Exetools  

Go Back   Exetools > General > General Discussion

Notices

Closed Thread
 
Thread Tools Display Modes
  #1  
Old 10-21-2003, 10:01
OHPen's Avatar
OHPen OHPen is offline
Friend
 
Join Date: Aug 2003
Location: lost in code...
Posts: 92
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
OHPen Reputation: 0
Armadillo Unpacking Plugin...

Hi,

i need different Armadillo packed targets in order to test the unpacker i wrote.
Version doesn't matter. If i success you will find the unpacking plugin in next retool release.

thx in advance,

OHPen
  #2  
Old 10-21-2003, 20:26
eric yo
 
Posts: n/a
hey

dudu,can u unpack mybase
hxxp://www2.wjjsoft.com/download.htm
its packed by Armadillo and also this a tricky one

[Edit by JMI: It seems I have to keep posting over and over: NO CLICKABLE LINKS, ESPECIALLY TO SOFTWARE COMPANIES.]
  #3  
Old 10-22-2003, 07:52
OHPen's Avatar
OHPen OHPen is offline
Friend
 
Join Date: Aug 2003
Location: lost in code...
Posts: 92
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
OHPen Reputation: 0
Lo,

i will take a look at it, thx.
But be sure, sooner or later i will add support for this version ;D

But atm i concentrating on older armadillo versions.
  #4  
Old 10-22-2003, 10:50
bunion bunion is offline
Friend
 
Join Date: Apr 2002
Posts: 227
Rept. Given: 45
Rept. Rcvd 11 Times in 8 Posts
Thanks Given: 0
Thanks Rcvd at 6 Times in 6 Posts
bunion Reputation: 11
Thanks Ohpen...heres one packed with dillo 2.5x - 2.6x

_http://etcai.com/digital4.exe

I tried doing it myself with Ricardo's tut BUT..instead of dillo unpacking code blocks of 1,000 byte chunks when i break on write process memory i see that it only writes 2 bytes at a time..ALSO in Ricardo's tut if you break on WaitForDebugEvent you,ll get the address of dillo's REPORT so that when you break on writeprocessmemory after you get to see the OEP..this worked on another target but on this one you dont get to see the OEP...The OEP was found another way but just shows you that this program does things slightly differently??

Good luck and thanks again

paul333

Last edited by bunion; 10-22-2003 at 10:53.
  #5  
Old 10-22-2003, 20:00
OHPen's Avatar
OHPen OHPen is offline
Friend
 
Join Date: Aug 2003
Location: lost in code...
Posts: 92
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
OHPen Reputation: 0
thx paul,

the more targets i get the better the plugin' will work in future.
I will check it as soon as possible.

regards,
OHPen
  #6  
Old 10-27-2003, 17:12
ggdd
 
Posts: n/a
THIS

hxxp://www.sunmoonsoft.com/download/newdown/ce2003zui.rar

[Edit by JMI: I say AGAIN. NO CLICKABLE LINKS.]
  #7  
Old 10-28-2003, 08:46
OHPen's Avatar
OHPen OHPen is offline
Friend
 
Join Date: Aug 2003
Location: lost in code...
Posts: 92
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
OHPen Reputation: 0
thx alot too

I nice that i get such support ;D
  #8  
Old 10-30-2003, 23:11
eric yo
 
Posts: n/a
hxxp://www.downme.com/down.php?nbr=16004&url=6

[Edit by JMI: eric yo:PAY ATTENTION!!!!! NO CLICKABLE LINKS!!!]
  #9  
Old 10-31-2003, 00:48
NakedFool
 
Posts: n/a
Question

Would it help if I posted a link to a cracked version of Armadillo 3.10? It works like a charm, but I'm not sure if it's "against the rules"....
  #10  
Old 10-31-2003, 09:25
JMI JMI is offline
Leader
 
Join Date: Jan 2002
Posts: 1,627
Rept. Given: 5
Rept. Rcvd 199 Times in 99 Posts
Thanks Given: 0
Thanks Rcvd at 98 Times in 96 Posts
JMI Reputation: 100-199 JMI Reputation: 100-199
The issue is CLICKABLE LINKS. Use "hxxp," "h**p," or "wxw" and TURN OFF THE CHECK MARK for "Automatically Parse URLs" at the bottom, BEFORE you save your post.

Regards.
__________________
JMI
  #11  
Old 11-04-2003, 12:19
NakedFool
 
Posts: n/a
Cracked version of Armadillo 3.10

http://www.x-mail.net/carlos2003/disk1.rar
http://www.x-mail.net/carlos2003/disk2.rar
http://www.x-mail.net/carlos2003/disk3.rar
  #12  
Old 11-05-2003, 00:10
thematrix
 
Posts: n/a
here is may be 1 of yur another victim
hxxp://www.regngo.com/vbrezq/
its vb tool and named
vbrezq
download link
hxxp://www.regngo.com/vbrezq/vbrdemo.zip

[Edit by JMI: You still have to TURN OFF the check mark on "Automatically parse URLs."]

Last edited by thematrix; 11-05-2003 at 00:12.
  #13  
Old 11-06-2003, 08:21
OHPen's Avatar
OHPen OHPen is offline
Friend
 
Join Date: Aug 2003
Location: lost in code...
Posts: 92
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
OHPen Reputation: 0
thx a lot for all your replies,

this will help me to improve and finish the unpacker sooner,

more help is always welcome

regards,

OH
  #14  
Old 11-07-2003, 16:45
ricnar456 ricnar456 is offline
Friend
 
Join Date: May 2002
Posts: 290
Rept. Given: 1
Rept. Rcvd 28 Times in 10 Posts
Thanks Given: 0
Thanks Rcvd at 52 Times in 40 Posts
ricnar456 Reputation: 28
For paul 3333

If you go to mi FTP or crackslatinos page (this tut today is not in the page but tomorrow will be posted), you will see the tut

150-ARMADILLO con COPYMEM2 sin truco de los 1000 bytes por FLIPI.rar

is in spanish but is the case you mention The father not work with the 1000 bytes trick, only put a son to run and this selfunpack.

Is very easy when you reach the second WriteMemoryProcess y you look in the buffer the 2 bytes will be copied are the bytes of the EP (not OEP), of the father (and the son too), well you can change this bytes to EB FE, and run, the father will be RUNNING and the son looping in your proper EP.
In this moment you can pause the father and detach the son BUT DONT CLOSE THE OLLY WITH THE FATHER AND DONT CLOSE THE FATHER PROCESS, ONLY MINIMIZE.
Open other ollydbg atach the son and quit the infinite loop of the oep, and if you dont close the father, the son run in rhe same form an armadillo without copymem2, and unpack in this form.

ah mi FTP is


ftp://curso:[email protected]/


user:curso
pass:curso

carpeta NUEVO CURSO-TEORIASand crackslatinos page is

http://www.crackslatinos.hispadominio.net/

Ricardo
  #15  
Old 11-08-2003, 02:32
donneraza
 
Posts: n/a
Mr Ricardo

Following the <<150-ARMADILLO .... >

I reach here
<<
In this moment you can pause the father and detach the son BUT DONT CLOSE THE OLLY WITH THE FATHER AND DONT CLOSE THE FATHER PROCESS, ONLY MINIMIZE.
>>
and how do you do to detach the son ? I don't see in OLLY cmd any detach option.

And if I go on << Open other ollydbg atach the son and quit the infinite loop of the oep ... >>
OLLY reject by "Unable to attach ... ".

Thanks for reply
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 02:52.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )