﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>C++博客-随笔</title><link>http://www.cppblog.com/plzy86/</link><description /><language>zh-cn</language><lastBuildDate>Sat, 18 Apr 2026 06:46:45 GMT</lastBuildDate><pubDate>Sat, 18 Apr 2026 06:46:45 GMT</pubDate><ttl>60</ttl><item><title>PTE的获取</title><link>http://www.cppblog.com/plzy86/archive/2008/04/16/47222.html</link><dc:creator>A-Yu</dc:creator><author>A-Yu</author><pubDate>Wed, 16 Apr 2008 06:10:00 GMT</pubDate><guid>http://www.cppblog.com/plzy86/archive/2008/04/16/47222.html</guid><wfw:comment>http://www.cppblog.com/plzy86/comments/47222.html</wfw:comment><comments>http://www.cppblog.com/plzy86/archive/2008/04/16/47222.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/plzy86/comments/commentRss/47222.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/plzy86/services/trackbacks/47222.html</trackback:ping><description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;MS中的内存管理以进程为单位,每个进程都有4G的空间,从操作系统原理可得逻辑地址到物理地址之间是以CR3做选择子,与逻辑地址的高十位相加得到页目录的地址,在以次高十位做索引,从页目录中得到页表的地址,在加上12位偏移量就可得到物理地址.<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;但在WINDOWS中,每个进程的页目录项总是被映射在0xC0000000到0xC03FFFFF的逻辑地址中,因此,如果在用户层的当前进程地址空间中求已知地址的页表项将变得简单,只需从0XC0000000开始以高十位作为索引移动到对应的页目录项,在以次10位为索引就可以找到页表项的地址,有了这个,我们就可以修改这一些的控制信息,比如把只读改为可写,绕过COPY ON WRITE机制等等..当然以上之所以方便都是以逻辑地址为操作单位的.<br>上面的公式整理一下就可得:<br>假设地址为VA<br><br>
<div style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; BACKGROUND-COLOR: #99ccff">PPTE=0xC000000 + (VA&gt;&gt;22)*PAGE_SIZE + (VA&amp;0x003FFFFF) &gt;&gt;12<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=(VA &gt;&gt; 10) &amp; 0xFFFFFFFC + 0xC0000000<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=&nbsp;&nbsp;&nbsp;(VA &gt;&gt; 12) &lt;&lt; 2 +0xC0000000<br>因此我们可以直接定义一个宏,从而在我们要修改我们要访问的页属性时更加方便<br>#define GET_PTE(VA)&nbsp;&nbsp;&nbsp; ((VA &gt;&gt; 12 ) * 4 +0xC0000000)<br></div>
当我们要将自己的代码插入别人的地址时,仅仅需要 *(PUCHAR)(GET_PTE(VA)+3) |= 2 就可以把该页的ReadOnly去掉
<img src ="http://www.cppblog.com/plzy86/aggbug/47222.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/plzy86/" target="_blank">A-Yu</a> 2008-04-16 14:10 <a href="http://www.cppblog.com/plzy86/archive/2008/04/16/47222.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>报个到</title><link>http://www.cppblog.com/plzy86/archive/2008/03/31/45825.html</link><dc:creator>A-Yu</dc:creator><author>A-Yu</author><pubDate>Mon, 31 Mar 2008 09:07:00 GMT</pubDate><guid>http://www.cppblog.com/plzy86/archive/2008/03/31/45825.html</guid><wfw:comment>http://www.cppblog.com/plzy86/comments/45825.html</wfw:comment><comments>http://www.cppblog.com/plzy86/archive/2008/03/31/45825.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cppblog.com/plzy86/comments/commentRss/45825.html</wfw:commentRss><trackback:ping>http://www.cppblog.com/plzy86/services/trackbacks/45825.html</trackback:ping><description><![CDATA[博客刚开通,先占个位......
<img src ="http://www.cppblog.com/plzy86/aggbug/45825.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cppblog.com/plzy86/" target="_blank">A-Yu</a> 2008-03-31 17:07 <a href="http://www.cppblog.com/plzy86/archive/2008/03/31/45825.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item></channel></rss>