使用NASM编译以下汇编代码
BITS 64
ORG 0
section .text
global _start
_start:
push rbx
mov rax,QWORD [gs:0x38]
mov rax,QWORD [rax+0x4]
shr rax,0xc
shl rax,0xc
_x64_find_nt_walk_page:
mov rbx,QWORD [rax]
cmp bx,0x5a4d
je _found
sub rax,0x1000
jmp _x64_find_nt_walk_page
_found:
pop rbx
ret
验证结果,最终RAX保存的是NT基址