![]() |
|
#5
|
||||
|
||||
|
oh sorry but i haven't much time last days so i can't repost.
I see that i have done a big mistake cos i don't call dword ptr:[IAT_address] i call call dword ptr:[ImportTable_address] and there's no valid IAT in the file. There are 2 IAT but both aren't valid i guess. And no one is set in the PE header IAT entry field. But i have a Import Table located at 1000h cos vb6 app. ![]() Ok the protection i'm dealing with is again securom v4.8xx. here a snippet of the code.. Code:
NOP NOP NOP NOP NOP NOP NOP NOP NOP NOP NOP PUSH EBP MOV EBP,ESP SUB ESP,0C PUSH s*******.00401AB6 ; SE handler installation MOV EAX,DWORD PTR FS:[0] PUSH EAX MOV DWORD PTR FS:[0],ESP SUB ESP,2C PUSH EBX PUSH ESI PUSH EDI MOV DWORD PTR SS:[EBP-C],ESP MOV DWORD PTR SS:[EBP-8],s*******.00401338 MOV EDX,DWORD PTR SS:[EBP+8] XOR ESI,ESI LEA ECX,DWORD PTR SS:[EBP-24] MOV DWORD PTR SS:[EBP-1C],ESI MOV DWORD PTR SS:[EBP-24],ESI MOV DWORD PTR SS:[EBP-2C],ESI MOV DWORD PTR SS:[EBP-30],ESI MOV DWORD PTR SS:[EBP-34],ESI CALL DWORD PTR DS:[939510] ;this call guide also to secu but no problem fixing this one LEA EAX,DWORD PTR SS:[EBP-28] PUSH EAX PUSH 800 INC EAX CALL s*******.00911E00 ;this call also guide to sec but i can't fix it so easy as the one above MOV ECX,DWORD PTR SS:[EBP+C] PUSH ESI PUSH ESI PUSH ESI PUSH ECX LEA EDX,DWORD PTR SS:[EBP-30] PUSH s*******.006203B0 PUSH EDX DAA CALL s*******.00911FC0 ;here again also secu PUSH EAX CALL s*******.0061FB50 ;here no secu call |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| How to log all procedure calls? | morgot | General Discussion | 2 | 10-01-2024 03:30 |
| VB calls | obfuscator | General Discussion | 7 | 06-04-2014 13:46 |
| How do you find all modular calls with Olly? | Fade | General Discussion | 2 | 04-09-2007 06:06 |
| Ida 4.6 calls back home??? | loman | General Discussion | 3 | 09-22-2004 03:29 |
| Problem with fixing IAT | K3nny | General Discussion | 5 | 01-04-2004 19:26 |