Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 05-07-2005, 06:43
AdamD
 
Posts: n/a
zClient rebuilding IAT - Armadillo 3.78

This is a prolongation of http://forum.exetools.com/showthread.php?t=7425
devoted towards zclient posted below.

The problem is rebuilding the IAT because of Armadillo's alterations. The OOP for the attached file is 0x00029B73 for anyone who would like to take a stab at it. I would really like to know how it's done so I can learn from this specific attachment. Thanks to anyone who helps, it's greatly appreciated.

Lownoise, I'm interested in how you got the working dump, if you would please enlighten me.


Attachment
zclient.zip
http://forum.exetools.com/attachment.php?attachmentid=3005

Last edited by AdamD; 05-07-2005 at 06:46.
Reply With Quote
  #2  
Old 05-07-2005, 19:42
MEPHiST0 MEPHiST0 is offline
Friend
 
Join Date: Jul 2004
Location: In the depth of my soul
Posts: 33
Rept. Given: 1
Rept. Rcvd 28 Times in 5 Posts
Thanks Given: 1
Thanks Rcvd at 9 Times in 9 Posts
MEPHiST0 Reputation: 28
Lightbulb

seems to be Armadillo v4.xx, and an easy one at that...

the reason you probly cant get the whole IAT is armadillo moves it all around cause it doesnt need it all fancy to read it..
you can find tutorials on how to defeat arma and the normal iat screw here on exet00lz.. its just a simple jump patch and imprec will read the iat fine
and the only really noticable difference in normal arma 4, is the OutputDebugStringA exploit that chad uses..

:P
Reply With Quote
  #3  
Old 05-08-2005, 02:37
lownoise
 
Posts: n/a
First You have to patch the magic jump for the IAT so that are no redirected entrys
Then the import you find with Imprec you'll save it to file.
Code a startup routine or use Armtools to read your import table at startup of the program.
Last part is to dump the codesplicing sections and insert it in your dumped app.
When i'm at work i'll will attach a tutorial wich you can follow to recreate you app.
Remember that you have to read some tutorials about unpacking armadillo with iat screw and codesplicing!

Good luck


Found the tutorials on my hdd so here they are...
Attached Files
File Type: zip ArmaTute3x4x.zip (594.4 KB, 138 views)

Last edited by lownoise; 05-08-2005 at 02:45. Reason: Found the tuts on my hdd
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Rebuilding Problem ! Unforgiv3N General Discussion 10 09-09-2005 03:55
Import Rebuilding Without Import Table Kerlingen General Discussion 11 01-13-2005 10:24


All times are GMT +8. The time now is 12:16.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )