Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 01-08-2008, 05:39
ahmadmansoor's Avatar
ahmadmansoor ahmadmansoor is offline
Coder
 
Join Date: Feb 2006
Location: Syria
Posts: 1,047
Rept. Given: 517
Rept. Rcvd 374 Times in 142 Posts
Thanks Given: 380
Thanks Rcvd at 416 Times in 119 Posts
ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399
Hi my dear friend Newbie_Cracker :
about this protecter for hide ur olly it easy hehehe... How ? this is
tools :
if u use olly without unpatch version (normal) all u have to do is :
use just Olly Advanced 1.26 beta 12 with this option
Anti-Debug : Enable all except :kill anti-Attach
Get TickCount : counter+1
debug bits : Enable all
Then use HideToolz V2.1
and all will work
Don't use any of HideOD or PhantOm make them all disable
___________
but if u use OllyIce patched version by Hacnho u don't want to use

HideToolz
__________________________________________
note BP and HBP will not work it will catch it . but i have way to pass it
wait to next Post Or PM
Ur best Friend AhmadMansoor

by the way did u fiend the way to modify Olly 2.0 to enable Plgins menu . I

am working on it ...
__________________
Ur Best Friend Ahmadmansoor
Always My Best Friend: Aaron & JMI & ZeNiX
Reply With Quote
  #2  
Old 01-08-2008, 08:14
Newbie_Cracker's Avatar
Newbie_Cracker Newbie_Cracker is offline
VIP
 
Join Date: Jan 2005
Posts: 227
Rept. Given: 72
Rept. Rcvd 26 Times in 12 Posts
Thanks Given: 50
Thanks Rcvd at 25 Times in 18 Posts
Newbie_Cracker Reputation: 26
Dear AhmadMansoor, my patched OllyDbg is hidden agains SD blacklist, like ACPU, ACPUASM...etc. So HideTools is not needed. StrongOD plugin works like HideToolz. But I had used them with no success.
SndDbg and hacnho OllyIce failed too.

The father process has no problem, but if I wanna bypass child creation (by moving 8 to eax at the end of routine), debugger will be detected.

On some targets, this procedure will works:
1- BP on CreateFileA,ALt+F9, CTRL+F9, move 8 into EAX, F9... and Debugger is detected !.
Now CTRL+F2 and restart the target.
2- This time I just press F9 and target will run inside OllyDbg (this worked on just one target, but not worked for others. I thinks because of minimum protection)

Why child won't be created?
Because temp files are created before and SD thinks fathers has run this child process

So It's not because of single step breakpoint (I used HW BP for tracing too), but maybe because of timing check.

The attached target is SD1.12, but too restive !

Maybe unpacking and reversing loveboom unpacker is the last way !

PS: Olly 2.0 has no export needed for plugins, so they cann't be run !
Attached Files
File Type: rar SDProtector1.12.Unpackme.rar (46.4 KB, 19 views)
__________________
In memory of UnREal RCE...
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
SVKP, Armadillo or SDProtector TmC General Discussion 15 12-10-2004 22:19
Unpacking SdProtector Pro bLaCk-eye General Discussion 2 08-12-2004 22:10


All times are GMT +8. The time now is 15:30.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )