2016四月18
VMP-异常处理SEH4的Handle和Filter反汇编查找
异常处理Handle和Filter反汇编查找
﹎゛Never Give Up Your Dream ..ヽ..
TIB(线程信息块) 0:000> dt ntdll!_TEB +0x000 NtTib : _NT_TIB typedef struct _NT_TIB { struct _EXCEPTION_REGISTRATION_RECORD *ExceptionList; PVOID StackBase; PVOID StackLimit; PVOID SubSystemTib; union { PVOID FiberData; DWORD Version; }; PVOID ArbitraryUserPointer; struct _NT_TIB *Self; } NT_TIB; typedef NT_TIB *PNT_TIB; ExceptionL …