www.softrce.net/archives/114</link>
		<comments>http://www.softrce.net/archives/114#comments</comments>
		<pubDate>Fri, 01 May 2009 01:39:09 +0000</pubDate>
		<dc:creator>caterqiu</dc:creator>
				<category><![CDATA[乾坤挪移（RCE）]]></category>
		<category><![CDATA[Symbian]]></category>

		<guid isPermaLink="false">http://www.softrce.net/?p=114</guid>
		<description><![CDATA[得去年 Cater 曾经在某群里说过要写六个手机平台的解密教程

只是 Cater 真的好忙 好辛苦的说

Symbian 是我06年久接触了，那个时候S60 2nd 版本的手机有碰过

感觉 ARM 的汇编指令也不是很难，也过了几个软件

时隔今日，塞班 S60 三版的(OS 9.x)的系统也总结总结些个教程

满足下 某人 总是威逼 小 Cater 的野兽般的欲望吧。

大成，大成成就你一个家。]]></description>
			<content:encoded><![CDATA[<p>作者：Cater.Qiu</p>
<p>得去年 Cater 曾经在某群里说过要写六个手机平台的解密教程</p>
<p>只是 Cater 真的好忙 好辛苦的说</p>
<p>Symbian 是我06年久接触了，那个时候S60 2nd 版本的手机有碰过</p>
<p>感觉 ARM 的汇编指令也不是很难，也过了几个软件</p>
<p>时隔今日，塞班 S60 三版的(OS 9.x)的系统也总结总结些个教程</p>
<p>满足下 某人 总是威逼 小 Cater 的野兽般的欲望吧。<span id="more-114"></span></p>
<h1><span style="font-size: 42pt; line-height: 240%;" lang="EN-US"></span></h1>
<hr />
<h1><span style="font-size: 26pt; line-height: 240%;" lang="EN-US"><span style="font-family: Times New Roman;">Symbian S60 3<sup>rd</sup> </span></span></h1>
<h1><span lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></h1>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></p>
<h1><span style="font-size: 26pt; line-height: 240%;" lang="EN-US"><span style="font-family: Times New Roman;">Reverse CrAcKiNg Tutorial</span></span></h1>
<h1><span lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></h1>
<h1><span lang="EN-US"><span style="font-family: Times New Roman;">By_CaterQiu</span></span></h1>
<h1><span lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></h1>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 22pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: center;" align="center"><span style="font-size: 16pt;" lang="EN-US"><span style="font-family: Times New Roman;">Mail: Cater.Qiu[At]Gmail.Com</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: center;" align="center"><span style="font-size: 16pt;" lang="EN-US"><span style="font-family: Times New Roman;">MyBlog<strong>: </strong></span><a href="http://www.caterqiu.cn/"><span style="font-family: Times New Roman;">Http://www.caterqiu.cn</span></a></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: center;" align="center"><span style="font-size: 16pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<h1><span style="font-weight: normal; font-size: 18pt; line-height: 240%; mso-bidi-font-weight: bold;" lang="EN-US"><span style="font-family: Times New Roman;">May 1th,2009</span></span><strong><span style="font-size: 22pt; line-height: 240%; font-family: 'Times New Roman'; mso-fareast-font-family: 宋体; mso-fareast-language: ZH-CN; mso-ansi-language: EN-US; mso-font-kerning: 22.0pt; mso-bidi-language: AR-SA;" lang="EN-US"><br /></span></strong></h1>
<p> </p>
<p> </p>
<hr />
<h1><span style="font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">基础知识</span></h1>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Symbain OS</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 24pt; mso-char-indent-count: 2.0;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;" lang="SV">Symbian OS(</span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;">中文译音“塞班系统”<span lang="SV">)</span>由诺基亚、索尼爱立信、摩托罗拉、西门子等几家大型移动通讯设备商共同出资组建的一个合资公司，专门研发智能手机操作系统，现在已经被诺基亚收购。<span lang="SV"></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 24pt; mso-char-indent-count: 2.0;"><span style="font-size: 12pt; color: blue; font-family: 宋体; mso-ansi-language: SV;" lang="SV">Symbian OS</span><span style="font-size: 12pt; color: blue; font-family: 宋体; mso-ansi-language: SV;">硬件<span lang="SV">CPU</span>采用的是<span lang="SV">ARM</span>系列，使用的是<span lang="SV">ARM 32</span>位指令而非<span lang="SV">THUMB</span>。<span lang="SV"></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 14pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;">EPCO</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 24pt; mso-char-indent-count: 2.0;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;" lang="SV">Symbian</span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;">操作系统的前身是<span lang="SV">EPOC</span>，<span lang="SV">“EPOC</span>”这个词起源于世界将会进入“<span lang="SV">a new epoch of personal convenience</span>”。<span lang="SV">EPOC</span>是一个开放的操作系统，一开始的时候<span lang="SV">EPOC</span>就加上了无线通信和一个外加应用程序的体系，因此在无线通信方面与其他操作系统相比具备先天的优势。<span lang="SV"></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 24pt; mso-char-indent-count: 2.0;"><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 14pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;">Symbian S60</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 23.5pt; mso-char-indent-count: 1.96;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;" lang="SV">Nokia S60 </span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;">系列手机是市面上智能机里流行最广的手机。<span lang="SV"></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 23.5pt; mso-char-indent-count: 1.96;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;" lang="SV">Symbian Series 60 </span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;">是<span lang="SV">Symbian S60 </span>的全称<span lang="SV"></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 23.5pt; mso-char-indent-count: 1.96;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;" lang="SV">S60</span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;">可以细化分为第一版、第二版、第三版、第四版、第五版<span lang="SV"></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 23.5pt; mso-char-indent-count: 1.96;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;">第一版和第二版差别不大，笼统概括为<span lang="SV">S60 2nd </span>、<span lang="SV">S60</span>二版。（包含<span lang="SV">OS6</span>、<span lang="SV">OS7</span>、<span lang="SV">OS8 </span>三个系列）<span lang="SV"></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 23.5pt; mso-char-indent-count: 1.96;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;">第三版第四版第五版核心是<span lang="SV"> OS9</span>系列的，笼统概括为<span lang="SV">S60 3rd </span>、<span lang="SV">S60</span>三版<span lang="SV"></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 23.5pt; mso-char-indent-count: 1.96;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;" lang="SV"> </span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 14pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;">2nd And 3rd</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 23.5pt; mso-char-indent-count: 1.96;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;" lang="SV">S60 3rd </span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;">和<span lang="SV"> S60 2nd</span>从操作系统上看有很大的区别：<span lang="SV"></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 41.5pt; text-indent: -18pt; mso-list: l0 level1 lfo1; tab-stops: list 41.5pt;"><span style="font-size: 12pt; color: blue; font-family: 宋体; mso-ansi-language: SV; mso-bidi-font-family: 宋体;" lang="SV"><span style="mso-list: Ignore;">1、</span></span><span style="font-size: 12pt; color: blue; font-family: 宋体; mso-ansi-language: SV;">三版引入了权限签名这一安全机制，可通过对程序安装包进行签名授权。<span lang="SV"></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 41.5pt; text-indent: -18pt; mso-list: l0 level1 lfo1; tab-stops: list 41.5pt;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV; mso-bidi-font-family: 宋体;" lang="SV"><span style="mso-list: Ignore;">2、</span></span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;" lang="SV">S60 2nd</span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;">是<span lang="SV">EPOC6</span>，<span lang="SV">S60 3rd </span>是<span lang="SV">EPOC9</span>，这也意味着其<span lang="SV">ELF</span></span><span style="font-size: small;"><span lang="SV"><span style="font-family: Times New Roman;"> </span></span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;" lang="SV">(Executable and Linking Format)</span></span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;">是可执行连接格式也发生了改变<span lang="SV"></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 23.5pt;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;">在<span lang="SV"> S60 2nd </span>版本中，可执行体是<span lang="SV"> EPOC6 </span>格式的<span lang="SV"> .APP </span>文件和<span lang="SV"> .DLL </span>文件<span lang="SV"></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 23.5pt;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;">在<span lang="SV"> S60 3rd </span>版本中，可执行体是<span lang="SV"> EPOC9 </span>格式的<span lang="SV"> .EXE </span>文件和<span lang="SV"> .DLL </span>文件<span lang="SV"></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 23.5pt;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;" lang="SV">3</span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;">、三版和二版</span><span style="font-size: 12pt; font-family: 宋体;">的程序安装包，格式是不一样的</span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;">，</span><span style="font-size: 12pt; font-family: 宋体;">尽管都是</span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;" lang="SV">.sis </span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;">结尾的文件 <span lang="SV"></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 23.5pt;"><span style="font-size: 12pt; color: blue; font-family: 宋体; mso-ansi-language: SV;" lang="SV">EPOC9 </span><span style="font-size: 12pt; color: blue; font-family: 宋体; mso-ansi-language: SV;">格式的可执行文件是可以压缩的，三版签名后的安装包一般是<span lang="SV">.sisx</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 23.5pt;"><span style="font-size: 12pt; color: blue; font-family: 宋体; mso-ansi-language: SV;" lang="SV"> </span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 14pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;">ARM CPU</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 24pt; mso-char-indent-count: 2.0;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;" lang="SV">ARM </span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;">公司是专门从事基于<span lang="SV"> RISC</span>（<span lang="SV">reduced instruction set computer</span>，精简指令集计算机<span lang="SV">) </span>微处理芯片制造的企业。设计出的产品性能高、成本低和能耗省的特点，适用于多种领域，例如嵌入式系统、<span lang="SV">DSP</span>、和手机。<span lang="SV"></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;" lang="SV"> </span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; text-align: center;" align="center"><span style="font-size: 12pt; color: blue; font-family: 宋体; mso-ansi-language: SV;" lang="SV">ARM</span><span style="font-size: 12pt; color: blue; font-family: 宋体; mso-ansi-language: SV;">处理器本身是<span lang="SV">32</span>位设计，但也配备<span lang="SV">Thumb 16</span>位指令集</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; text-align: center;" align="center"> </p>
<hr />
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; text-align: center;" align="center"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; text-align: center;" align="center"><span style="mso-ansi-language: SV;" lang="SV"><br /></span><strong><span style="font-family: 宋体;"><span class="1Char"><span style="font-size: 22pt; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">准备工作</span></span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV;" lang="SV"></span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">IDA Pro 5.2</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">鬼斧神工逆向分析利器</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">下载地址</span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">：</span><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"><a href="http://bbs.pediy.com/showthread.php?t=55801"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-family: Times New Roman;">http://bbs.pediy.com/showthread.php?t=55801</span></span></a></span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">IDS files for EPOC6 and EPOC9</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;">Symbian EPOC</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">格式标示符文件</span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">，</span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">配合</span><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;">IDA5.2</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">使用</span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">，</span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">解压置</span><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;">IDA</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">相关目录即可</span><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">下载地址</span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">：</span><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"><a href="http://arteam.biz.hr/downloads/Symbian_EPOC6_EPOC9_Unleashed_IDS_Files_for_IDA_Pro_by_argv.rar"><span style="font-family: Times New Roman;">http://arteam.biz.hr/downloads/Symbian_EPOC6_EPOC9_Unleashed_IDS_Files_for_IDA_Pro_by_argv.rar</span></a></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 14pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;">WinHex</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">强大的磁盘编辑工具，也是非常棒的十六进制编辑器。</span><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">SisContents</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">S60 </span></span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">三版程序</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">(Sis,Sisx) </span></span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">打包、解包、签名工具。</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"><a href="http://symbiandev.cdtools.net/"><span style="font-family: Times New Roman;">http://symbiandev.cdtools.net</span></a></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-family: Times New Roman;"><strong><span style="font-size: 14pt; mso-ansi-language: SV;" lang="SV">CeleASM</span></strong><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">用于查看</span><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;">ARM OPCODE</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">宇宙杰出青年</span><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;">Yonsm(</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">郭春杨</span><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;">) </span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">之作</span><span style="font-size: 12pt; mso-ansi-language: SV;"><span style="font-family: Times New Roman;"> <span lang="SV"></span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">主页</span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">：</span><span style="font-size: 12pt;" lang="EN-US"><a href="http://www.yonsm.net/"><span style="mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;">WWW.Yonsm.NET</span></span></a></span><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 14pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;">Symbian_OS_9.x-ELF_Toolz</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">用于解压和压缩</span><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;">3rd<span style="mso-spacerun: yes;">  </span>EXE</span></span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">和</span><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;">DLL</span></span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">工具</span><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">当然我不是宇宙杰出青年，博客还是有的</span><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; mso-ansi-language: SV;" lang="SV"><span style="font-family: Times New Roman;">Blog</span></span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: SV; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">：</span><span style="font-size: 12pt; mso-ansi-language: SV;"><span style="font-family: Times New Roman;"> <span lang="SV"><a href="http://www.caterqiu.cn/">WwW.CaterQiu.Cn</a></span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">RESEdit.exe</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">S60 </span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">三版程序</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">RSC</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">资源修改工具，主要用作汉化</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">这四款小工具我的博客有文件打包，详情参阅</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt;" lang="EN-US"><a href="http://www.caterqiu.cn/Article/Symbian_S60_3rd_Reverse_CrAcKiNg_Tutorial_By_CaterQiu.html"><span style="font-family: Times New Roman;">WwW.CaterQiu.Cn/Article/Symbian_S60_3rd_Reverse_CrAcKiNg_Tutorial_By_CaterQiu.html</span></a></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"> </p>
<hr /><strong><span style="font-size: 22pt; line-height: 240%; font-family: 'Times New Roman'; mso-fareast-font-family: 宋体; mso-fareast-language: ZH-CN; mso-ansi-language: EN-US; mso-font-kerning: 22.0pt; mso-bidi-language: AR-SA;" lang="EN-US"><br /></span></strong></p>
<h1><span style="font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">实战操作</span></h1>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Example</span></span></strong><strong><span style="font-size: 14pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">：</span></strong><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">DVDPlayer 1.26.SISx </span></span></strong><strong><span style="font-size: 14pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">（</span></strong><strong><span style="font-size: 14pt;" lang="EN-US"><a href="http://www.viking.tm/"><span style="font-family: Times New Roman;">http://www.viking.tm</span></a></span></strong><strong><span style="font-size: 14pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">）</span></strong><strong><span style="font-size: 14pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Setp 1</span></span></strong><strong><span style="font-size: 14pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">：</span></strong><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Unpack Sis/Sisx File</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 0.1pt; text-indent: -44.95pt; mso-char-indent-count: -3.2; mso-para-margin-left: -4.27gd;"><strong><span style="font-size: 14pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.45pt; text-indent: -38.4pt; text-align: center; mso-char-indent-count: -3.2; mso-para-margin-left: -4.27gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step1.Use_SisContents_Unpack_S60_3rd_Target_Sis_File.gif" alt="" /></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.45pt; text-indent: -38.4pt; text-align: center; mso-char-indent-count: -3.2; mso-para-margin-left: -4.27gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">Use_SisContents_Unpack_S60_3rd_Target_Sis_File</span></span></p>
<p><span style="font-size: 12pt; font-family: 'Times New Roman'; mso-fareast-font-family: 宋体; mso-fareast-language: ZH-CN; mso-ansi-language: EN-US; mso-font-kerning: 1.0pt; mso-bidi-language: AR-SA;" lang="EN-US"><br /></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Setp 2</span></span></strong><strong><span style="font-size: 14pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">：</span></strong><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">UnComPress ELF File</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.1pt; text-indent: -2.95pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><strong><span style="font-size: 14pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step2.Use_Symbian_OS_9.x_ELF_Toolz_UnComPress_Target_ELF_File.gif" alt="" /></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">Use_Symbian_OS_9.x_ELF_Toolz_UnComPress_Target_ELF_File</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.45pt; text-indent: -38.4pt; text-align: center; mso-char-indent-count: -3.2; mso-para-margin-left: -4.27gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.45pt; text-indent: -38.4pt; text-align: center; mso-char-indent-count: -3.2; mso-para-margin-left: -4.27gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.45pt; text-indent: -38.4pt; mso-char-indent-count: -3.2; mso-para-margin-left: -4.27gd;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">Compare File Size Between Original(BAK_dvdplayer.exe) And NoCompress(dvdplayer.exe),</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.45pt; text-indent: -38.4pt; mso-char-indent-count: -3.2; mso-para-margin-left: -4.27gd;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">You Have Found dvdplayer.exe Was Unpacked.</span></span></p>
<p><span style="font-size: 12pt; font-family: 'Times New Roman'; mso-fareast-font-family: 宋体; mso-fareast-language: ZH-CN; mso-ansi-language: EN-US; mso-font-kerning: 1.0pt; mso-bidi-language: AR-SA;" lang="EN-US"><br /></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Setp 3</span></span></strong><strong><span style="font-size: 14pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">：</span></strong><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Analysis Program Flow</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.1pt; text-indent: -2.95pt; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step3.IDA_Analysis_1.gif" alt="" /></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">把脱壳后的程序拖入</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">IDA</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">中</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step3.IDA_Analysis_2.gif" alt="" /></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">勾上</span><span style="font-size: 12pt;"><span style="font-family: Times New Roman;"> </span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">堆栈指针和机器码字节数为</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">8</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step3.IDA_Analysis_3.gif" alt="" />.</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">Shift+F12</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">设置下字符串类型，</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">Unicode </span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">要的</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step3.IDA_Analysis_4.gif" alt="" /></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">字符串窗口中</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> 357062008960014</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">类似</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">IMEI</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">的串号，双击过来</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step3.IDA_Analysis_5.gif" alt="" /></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">继续向上回溯字符串被调用的地方</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step3.IDA_Analysis_6.gif" alt="" /></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">回溯到到</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">sub_8A2C</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -2.55pt; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -2.55pt; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">注意：</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -2.55pt; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">MOV R12,SP</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -2.55pt; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">STMFD SP!,{R4,R5,R7,R11,R12,LR,PC}</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -2.55pt; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">这两句类似</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">Win32</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">程序汇编代码中</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -2.55pt; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">PUSH EBP</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -2.55pt; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">MOV EBP</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">，</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">ESP</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -2.55pt; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">ADD ESP</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">，</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">XXX</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -2.55pt; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">意味着什么呢？意味着这个是子功能函数的函数入口</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step3.IDA_Analysis_7.gif" alt="" /></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">既然这个已经是子函数的入口了</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">我大致猜测刚才显示的那个串号是作者自己用来做的手机串号</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">我估计写入这个串号是为了检测</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">当串号为</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> 357062008960014</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">就不需要启动软件注册功能</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">暂时这么猜测吧</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">按下</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">X</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">按键看看有哪些地方调用</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">还好只有一处</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.55pt; text-indent: -2.5pt; text-align: center; mso-char-indent-count: -.21; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step3.IDA_Analysis_8.gif" alt="" /> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.6pt; text-indent: -56.4pt; text-align: center; mso-char-indent-count: -4.7; mso-para-margin-left: -6.0gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.6pt; text-indent: -56.4pt; text-align: center; mso-char-indent-count: -4.7; mso-para-margin-left: -6.0gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">返回到这里</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.6pt; text-indent: -56.4pt; text-align: center; mso-char-indent-count: -4.7; mso-para-margin-left: -6.0gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">分析代码详细过程我就不在这里细说了</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.6pt; text-indent: -56.4pt; text-align: center; mso-char-indent-count: -4.7; mso-para-margin-left: -6.0gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">Loc _8280 </span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">这里与解密有关的部分，我们进入分析</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -65.4pt; text-align: center; mso-char-indent-count: -5.45; mso-para-margin-left: -6.85gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -65.4pt; text-align: center; mso-char-indent-count: -5.45; mso-para-margin-left: -6.85gd;" align="center"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -65.4pt; text-align: center; mso-char-indent-count: -5.45; mso-para-margin-left: -6.85gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step3.IDA_Analysis_9.gif" alt="" /></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -65.4pt; text-align: center; mso-char-indent-count: -5.45; mso-para-margin-left: -6.85gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">进来后，再进入</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> sub_9114 </span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">分析看看</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -65.4pt; text-align: center; mso-char-indent-count: -5.45; mso-para-margin-left: -6.85gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.85pt; text-indent: -2.4pt; text-align: center; mso-char-indent-count: -.2; mso-para-margin-left: -.88gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -65.4pt; text-align: center; mso-char-indent-count: -5.45; mso-para-margin-left: -6.85gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">很显然</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> sub_9114 </span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">也是一个子函数</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -65.4pt; text-align: center; mso-char-indent-count: -5.45; mso-para-margin-left: -6.85gd;" align="center"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -65.4pt; text-align: center; mso-char-indent-count: -5.45; mso-para-margin-left: -6.85gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -65.4pt; text-align: center; mso-char-indent-count: -5.45; mso-para-margin-left: -6.85gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step3.IDA_Analysis_10.gif" alt="" /></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -65.4pt; text-align: center; mso-char-indent-count: -5.45; mso-para-margin-left: -6.85gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">这里这号是图形化的，看看整个分支流程</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -65.4pt; text-align: center; mso-char-indent-count: -5.45; mso-para-margin-left: -6.85gd;" align="center"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -65.4pt; text-align: center; mso-char-indent-count: -5.45; mso-para-margin-left: -6.85gd;" align="center"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.5pt; text-indent: -65.4pt; text-align: center; mso-char-indent-count: -5.45; mso-para-margin-left: -6.85gd;" align="center"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.65pt; text-indent: -74.3pt; text-align: center; mso-char-indent-count: -6.19; mso-para-margin-left: -7.71gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step3.IDA_Analysis_11.gif" alt="" /></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">CompareF </span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">比较函数</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">再猜测下咯</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">刚才是作者手机串号的代码</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">这里的比较</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">很大何能是判断是不是作者的手机</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">R0</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">寄存器和</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">8&#215;86 EAX</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">寄存器一样常用语函数返回值</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">没查</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">SDK</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">了，和</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">Windows</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">比较函数一样</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">一般返回</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">0 </span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">说明两参数比较相等</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">加个注解解释下吧</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -7.05pt; text-indent: -2pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: small;"><span style="background: #d9d9d9; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;" lang="EN-US"><span style="font-family: Times New Roman;">LDR<span style="mso-tab-count: 2;">          </span>R0, [R6,#0x98]<span style="mso-spacerun: yes;">  </span><span style="mso-tab-count: 1;">  </span>; <span style="mso-tab-count: 1;">    </span></span></span><span style="background: #d9d9d9; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman'; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;">相当于</span><span style="background: #d9d9d9; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;" lang="EN-US"><span style="font-family: Times New Roman;"><span style="mso-tab-count: 1;">    </span>MOV R0,[R6+0x98]</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -7.05pt; text-indent: -2pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: small;"><span style="background: #d9d9d9; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;" lang="EN-US"><span style="font-family: Times New Roman;">MOV<span style="mso-spacerun: yes;">     </span>R1, R10<span style="mso-spacerun: yes;">         </span>; <span style="mso-tab-count: 1;">     </span></span></span><span style="background: #d9d9d9; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman'; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;">相当于</span><span style="background: #d9d9d9; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;" lang="EN-US"><span style="font-family: Times New Roman;"><span style="mso-tab-count: 1;">    </span>MOV R1,R10</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -7.05pt; text-indent: -2pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: small;"><span style="background: #d9d9d9; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;" lang="EN-US"><span style="font-family: Times New Roman;">BL<span style="mso-spacerun: yes;">      </span><span style="mso-tab-count: 1;">   </span>TDesC16::CompareF(TDesC16 const&amp;) ;<span style="mso-tab-count: 1;">     </span></span></span><span style="background: #d9d9d9; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman'; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;">相当于</span><span style="background: #d9d9d9; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;" lang="EN-US"><span style="font-family: Times New Roman;"> Comparf(R0,R1)</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -7.05pt; text-indent: -2pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: small;"><span style="background: #d9d9d9; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;" lang="EN-US"><span style="font-family: Times New Roman;">CMP<span style="mso-spacerun: yes;">     </span>R0, #0<span style="mso-spacerun: yes;">          </span>; R0</span></span><span style="background: #d9d9d9; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman'; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;">为函数的返回值，为</span><span style="background: #d9d9d9; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;" lang="EN-US"><span style="font-family: Times New Roman;">0</span></span><span style="background: #d9d9d9; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman'; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;">，说明参数</span><span style="background: #d9d9d9; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;" lang="EN-US"><span style="font-family: Times New Roman;"> R0</span></span><span style="background: #d9d9d9; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman'; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;">和参数</span><span style="background: #d9d9d9; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;" lang="EN-US"><span style="font-family: Times New Roman;"> R1 </span></span><span style="background: #d9d9d9; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman'; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;">相等</span><span style="background: #d9d9d9; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;" lang="EN-US"></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -7.05pt; text-indent: -2pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="background: #d9d9d9; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Times New Roman;">MOVEQ <span style="mso-tab-count: 1;">   </span>R8, #1<span style="mso-spacerun: yes;">          </span>; IF R0=0 Then R8=1</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -7.05pt; text-indent: -2pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="background: #d9d9d9; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Times New Roman;">STREQ<span style="mso-spacerun: yes;">   </span>R8, [R6,#0x90]<span style="mso-spacerun: yes;">  </span><span style="mso-tab-count: 1;">   </span>; IF R0=0 Then Storage R8 To R6+0&#215;90 Memory</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -7.05pt; text-indent: -2pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="background: #d9d9d9; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Times New Roman;">BEQ<span style="mso-spacerun: yes;">     </span>loc_922C<span style="mso-spacerun: yes;">        </span>; IF R0=0 Then Call Loc_922C Function</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -7.05pt; text-indent: -2pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="background: #d9d9d9; mso-bidi-font-size: 10.5pt; mso-shading: white; mso-pattern: gray-15 auto;" lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">很明显要改变程序流程</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">需要</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">patch</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">下代码</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">修改</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">CMP R0</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">，</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">#0</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">变成</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">CMP R0</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">，</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">R0</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">可以一直作用下列的流程</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">自然而然</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">我们的补丁代码也就是这个了</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p><span style="font-size: 12pt; font-family: 'Times New Roman'; mso-fareast-font-family: 宋体; mso-fareast-language: ZH-CN; mso-ansi-language: EN-US; mso-font-kerning: 1.0pt; mso-bidi-language: AR-SA;" lang="EN-US"><br /></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Setp 4</span></span></strong><strong><span style="font-size: 14pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">：</span></strong><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Make ARM OPCODE</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step4.Use_CeleASM_Make_OPCODE.gif" alt="" /></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">Use_CeleASM_Make_OPCODE</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">生成的</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">OPCODE</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">是</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: 12pt; background: #d9d9d9; mso-ansi-language: DE; mso-shading: white; mso-pattern: gray-15 auto;" lang="DE"><span style="font-family: Times New Roman;"><span style="mso-spacerun: yes;">    </span>5 00000004 e3500000<span style="mso-spacerun: yes;">         </span>CMP R0,#0 </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: 12pt; background: #d9d9d9; mso-ansi-language: DE; mso-shading: white; mso-pattern: gray-15 auto;" lang="DE"><span style="font-family: Times New Roman;"><span style="mso-spacerun: yes;">    </span>6 00000008 e1500000<span style="mso-spacerun: yes;">         </span>CMP R0,R0</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: 12pt; background: #d9d9d9; mso-ansi-language: DE; mso-shading: white; mso-pattern: gray-15 auto;" lang="DE"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: DE; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">看看</span><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"><span style="font-family: Times New Roman;"> CMP R0</span></span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: DE; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">，</span><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"><span style="font-family: Times New Roman;">#0 </span></span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: DE; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">的</span><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"><span style="font-family: Times New Roman;">OPCODE</span></span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: DE; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">和我们途中的</span><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"><span style="font-family: Times New Roman;"> OPCODE</span></span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: DE; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">是否相同</span><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: 12pt; background: #d9d9d9; mso-ansi-language: DE; mso-shading: white; mso-pattern: gray-15 auto;" lang="DE"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; background: #d9d9d9; mso-ansi-language: DE; mso-shading: white; mso-pattern: gray-15 auto;" lang="DE"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: DE; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step4.Use_CeleASM_Make_OPCODE_1.gif" alt="" /></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: DE; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">不难看出</span><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; background: #d9d9d9; mso-ansi-language: DE; mso-shading: white; mso-pattern: gray-15 auto;" lang="DE"><span style="font-family: Times New Roman;">5 00000004 e3500000<span style="mso-spacerun: yes;">         </span>CMP R0,#0</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: DE; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">是对应</span><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"><span style="font-family: Times New Roman;">Little-Endianl</span></span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: DE; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">数据存储类型的</span><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"><span style="font-family: Times New Roman;">ARM CPU</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: DE; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">也就是低位字节排在内存较低地址</span><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">Patch_OPCODE: <span style="color: blue;">00 00 50 E1 (CMP <span style="mso-tab-count: 1;">  </span>R0</span></span></span></strong><strong><span style="font-size: 12pt; color: blue; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">，</span></strong><strong><span style="font-size: 12pt; color: blue;" lang="EN-US"><span style="font-family: Times New Roman;">R0)</span></span></strong><span style="font-size: 12pt;" lang="EN-US"><br /></span><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Setp 5</span></span></strong><strong><span style="font-size: 14pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">：</span></strong><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Patch Data</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: DE; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step5.Use_WinHex_Patch_Data1.gif" alt="" /></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: DE; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">先从</span><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"><span style="font-family: Times New Roman;">IDA</span></span><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: DE; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">中查看需要修改代码对应的文件偏移</span><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"><span style="font-family: Times New Roman;">0x000012AC</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: DE; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step5.Use_WinHex_Patch_Data2.gif" alt="" /></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: DE; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">原来的</span><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: DE; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step5.Use_WinHex_Patch_Data3.gif" alt="" /></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: DE; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">修改后就这样了</span><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; font-family: 宋体; mso-ansi-language: DE; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">最后存盘即可。</span><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"></span></p>
<p><span style="font-size: 12pt; font-family: 'Times New Roman'; mso-fareast-font-family: 宋体; mso-fareast-language: ZH-CN; mso-ansi-language: DE; mso-font-kerning: 1.0pt; mso-bidi-language: AR-SA;" lang="DE"><br /></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Setp 6</span></span></strong><strong><span style="font-size: 14pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">：</span></strong><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Compress ELF File</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.4pt; text-indent: -2.65pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt; mso-ansi-language: DE;" lang="DE"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"><img src="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_Reverse_Cracking_Tutorial/Step6.Use_Symbian_OS_9.x_ELF_Toolz_ComPress_Target_ELF_File.gif" alt="" /></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; text-align: center; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;" align="center"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">Use_Symbian_OS_9.x_ELF_Toolz_ComPress_Target_ELF_File</span></span></p>
<p><span style="font-size: 12pt; font-family: 'Times New Roman'; mso-fareast-font-family: 宋体; mso-fareast-language: ZH-CN; mso-ansi-language: EN-US; mso-font-kerning: 1.0pt; mso-bidi-language: AR-SA;" lang="EN-US"><br /></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Setp 7</span></span></strong><strong><span style="font-size: 14pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">：</span></strong><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Pack S60 3<sup>rd</sup> File</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">1</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">、把之前破解好，加压缩的</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">dvdplayer.exe </span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">复制一份到别处</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">2</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">、删除之前解包出来的文件夹</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -9.05pt; text-indent: 21pt; mso-char-indent-count: 1.75; mso-para-margin-left: -.86gd;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">D:Symbian_Reverse_ToolzToolzSisContents121DVDPlayer 1.26</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">3</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">、再次用</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">SisContents</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">打开原版的</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">.sis</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">文件，点击</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> Extract Files </span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">图标</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">4</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">、拷贝之前破解好，加压缩的</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">dvdplayer.exe</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">，复制到</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.7pt; text-indent: 18pt; mso-char-indent-count: 1.5; mso-para-margin-left: -.64gd;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">D:Symbian_Reverse_ToolzToolzSisContents121DVDPlayer 1.26sysbin</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.7pt; text-indent: 18pt; mso-char-indent-count: 1.5; mso-para-margin-left: -.64gd;"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">替换掉解包出来的</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.6pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.85gd;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">5</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">、删除原来的签名：回到</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">SisContents</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">中，</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> Tools-&gt;Delete Signatures</span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">6</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">、</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">File-&gt;Save As-&gt;</span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">另存文件即可。</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.4pt; text-indent: -2.65pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.4pt; text-indent: -2.65pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.4pt; text-indent: -2.65pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Setp 8</span></span></strong><strong><span style="font-size: 14pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">：</span></strong><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Run Patched .Sis File With Mobile</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">在手机上测试我们修改后的程序，破解成功。</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -6.75pt; text-indent: -2.3pt; mso-char-indent-count: -.19; mso-para-margin-left: -.86gd;"><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt -12.05pt; mso-para-margin-left: -1.15gd;"><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">说明那个串号是一个作者留下的小路吧，当然如果替换作者原来测试机的串号</span><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">357062008960014 </span></span><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">成自己的串号，那么程序也是一路绿灯通行的。</span><span style="font-size: 12pt;" lang="EN-US"></span></p>
<p><strong><span style="font-size: 22pt; line-height: 240%; font-family: 'Times New Roman'; mso-fareast-font-family: 宋体; mso-fareast-language: ZH-CN; mso-ansi-language: EN-US; mso-font-kerning: 22.0pt; mso-bidi-language: AR-SA;" lang="EN-US"><br /></span></strong></p>
<h1><span style="font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">学习小结</span></h1>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">ARM</span></span></strong><strong><span style="font-size: 14pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">指令集需要掌握</span></strong><strong><span style="font-size: 14pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt;"><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">遇到</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">B</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">当</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">CALL</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">指令用即可</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt;"><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">BL</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">是调用系统函数</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt;"><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">Bxx</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">是条件调用类似条件跳转</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">Jxx</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">指令</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt;"><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">R0-R3</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">可以用作参数传递</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt;"><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">R0</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">和</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">Win32</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">汇编中</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">EAX</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">作用一样常用语存放函数返回值</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 14pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">解密思路和</span></strong><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Windows</span></span></strong><strong><span style="font-size: 14pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">上的解密思路是一样的</span></strong><strong><span style="font-size: 14pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt;"><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">可以通过字符串来定位关键代码，</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt;"><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">也可以通过相关</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">API</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">找关键代码</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt;"><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Symbian</span></span></strong><strong><span style="font-size: 14pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">解密注意事项</span></strong><strong><span style="font-size: 14pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 12pt;" lang="EN-US"><span style="mso-tab-count: 1;"><span style="font-family: Times New Roman;">       </span></span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">解包后记得先解压</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">EXE</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">或者</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">DLL</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">文件</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt;"><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">修改后的</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">EXE</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">、</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">DLL</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">程序不可以直接替换到手机中使用，需要做成安装包</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 12pt;" lang="EN-US"><span style="mso-tab-count: 1;"><span style="font-family: Times New Roman;">       </span></span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">打包前一定要给</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">EXE</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">、</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;">DLL</span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">压缩下</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 12pt;" lang="EN-US"><span style="mso-tab-count: 1;"><span style="font-family: Times New Roman;">       </span></span></span></strong><strong><span style="font-size: 12pt; font-family: 宋体; mso-hansi-font-family: 'Times New Roman'; mso-ascii-font-family: 'Times New Roman';">打包时要注意签名，最好先删除所有的签名</span></strong><strong><span style="font-size: 12pt;" lang="EN-US"></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><strong><span style="font-size: 12pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="mso-bidi-font-size: 10.5pt;" lang="EN-US"><a href="http://www.caterqiu.cn/Article/Symbian_S60_3rd_Reverse_CrAcKiNg_Tutorial_By_CaterQiu.html"><span style="font-size: small; font-family: Times New Roman;">WwW.CaterQiu.Cn/Article/Symbian_S60_3rd_Reverse_CrAcKiNg_Tutorial_By_CaterQiu.html</span></a></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="mso-bidi-font-size: 10.5pt;" lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="mso-bidi-font-size: 10.5pt;" lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt;"><span style="mso-bidi-font-size: 10.5pt;" lang="EN-US"><span style="font-size: small; font-family: Times New Roman;"> </span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: center;" align="center"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Symbian S60 3<sup>rd</sup> Reverse CrAcKiNg_Tutorial</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: center;" align="center"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;"> </span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: center;" align="center"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">By CaterQiu</span></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: center;" align="center"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Blog </span><a href="http://www.caterqiu.cn/"><span style="font-family: Times New Roman;">www.caterqiu.cn</span></a></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: center;" align="center"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">Mail </span><a href="mailto:Cater.Qiu@Gmail.com"><span style="font-family: Times New Roman;">Cater.Qiu@Gmail.com</span></a></span></strong></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-align: center;" align="center"><strong><span style="font-size: 14pt;" lang="EN-US"><span style="font-family: Times New Roman;">2009-5-1</span></span></strong></p>
<hr /><a href="http://www.caterqiu.cn/UPLOAD/2009/4/Symbian_S60_3rd_Reverse_CrAcKiNg_Tutorial_By_CaterQiu.rar" target="_blank">相关文件下载</a></p>
<p> 实话的说，本来教程想拿英文写的，顺带练习练习的</p>
<p>只是越写越困 越不通顺~所以后面 就用中文混淆一下吧~</p>
<p>顺带说下，明天是某人生日，某人很寂寞，先睡觉了。<br />
大成，大成成就你一个家。</p>
<hr /><h2>Comments</h2><ul><li><a href="http://www.softrce.net/archives/114">2009年05月4日</a>, gz1x writes: 不错，看着很新颖。嵌入式平台的安全确实是个好方向。</li><li><a href="http://www.softrce.net/archives/114">2009年05月4日</a>, dge writes: 文章写的很好，很漂亮</li><li><a href="http://www.softrce.net/archives/114">2009年05月9日</a>, lwjef writes: 页面不是很流畅~
好迟滞~~
Cater以前是OPDA编程组的成员~~</li><li><a href="http://www.softrce.net/archives/114">2009年05月9日</a>, lwjef writes: 郁闷来~~
原来也是Cater的博客呀~~</li><li><a href="http://www.softrce.net/archives/114">2009年05月9日</a>, robinh00d writes: @lwjef, 这是一个集体的BLOG呵呵</li></ul><hr /><small>Copyright &copy; 2008<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. If this content is not in your news reader, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint:<br /> 8e761b2ea8edc3ca311452b020051837)</small><h3  class="related_post_title">随机日志</h3><ul class="related_post"><li>2008年09月29日 -- <a href="http://www.softrce.net/archives/9" title="文章预告：Exploiting Windows Device Drivers">文章预告：Exploiting Windows Device Drivers</a></li><li>2010年04月21日 -- <a href="http://www.softrce.net/archives/302" title="WinMount mou文件格式溢出漏洞分析">WinMount mou文件格式溢出漏洞分析</a></li><li>2009年12月27日 -- <a href="http://www.softrce.net/archives/210" title="Symbian_S60_3rd_Application_Cracking_With_IDA_Remote_Debugger_Tutorial">Symbian_S60_3rd_Application_Cracking_With_IDA_Remote_Debugger_Tutorial</a></li><li>2010年08月3日 -- <a href="http://www.softrce.net/archives/320" title="SoftRCE官方T恤开始订购了~">SoftRCE官方T恤开始订购了~</a></li><li>2008年10月19日 -- <a href="http://www.softrce.net/archives/14" title="Vista Bootmgr/Winload使用的大部分选项ID">Vista Bootmgr/Winload使用的大部分选项ID</a></li><li>2011年04月8日 -- <a href="http://www.softrce.net/archives/381" title="Microsoft Windows xp AFD.sys Local Kernel DoS Vulnerability">Microsoft Windows xp AFD.sys Local Kernel DoS Vulnerability</a></li><li>2008年11月16日 -- <a href="http://www.softrce.net/archives/19" title="[转载]在英特尔软件网络博客上看到的">[转载]在英特尔软件网络博客上看到的</a></li><li>2008年10月22日 -- <a href="http://www.softrce.net/archives/15" title="构造无人之境: Exploiting Realtek RTL8139单芯片以太网控制器">构造无人之境: Exploiting Realtek RTL8139单芯片以太网控制器</a></li><li>2010年01月12日 -- <a href="http://www.softrce.net/archives/213" title="MS07-014调试手记">MS07-014调试手记</a></li><li>2008年09月30日 -- <a href="http://www.softrce.net/archives/10" title="[国庆礼]Exploiting Windows Device Drivers译文版">[国庆礼]Exploiting Windows Device Drivers译文版</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.softrce.net/archives/114/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>容易被忽略的IDA快捷键</title>
		<link>http://www.softrce.net/archives/21</link>
		<comments>http://www.softrce.net/archives/21#comments</comments>
		<pubDate>Sat, 10 Jan 2009 07:04:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[乾坤挪移（RCE）]]></category>

		<guid isPermaLink="false">http://174.132.145.120/~crackidz/archives/21</guid>
		<description><![CDATA[1. 选中寄存器按V，用输入内容替换寄存器名<br /><br /><br />2. 选定汇编指令段按T，批量修改范围内结构偏移<br /><br /><br />3. 选中操作数按Alt+F1，输入内容替换操作数<br /><br /><br />4. 选定汇编指令行按Alt+F2，输入内容替换原有指令<br /><br /><br />5. Insert，输入段前注释<br /><br /><br />6. Shift+Insert，输入段后注释
]]></description>
			<content:encoded><![CDATA[<p>1. 选中寄存器按V，用输入内容替换寄存器名</p>
<p>2. 选定汇编指令段按T，批量修改范围内结构偏移</p>
<p>3. 选中操作数按Alt+F1，输入内容替换操作数</p>
<p>4. 选定汇编指令行按Alt+F2，输入内容替换原有指令</p>
<p>5. Insert，输入段前注释</p>
<p>6. Shift+Insert，输入段后注释</p>
<hr /><small>Copyright &copy; 2008<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. If this content is not in your news reader, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint:<br /> 8e761b2ea8edc3ca311452b020051837)</small><h3  class="related_post_title">随机日志</h3><ul class="related_post"><li>2009年05月16日 -- <a href="http://www.softrce.net/archives/140" title="静态分析驱动的一点技巧">静态分析驱动的一点技巧</a></li><li>2008年11月16日 -- <a href="http://www.softrce.net/archives/19" title="[转载]在英特尔软件网络博客上看到的">[转载]在英特尔软件网络博客上看到的</a></li><li>2010年03月11日 -- <a href="http://www.softrce.net/archives/296" title="Think Different">Think Different</a></li><li>2009年05月30日 -- <a href="http://www.softrce.net/archives/189" title="基于NDIS Filter 抓包">基于NDIS Filter 抓包</a></li><li>2009年05月1日 -- <a href="http://www.softrce.net/archives/96" title="暴风影音2009(mps.dll)ActiveX远程栈溢出漏洞">暴风影音2009(mps.dll)ActiveX远程栈溢出漏洞</a></li><li>2009年05月1日 -- <a href="http://www.softrce.net/archives/114" title="Symbian S60 3rd Reverse CrAcKiNg Tutorial">Symbian S60 3rd Reverse CrAcKiNg Tutorial</a></li><li>2008年11月16日 -- <a href="http://www.softrce.net/archives/18" title="今天又地震～～">今天又地震～～</a></li><li>2009年04月30日 -- <a href="http://www.softrce.net/archives/83" title="中国游戏中心游戏大厅ActiveX远程栈溢出漏洞">中国游戏中心游戏大厅ActiveX远程栈溢出漏洞</a></li><li>2010年05月7日 -- <a href="http://www.softrce.net/archives/310" title="IoRegisterDriverReinitialization 和IoRegisterBootDriverReinitialization">IoRegisterDriverReinitialization 和IoRegisterBootDriverReinitialization</a></li><li>2010年04月21日 -- <a href="http://www.softrce.net/archives/302" title="WinMount mou文件格式溢出漏洞分析">WinMount mou文件格式溢出漏洞分析</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.softrce.net/archives/21/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vista Bootmgr/Winload使用的大部分选项ID</title>
		<link>http://www.softrce.net/archives/14</link>
		<comments>http://www.softrce.net/archives/14#comments</comments>
		<pubDate>Sat, 18 Oct 2008 19:46:42 +0000</pubDate>
		<dc:creator>mj0011</dc:creator>
				<category><![CDATA[乾坤挪移（RCE）]]></category>

		<guid isPermaLink="false">http://174.132.145.120/~crackidz/archives/14</guid>
		<description><![CDATA[<h4>&#160;</h4><div class="tpc_content" id="read_tpc">vista bootmgr的选项存储在systemdevice\boot\bcd，这个HIVE文件类似以前的boot,ini <br /><br />boot.ini的选项在该HIVE中是以guid-&#62;option id的形式来体现的 <br /><br />除了保留了原来boot.ini可以使用的大部分选项外，还新增了许多选项，例如test signing, disable integrity checks,hypervisor debug options,cmdcons等等等 <br />...</div>
]]></description>
			<content:encoded><![CDATA[<h4></h4>
<div id="read_tpc" class="tpc_content">vista bootmgr的选项存储在systemdevice\boot\bcd，这个HIVE文件类似以前的boot,ini</p>
<p>boot.ini的选项在该HIVE中是以guid-&gt;option id的形式来体现的</p>
<p>除了保留了原来boot.ini可以使用的大部分选项外，还新增了许多选项，例如test signing, disable integrity checks,hypervisor debug options,cmdcons等等等</p>
<p>以下是我分析WINLOAD.EXE和bootmgr找出的一些选项ID(50个，包括大部分选项），通过这些选项ID可以查看、修改VISTA的许多启动设置（结合参考：<a href="http://www.debugman.com/read.php?tid=1999" target="_blank"><span style="color: #314d84;">http://www.debugman.com/read.php?tid=1999</span></a>） <span id="more-14"></span></p>
<p><span style="font-size: large;"><span style="font-family: fixedsys">10100002 os type<br />
12000002 boot loader path<br />
12000004 os name<br />
12000005 locate language<br />
12000016 target name<br />
15000007 max memory<br />
1500000d relocate physical memory range<br />
15000011 1394 or usb debug<br />
15000013 debug port(COM 1 ,2 ,3 4)<br />
15000014 brudrate<br />
15000022 redirect(COM 1, 2, 3,4)<br />
15000023 redirect baudrate<br />
15000047 config access policy (default or disallow low memory config)<br />
15000052 graphics resolution (800&#215;600 or 1024&#215;768)<br />
16000009: recovery<br />
16000010 Boot debugging<br />
16000048 disable integrity checks or no integrity checks!<br />
16000049 test signing<br />
22000001 “cmdcons” :cmdcons(Windows Recovery Console)<br />
“undo” roll back<br />
22000002 system root<br />
22000011 kernel =<br />
22000012 hal =<br />
23000006 default resume os<br />
24000001 os list<br />
24000010 memory test<br />
25000004 boot menu timeout<br />
25000020 DEP option(optin/optout/alwayson/alwaysoff)<br />
25000021 pae or nopae<br />
25000032 3GB user memory(user rva)<br />
25000071 MSI policy (default or force disable)<br />
25000072 pci express policy (default or force disable)<br />
25000080 safeboot :boot network or dsrepair<br />
250000f6 :hypervisor dbg ch<br />
26000004 stamp disks (stamp raw disk when winpe)<br />
26000010 detect hal<br />
26000026 disable integrity checks<br />
26000027 test signing<br />
26000040 base video<br />
26000041 (noguiboot, bootlogo)load bitmap logo : \osload800x600.bmp or \osload1024x768.bmp<br />
26000042 novesa<br />
26000051 use physical APIC<br />
26000060 one cpu<br />
26000062 max processor<br />
26000070 pci lock<br />
26000081 safeboot :boot minimal or minimal(alter nate shell)<br />
26000090 boot log<br />
26000091 SOS<br />
260000a0 debug or nodebug<br />
260000a1 kernel debug break on ntoskrnl</span></span></div>
<hr /><small>Copyright &copy; 2008<br /> This feed is for personal, non-commercial use only. <br /> The use of this feed on other websites breaches copyright. If this content is not in your news reader, it makes the page you are viewing an infringement of the copyright. (Digital Fingerprint:<br /> 8e761b2ea8edc3ca311452b020051837)</small><h3  class="related_post_title">随机日志</h3><ul class="related_post"><li>2010年03月11日 -- <a href="http://www.softrce.net/archives/296" title="Think Different">Think Different</a></li><li>2011年09月13日 -- <a href="http://www.softrce.net/archives/405" title="Microsoft Windows NDISTAPI本地权限提升漏洞（MS11-062)">Microsoft Windows NDISTAPI本地权限提升漏洞（MS11-062)</a></li><li>2008年10月22日 -- <a href="http://www.softrce.net/archives/16" title="绕过主动防御的代码注入方法一点思考">绕过主动防御的代码注入方法一点思考</a></li><li>2008年09月30日 -- <a href="http://www.softrce.net/archives/10" title="[国庆礼]Exploiting Windows Device Drivers译文版">[国庆礼]Exploiting Windows Device Drivers译文版</a></li><li>2010年02月10日 -- <a href="http://www.softrce.net/archives/217" title="How to adjust the Ace of device object">How to adjust the Ace of device object</a></li><li>2010年01月12日 -- <a href="http://www.softrce.net/archives/213" title="MS07-014调试手记">MS07-014调试手记</a></li><li>2009年04月30日 -- <a href="http://www.softrce.net/archives/63" title="Native Application之键盘处理">Native Application之键盘处理</a></li><li>2010年02月21日 -- <a href="http://www.softrce.net/archives/256" title="Step deeply into NDIS6 LightWeight Filter, part 1">Step deeply into NDIS6 LightWeight Filter, part 1</a></li><li>2009年04月30日 -- <a href="http://www.softrce.net/archives/83" title="中国游戏中心游戏大厅ActiveX远程栈溢出漏洞">中国游戏中心游戏大厅ActiveX远程栈溢出漏洞</a></li><li>2009年05月1日 -- <a href="http://www.softrce.net/archives/114" title="Symbian S60 3rd Reverse CrAcKiNg Tutorial">Symbian S60 3rd Reverse CrAcKiNg Tutorial</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.softrce.net/archives/14/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

