Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 01-02-2005, 22:28
arkanoid
 
Posts: n/a
dyn!o // You're definitely right.
I didn't intend to offend you. I'm sorry if you felt like that.
What I tried to mean is it would be better if there's an external link or something like that, so that other guys could download and take a look.
(assuming that file is for less skilled people)
Reply With Quote
  #2  
Old 01-02-2005, 23:40
Teerayoot Teerayoot is offline
Friend
 
Join Date: Mar 2004
Location: ประเทศไทย
Posts: 83
Rept. Given: 0
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 2
Thanks Rcvd at 16 Times in 8 Posts
Teerayoot Reputation: 3
I know all protection can be feated all ,but time in defeating is not same some too much some too fast cracked it.


New version i got idea from armadilo about encrypt some code before execute then decrypt it again and also protect some importance byte code but it's very simple encryption in my debug me.
And another is memory patch checking it will replace with org byte when it modified .
0.2 i pack with PE compact ,i think it will not hard to unpack let enjoy

FOr noobie cracker only

Last edited by Teerayoot; 01-02-2005 at 23:43.
Reply With Quote
  #3  
Old 01-03-2005, 00:27
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
unfucked but i really like this way of protection...
Reply With Quote
  #4  
Old 01-03-2005, 03:58
JMI JMI is offline
Leader
 
Join Date: Jan 2002
Posts: 1,627
Rept. Given: 5
Rept. Rcvd 199 Times in 99 Posts
Thanks Given: 0
Thanks Rcvd at 98 Times in 96 Posts
JMI Reputation: 100-199 JMI Reputation: 100-199
MaRKuS-DJM you are definately NOT "less skilled." And I hope your took my comments in the spirit of gentle ribbing in which they were intended.

A "challenge" is often hard for the competitive spirit to resist accepting, and a competitive spirit usually enjoys demonstrating that they have defeated the "challenge" and particularly if they can demonstrate that they have arrived at the finish line "first." There is nothing "wrong" with that concept and it is encouraged in most societies.

Sometimes, however, the really successful competitor can advance to the point where they come to enjoy more the encouragement of others to sharpen their competitive skills and in such games of skill they tend only to offer "hints," rather than "solutions." This form of encouragement is highly valued and, in truth, more useful than being the "first' to find a solution, because it represents a sharing of knowledge and the passing on of such knowledge to the next group, who, ultimately, will need to pass it on, and so on and so on.

So take my comments as a compliment that I judge your "skill set" to be in that group "from whom" others can benefit and that as a mentor of "less skilled" you simply need to understand that the true value is not is giving the answer, but in teaching others how to find their own.

Regards,
__________________
JMI
Reply With Quote
  #5  
Old 01-03-2005, 04:57
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
to your post... very well & wise said but also from answers you can learn if you study them... earlier, when i started cracking, i looked at the differences... before patching, after patching. in this time i wasn't able to unpack any packer, this was really interesting what was done... why did a cracker that steps. and after that period, i figured out how to find my own solutions for everything. so much different ways to patch.

to be on the way you said... this target doesn't use a API to kill your olly. it has a way of anti-debug i never saw in other targets.
Reply With Quote
  #6  
Old 01-03-2005, 05:18
JMI JMI is offline
Leader
 
Join Date: Jan 2002
Posts: 1,627
Rept. Given: 5
Rept. Rcvd 199 Times in 99 Posts
Thanks Given: 0
Thanks Rcvd at 98 Times in 96 Posts
JMI Reputation: 100-199 JMI Reputation: 100-199
Your comments that comparison of solutions are very helpful is certainly correct. The only point I am suggesting is that if a solution is released too early, it does tend to cut down on efforts of others to find their "own" solution. That result is not "caused" by your posting of a solution, but by the nature of some to stop their own efforts when anyone gives them a solution.

Regards,
__________________
JMI
Reply With Quote
  #7  
Old 01-03-2005, 05:35
Michel Michel is offline
Friend
 
Join Date: Sep 2004
Location: France
Posts: 66
Rept. Given: 2
Rept. Rcvd 6 Times in 1 Post
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Michel Reputation: 6
@JMI : You seem to be a very fine "mind-unwrapper" ! nice !
Reply With Quote
  #8  
Old 01-03-2005, 05:37
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
do you think so? but i think if you really want to learn how to do it you will do it... and following the steps done in this solution is also own effort
Reply With Quote
  #9  
Old 01-10-2005, 22:11
NeOXOeN NeOXOeN is offline
Friend
 
Join Date: Jan 2005
Posts: 273
Rept. Given: 2
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 2
Thanks Rcvd at 18 Times in 18 Posts
NeOXOeN Reputation: 3
i think what Teerayoot did its very nice.. putting out exe and source so everyone cal learn from it ...there should be more ppl like him
Since now days not a lot of ppl are contributing to scene or reversing ..especially with their ideas and all .. A lot of good work stays priv.. and poor and more or less crap is comming out...


So i am glad something nice came out for a change


bye NeO
Reply With Quote
  #10  
Old 01-13-2005, 17:11
MARcoDEN
 
Posts: n/a
IMHO, very easy protection . The method of redirecting to OEP is old as my grandma - JMP EAX. As soon as it have been located, put there Hardware BP, step into and you are on OEP .
Attached Files
File Type: rar dumped_.rar (286.0 KB, 8 views)
Reply With Quote
  #11  
Old 01-15-2005, 04:43
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
marcoden, what you did is unpacking the PeCompact. the goal is to remove the anti-debug protection
Reply With Quote
  #12  
Old 01-03-2005, 03:56
Michel Michel is offline
Friend
 
Join Date: Sep 2004
Location: France
Posts: 66
Rept. Given: 2
Rept. Rcvd 6 Times in 1 Post
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Michel Reputation: 6
Thanks Teerayoot, I propose this solution but I am not sure it's you are waiting for
Attached Files
File Type: rar UNP.rar (289.9 KB, 26 views)

Last edited by Michel; 01-03-2005 at 04:19.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
x64 and anti-debugging lena151 x64 OS 19 11-15-2011 05:24
Win32 Debug Protection Idea nelix General Discussion 12 06-07-2004 19:24


All times are GMT +8. The time now is 06:43.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )