Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 08-26-2004, 04:12
hell
 
Posts: n/a
Getting to the oep is easy but cant find the end and start of IAT!!!!!!1

Any suggestions on how to find it!!!!!!!
Reply With Quote
  #2  
Old 08-26-2004, 04:21
Eggi
 
Posts: n/a
go to 401000 and then search for FF25 and you have an entry of the iat... and then you can find the begining and the end. Then set a hardware bp on write on the first iat value and let it run until it has the values which it had when you set the bp. You shoudl be in a loop then where you find a jump which makes the iat working for you .
Reply With Quote
  #3  
Old 08-26-2004, 04:31
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
there are different IAT-protection. mostly i saw one type which was easy to fix:

there was a msvcrt._stricmp, and after this a JE. if you change it to JMP, IAT will be auto-fixed.
to find this, set a hardware-BP on any IAT-entry and when you are at the command it is written, search up for this stricmp. good luck
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Unpackable packer ? jackdanielz General Discussion 9 02-12-2003 05:55


All times are GMT +8. The time now is 13:52.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )