#1
|
|||
|
|||
Resources....tools or manually??
I just want to sing a praise for the Resources Tab in Stud_PE. It helped me with an unpacked upx which Resource Hacker was not able to analyze.
I realized that if we want to take a look into the resources, it's recommended using more than one tool, because when Exescope doesn't see a thing, maybe ResHack can help us or ever some other ones... One more thing: these tools look into the resources section and can show us images like bitmaps that were compiled being RES files, isn't it? So my question is: What about that images that no resource editor "sees" but that lies inside the exe in its original form: for example, here we have the beginning of a BITMAP whose size is: 4EF6h. If we take HexWorkshop, we copy 4ef6h bytes (look that F6 4E after the BM header) and paste it in image.bmp, we'll be get the original image. .00408CC0: 6C 74 00 00-F7 4E 00 00-42 4D F6 4E-00 00 00 00 lt ÷N BMöN .00408CD0: 00 00 36 00-00 00 28 00-00 00 4F 00-00 00 54 00 6 ( O T .00408CE0: 00 00 01 00-18 00 00 00-00 00 C0 4E-00 00 12 0B ÀN .00408CF0: 00 00 12 0B-00 00 00 00-00 00 00 00-00 00 FF FF ÿÿ .00408D00: FF FF FF FF-FF FF FF FF-FF FF FF FF-FF FF FF FF ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ .00408D10: FF FF FF FF-FF FF FF FF-FF FF FF FF-FF FF FF FF ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ |
Thread Tools | |
Display Modes | |
|
|
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
Reversing resources | tecnmarl | General Discussion | 1 | 03-07-2018 17:58 |
Resources and packers | ancev | General Discussion | 1 | 10-05-2005 16:57 |
PE Explorer won't show resources (help) | Rhodium | General Discussion | 1 | 08-01-2003 15:14 |
Hide'n Resources | Bogdanbjn | General Discussion | 2 | 07-19-2003 18:58 |