View Single Post
  #13  
Old 10-24-2017, 13:50
giv's Avatar
giv giv is offline
VIP
 
Join Date: Jan 2011
Location: Romania
Posts: 1,663
Rept. Given: 803
Rept. Rcvd 1,283 Times in 561 Posts
Thanks Given: 228
Thanks Rcvd at 567 Times in 241 Posts
giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299
Quote:
Originally Posted by wilson bibe View Post
e.reverse is this: learn,learn,learn...brain,brain,brain....and patience.
I will add here the term "and rehearsal".

Quote:
Originally Posted by Benten View Post
From the bottom of my heart, I am not interested in cracking some software. I am interested in learning the real thing like in the PDF, that's it.
Just watch my commands in the unpack script and you will know when, why and what you must do to unpack a Armadillo file. And is there the IAT elimination feature present. IAT scrambling is import redirection - imports are in the import table but they are redirected and their names are not visible and you need to reconstruct their names - and IAT elimination is that imports table is scattered all over the file and you need to gather and put in one place. Just step command by command and you will see the magic reveal. You do not need any tutorial when a script is available. Just trace command by command and you will see live the things happening. Then you will conclude by yourself. All protectors do the same thing. Encapsulate the protected file into their own shell and try to fool the debugger by hiding the OEP and parts of the code or redirect or rebase some imports or resources. Just the method is different on each protector.
Attached Files
File Type: zip Armadillo 9.64 unpack script version. 0.2.zip (9.3 KB, 24 views)

Last edited by giv; 10-24-2017 at 14:08.
The Following 2 Users Say Thank You to giv For This Useful Post:
abhi93696 (10-24-2017), tonyweb (10-30-2017)