1.winmain Դ?Steamapi劫持源码?
winmain Դ??
ä½ å¯ä»¥ç §äºæ¥¼çè¿æ ·æ¥ç解,åºè¯¥è¯´åºæ¬è¿æ ·ç解ä¸ä¼è½è¯¯äºç.èä¸æ¯è¾å¥½ç解!
ä½æ¯ä½ çé®é¢çç¡®åçæ¡ä¸æ¯è¿æ ·ç:
ä¸ç®¡ä»ä¹æ ·çMAIN,å¨VCä¸ç¼è¯çæ¶å,å®é ä¸å¨MAINçå¤å±æ¯è¿æä¸è¥¿ç.ä½ å¯ä»¥çä¸crt0.CPPçæºä»£ç .
argc, argvçé½æ¯å¨crt0.cppéå®ç°,ç¶å以ret = (main(argc, argv));å¼å§è°ç¨mainå½æ°,å½mainç¨returnæ¶,retå°±æ¥åäºè¿ä¸ªreturnå¼.
å æ¤åç§main(WinMain,wWinMain,wMain,Main)çå¤å±æ¯å¨crt0(C RunTime)è¿ä¸ªCè¿è¡æ¶åºæºä»£ç æ件ä¸å®ç°,ä¸ç±è¿æ¥å¨å°å®ä¸æ们çMAINæ件è¿æ¥æ¥çææç»çEXEæ件.å½åå»EXEæ件æ¶,ç±æä½ç³»ç»çå è½½ç¨åºæ¥æEXEå è½½å°å åä¸,ä»é常çè¿ç¨èæå°å0Xå¼å§è®©CPUæ§è¡ä»£ç .
å¦å¤:å¦æä½ ä¸ç 究æä½ç³»ç»çè¯,ææ³è¯´ä½ å«å»æ·±ç©¶ä½ çè¿ä¸ªé®é¢äº,深究çè¯ä¼çµåºä¸å¤§å åæä½ç³»ç»æå ³çç¥è¯ç,ä¸æ¶æ ¹æ¬æ æ³å®å ¨è®²æ¸ æ¥.
åçè¡¥å ï¼
å½ç¶è½äºã
1ï¼å¨å½ä»¤æ示符ä¸ï¼è¾å ¥ä½ çEXEæ件åï¼ç¶åä¸ä¸ªç©ºæ ¼ï¼åè¾å ¥é便ä»ä¹åæ¯ãç¶åçä¸ç¨åºè¾åºçæ¯b. (EXEæ件åå¯ä»¥çææ¯ä¸ä¸ªåæ°ï¼å æ¤argc为1ï¼argv为NULL)
2ï¼ç¨VCçè¯ï¼çä¸å·¥ç¨å±æ§éå¯ä»¥è®¾ç½®ä¸ºç¨åºä¼ éçåæ°ãï¼æ æ³å¤è¯´äºï¼å¦åä½ å¯è½åä¼ææ°çé®é¢ï¼ä¸ºä»ä¹å¨VCå·¥ç¨å±æ§é设置äºåæ°å°±è½ä¼ ç»MAIN(ARGC,ARGV)ï¼ï¼
ä¸è¦åæ³è¿ä¸ªé®é¢äºï¼ä»¥ä½ ç°å¨çç¥è¯é¢æ²¡æ³ç解ï¼ä¹ä¸æ¯å å¥è¯å°±è½è®©ä½ å½»åºæç½çã
é´äºä½ çæ°´å¹³ï¼ä½ è´´é®é¢çè¯è¿æ¯å¨C/C++éè´´å§ï¼ä½ çé®é¢ä¸å±äºVC++èç´ã