![]() |
and whats the value of the byte @ ebp-1.. that seems somewhat critical
|
can you share your target (max 50 mb)?
|
|
Quote:
also that value is written by the above function as edx is treated as a pointer to that location, a value is being copied from another location |
Quote:
|
Quote:
|
did you tried to run your debugger as admin?
|
nop i dont have a reason to do so, do i?
|
Quote:
you just need debug file carefully to find out solution, you need look after decryption function for next step ;) (you have all needed info to reach oep). |
i am not running inside a vm and i dont know the key if it has already created, this api is not being called(can you tell me the key path so i can delete it?)..also i have to return 0 in eax and ebp-1?
also i am getting access violation if i return all 0 from the pattern function...strange! |
so i think this is doing something like xoring the first byte at that address where the exception is occuring, and as because registration is bypassed by xoring but our licence is still invalid so i get exception?
also this is wrapped by a loop and later one more loop to decrypt another function!! dont know how i can validate the licence keys! here: Code:
push ebx |
is 0x4c00000 is the oep?
|
my progress till now in python x64dbg:
Code:
from x64dbgpy import pluginsdk |
Quote:
|
previous oep is wrong, i am very sure it is 0x004BF9C0 but still contains all 0s. its hard!
|
| All times are GMT +8. The time now is 23:59. |
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX