Exetools

Exetools (https://forum.exetools.com/index.php)
-   Community Tools (https://forum.exetools.com/forumdisplay.php?f=47)
-   -   Scylla x64/x86 Imports Reconstruction (https://forum.exetools.com/showthread.php?t=13792)

tenketsu 10-22-2012 02:30

Scylla Imports Reconstruction 0.6b tested on Win7 x64 and works nice, thanks!

nikre 12-01-2012 04:23

1 Attachment(s)
Scylla v0.8

Quote:

many changes

WilliamElts 12-03-2012 15:34

The source code is now available at:
Quote:

https://github.com/NtQuery/Scylla
Changelog for version 0.8:
Quote:

added OriginalFirstThunk support. Thanks to p0c
fixed malformed dos header bug
NtCreateThreadEx added infos from waliedassar, thanks!

WilliamElts 02-11-2013 21:03

Version 0.9 has been released.
Homepage:
Quote:

https://github.com/NtQuery/Scylla
Changelog:
Quote:

updated to distorm v3.3
added application exception handler
fixed bug in dump engine
improved "suspend process" feature, messagebox on exit

cybercoder 05-05-2013 07:22

This works very well for me, just sometimes it may put the wrong import in place. This a great project looking forward to some extra features. :)

ahmadmansoor 09-01-2013 00:06

Bug fix
 
1 Attachment(s)
this is a bug fix from Aguila

Quote:

I noticed some problems with virtual devices.
thanks to him

giv 09-01-2013 01:39

At least some news from Aguila. And from Ahmad too. :-)

Carbon 09-03-2013 01:45

Code:

Version 0.9.1

- Fixed virtual device bug
- Fixed 2 minor bugs


ahmadmansoor 09-03-2013 19:52

is there are any way for the Src for the new version? .
Thanks for ur great work

sendersu 09-03-2013 20:11

Scylla author, could I ask you to pay some attention to this old issue please?

if import in form
libA.FnA
unknown func
libA.FnC

most probable the "unknown" is also from libA.
It means:
1. You can guess DLL name for "Select function" dialog
2. No need to split chunks on first unknown entry

Thanks

Newbie_Cracker 09-03-2013 21:24

Today I tried to unpack a DLL and use Scylla, but it did not read its OEP from file/memory.

It seems that Scylla does not read DLL OEP in case of DLL Unpacking.

Am I right?

Carbon 09-04-2013 02:53

@Newbie_Cracker
I don't get it. You need to find the OEP yourself?

@sendersu
I don't think this is a problem. I will think about it. It is because Scylla doesnt pay attention to the api order (like imprec). Scylla is using a different algorithm.

@ahmadmansoor
here: https://github.com/NtQuery/Scylla

Newbie_Cracker 09-04-2013 17:44

Quote:

Originally Posted by Carbon (Post 86588)
@Newbie_Cracker
I don't get it. You need to find the OEP yourself?

In Scylla, like ImpRec, when you choose a process, the OEP is read from PE header and automatically is shown in OEP text box.

Imprec does the same for DLLs, but Scylla does not.

It seems that it reads the ImageBase and ImageSize from memory (I haven't debugged it to check), but it does not read the OEP from the disk/memory.

ahmadmansoor 09-04-2013 21:21

just one thing pls upload the distorm 3.1 folder which u use .
I can't access it .
is there a problem to compile it with v10 instead of v9.0 of VS 2010
Thanks

deepzero 09-05-2013 20:07

where do these new version come from? They are not mentioned on t4u, Scylla's home.


All times are GMT +8. The time now is 21:42.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX