﻿{"id":1817,"date":"2017-11-26T22:03:28","date_gmt":"2017-11-26T14:03:28","guid":{"rendered":"http:\/\/www.th-sjy.com\/?p=1817"},"modified":"2017-11-26T22:03:28","modified_gmt":"2017-11-26T14:03:28","slug":"dll-%e6%b3%a8%e5%85%a5%e7%a7%bb%e9%99%a4%e5%b7%a5%e5%85%b7remotedll5-0%e6%b1%89%e5%8c%96%e5%8e%bb%e5%b9%bf%e5%91%8a%e7%89%88","status":"publish","type":"post","link":"http:\/\/www.th-sjy.com\/?p=1817","title":{"rendered":"DLL \u6ce8\u5165\u79fb\u9664\u5de5\u5177(RemoteDLL)5.0\u6c49\u5316\u53bb\u5e7f\u544a\u7248"},"content":{"rendered":"<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full\" src=\"http:\/\/oo3fu13aw.bkt.clouddn.com\/2017-11-26_215055.jpg\" width=\"627\" height=\"691\" \/><\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full\" src=\"http:\/\/oo3fu13aw.bkt.clouddn.com\/2017-11-26_215106.jpg\" width=\"375\" height=\"269\" \/><\/p>\n<p><strong>RemoteDLL<\/strong> \u662f\u4e00\u6b3e\u7b80\u5355\u6613\u7528\u7684\u4ece\u8fdc\u7a0b\u8fdb\u7a0b\u4e2d\u6ce8\u5165\u6216\u79fb\u9664 DLL \u7684\u5f3a\u5927\u5de5\u5177\u3002\u5b83\u662f\u57fa\u4e8e\u6d41\u884c\u7684 Dll \u6ce8\u5165\u6280\u672f\u3002<\/p>\n<p><strong>\u5b83\u652f\u6301\u4ee5\u4e0b DLL \u6ce8\u5165\u65b9\u6cd5\uff1a<\/strong><br \/>\n&#8211; \u521b\u5efa\u8fdc\u7a0b\u7ebf\u7a0b<br \/>\n&#8211; \u521b\u5efa NT \u7ebf\u7a0b\uff08\u9002\u7528\u4e8e Vista\/Windows 7 \u4e2d\u8de8\u4f1a\u8bdd DLL \u6ce8\u5165\uff09<br \/>\n&#8211; \u961f\u5217\u7528\u6237 APC\uff08\u5ef6\u8fdf\u6ce8\u5165\uff09<\/p>\n<p>\u4ece\u8fdb\u7a0b\u4e2d\u79fb\u9664 DLL \u6216\u91ca\u653e DLL \u662f RemoteDLL \u7684\u72ec\u7279\u529f\u80fd\u3002\u5b83\u53ef\u5e2e\u52a9\u60a8\u7acb\u5373\u4ece\u76ee\u6807\u8fdb\u7a0b\u4e2d\u5b8c\u5168\u79fb\u9664 DLL\u3002\u5b83\u652f\u6301 32 \u4f4d\u548c 64 \u4f4d\u8fdb\u7a0b\u4e2d\u7684 DLL \u6ce8\u5165\u548c\u79fb\u9664\u3002<\/p>\n<p>\u73b0\u5728\uff0c\u8bb8\u591a\u6076\u610f\u8f6f\u4ef6\u548c\u95f4\u8c0d\u8f6f\u4ef6\u7a0b\u5e8f\u4f7f\u7528 DLL \u6ce8\u5165\u6280\u672f\u5c06\u81ea\u5df1\u9690\u85cf\u5230\u5408\u6cd5\u7684\u7cfb\u7edf\u8fdb\u7a0b\u4e2d\u3002\u4e00\u65e6\u6ce8\u5165\uff0c\u9664\u4e86\u6740\u6b7b\u8fdb\u7a0b\u672c\u8eab\u4e4b\u5916\uff0c\u6ca1\u6709\u529e\u6cd5\u5220\u9664\u8fd9\u6837\u7684 DLL\u3002\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0cRemoteDLL \u53ef\u5e2e\u52a9\u60a8\u8f7b\u677e\u5730\u4ece\u76ee\u6807\u8fdb\u7a0b\u4e2d\u5220\u9664\u8fd9\u4e9b\u6076\u610f\u7684 DLL\u3002<\/p>\n<p><strong>\u7279\u70b9\uff1a<\/strong><br \/>\n&#8211; \u8de8\u4f1a\u8bdd\u8fb9\u754c\u5411\u8fdc\u7a0b\u8fdb\u7a0b\u6ce8\u5165 DLL<br \/>\n&#8211; \u652f\u6301\u6240\u6709\u5e73\u53f0\u4e0a\u7684 32 \u4f4d\u548c 64 \u4f4d\u8fdb\u7a0b\u3002<br \/>\n&#8211; \u5b8c\u5168\u79fb\u9664\u8fdc\u7a0b\u8fdb\u7a0b\u4e2d\u7684 DLL\u3002<br \/>\n&#8211; \u652f\u6301\u591a\u79cd\u6ce8\u5165\u65b9\u6cd5\uff0c\u5305\u62ec\u521b\u5efa\u8fdc\u7a0b\u7ebf\u7a0b\u3001\u521b\u5efa NT \u7ebf\u7a0b\u3001\u961f\u5217\u7528\u6237 APC<br \/>\n&#8211; \u901a\u8fc7\u52a8\u6001\u8ba1\u7b97\u5730\u5740\u4e0e ASLR\uff08\u5730\u5740\u7a7a\u95f4\u5e03\u5c40\u968f\u673a\u5316\uff09\u4e00\u8d77\u5de5\u4f5c\u3002<br \/>\n&#8211; \u9ad8\u7ea7\u8fdb\u7a0b\u5217\u8868\uff0c\u5305\u542b\u8be6\u7ec6\u7684\u8fdb\u7a0b\u4fe1\u606f\uff0c\u5982 PID\u3001\u4f1a\u8bdd\u3001ASLR\u3001DEP\u3001\u7528\u6237\u540d\u79f0\u7b49\u3002<br \/>\n&#8211; \u62d6\u653e\u529f\u80fd\u53ef\u5feb\u901f\u62d6\u52a8 DLL \u6587\u4ef6\u8fdb\u884c\u9009\u62e9\u3002<br \/>\n&#8211; \u5c06 DLL \u64cd\u4f5c\u62a5\u544a\u4fdd\u5b58\u5230\u6587\u672c\u6587\u4ef6<br \/>\n&#8211; \u6613\u4e8e\u4f7f\u7528\uff0c\u6709\u5438\u5f15\u529b\u7684 GUI \u754c\u9762<br \/>\n&#8211; \u5b8c\u5168\u4fbf\u643a\u5f0f\u7248\u672c\uff0c\u60a8\u53ef\u4ee5\u76f4\u63a5\u8fd0\u884c\u5b83\uff0c\u800c\u65e0\u9700\u4efb\u4f55\u5b89\u88c5\u3002<\/p>\n<p><strong>\u4f7f\u7528 RemoteDLL\uff1a<\/strong><br \/>\nRemoteDLL \u662f\u975e\u5e38\u5bb9\u6613\u4f7f\u7528\u5177\u6709\u7b80\u5355 GUI \u754c\u9762\u7684\u5de5\u5177\u3002\u60a8\u53ef\u4ee5\u4f7f\u7528\u5b83\u6765\u5c06 DLL \u6ce8\u5165\u5230\u76ee\u6807\u8fdb\u7a0b\u6216\u4ece\u8fdc\u7a0b\u8fdb\u7a0b\u4e2d\u5220\u9664\u6076\u610f\u7684 DLL\u3002<\/p>\n<p>\u5bf9\u4e8e\u4ece 32 \u4f4d\u8fdb\u7a0b\uff08\u5728 32 \u4f4d\u6216 64 \u4f4d\u5e73\u53f0\u4e0a\uff09\u6ce8\u5165 DLL \u6216\u5220\u9664 DLL \u8bf7\u4f7f\u7528 RemoteDll32.exe\u3002\u5bf9\u4e8e 64 \u4f4d\u7684\u8fdb\u7a0b\u8bf7\u4f7f\u7528 RemoteDll64.exe\u3002<\/p>\n<p><strong>\u5c06 DLL \u6ce8\u5165\u8fdc\u7a0b\u8fdb\u7a0b\uff1a<\/strong><br \/>\n&#8211; \u542f\u52a8 RemoteDll<br \/>\n&#8211; \u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u201c\u6ce8\u5165 DLL\u201d\u64cd\u4f5c\u88ab\u9009\u4e2d\u3002<br \/>\n&#8211; \u9009\u62e9\u6ce8\u5165\u65b9\u6cd5\uff0c\u5efa\u8bae\u4f7f\u7528\u201c\u521b\u5efa\u8fdc\u7a0b\u7ebf\u7a0b\u201d\u3002<br \/>\n&#8211; \u70b9\u51fb\u201c\u8fdb\u7a0b\u201d\u6309\u94ae\u9009\u62e9\u76ee\u6807\u8fdb\u7a0b\uff0c\u8fd9\u5c06\u663e\u793a\u6240\u6709\u6b63\u5728\u8fd0\u884c\u8fdb\u7a0b\u7684\u8be6\u7ec6\u4fe1\u606f\u3002<br \/>\n&#8211; \u7a0b\u9009\u62e9\u8fdb\u540e\uff0c\u60a8\u5fc5\u987b\u9009\u62e9\u8981\u6ce8\u5165\u7684 DLL\uff0c\u60a8\u53ef\u4ee5\u5c06 DLL \u6587\u4ef6\u62d6\u653e\u5230\u7a97\u53e3\u3002<br \/>\n&#8211; \u6700\u540e\u70b9\u51fb\u201c\u6ce8\u5165 DLL\u201d\u6309\u94ae\u5f00\u59cb\u64cd\u4f5c\u3002<br \/>\n&#8211; \u60a8\u5c06\u770b\u5230\u8be6\u7ec6\u7684\u72b6\u6001\u62a5\u544a\u3002\u70b9\u51fb\u201c\u4fdd\u5b58\u201d\u6309\u94ae\u53ef\u5c06\u6574\u4e2a\u72b6\u6001\u4fdd\u5b58\u5230\u4e00\u4e2a\u6587\u672c\u6587\u4ef6\u4e2d\u3002<\/p>\n<p><strong>\u4ece\u8fdc\u7a0b\u8fdb\u7a0b\u4e2d\u79fb\u9664 DLL\uff1a<\/strong><br \/>\n&#8211; \u542f\u52a8 RemoteDll<br \/>\n&#8211; \u9009\u62e9\u201c\u79fb\u9664 DLL\u201d\u64cd\u4f5c\u3002<br \/>\n&#8211; \u7136\u540e\u9009\u62e9\u6ce8\u5165\u65b9\u6cd5\uff0c\u5efa\u8bae\u4f7f\u7528\u201c\u521b\u5efa\u8fdc\u7a0b\u7ebf\u7a0b\u201d\u3002<br \/>\n&#8211; \u70b9\u51fb\u201c\u8fdb\u7a0b\u201d\u6309\u94ae\u9009\u62e9\u76ee\u6807\u8fdb\u7a0b\uff0c\u8fd9\u5c06\u663e\u793a\u6240\u6709\u6b63\u5728\u8fd0\u884c\u8fdb\u7a0b\u7684\u8be6\u7ec6\u4fe1\u606f\u3002<br \/>\n&#8211; \u9009\u62e9\u8fdb\u7a0b\u540e\uff0c\u70b9\u51fb\u201cDLL\u201d\u6309\u94ae\u9009\u62e9\u8981\u4ece\u6b64\u8fdb\u7a0b\u4e2d\u5220\u9664\u7684 DLL\u3002<br \/>\n&#8211; \u8fd9\u5c06\u542f\u52a8\u4e00\u4e2a\u65b0\u7684\u5bf9\u8bdd\u6846\uff0c\u663e\u793a\u9009\u62e9\u8fdb\u7a0b\u4e2d\u52a0\u8f7d\u7684\u6240\u6709 DLL\u3002\u53ea\u80fd\u4ece\u8fdb\u7a0b\u4e2d\u79fb\u9664\u52a8\u6001\u52a0\u8f7d\u7684 DLL\u3002<br \/>\n&#8211; \u6700\u540e\u70b9\u51fb\u201c\u79fb\u9664 DLL\u201d\u6309\u94ae\u5f00\u59cb\u64cd\u4f5c\u3002<br \/>\n&#8211; \u60a8\u5c06\u770b\u5230\u8be6\u7ec6\u7684\u72b6\u6001\u62a5\u544a\u3002\u70b9\u51fb\u201c\u4fdd\u5b58\u201d\u6309\u94ae\u53ef\u5c06\u6574\u4e2a\u72b6\u6001\u4fdd\u5b58\u5230\u4e00\u4e2a\u6587\u672c\u6587\u4ef6\u4e2d\u3002<\/p>\n<p><strong>\u6ce8\u610f\uff1a<\/strong><br \/>\n1\u3001\u5728\u4ece\u9ad8\u6743\u9650\u6216\u7cfb\u7edf\u8fdb\u7a0b\u4e2d\u6ce8\u5165\u6216\u79fb\u9664 DLL \u65f6\uff0c\u8bf7\u4ee5\u7ba1\u7406\u5458\u8eab\u4efd\u8fd0\u884c RemoteDll\uff1b<br \/>\n2\u3001\u5bf9\u4e8e\u4ece 64 \u4f4d\u8fdb\u7a0b\u6ce8\u5165\u6216\u5220\u9664 DLL \u65f6\uff0c\u53ea\u652f\u6301\u201c\u521b\u5efa\u8fdc\u7a0b\u7ebf\u7a0b\u201d\u7684\u65b9\u6cd5\u3002\u5bf9\u4e8e 32 \u4f4d\u8fdb\u7a0b\uff0c\u652f\u6301\u6240\u6709\u7684 3 \u79cd\u6ce8\u5165\u65b9\u6cd5\u3002<\/p>\n<p><strong>\u652f\u6301\u7cfb\u7edf\uff1a<\/strong>Windows XP\u30012003\u3001Vista\u3001Windows 7\u3001Windows 8\u3001Windows 10<\/p>\n<p><strong>v5.0 \u7248\u672c\u66f4\u65b0\uff1a<\/strong>2017\u5e747\u670814\u65e5<br \/>\n\u65b0\u7248\u672c\u652f\u6301\u5728 Windows 10 \u4e0a\u6ce8\u5165\u548c\u5220\u9664 DLL\u3002\u8fd8\u5305\u62ec\u65b0\u7684\u5b89\u88c5\u7a0b\u5e8f\u3002<\/p>\n<p><strong>\u6b64\u6c49\u5316\u53bb\u5e7f\u544a\u7248\u7531 th_sjy \u6c49\u5316\u5206\u4eab\uff0c\u53bb\u9664\u4e86\u6240\u6709\u70b9\u51fb\u5e7f\u544a\u548c\u94fe\u63a5\u3002<\/strong><\/p>\n<p><span style=\"color: #008000;\"><strong>v5.0 \u6c49\u5316\u53bb\u5e7f\u544a\u7248\u4e0b\u8f7d\uff1a<\/strong><\/span><br \/>\n<span style=\"color: #008000;\"><strong>32 \u4f4d\uff1a<\/strong><\/span><span class=\"easy2hide_notice\"><span style=\"color: #ff0000;\">\u6b64\u5185\u5bb9\u5df2\u9690\u85cf\uff0c\u8bc4\u8bba\u540e\u5237\u65b0\u9875\u9762\u67e5\u770b<\/span><\/span><br \/>\n<span style=\"color: #008000;\"><strong>64 \u4f4d\uff1a<\/strong><\/span><span class=\"easy2hide_notice\"><span style=\"color: #ff0000;\">\u6b64\u5185\u5bb9\u5df2\u9690\u85cf\uff0c\u8bc4\u8bba\u540e\u5237\u65b0\u9875\u9762\u67e5\u770b<\/span><\/span><\/p>\n<p>\u8f6c\u8f7d\u8bf7\u6ce8\u660e\uff1a<a href=\"http:\/\/www.th-sjy.com\">th_sjy \u4e13\u6ce8\u8f6f\u4ef6\u6c49\u5316\u548c\u8d44\u6e90\u5206\u4eab\uff0c<\/a> &raquo; <a href=\"http:\/\/www.th-sjy.com\/?p=1817\">DLL \u6ce8\u5165\u79fb\u9664\u5de5\u5177(RemoteDLL)5.0\u6c49\u5316\u53bb\u5e7f\u544a\u7248<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>RemoteDLL \u662f\u4e00\u6b3e\u7b80\u5355\u6613\u7528\u7684\u4ece\u8fdc\u7a0b\u8fdb\u7a0b\u4e2d\u6ce8\u5165\u6216\u79fb\u9664 DLL \u7684\u5f3a\u5927\u5de5\u5177\u3002\u5b83\u662f\u57fa\u4e8e\u6d41\u884c\u7684 Dll \u6ce8\u5165\u6280 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_links_to":"","_links_to_target":""},"categories":[4],"tags":[],"_links":{"self":[{"href":"http:\/\/www.th-sjy.com\/index.php?rest_route=\/wp\/v2\/posts\/1817"}],"collection":[{"href":"http:\/\/www.th-sjy.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.th-sjy.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.th-sjy.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.th-sjy.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1817"}],"version-history":[{"count":0,"href":"http:\/\/www.th-sjy.com\/index.php?rest_route=\/wp\/v2\/posts\/1817\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.th-sjy.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1817"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.th-sjy.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1817"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.th-sjy.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1817"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}