Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 09-30-2014, 16:17
bridgeic bridgeic is offline
Friend
 
Join Date: Jun 2012
Posts: 88
Rept. Given: 7
Rept. Rcvd 3 Times in 3 Posts
Thanks Given: 0
Thanks Rcvd at 7 Times in 6 Posts
bridgeic Reputation: 3
Question Anyone can help interpret the algorithm on the data conversion below(ECC related)?

Test case: as attached
Command used: test.exe -i testin.txt -o testout.txt


Anyone can help interpret the algorithm on the data conversion below(ECC related)?

1irst time data conversion:
0E 8D 2D 71 D1 03 6B 26 A3 B8 B5 97 43 B9 FF 2B 50 F1 73 34 FB 45 DD 51 33 07 0F F8 36 0D
=>
EF A2 E5 5E 0E 3D 96 AB 9E E2 33 71 F6 28 A3 2D F4 7A DB 36 43 8D 7C A7 C7 4E 59 B5 B3 0A

2nd time data conversion:
EF A2 E5 5E 0E 3D 96 AB 9E E2 33 71 F6 28 A3 2D F4 7A DB 36 43 8D 7C A7 C7 4E 59 B5 B3 0A
=>
B6 D5 FE A1 99 E0 85 73 4A D4 48 55 08 51 B7 D2 0B 85 24 C9 BC 72 83 58 38 B1 A6 4A 4C 15


Trace details with OD:
00464B73 |. 56 |PUSH ESI
00464B74 |. 51 |PUSH ECX
00464B75 |. 52 |PUSH EDX
00464B76 |. E8 B5C9FFFF |CALL test._Ox4993

ESI = 0012D244, run throuth 00464B76,check [0012D248],
0012D248 0E 8D 2D 71 D1 03 6B 26 A3 B8 B5 97 43 B9 FF 2B
0012D258 50 F1 73 34 FB 45 DD 51 33 07 0F F8 36 0D 00 00

(a) 1st time data conversion
0049FE03 |. 57 PUSH EDI
0049FE04 |. 56 PUSH ESI
0049FE05 |. 52 PUSH EDX
0049FE06 |. E8 654CFCFF CALL test._Ox5206

run through 0049FE06, check [0012D248]
0012D248 EF A2 E5 5E 0E 3D 96 AB 9E E2 33 71 F6 28 A3 2D
0012D258 F4 7A DB 36 43 8D 7C A7 C7 4E 59 B5 B3 0A 00 00

(b) 2nd time data conversion
0049FE18 |. 57 PUSH EDI
0049FE19 |. 57 PUSH EDI
0049FE1A |. 56 PUSH ESI
0049FE1B |. E8 00160000 CALL test._Ox5164

run through 0049FE1B, check [0012D248]
0012D248 B6 D5 FE A1 99 E0 85 73 4A D4 48 55 08 51 B7 D2
0012D258 0B 85 24 C9 BC 72 83 58 38 B1 A6 4A 4C 15 00 00
Attached Files
File Type: rar testcase.rar (292.0 KB, 7 views)

Last edited by bridgeic; 09-30-2014 at 16:55.
Reply With Quote
  #2  
Old 10-01-2014, 17:39
bridgeic bridgeic is offline
Friend
 
Join Date: Jun 2012
Posts: 88
Rept. Given: 7
Rept. Rcvd 3 Times in 3 Posts
Thanks Given: 0
Thanks Rcvd at 7 Times in 6 Posts
bridgeic Reputation: 3
The second time data conversion can be skipped, just ECC order n minus 1st number

n = 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 5A 79 FE C6 7C B6 E9 1F 1C 1D A8 00 E4 78 A5
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Firmware Analysis - ZLIB file conversion to Bitmap psgama General Discussion 3 08-02-2021 05:03
About cracking related IRC channels Hero General Discussion 1 07-11-2005 04:32


All times are GMT +8. The time now is 21:38.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )