Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 04-27-2004, 02:46
TheDutchJewel's Avatar
TheDutchJewel TheDutchJewel is offline
VIP
 
Join Date: Aug 2002
Posts: 716
Rept. Given: 27
Rept. Rcvd 464 Times in 267 Posts
Thanks Given: 20
Thanks Rcvd at 642 Times in 183 Posts
TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499
Trick to misleading debuggers...?

I've a prob with "OEM Logo Stamper Professional Edition v1.0a" (http://www.crdrc.org/download/olspe.exe). For the 1.00 version I found a serial using the point-h method, but it seems the author changed something in this new version (to mislead debuggers?). When I run the program after set a breakpoint for the Point-h or CallStack method or even on a simply NAG, OllyDbg now allways gives an "Inexact floating-point result" error, after a few seconds followed by an "Thread 00000970 terminated, exit code 0" error. I tried it with OllyDbg v1.10.2 and v1.10.3: same result. Anyone knows what happens and how to solve this prob?
__________________
thedutchjewel.freehostia.com

Last edited by TheDutchJewel; 04-27-2004 at 04:37. Reason: Error appears at more breakpoints then only point-h and callstack
Reply With Quote
  #2  
Old 04-27-2004, 05:03
Rhodium
 
Posts: n/a
Try breaking on some actual APIs instead of just point-h.

You can spy which APIs are happening with a program like AutoDebug.
Reply With Quote
  #3  
Old 05-03-2004, 23:15
TheDutchJewel's Avatar
TheDutchJewel TheDutchJewel is offline
VIP
 
Join Date: Aug 2002
Posts: 716
Rept. Given: 27
Rept. Rcvd 464 Times in 267 Posts
Thanks Given: 20
Thanks Rcvd at 642 Times in 183 Posts
TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499
Fixed

Quote:
Originally Posted by Rhodium
Try breaking on some actual APIs instead of just point-h.
Thanks. I tried it on two pc's and only on my main pc registration ends up with a crash. I traced it using MSVBVM60 API and found that the program crashed after Olly showed the last four numbers of my hardware fingerprint. Maybe I've a blacklisted pc?

Anyway, I found the place where the program crashed, jumped over it and everything works ok now. Even found a new serial by using the point-h method....
__________________
thedutchjewel.freehostia.com
Reply With Quote
  #4  
Old 05-04-2004, 05:42
neogen
 
Posts: n/a
Hi TheDutchJewel,

So i'm not familar with the point-h method, but if it checks for a debugger, have you installed the hidedebugger plugin for ollydbg? Its available in the tutorial for asprotect. Get this and try again. May be you have it already...

Cheers, neogen
Reply With Quote
  #5  
Old 05-04-2004, 20:08
TheDutchJewel's Avatar
TheDutchJewel TheDutchJewel is offline
VIP
 
Join Date: Aug 2002
Posts: 716
Rept. Given: 27
Rept. Rcvd 464 Times in 267 Posts
Thanks Given: 20
Thanks Rcvd at 642 Times in 183 Posts
TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499
Quote:
Originally Posted by neogen
So i'm not familar with the point-h method, but if it checks for a debugger, have you installed the hidedebugger plugin for ollydbg?
Hi neogen,

I have it installed. But it seems not to be a debug protection, because the error appears only on my main pc, also if I run it w/o Olly... So it has something to do with my pc only.
__________________
thedutchjewel.freehostia.com
Reply With Quote
  #6  
Old 05-04-2004, 21:21
Nilrem
 
Posts: n/a
Happened with your hardware fingerprint, hmm that is weird, I've had a quick think about it, but I'm drawing a blank tDJ, ever thought about contacting them? Heh.

Last edited by Nilrem; 05-06-2004 at 01:30.
Reply With Quote
  #7  
Old 05-04-2004, 23:45
TheDutchJewel's Avatar
TheDutchJewel TheDutchJewel is offline
VIP
 
Join Date: Aug 2002
Posts: 716
Rept. Given: 27
Rept. Rcvd 464 Times in 267 Posts
Thanks Given: 20
Thanks Rcvd at 642 Times in 183 Posts
TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499
Quote:
Originally Posted by Nilrem
... but I'm drawing a blank tDJ, ever thought about contacting them?
Sorry, but I don't understand this. Do you mean that I'll install a clean Windows to check if it's a software prob? I already restored my Ghost dump sometimes, but same prob. Or do you mean that I contacted them by mail or cookie or something? I never contacted that way to the author. But maybe one time I forgot to block my connection to them after which they have some info about me. No idea...
__________________
thedutchjewel.freehostia.com
Reply With Quote
  #8  
Old 05-06-2004, 01:32
Nilrem
 
Posts: n/a
tDJ, no no no, I simply meant just contact them, tell the company that you found a bug (make something up), and that you are a software developer too, so you used a debugger, but the debugger kept crashing when it had your hardware fingerprint, but on another computer the debugger worked fine with it.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
how to get the address of the entry point in an API Warren General Discussion 6 08-30-2005 16:18


All times are GMT +8. The time now is 18:30.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )