Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 02-05-2004, 03:46
ceK52z
 
Posts: n/a
Dumping a dll with ollydump

Hi,

I'm trying to dump a packed DLL using ollydump. I wrote a simple program that just loads the DLL, and I've traced to the original entrypoint and am ready to dump, but I don't know how to figure out what addresses I should put in "Base of Code" and "Base of Data". Do I also need to change something in the section table?

Please help me out...
Reply With Quote
  #2  
Old 02-05-2004, 20:55
Nilrem
 
Posts: n/a
(Just a general note before you read this, I'm not 100% sure of the advice I'm going to give, so be weary.)
Why don't you load the dll into Olly?
If you're using your method, as far as I'm aware that's fine, but when it comes to dumping it, isn't the base addresses automatically put there? As for the tables, are you on about the reconstruction of the import tables, if so I'd use Imprec (Import reconstructor) to do that.
Reply With Quote
  #3  
Old 02-06-2004, 00:33
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
how want you do that? a dll can't loaded without a executable. and the base-address is then from the dll-loader & wrong OEP.
Reply With Quote
  #4  
Old 02-06-2004, 00:49
Nilrem
 
Posts: n/a
Oh I understand what he wants to do now. Why would you want to do that? Is the dll what does the protection? I'm not 100% sure of the big picture here, perhaps you could paint it for us?
Reply With Quote
  #5  
Old 02-06-2004, 21:49
ceK52z
 
Posts: n/a
Well I managed to dump it successfully with procdump and imprec. I originally thought the dll would have something to do with the protection, but it turns out it had nothing of interest. Oh well.. at least I learned something new.

sorry to waste your time...
Reply With Quote
  #6  
Old 02-07-2004, 20:58
Nilrem
 
Posts: n/a
Thumbs up

You solved it, so I don't think our time was wasted, anyways, congratulations.

Last edited by Nilrem; 02-08-2004 at 20:15.
Reply With Quote
  #7  
Old 02-08-2004, 19:39
britedream britedream is offline
Friend
 
Join Date: Jun 2002
Posts: 436
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 7 Times in 7 Posts
britedream Reputation: 0
yes, you can dump packed dll, just view excutable,right click on
dll , choose follow entry , set he on entry , run , once stopped on entry ,do as you would with exe for finding oep,
dump from there.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Question regarding .NET dumping 0x22 General Discussion 3 08-23-2014 16:37
Dumping sfld General Discussion 2 03-20-2004 23:56


All times are GMT +8. The time now is 14:44.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )