Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #16  
Old 10-28-2003, 15:56
xobor xobor is offline
Friend
 
Join Date: May 2002
Location: Slovakia
Posts: 115
Rept. Given: 6
Rept. Rcvd 4 Times in 4 Posts
Thanks Given: 2
Thanks Rcvd at 19 Times in 14 Posts
xobor Reputation: 5
so you have to wrote some kind of debugger, start app via createprocess and then in loop do WaitForDebugEvent, after start you can set bp at code location where loader writes unpacked section of code to memory, look if written unpacked code is what you are waiting for and if it is, you can patch code in memory, unset bp and let your app run.

maybe this helps
Reply With Quote
  #17  
Old 10-28-2003, 22:12
yaa
 
Posts: n/a
xobor it helps ... but that "look if written unpacked code is what you are waiting for" is kind of frightening.

yaa
Reply With Quote
  #18  
Old 10-29-2003, 14:48
xobor xobor is offline
Friend
 
Join Date: May 2002
Location: Slovakia
Posts: 115
Rept. Given: 6
Rept. Rcvd 4 Times in 4 Posts
Thanks Given: 2
Thanks Rcvd at 19 Times in 14 Posts
xobor Reputation: 5
hehe sorry for my ?English?

I mean that if you know you want to change e.g. 3B46FA7403 to 8B46FAEB03 you can wait in your debugee code for unpacking to 3B46FA7403 and then change it.

I can't explain it better so if it is not clear enough forget about it.

regards
Reply With Quote
  #19  
Old 10-30-2003, 04:00
yaa
 
Posts: n/a
Clear enough. Thx.

yaa
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Usermode APC Injection WorldCrackersUnited Source Code 4 06-05-2017 15:42


All times are GMT +8. The time now is 10:25.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )