#1
|
|||
|
|||
Dumping a dll with ollydump
Hi,
I'm trying to dump a packed DLL using ollydump. I wrote a simple program that just loads the DLL, and I've traced to the original entrypoint and am ready to dump, but I don't know how to figure out what addresses I should put in "Base of Code" and "Base of Data". Do I also need to change something in the section table? Please help me out... |
#2
|
|||
|
|||
(Just a general note before you read this, I'm not 100% sure of the advice I'm going to give, so be weary.)
Why don't you load the dll into Olly? If you're using your method, as far as I'm aware that's fine, but when it comes to dumping it, isn't the base addresses automatically put there? As for the tables, are you on about the reconstruction of the import tables, if so I'd use Imprec (Import reconstructor) to do that. |
#3
|
||||
|
||||
how want you do that? a dll can't loaded without a executable. and the base-address is then from the dll-loader & wrong OEP.
|
#4
|
|||
|
|||
Oh I understand what he wants to do now. Why would you want to do that? Is the dll what does the protection? I'm not 100% sure of the big picture here, perhaps you could paint it for us?
|
#5
|
|||
|
|||
Well I managed to dump it successfully with procdump and imprec. I originally thought the dll would have something to do with the protection, but it turns out it had nothing of interest. Oh well.. at least I learned something new.
sorry to waste your time... |
#6
|
|||
|
|||
You solved it, so I don't think our time was wasted, anyways, congratulations.
Last edited by Nilrem; 02-08-2004 at 20:15. |
#7
|
|||
|
|||
yes, you can dump packed dll, just view excutable,right click on
dll , choose follow entry , set he on entry , run , once stopped on entry ,do as you would with exe for finding oep, dump from there. |
Thread Tools | |
Display Modes | |
|
|
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
Question regarding .NET dumping | 0x22 | General Discussion | 3 | 08-23-2014 16:37 |
Dumping | sfld | General Discussion | 2 | 03-20-2004 23:56 |