Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 05-28-2011, 21:06
BackTangent
 
Posts: n/a
About .Net Packing and Introduction

Hi,

First of all i will like to say thanks for accepting me as a part of the community. I should start the conversation by introducing my self. My name is Malik and a am from Pakistan and i am learning Reverse Engineering.

I had been a part of other communities but no one replies properly at most of them, but this looks a solid community.

As a question i would like to ask, how can one detect packing on a .Net software, How many packings are there.

If you can refer to a tutorial or anything i would be grateful, i have read almost all the tuts on tuts4you but they where of no use.

Regards
Reply With Quote
  #2  
Old 05-29-2011, 03:49
Kurapica's Avatar
Kurapica Kurapica is offline
VIP
 
Join Date: Jun 2009
Location: Archives
Posts: 190
Rept. Given: 20
Rept. Rcvd 143 Times in 42 Posts
Thanks Given: 67
Thanks Rcvd at 405 Times in 87 Posts
Kurapica Reputation: 100-199 Kurapica Reputation: 100-199
Sorry for the spam but this place could be useful

http://board.b-at-s.info/

all forums are one big family

good luck
Reply With Quote
  #3  
Old 05-29-2011, 09:50
disauto disauto is offline
Friend
 
Join Date: May 2011
Posts: 115
Rept. Given: 14
Rept. Rcvd 22 Times in 15 Posts
Thanks Given: 14
Thanks Rcvd at 77 Times in 22 Posts
disauto Reputation: 22
@BackTangent
try this
http://pid.gamecopyworld.com/ProtectionID_v6.4.0.rar
Reply With Quote
The Following User Gave Reputation+1 to disauto For This Useful Post:
chessgod101 (05-30-2011)
  #4  
Old 05-29-2011, 21:55
giv's Avatar
giv giv is offline
VIP
 
Join Date: Jan 2011
Location: Romania
Posts: 1,657
Rept. Given: 801
Rept. Rcvd 1,283 Times in 561 Posts
Thanks Given: 226
Thanks Rcvd at 562 Times in 240 Posts
giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299
Hi there. You were a neighbor of Bin Laden... Welcome here.

Quote:
Originally Posted by BackTangent View Post
Hi,

As a question i would like to ask, how can one detect packing on a .Net software, How many packings are there.

Regards
Try Peid or RDG packer detector. They shows usefull information about the protection of the packed exe and the compiler also.
Reply With Quote
  #5  
Old 05-30-2011, 23:03
BackTangent
 
Posts: n/a
Quote:
Originally Posted by Kurapica View Post
Sorry for the spam but this place could be useful

http://board.b-at-s.info/

all forums are one big family

good luck
I had been a member at your forum, and asked a question on this thread http://board.b-at-s.info/index.php?showtopic=8131 but it is still un answered.
Reply With Quote
  #6  
Old 05-30-2011, 23:06
BackTangent
 
Posts: n/a
Quote:
Originally Posted by giv View Post
Try Peid or RDG packer detector. They shows usefull information about the protection of the packed exe and the compiler also.
I knew about pied and RDG packer but do not know about the packer information they show, like for an exe RDG shows using DLL. Now what i do not know is that what does it mean.

what my intent to post at the forum is to look for a detailed guide on types of packing and how to counter them.

Regards
Reply With Quote
  #7  
Old 06-03-2011, 22:01
giv's Avatar
giv giv is offline
VIP
 
Join Date: Jan 2011
Location: Romania
Posts: 1,657
Rept. Given: 801
Rept. Rcvd 1,283 Times in 561 Posts
Thanks Given: 226
Thanks Rcvd at 562 Times in 240 Posts
giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299
http://forum.exetools.com/showthread.php?t=13149&highlight=unpacking
Reply With Quote
  #8  
Old 06-04-2011, 00:41
congviet congviet is offline
Family
 
Join Date: Jun 2010
Location: Vi
Posts: 151
Rept. Given: 30
Rept. Rcvd 76 Times in 42 Posts
Thanks Given: 56
Thanks Rcvd at 52 Times in 30 Posts
congviet Reputation: 76
Lightbulb

BackTangent

You try DNid v0.12b & Dotnet ID 1.003 by RONGCHAUA.NET.
It is two tool for detect packing a .NET software.
I already attach they here:
DNID.zip

or
DNid v0.12b
hxtp://www.mediafire.com/?gtj38dm60ddcmma
Dotnet ID v1.003 by Rongchaua.net
hxtp://rongchaua.net/Web/Tool/DotNet Id.zip
Reply With Quote
The Following User Gave Reputation+1 to congviet For This Useful Post:
yogi_saw (06-13-2011)
  #9  
Old 06-09-2011, 16:37
BackTangent
 
Posts: n/a
My Question is not still answered. Let me rephrase my question. What i am asking is how to debug a specific packer scheme. you people are understanding i am asking about how to find a packer scheme, i know about it, there are tons of tool out there which can do that. What i do not know is how to tackle a specific scheme. There would be some documents which discuss specific packing schemes and how to crack them.

If you can help in that, i would be thankful .
Reply With Quote
  #10  
Old 06-12-2011, 00:21
giv's Avatar
giv giv is offline
VIP
 
Join Date: Jan 2011
Location: Romania
Posts: 1,657
Rept. Given: 801
Rept. Rcvd 1,283 Times in 561 Posts
Thanks Given: 226
Thanks Rcvd at 562 Times in 240 Posts
giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299 giv Reputation: 1100-1299
Check this link or this link or this.

Last edited by giv; 06-12-2011 at 00:22. Reason: Add some links.
Reply With Quote
  #11  
Old 06-12-2011, 20:24
atomix atomix is offline
Friend
 
Join Date: Aug 2004
Posts: 50
Rept. Given: 2
Rept. Rcvd 3 Times in 3 Posts
Thanks Given: 0
Thanks Rcvd at 4 Times in 2 Posts
atomix Reputation: 3
Quote:
Originally Posted by BackTangent View Post
My Question is not still answered. Let me rephrase my question. What i am asking is how to debug a specific packer scheme. you people are understanding i am asking about how to find a packer scheme, i know about it, there are tons of tool out there which can do that. What i do not know is how to tackle a specific scheme. There would be some documents which discuss specific packing schemes and how to crack them.

If you can help in that, i would be thankful .
AFAIK, there is no generic way to unpack/crack all types of protections. You need to detect first the packer (using suggestions above), then unpack the executable (manually or using special/generic tools available) and finally crack it (providing that there is any additional protection to the packer).

Perhaps it will help more if you provide more details on the protection scheme that you are trying to defeat.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Introduction to x64 Assembly Git x64 OS 11 01-03-2011 17:48
packing-format MaRKuS-DJM General Discussion 4 11-11-2004 03:05
How to determine packing method? vxd General Discussion 2 12-01-2002 05:50


All times are GMT +8. The time now is 00:55.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )