Exetools  

Go Back   Exetools > General > General Discussion

Notices

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1  
Old 10-23-2012, 02:06
chessgod101's Avatar
chessgod101 chessgod101 is offline
Co-Administrator
 
Join Date: Jan 2011
Location: United States
Posts: 539
Rept. Given: 2,242
Rept. Rcvd 704 Times in 224 Posts
Thanks Given: 754
Thanks Rcvd at 1,021 Times in 191 Posts
chessgod101 Reputation: 700-899 chessgod101 Reputation: 700-899 chessgod101 Reputation: 700-899 chessgod101 Reputation: 700-899 chessgod101 Reputation: 700-899 chessgod101 Reputation: 700-899 chessgod101 Reputation: 700-899
Windows 7 basing problem

I am having a problem with a target I am attempting to reverse. I have added a new section to the file to use to modify some data that is calculated and stored into the program.This code works correctly on XP. However, the feature of random basing that is present in the windows 7 operating system is causing my address references to point to invalid data due to their base not being altered with the rest of the program. Here is my current code:
Code:
01515234    803D 6A525101 0>CMP BYTE PTR DS:[151526A],1
0151523B    0F8D 37010000   JGE Houdini_.01515378
01515241 >  B9 30515101     MOV ECX,Houdini_.01515130
01515246    8B0C08          MOV ECX,DWORD PTR DS:[EAX+ECX]
01515249    3E:894C04 18    MOV DWORD PTR DS:[ESP+EAX+18],ECX
0151524E    66:83C0 04      ADD AX,4
01515252    66:3D 0001      CMP AX,100
01515256  ^ 75 E9           JNZ SHORT <Houdini_.myloop>
01515258    C605 6A525101 0>MOV BYTE PTR DS:[151526A],1
My problem is the pointer to 151526a and the pointer to 1515378. When windows 7 applys the rebasing, these addresses are not rebased, resulting in them pointing to invalid data. Is there any method to insure that these addresses are rebased with the rest of the program?
__________________
"As the island of our knowledge grows, so does the shore of our ignorance." John Wheeler
Reply With Quote
 


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
C# (Classic .exe, Windows 10, Windows Phone etc.) Protection delidolunet General Discussion 7 10-11-2016 01:10
(Q) .NET App Source Code Protection (Silverlight, Windows Phone, Windows 8) delidolunet General Discussion 7 08-02-2013 10:33
Windows 2000 and Windows nt 4 sources, question shady General Discussion 2 04-15-2004 04:17


All times are GMT +8. The time now is 18:18.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )