View Single Post
  #2  
Old 01-08-2008, 08:14
Newbie_Cracker's Avatar
Newbie_Cracker Newbie_Cracker is offline
VIP
 
Join Date: Jan 2005
Posts: 227
Rept. Given: 72
Rept. Rcvd 26 Times in 12 Posts
Thanks Given: 50
Thanks Rcvd at 25 Times in 18 Posts
Newbie_Cracker Reputation: 26
Dear AhmadMansoor, my patched OllyDbg is hidden agains SD blacklist, like ACPU, ACPUASM...etc. So HideTools is not needed. StrongOD plugin works like HideToolz. But I had used them with no success.
SndDbg and hacnho OllyIce failed too.

The father process has no problem, but if I wanna bypass child creation (by moving 8 to eax at the end of routine), debugger will be detected.

On some targets, this procedure will works:
1- BP on CreateFileA,ALt+F9, CTRL+F9, move 8 into EAX, F9... and Debugger is detected !.
Now CTRL+F2 and restart the target.
2- This time I just press F9 and target will run inside OllyDbg (this worked on just one target, but not worked for others. I thinks because of minimum protection)

Why child won't be created?
Because temp files are created before and SD thinks fathers has run this child process

So It's not because of single step breakpoint (I used HW BP for tracing too), but maybe because of timing check.

The attached target is SD1.12, but too restive !

Maybe unpacking and reversing loveboom unpacker is the last way !

PS: Olly 2.0 has no export needed for plugins, so they cann't be run !
Attached Files
File Type: rar SDProtector1.12.Unpackme.rar (46.4 KB, 19 views)
__________________
In memory of UnREal RCE...
Reply With Quote