Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 08-24-2004, 07:07
drocon
 
Posts: n/a
DEP, as far as i've seen/heard, just prohibits code from being executed in the stack/heap, and requires VirtualAlloc() with the right flags, or VirtualProtect() to alter the page. am i missing something here? is it not possible to alter the page for the stack/heap?
Reply With Quote
  #2  
Old 08-24-2004, 13:30
LordVader
 
Posts: n/a
Use LordPE...

Use Lord PE or WinHex to scan the memory (before your proggy) to see what is set originally... Maybe you're setting the memory range incorrectly.

/LordVader/
Reply With Quote
  #3  
Old 08-24-2004, 14:37
tr1stan
 
Posts: n/a
Thx for the help...I think i have found my problem...the programm
starts itself again via CreateProcessA so i always use a false PID
for reading memory have to fix that asap.

tAz: nice info thx...will give it a try
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Question regarding .NET dumping 0x22 General Discussion 3 08-23-2014 16:37
Dumping protected DLL 'perplex' data section grimm General Discussion 4 02-28-2005 08:19
Dumping Armadillo protected DLL? FEARHQ General Discussion 10 02-09-2005 11:08
Dumping sfld General Discussion 2 03-20-2004 23:56
Dumping a dll with ollydump ceK52z General Discussion 6 02-08-2004 19:39


All times are GMT +8. The time now is 00:53.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )