32bit 程序的 GDI Shared Handle Table 段是没有的,即 _PEB.GdiSharedHandleTable = NULL。有了这些前置基础,接下来就可以开挖了。复制代码
- 0:002> dt ntdll!_PEB GdiSharedHandleTable 01051000
- +0x0f8 GdiSharedHandleTable : (null)
欢迎光临 ToB企服应用市场:ToB评测及商务社交产业平台 (https://dis.qidao123.com/) | Powered by Discuz! X3.4 |