Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 03-24-2004, 15:53
britedream britedream is offline
Friend
 
Join Date: Jun 2002
Posts: 436
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 7 Times in 7 Posts
britedream Reputation: 0
0041EFE6 55 PUSH EBP
0041EFE7 8BEC MOV EBP,ESP
0041EFE9 6A FF PUSH -1
0041EFEB 68 A05F4200 PUSH DVDIdleP.00425FA0
0041EFF0 68 40EF4100 PUSH DVDIdleP.0041EF40 ; JMP to MSVCRT._except_handler3
0041EFF5 64:A1 00000000 MOV EAX,DWORD PTR FS:[0]
0041EFFB 50 PUSH EAX
0041EFFC 64:8925 0000000>MOV DWORD PTR FS:[0],ESP
0041F003 83EC 68 SUB ESP,68
0041F006 53 PUSH EBX
0041F007 56 PUSH ESI
0041F008 57 PUSH EDI
0041F009 8965 E8 MOV DWORD PTR SS:[EBP-18],ESP
0041F00C 33DB XOR EBX,EBX
0041F00E 895D FC MOV DWORD PTR SS:[EBP-4],EBX
0041F011 6A 02 PUSH 2

this is the correct stolen.
Reply With Quote
  #2  
Old 03-24-2004, 16:06
britedream britedream is offline
Friend
 
Join Date: Jun 2002
Posts: 436
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 7 Times in 7 Posts
britedream Reputation: 0
for the stack everything follow my tut. except 12ffbc == 00000000 instead of ffffffff, but if you folllow the code ,it was there but just over written by:
mov dword ptr ss:[ebp-4],ebx; the ebp== 12ffc0 if you substract 4 from it, you will end up at 12ffbc, where ebx with value of 0 moved to it.

learn to use the stack with the trace, not the trace alone.

sorry I relied on lownoise first finding and it was wrong.

Last edited by britedream; 03-24-2004 at 16:14.
Reply With Quote
  #3  
Old 03-24-2004, 17:42
SvensK
 
Posts: n/a
Hmm, lots of imports the aspr2 plugin can't handle on this one...
Reply With Quote
  #4  
Old 03-24-2004, 20:05
Maltese
 
Posts: n/a
Thank You both Lownoise & Britedream.

So now I understand why the PEiD shows compiler. I must see how a normal program compiled with that particular brand compiler has it's startup code. Got it.

Since there is nothing in the "K" (STACK) window, I do not need a JMP I just fill in the 45 blank "00" bytes with the stolen bytes. Got it.

I apologize...when I learned to crack on the Apple ][e (Don't laugh... I know you are ) *Hey my Algebra teacher got me started. A Push was a push. After looking at another tutorial I saw that MOV DWORD PTR SS:[ESP+number],EBP is the same as PUSH EBP. This is my failure. Now I know.

Thank you everyone for your patience... and willingness to help.

I am using Imprec now. I tried setting size to 1000 and only found 2 instances where dissasemble/hex said no data. I have to go to work... I look at it with Imprec later today after work.

I'll share with you what I find out.

Thanks again everyone!

-Malt

Last edited by Maltese; 03-24-2004 at 20:48.
Reply With Quote
  #5  
Old 03-24-2004, 22:12
britedream britedream is offline
Friend
 
Join Date: Jun 2002
Posts: 436
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 7 Times in 7 Posts
britedream Reputation: 0
To svensk

the target runs on this iat:
there are only two exceptions, if you fix the first one you are registered, the second is to correct the stack.(I haven't test the program but it runs fine).
Attached Files
File Type: txt tree.txt (21.0 KB, 25 views)

Last edited by britedream; 03-24-2004 at 22:16.
Reply With Quote
  #6  
Old 03-24-2004, 22:25
SvensK
 
Posts: n/a
Ok, I'll check it out and thanks for the nice scripts for OllyScript btw. Saves alot of time
Reply With Quote
  #7  
Old 03-24-2004, 22:36
britedream britedream is offline
Friend
 
Join Date: Jun 2002
Posts: 436
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 7 Times in 7 Posts
britedream Reputation: 0
my pleasure!,

Some time it is usefull to use my script "asprsto", it will stop where we should be looking in the stack, that is 12ffc4:77e814c7(for this program), F9 few times till you are at mov ebp,esp; then follow the execution of your stolen with F8.

Last edited by britedream; 03-24-2004 at 22:38.
Reply With Quote
  #8  
Old 03-24-2004, 22:49
SvensK
 
Posts: n/a
Nice stuff, I followed the stolen bytes during execution with your method.
Still having problems with my dumped exe though. After the trace I end up at:

0041F013 FF15 68274200 CALL DWORD PTR DS:[422768] ; MSVCRT.__set_app_type

I insert the stolen bytes and change the origin to PUSH EBP at 41EFE6 and then dump the exe with OllyDump, unchecking Rebuild Import. I load your tree in ImpRec and press Fix Dump. I load the exe in LordPE and change OEP to 1EFE6. Problem is the exe still wont run.

It crashes at: 0041F115 |. E8 F6020000 CALL dumpLord.0041F410
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ASProtect SKE unpacking TempoMat General Discussion 10 08-24-2016 17:48
need help unpacking ASProtect Fade General Discussion 8 05-25-2011 22:12
Unpacking asprotect britedream General Discussion 7 09-01-2004 01:46


All times are GMT +8. The time now is 22:45.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )