cloud_y
February 24th, 2004, 05:21
I use w32dasm to disassemble the kernel32.dll of win98, and see this:
Exported fn(): BackupRead - Ord:007Fh
Exported fn(): BackupWrite - Ord:0081h
Exported fn(): CallNamedPipeW - Ord:008Ah
Exported fn(): CreateFileW - Ord:00BCh
Exported fn(): CreateRemoteThread - Ord:00C8h
Exported fn(): FormatMessageW - Ord:012Eh
Exported fn(): GetNamedPipeHandleStateW - Ord:0190h
:BFFA9B8D 33C0 xor eax, eax
:BFFA9B8F B107 mov cl, 07
* Reference To: KERNEL32.Ordinal:0011
|
:BFFA9B91 E98377FCFF jmp BFF71319
I don't believe these export functions are the same, but why their address
are all 0xBFFA9B8D?
//thanks
Exported fn(): BackupRead - Ord:007Fh
Exported fn(): BackupWrite - Ord:0081h
Exported fn(): CallNamedPipeW - Ord:008Ah
Exported fn(): CreateFileW - Ord:00BCh
Exported fn(): CreateRemoteThread - Ord:00C8h
Exported fn(): FormatMessageW - Ord:012Eh
Exported fn(): GetNamedPipeHandleStateW - Ord:0190h
:BFFA9B8D 33C0 xor eax, eax
:BFFA9B8F B107 mov cl, 07
* Reference To: KERNEL32.Ordinal:0011
|
:BFFA9B91 E98377FCFF jmp BFF71319
I don't believe these export functions are the same, but why their address
are all 0xBFFA9B8D?
//thanks