转至:http://www.pediy.com/kssd/pediy08/pediy8-682.htm
下面是反汇编ntdll.dll的NtCreateEvent部分 NtCreateEvent调用了int 2E
Exported fn(): NtCreateEvent – Ord:005Ah
Exported fn(): ZwCreateEvent – Ord:02E2h
:77F83219 B81E000000 mov eax, 0000001E
:77F8321E 8D542404 lea edx, dword ptr [esp+04]
:77F83222 CD2E int 2E
:77F83224 C21400 ret 0014
int 2e的使用方法:
mov eax, service_id
lea edx, service_param
int 2e
Windows 2000 int 2e 功能表
共248个
EAX = function number
EDX = address of parameter block
0x0 AcceptConnectPort
0x1 AccessCheck
0x2 AccessCheckAndAuditAlarm
0x3 AccessCheckByType
0x4 AccessCheckByTypeAndAuditAlarm
0x5 AccessCheckByTypeResultList
0x6 AccessCheckByTypeResultListAndAuditAlarm
0x7 AccessCheckByTypeResultListAndAuditAlarmByHandle
继续阅读“关于INT 2E 转帖留用 关于ANTI-DEBUG&ANTI-ANTI-DEBUG”