[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <001f01c52486$b02bb840$0200a8c0@box>
From: class101 at hat-squad.com (class 101)
Subject: 2 nice pop/pop/ret :) (update)
Here is the result of comparing some huge list of pop/pop/ret of XP SP1,
SP1a, SP2 ENGLISH
I got 2 universal offsets accross those 3 Os
SP2 ENGLISH
0x71ABE325 pop esi - pop - retbis - WS2_32.DLL
0x77E7F69E pop ebx - pop - retbis - RPCRT4.DLL
SP1a ENGLISH
0x71ABE325 pop edi - pop - retbis - WS2_32.DLL
0x77E7F69E pop ebx - pop - retbis - KERNEL32.DLL
SP1 ENGLISH
0x71ABE325 pop edi - pop - retbis - WS2_32.DLL
0x77E7F69E pop ebx - pop - retbis - KERNEL32.DLL
enjoy :)
-------------------------------------------------------------
class101
Jr. Researcher
Hat-Squad.com
-------------------------------------------------------------
Powered by blists - more mailing lists