$$ $><C:\Users\admin\Desktop\a\CreateFileW_script.wds
bp CreateFileW "
r $t0=poi(esp+4)
as /mu ${/v:$FileName} $t0
.echo
.printf \"[*] Currently open file:%mu\",$t0
.echo
.block
{
.if($spat(@\"${$FileName}\",@\"*test.hwp\"))
{
.printf \"[+] ok...find file:%mu\",$t0
.echo
kb
ad ${/v:$FileName}
gu
!handle eax f
}
.else
{
.printf \"[-] no...find file:%mu\",$t0
.echo
ad ${/v:$FileName}
g
}
}
windbg别名用法
最新推荐文章于 2023-08-09 21:10:13 发布