<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>阁楼机房</title>
  <subtitle>自托管与家庭实验室笔记</subtitle>
  <link href="https://shabiwanyi.pkkb2.xyz/atom.xml" rel="self"/>
  <link href="https://shabiwanyi.pkkb2.xyz/"/>
  <id>https://shabiwanyi.pkkb2.xyz/</id>
  <updated>2026-10-02T10:00:00+08:00</updated>

  <entry>
    <title>某游戏大厂反作弊驱动分析：从代码去混淆到敏感行为还原，CVE-2025-45737任意内核读写漏洞复现、提权实验，附PoC</title>
    <link href="https://shabiwanyi.pkkb2.xyz/posts/kx-293132.html"/>
    <id>https://shabiwanyi.pkkb2.xyz/posts/kx-293132.html</id>
    <updated>2026-10-02T10:00:00+08:00</updated>
    <summary>​ 本文定位为抛砖引玉，分享一些实验性质的分析思路、代码验证方法，华中这几天降温有点猛，搞得有点小感冒，文章中如果存在表述不严谨、甚至出错的地方，欢迎在评论区指正</summary>
  </entry>
  <entry>
    <title>某网站瑞数6反爬逆向：从 412 拦截到借道浏览器会话，一次性翻完全部页列表</title>
    <link href="https://shabiwanyi.pkkb2.xyz/posts/kx-293131.html"/>
    <id>https://shabiwanyi.pkkb2.xyz/posts/kx-293131.html</id>
    <updated>2026-10-02T10:00:00+08:00</updated>
    <summary>需求是抓某网站「公告」频道的列表，自动翻页，把标题、链接、发布日期全量收下来。</summary>
  </entry>
  <entry>
    <title>闲来无事,逆向一个银狐病毒</title>
    <link href="https://shabiwanyi.pkkb2.xyz/posts/kx-293124.html"/>
    <id>https://shabiwanyi.pkkb2.xyz/posts/kx-293124.html</id>
    <updated>2026-10-02T10:00:00+08:00</updated>
    <summary>样本：chat-deepseek.exe，2,085,620 字节，x64，无签名。样本下载在最后面。 SHA256 68ae0cabadce8467534f8a41e9ca139b4b9a066aa20d1542547</summary>
  </entry>
  <entry>
    <title>一个 ARM64 自定义 VM 的分析与还原</title>
    <link href="https://shabiwanyi.pkkb2.xyz/posts/kx-293114.html"/>
    <id>https://shabiwanyi.pkkb2.xyz/posts/kx-293114.html</id>
    <updated>2026-10-01T10:00:00+08:00</updated>
    <summary>前段时间分析一个 Android ARM64 程序时，在 native 层遇到了一套自定义虚拟机。</summary>
  </entry>
  <entry>
    <title>某复合型木马分析（ScreenConnect后续）</title>
    <link href="https://shabiwanyi.pkkb2.xyz/posts/kx-293105.html"/>
    <id>https://shabiwanyi.pkkb2.xyz/posts/kx-293105.html</id>
    <updated>2026-10-01T10:00:00+08:00</updated>
    <summary>—— WinSysCache（SimpleRunPE）复合型恶意软件家族的挖矿、窃密、带宽变现分析</summary>
  </entry>
  <entry>
    <title>SigilHook：用 AngelScript 做 x86/x64 函数 Hook 的注入式运行时</title>
    <link href="https://shabiwanyi.pkkb2.xyz/posts/kx-293112.html"/>
    <id>https://shabiwanyi.pkkb2.xyz/posts/kx-293112.html</id>
    <updated>2026-09-30T10:00:00+08:00</updated>
    <summary>一句话概括：这是一个基于 PolyHook 2、用 AngelScript 驱动脚本 Hook 的 x86/x64 注入式运行时。目标是让常见的 Hook 逻辑尽量写在脚本里，改逻辑不用反复编译 DLL、重启工具链。</summary>
  </entry>
  <entry>
    <title>记一次 .ncm 文件格式分析</title>
    <link href="https://shabiwanyi.pkkb2.xyz/posts/kx-293108.html"/>
    <id>https://shabiwanyi.pkkb2.xyz/posts/kx-293108.html</id>
    <updated>2026-09-30T10:00:00+08:00</updated>
    <summary>先交代两句：样本是自己电脑上的本地文件，纯好奇这格式怎么封的，不干别的。地址和反编译都来自我手上某一个特定构建，仅供研究参考，别拿去对号入座。</summary>
  </entry>
  <entry>
    <title>头条评论 `_signature` 逆向实战：从 `_$jsvmprt` VM 字节码到纯 Node 零 Cookie 爬取用户评论</title>
    <link href="https://shabiwanyi.pkkb2.xyz/posts/kx-293096.html"/>
    <id>https://shabiwanyi.pkkb2.xyz/posts/kx-293096.html</id>
    <updated>2026-09-29T10:00:00+08:00</updated>
    <summary>摘要：本文按时间顺序，完整记录一条&quot;还原 _signature 并爬取评论&quot;的逆向全过程。目标接口的签名藏在 acrawler SDK 里，而 acrawler 的算法本体是一台自研 JS 虚拟机 _$jsvmprt 解</summary>
  </entry>
  <entry>
    <title>Windows 会话、Session 0 与进程 Token 隔离身份</title>
    <link href="https://shabiwanyi.pkkb2.xyz/posts/kx-293089.html"/>
    <id>https://shabiwanyi.pkkb2.xyz/posts/kx-293089.html</id>
    <updated>2026-09-28T10:00:00+08:00</updated>
    <summary>这个程序的功能是读取指定进程的会话位置、进程对象 Owner 和主 Token 身份字段。它把会话、对象安全描述符和访问令牌分开记录，避免把“在哪个登录环境运行”“谁拥有进程对象”和“进程以什么身份运行”混为同一个结论。</summary>
  </entry>
  <entry>
    <title>010 Editor 注册算法分析与注册机实现</title>
    <link href="https://shabiwanyi.pkkb2.xyz/posts/kx-293074.html"/>
    <id>https://shabiwanyi.pkkb2.xyz/posts/kx-293074.html</id>
    <updated>2026-09-28T10:00:00+08:00</updated>
    <summary>贴主是逆向初学菜鸟，第一次逆向学习大型软件（虽然是入门级），写下这个文章留作纪念</summary>
  </entry>
</feed>
