Positioning method and positioning system for target address
A technology of target address and positioning method, applied in the field of target address positioning method and system, can solve the problems of feature hard coding failure, poor backward compatibility, weak cross-platform capability of original address positioning technology, etc. Good post-compatibility, overcoming blue screen or crash effect
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0031] Embodiment 1, reference figure 1 , showing a method for locating a target address, which may specifically include:
[0032] Step 101, loading the target driver program to the user mode memory space;
[0033] Step 102, simulating the parameters and environment required for the operation of the target driver;
[0034] Step 103, the target driver runs in the user state, and obtains the original address of the target driver.
[0035] During specific implementation, step 102 may include (refer to figure 2 ):
[0036] Step 1021, forging and traversing and replacing all imported functions of the target driver;
[0037] Step 1022, creating a thread, forging and initializing the target driver object structure and string pointer;
[0038] Step 1023, call the export entry of the target driver in the thread.
[0039] When specifically implementing the above-mentioned embodiment 1 step 103 to obtain the original address of the target driver, it may include (refer to image 3...
Embodiment 6
[0066] In embodiment 6, the present invention also discloses a target address positioning system (refer to Image 6 ). Embodiment 6, a system for locating a target address includes: a loading device 601, configured to load the target driver program into the user-mode memory space; a simulation device 602, used to simulate the parameters and environment required for the operation of the target driver program; an acquisition device 603, It is used for the target driver to run in the user mode and obtain the original address of the target driver. After the loading device 601 loads the target driver program into the user mode memory space, the simulation device 602 simulates the parameters and environment required for the target driver program to run in the user mode; during the target driver program running process, some required system variables Values such as the address of the routine and the address of the routine are filled by execution, and the actual original address of...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


