Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #16  
Old 01-03-2005, 04:57
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
to your post... very well & wise said but also from answers you can learn if you study them... earlier, when i started cracking, i looked at the differences... before patching, after patching. in this time i wasn't able to unpack any packer, this was really interesting what was done... why did a cracker that steps. and after that period, i figured out how to find my own solutions for everything. so much different ways to patch.

to be on the way you said... this target doesn't use a API to kill your olly. it has a way of anti-debug i never saw in other targets.
Reply With Quote
  #17  
Old 01-03-2005, 05:18
JMI JMI is offline
Leader
 
Join Date: Jan 2002
Posts: 1,627
Rept. Given: 5
Rept. Rcvd 199 Times in 99 Posts
Thanks Given: 0
Thanks Rcvd at 98 Times in 96 Posts
JMI Reputation: 100-199 JMI Reputation: 100-199
Your comments that comparison of solutions are very helpful is certainly correct. The only point I am suggesting is that if a solution is released too early, it does tend to cut down on efforts of others to find their "own" solution. That result is not "caused" by your posting of a solution, but by the nature of some to stop their own efforts when anyone gives them a solution.

Regards,
__________________
JMI
Reply With Quote
  #18  
Old 01-03-2005, 05:35
Michel Michel is offline
Friend
 
Join Date: Sep 2004
Location: France
Posts: 66
Rept. Given: 2
Rept. Rcvd 6 Times in 1 Post
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Michel Reputation: 6
@JMI : You seem to be a very fine "mind-unwrapper" ! nice !
Reply With Quote
  #19  
Old 01-03-2005, 05:37
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
do you think so? but i think if you really want to learn how to do it you will do it... and following the steps done in this solution is also own effort
Reply With Quote
  #20  
Old 01-03-2005, 06:19
JMI JMI is offline
Leader
 
Join Date: Jan 2002
Posts: 1,627
Rept. Given: 5
Rept. Rcvd 199 Times in 99 Posts
Thanks Given: 0
Thanks Rcvd at 98 Times in 96 Posts
JMI Reputation: 100-199 JMI Reputation: 100-199
But are you taking into full account the tendency of many to "settle" for the easy way out?? They may "want to do it," but just how hard are they willing to work at it themselves, especially if the going gets slow and they have little patience for a lack of "instant gratification." There are certainly many who are equally determined to "do it on their own" who would not want to look at someone else's solution until they had exhausted their own efforts and, hopefully, reached a solution on their own.

However, consider that it is often those who are not sufficiently skilled who discover a "new" way to accomplish the solution, simply because those more "trained" tend to think there is a "correct" way to do something, and the "less skilled" simply don't know that one is not "supposed" to be able to do it the way they finally figured out how to accomplish the task.

So, I simply suggest that "hints" and "nudges" are of more assistance to such individuals at this early stage in their development. Asking them to exercise their brain with "original" though is usually of more benefit in the learning process, than asking them simply to analyze someone else��s solution to the problem. But clearly this also can be of great benefit, when one's own thought have seemed to hit a dead end or lack of inspiration. I don��t think we are really disagreeing on anything.

Regards,
__________________
JMI
Reply With Quote
  #21  
Old 01-04-2005, 07:32
Android
 
Posts: n/a
Hi,
There is a command
INT 2E
If I'm able to nop it all the ptotection is gone.
But the problem is that I can't NOP it.
Any Suggestion?
Regards,
Android.

Last edited by Android; 01-04-2005 at 19:14.
Reply With Quote
  #22  
Old 01-04-2005, 19:31
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
there's a function inside this program which overwrites your patch again and again... so maybe a memory-bp helps
Reply With Quote
  #23  
Old 01-10-2005, 21:53
Teerayoot Teerayoot is offline
Friend
 
Join Date: Mar 2004
Location: ประเทศไทย
Posts: 83
Rept. Given: 0
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 2
Thanks Rcvd at 16 Times in 8 Posts
Teerayoot Reputation: 3
source code provided

*I love to provide all source code i made,hope for help some newbie coder*

Last edited by Teerayoot; 01-10-2005 at 21:55.
Reply With Quote
  #24  
Old 01-10-2005, 22:11
NeOXOeN NeOXOeN is offline
Friend
 
Join Date: Jan 2005
Posts: 273
Rept. Given: 2
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 2
Thanks Rcvd at 18 Times in 18 Posts
NeOXOeN Reputation: 3
i think what Teerayoot did its very nice.. putting out exe and source so everyone cal learn from it ...there should be more ppl like him
Since now days not a lot of ppl are contributing to scene or reversing ..especially with their ideas and all .. A lot of good work stays priv.. and poor and more or less crap is comming out...


So i am glad something nice came out for a change


bye NeO
Reply With Quote
  #25  
Old 01-13-2005, 17:11
MARcoDEN
 
Posts: n/a
IMHO, very easy protection . The method of redirecting to OEP is old as my grandma - JMP EAX. As soon as it have been located, put there Hardware BP, step into and you are on OEP .
Attached Files
File Type: rar dumped_.rar (286.0 KB, 8 views)
Reply With Quote
  #26  
Old 01-15-2005, 04:43
MaRKuS-DJM's Avatar
MaRKuS-DJM MaRKuS-DJM is offline
Cracker + Unpacker
 
Join Date: Aug 2003
Location: Virtual World / Network
Posts: 553
Rept. Given: 7
Rept. Rcvd 6 Times in 4 Posts
Thanks Given: 3
Thanks Rcvd at 16 Times in 10 Posts
MaRKuS-DJM Reputation: 6
marcoden, what you did is unpacking the PeCompact. the goal is to remove the anti-debug protection
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
x64 and anti-debugging lena151 x64 OS 19 11-15-2011 05:24
Win32 Debug Protection Idea nelix General Discussion 12 06-07-2004 19:24


All times are GMT +8. The time now is 17:03.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )