Exetools  

Go Back   Exetools > General > General Discussion

Notices

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #4  
Old 02-22-2022, 06:07
h4sh3m h4sh3m is offline
Friend
 
Join Date: Aug 2016
Location: RCE
Posts: 61
Rept. Given: 1
Rept. Rcvd 4 Times in 2 Posts
Thanks Given: 54
Thanks Rcvd at 81 Times in 35 Posts
h4sh3m Reputation: 4
Hi

It might happens because :
1- your target is .NET file and your patched file has another copy in GAC folder (mostly dll files in this case)!

2- sometimes when you're patching files (dll files in .NET I mean) and just renaming original files, windows loader keep going to load original file (don't know why) so you just need to change original file's extension of re/move it solve problem.

3- in native files, sometimes you need to disable ASLR and/or relocation flag, also you need to use rva instead va to have better results (needs more steps but its better).

...

xyz- let me know if some parts (or all of them) is not correct


BR,
h4sh3m
Reply With Quote
The Following 2 Users Say Thank You to h4sh3m For This Useful Post:
Doit (02-23-2022), niculaita (02-22-2022)
 


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Evading behavior analysis 0xall0c General Discussion 3 05-14-2018 23:44
armadillo strange behavior drequinox General Discussion 0 02-11-2006 08:52
weird search behavior abitofboth General Discussion 0 01-30-2005 20:48
A weird debugging question sgdt General Discussion 5 06-28-2004 13:11


All times are GMT +8. The time now is 18:55.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )