Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 12-10-2004, 21:01
iwill
 
Posts: n/a
Ricardo
Quote:
if you look the api GetTickCount the program take the time, but in a moment compare the time witha previous time and decide if create the second process or not.
In this form altering only one jump or playing with the times you can run in one single process mode and the unpack is very easy.

armadillo is very more difficult obviously.
Have you ever tried the lastest version - SDProtector 1.16? It's not so easy as you said; soft defender is just a very old version of SDProtector, it seems the author has already switched to SDProtector and given up soft defender.
Reply With Quote
  #2  
Old 12-10-2004, 21:25
nikita@work
 
Posts: n/a
Quote:
Originally Posted by iwill
Have you ever tried the lastest version - SDProtector 1.16? It's not so easy as you said; soft defender is just a very old version of SDProtector, it seems the author has already switched to SDProtector and given up soft defender.
Very interesting, can you provide setup or sample?
Reply With Quote
  #3  
Old 12-10-2004, 21:58
ricnar456 ricnar456 is offline
Friend
 
Join Date: May 2002
Posts: 290
Rept. Given: 1
Rept. Rcvd 28 Times in 10 Posts
Thanks Given: 0
Thanks Rcvd at 52 Times in 40 Posts
ricnar456 Reputation: 28
I have a old tut

than is based in old softdefender and with non registered version but i think the idea for make one only single process is the same in sdpro, i don't know if all is exactly in the last version and when i look i add the newer additions but i think the idea can help others here the tuts of softdefender.



Ricardo Narvaja
Reply With Quote
  #4  
Old 12-10-2004, 22:19
Line79
 
Posts: n/a
SDProtector isn't hard.

It has a funny way to jmp to entry point, which i call a kind of domino..

The anti debugging isn't really hard to bypass. The threads used to detect
Debuggers, dumpers , and IAT recoverer are easy to disable because of a bad vulnerability in the implementation.

The IAT redirection is simple as shit. you just need to write a simple Imprec plugin and its gone.. Beside, i have noticed that it will sometimes change his
redirection, i don't even bother to re write the plugin.. i just close the app, and try again

The only fun part is the jmp to oep, which i have already seen in some custom protection.

to me : Armadillo
SDProtector
SVKP

Bye.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Problem with old SDProtector Newbie_Cracker General Discussion 8 01-28-2008 07:16
Unpacking SdProtector Pro bLaCk-eye General Discussion 2 08-12-2004 22:10


All times are GMT +8. The time now is 13:52.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )