Exetools

Exetools (https://forum.exetools.com/index.php)
-   General Discussion (https://forum.exetools.com/forumdisplay.php?f=2)
-   -   hmmm... (https://forum.exetools.com/showthread.php?t=11766)

D-Jester 08-06-2008 23:14

hmmm...
 
So I see....

There is now an official Exetools team now; Grats to the people of the new elite group.

But why (and maybe PM'ing JMI would have been easier) is the Off Topic forum password protected?

JMI 08-07-2008 03:41

I was not aware that it was. :eek: Maybe Aaron did it while he was creating the ExeTools Team forum, either on purpose or by accident.

I'll try to check it out tomorrow.

Regards,

ahmadmansoor 08-07-2008 17:34

hehehe
 
Quote:

Originally Posted by D-Jester (Post 60475)
So I see....

There is now an official Exetools team now; Grats to the people of the new elite group.

@D-Jester : u will won a prize . for this inf ....anyway wait and watch and u will be surprise .:p

D-Jester 08-07-2008 21:38

Quote:

Originally Posted by ahmadmansoor (Post 60484)
@D-Jester : u will won a prize . for this inf ....anyway wait and watch and u will be surprise .:p

prizes are always welcome :p, lol

You been looking at armadillo 6 yet?
I started playing with it last night, good stuff.
Doesn't like my Olly, so I'm back to using Softice in VMWare :(
Looks like I need to catchup a bit.
Last version I played with was 4.x, back when nanomites/code splicing were the shit.

Does anyone know what the heck happened to Olly 2.x? I saw an alpha preview but nothing else in like 2yrs.

Archer 08-08-2008 01:12

Olly is developing very slowly. Just several betas were released.
I've been looking at Armadillo 6. Nothing changed from 4, just several useless options like random section names for some reason available only in custon build and GetWindowText against some tools, nothing more.

D-Jester 08-10-2008 00:30

Armadillo 6.04 Public

My Observations so far:
JMP <ModuleEntrypoint> patch (EB FE) doesn't make it to the child process from the first WriteProcessMemory call.

My custom spin on the DebugActiveProcessStop patch now causes a crash

Code:

PUSH %PID%
CALL DEBUGACTIVEPROCESSSTOP
JMP EIP <-- CAUSES WINDOWS TO DUMP ARMADILLO MEMORY VIA WATSON

Haven't actually made it into the child process yet, back to the tutorials.


All times are GMT +8. The time now is 11:43.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX