View Single Post
  #1  
Old 03-12-2007, 10:16
Newbie_Cracker's Avatar
Newbie_Cracker Newbie_Cracker is offline
VIP
 
Join Date: Jan 2005
Posts: 227
Rept. Given: 72
Rept. Rcvd 26 Times in 12 Posts
Thanks Given: 50
Thanks Rcvd at 25 Times in 18 Posts
Newbie_Cracker Reputation: 26
int3 and stolen bytes !

Hi friends.

I think it's an old question.

Tonight I played with CD-Cops and it defeated me !!

The question is:

How to find the stolen bytes in child process which is debugged by its father?
I debugged the father, but I didn't understand where the original bytes written back to child.

As you know, Armadillo with Nanomite protection, Safedisk and Securom use the same method.

How do they execute original bytes? Father executes the codes virtually or child executes them when they were written back at original addresses?

Regards

--------------
edited:

I red the haggar's tut on unpacking SafeDisk. Is there anybody to know the tricks of CD-COPS?
__________________
In memory of UnREal RCE...

Last edited by Newbie_Cracker; 03-12-2007 at 20:00.
Reply With Quote