Dave.exe
TeamRingZero
DWORD GetKernel32Address()
{
DWORD kernelAddr = 0;

__asm
{
mov ebx, fs:[0x30] // Get PEB
mov ebx, [ebx + 0xC] // Get PEB->Ldr
mov ebx, [ebx + 0x14] // Get 1st Entry
mov ebx, [ebx] // Get 2nd Entry
mov ebx, [ebx] // Get 3rd Entry
mov ebx, [ebx + 0x10] // Get the 3rd entry's base address (kernel32)
mov kernelAddr, ebx
}
return kernelAddr;
DWORD GetKernel32Address()
{
DWORD kernelAddr = 0;

__asm
{
mov ebx, fs:[0x30] // Get PEB
mov ebx, [ebx + 0xC] // Get PEB->Ldr
mov ebx, [ebx + 0x14] // Get 1st Entry
mov ebx, [ebx] // Get 2nd Entry
mov ebx, [ebx] // Get 3rd Entry
mov ebx, [ebx + 0x10] // Get the 3rd entry's base address (kernel32)
mov kernelAddr, ebx
}
return kernelAddr;
Currently Offline
Comments
L>E>G>I>T 13 Oct, 2017 @ 10:11am 
p i z z a
Dave.exe 13 Oct, 2017 @ 8:21am 
b o n e l e s s
ad2fs 13 Oct, 2017 @ 6:34am 
-rep h4xor