Exetools  

Go Back   Exetools > General > General Discussion

Notices

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #2  
Old 09-05-2004, 18:30
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
you are trying to break CopyMem II enhanced version of Armadillo. put EBFE on the start of the 1000 bytes is wrong and so you won't get OEP.

a description how it works:
the main-process act as a debugger on the second, the second process is crypted. the second process throws an exception @OEP because OEP is crypted, so the main-process decrypts it, but only 1000 bytes. now the second process will be executed till it lands again at crypted code, throws an exception and the main-process decrypts again a 1000 byte block and the other block will be encrypted which was executed before. you have to manage to decrypt the second process completely and then dump. WaitForDebugEvent is the key to get OEP and put it in a endless loop.
i think you should read Ricardos tutorial on GetRight 5. it's great for this type of Armadillo. there's also an OllyScript plugin which can do it automatically, but it doesn't work in all cases.

best regards,
MaRKuS TH-DJM

PS: WaitForDebugEvent is the communicator between main-process and second process, so it's the key for all, i think.
Reply With Quote
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
question about armadillo keytool SubzEro General Discussion 1 02-01-2015 08:29
2 small question about armadillo... Hero General Discussion 1 03-28-2007 19:39
Question about Armadillo 3.76 OrionOnion General Discussion 0 01-03-2005 09:17
Armadillo Question obelisk General Discussion 2 12-31-2004 12:14
Armadillo Question truth General Discussion 7 08-31-2004 18:46


All times are GMT +8. The time now is 13:27.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )