This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
int add_func(int a, int b) { | |
int c = a + b; | |
return c; | |
} | |
// main | |
int main(int argc, char *argv[]) { | |
int d = add_func(1, 2); |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
using System; | |
using System.Windows.Forms; | |
namespace ManagedDll{ | |
public class Test{ | |
public static int func(String pwzArgument){ | |
MessageBox.Show(pwzArgument, "Caption"); | |
return 0; | |
} | |
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
#include<metahost.h> | |
#include<stdio.h> | |
#include<Windows.h> | |
#pragma comment(lib, "mscoree.lib") | |
void clr(){ | |
HRESULT hr; | |
DWORD dRet = 0; |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003"> | |
<Target Name="Sample"> | |
<hoge /> | |
</Target> | |
<UsingTask | |
TaskName="hoge" | |
TaskFactory="CodeTaskFactory" | |
AssemblyFile="C:\Windows\Microsoft.Net\Framework\v4.0.30319\Microsoft.Build.Tasks.v4.0.dll" > | |
<Task> | |
<Code Type="Class" Language="cs"> |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
import idaapi | |
class Test(idaapi.plugin_t): | |
flags = idaapi.PLUGIN_PROC | |
comment = "My Test IDA Plugin" | |
help = "Test Plugin help" | |
wanted_name = "My_Test_Plugin" | |
wanted_hotkey = "" | |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
#include<Windows.h> | |
#include<iphlpapi.h> | |
#include<stdio.h> | |
#pragma comment(lib,"IPHLPAPI.lib") | |
char DomainName[0x84]; | |
char HostName[0x84]; | |
char BufStr[304]; |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
from idaapi import * | |
from idautils import * | |
from idc import * | |
b_addr = 0x003021AA | |
LoadDebugger("windbg", 1) | |
add_bpt(b_addr,0,BPT_SOFT) |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
from idaapi import * | |
from idautils import * | |
from idc import * | |
ea = BeginEA() | |
for func in Functions(SegStart(ea),SegEnd(ea)): | |
func_name = GetFunctionName(func) | |
if func_name.find("sub_") != -1: |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
from idaapi import * | |
from idautils import * | |
from idc import * | |
func = ["sub_12A1E00"] | |
for x in func: | |
addr = LocByName(x) | |
pseudo_code = decompile(addr) |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
typedef struct _PEB { | |
BYTE Reserved1[2]; | |
BYTE BeingDebugged; | |
BYTE Reserved2[1]; | |
PVOID Reserved3[2]; | |
PPEB_LDR_DATA Ldr; | |
PRTL_USER_PROCESS_PARAMETERS ProcessParameters; | |
PVOID Reserved4[3]; | |
PVOID AtlThunkSListPtr; | |
PVOID Reserved5; |
NewerOlder