Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 06-05-2006, 22:34
Human
 
Posts: n/a
Odbgscript bug or script?

i wanted to play with safecast but i cant run zuma due it has already expired. so i choose other target astro pop.
http://us.boonty.com/fiche.php?intIdGame=65025
but because we have odbgscript why inject code so i decided to learn a little that script language. in my scripts i found old sd 2.43.0 script for iat by Fly
i modded it a little to run with that target. it correctly finds jump to oep, sets hwbp, then on createevent bp goes to user code and searches for magicjump.
if found then deletes hwbp on createevent and sets bp on magic jump if magic jump then it does add eip,4 to always do writing of api. after all on bp checks for eip==jump to oep and jumps there and script is over.
ofcource target crashes, maybe its newer safecast. case is this only works when i use S to step script, magicjump is after createevent, when we press play trial. when i just run script it runs and doesnt fix iat after pressing play we end with frozen olly with back to user at bottom, when i press F12 game runs but switching to olly show nothing is fixed. like it never break on magicjump.
any advice?
script is by fly, modded to my needs and learning just by me so no comments about stealing!

ps.
before runin we have to enable checkforremote and all zwquery and ok, then ctrl+F2 so ollyadvanced will hide olly.
seems this target compared to zuma also have activemark sdk not only flexnet dll
Attached Files
File Type: txt Safecast 2.60.30 OEP Finder + Fix IAT.txt (1.1 KB, 9 views)

Last edited by Human; 06-05-2006 at 22:40.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 07:34.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )