![]() |
reply to crusaders reloc issue on rce
don't have rce login, sorry. thought i'd post something
Quote:
another tip for dumping dll's is to use the ollyloader. it is nice cuz most of the time it will load the dll into its native imagebase making it easier to dump. you will notice that it will load if you change the imagebase to what you had dumped it to because the reloc addresses have already been fixed to that imagebase and will not work simply by changing the imagebase value in the pe header cuz the values simply don't align. if this wasn't the problem you were having and i have misunderstood you, then forget what you just read :) otherwise, please try the aforementioned advise. |
heh.. what is this :)?
Thread hijacking :)? Anyway, thanks for the reply... but that wasnt exactly my problem... my dll loaded at its native imagebase when unpacking... it works fine unless there is another dll already loaded at that iamge base then it wont load... I can rebase the dll with lordpe and it works fine again as long as there is no dll already loaded at the same imagebase... so while LordPE seems to recognise the reloc struct, windows doesnt :/ Quote:
|
just a stab in the dark, have set correct reloc size in the header ?
- Darren |
Quote:
Quote:
still tho, with relocs in place it should be assigned a different area to live. i know this is of little or no help, just putting thoughts out there :) Darren makes a good point as well |
| All times are GMT +8. The time now is 15:04. |
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX