Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #16  
Old 03-11-2009, 21:53
bedrock's Avatar
bedrock bedrock is offline
Friend
 
Join Date: May 2002
Posts: 96
Rept. Given: 8
Rept. Rcvd 5 Times in 2 Posts
Thanks Given: 20
Thanks Rcvd at 2 Times in 2 Posts
bedrock Reputation: 5
is there some news on 5.3 (or 5.4) there seems to be a bit more talk recently, but i have seen no news yet?

--
bedrock
Reply With Quote
  #17  
Old 03-13-2009, 14:38
redbull redbull is offline
Friend
 
Join Date: Mar 2004
Posts: 160
Rept. Given: 17
Rept. Rcvd 5 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 6 Times in 6 Posts
redbull Reputation: 5
This doesn't remove the water mark but you have patched the routine which warns that a bad file has been loaded. (Correct me if I am wrong).

So you can use any pirated IDA, change the signature and still be able to use the databases? (even though the MD5 does not match ?) or does this patch the checksum checking on the IDB only ?
Reply With Quote
  #18  
Old 03-13-2009, 23:02
arlequim's Avatar
arlequim arlequim is offline
IBMSecuritySystemsXForce
 
Join Date: Feb 2009
Location: Punta Entinas-Sabinar, ALMERIMAR
Posts: 295
Rept. Given: 52
Rept. Rcvd 317 Times in 104 Posts
Thanks Given: 46
Thanks Rcvd at 193 Times in 63 Posts
arlequim Reputation: 300-399 arlequim Reputation: 300-399 arlequim Reputation: 300-399 arlequim Reputation: 300-399
Quote:
Originally Posted by redbull View Post
This doesn't remove the water mark but you have patched the routine which warns that a bad file has been loaded. (Correct me if I am wrong).

So you can use any pirated IDA, change the signature and still be able to use the databases? (even though the MD5 does not match ?) or does this patch the checksum checking on the IDB only ?
Hello
i have only patched the check about "database corrupt" and "pirated copy" (you right)
Quote:
So you can use any pirated IDA, change the signature...
To be honest i dont know, i have only loaded the conficker database. That means you should to try other databases and if you encounter some prob i will try to analyze the MD5 check procedure.
Reply With Quote
  #19  
Old 03-14-2009, 00:19
ZeNiX's Avatar
ZeNiX ZeNiX is offline
Administrator
 
Join Date: Feb 2009
Posts: 735
Rept. Given: 177
Rept. Rcvd 772 Times in 259 Posts
Thanks Given: 226
Thanks Rcvd at 910 Times in 247 Posts
ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899 ZeNiX Reputation: 700-899
It would be more clear and helpful if somebody can show up and give us more information about the water mark.

Then, we can try to fake or erase the water mark.

I wonder if some one has a tool to show the water mark.
It would be a great help, though.
Reply With Quote
  #20  
Old 03-14-2009, 02:03
arlequim's Avatar
arlequim arlequim is offline
IBMSecuritySystemsXForce
 
Join Date: Feb 2009
Location: Punta Entinas-Sabinar, ALMERIMAR
Posts: 295
Rept. Given: 52
Rept. Rcvd 317 Times in 104 Posts
Thanks Given: 46
Thanks Rcvd at 193 Times in 63 Posts
arlequim Reputation: 300-399 arlequim Reputation: 300-399 arlequim Reputation: 300-399 arlequim Reputation: 300-399
Quote:
Originally Posted by zenix View Post
It would be more clear and helpful if somebody can show up and give us more information about the water mark.

Then, we can try to fake or erase the water mark.

I wonder if some one has a tool to show the water mark.
It would be a great help, though.
Exactly, you right: i'm not great user of IDA so i need more infos about "water mark". Then i can go on, but let me know how many times you need to load .idb files??? Most of times i open .exe or .dll files.
Reply With Quote
  #21  
Old 03-14-2009, 05:54
Darren Darren is offline
Friend
 
Join Date: May 2003
Posts: 28
Rept. Given: 3
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 16
Thanks Rcvd at 5 Times in 4 Posts
Darren Reputation: 0
Watermark

Well if someone was able to get 2 copies of a product same version / same build and do a comparison, it might shed some light, hehe but I think its hard enough to get ahold of 1 copy of this product, never mind about 2 copies

Darren
Reply With Quote
  #22  
Old 03-14-2009, 19:50
Git's Avatar
Git Git is offline
Old Git
 
Join Date: Mar 2002
Location: Torino
Posts: 1,116
Rept. Given: 220
Rept. Rcvd 265 Times in 157 Posts
Thanks Given: 110
Thanks Rcvd at 220 Times in 126 Posts
Git Reputation: 200-299 Git Reputation: 200-299 Git Reputation: 200-299
Depends on if you shut down your machine at night, but I have IDB files I have opened hundreds of times. I doubt I have any that have not been opened at least 20 times. Exe's and Dll's get opened only once, thereafter you are working on the IDB file.

Git
Reply With Quote
  #23  
Old 03-21-2009, 01:15
Pyrae Pyrae is offline
Friend
 
Join Date: Jan 2002
Posts: 22
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Pyrae Reputation: 0
Quote:
Originally Posted by Jupiter View Post
quick patch:

ida.wll
Offset | Old | New
000F05F9: D0 D1

ida64.wll
Offset | Old | New
0010DF31: CC CD
Elegant one, Jupiter.
Here's an additional 'assignment' (if ne1 is insterested in this little game ):
How many bits do u need to patch w/o touching any code and/or how many other possibilities of 1-bit code patches do u have in order to achieve the same goal?


Have fun,
Pyrae
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Database programming in C++ hmora General Discussion 1 07-12-2004 09:48


All times are GMT +8. The time now is 13:01.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )