Exetools  

Go Back   Exetools > General > General Discussion

Notices

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #3  
Old 10-30-2004, 07:27
gabri3l's Avatar
gabri3l gabri3l is offline
Parity Error 0x0FF2131D
 
Join Date: Aug 2003
Location: Eastern Shore
Posts: 118
Rept. Given: 0
Rept. Rcvd 5 Times in 1 Post
Thanks Given: 8
Thanks Rcvd at 21 Times in 10 Posts
gabri3l Reputation: 5
Talked to you over email. It seems you progressed as far as you could before using Olly. This is where you started to have problems. You could not find calls to set breakpoints on in Olly.

Using stripper to unpack; your entry point lies outside of the code section. This is why Olly is giving you trouble. The code section for this program (after unpack) begins at 00401000. The entry point is at location 0058A000.
To verify this use LordPe to examine the file. You will see your entrypoint as 18A000. Then click the sections button. You will see size of the code section (.text) is only 113000.
1000 + 113000 = 114000 Which means 18A000 is very far outside your code section. What you need to do is let Olly run from the entry point until you get inside your code section.

Now, to correctly find API calls in Olly:
1. Make sure you have the commandbar plugin
2. load the file
3. In the commandbar type "tc eip<500000" without the quotes.
*I am using Win 2000, so your address may need to be different than mine.
**Basically you want to trace until the next execution occurs inside your code section.
4. Then press enter.
5. You should stop here: JMP DWORD PTR DS:[<&kernel32.GetModuleHa>; kernel32.GetModuleHandleA
6. Search for all intermodular calls. And continue as normal.

Hopefully that helps you, and also gives you an idea as to WHY Olly was not finding the calls. I did not continue on and find a serial I figured I would leave that up to you.

Last edited by gabri3l; 10-30-2004 at 07:35.
Reply With Quote
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Any pointers on this troublesome algorithm? Cryo General Discussion 11 12-05-2016 07:35
Pointers in Delphi chessgod101 Source Code 1 04-06-2014 23:54
Need some pointers with a .Net target Sailor_EDA General Discussion 10 03-03-2010 12:18
x64 Website Pointers Evilcry x64 OS 3 10-01-2009 22:25


All times are GMT +8. The time now is 01:28.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )