Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 05-04-2004, 09:50
MrAnonymous
 
Posts: n/a
Yup same thing happened on my machine here, so defenetly not just you!

Where can i get the AsprDbgr?
Try the search button as usual, I believe it was posted in Software Releases.
Quote:
Originally Posted by IWarez
There is indeed something not working.

Steps to reproduce error:
1. Start empty
2. Create a certificate
3. Try to create a domain, you'll see an error

Also, when I tried to create a domain and make it create a certificate it works but then I couldn't access my domain properties.

I wonder by myself wheter core was too lazy to unpack the .exe or that they discovered too many traps in the packed .exe that they decided this would be easier. Anyway, back to the drawingboard core

Last edited by MrAnonymous; 05-04-2004 at 09:55.
Reply With Quote
  #2  
Old 05-04-2004, 10:11
Crk
 
Posts: n/a
this exe has many crc checks after detecting aspr. is not longer present , also some invalid stuff left by aspr. after unpacking , stolen bytes etc.. best idea is inline patching it to ensure you'll have a full working exe however if you're too newbie i wouldn't recomend you to start with this target...

Regards
Reply With Quote
  #3  
Old 05-04-2004, 16:46
SvensK
 
Posts: n/a
Hmm, NOD32 displays a virus warning when trying to access that cracked .exe by TSRh. Did anyone else run into this problem?
Reply With Quote
  #4  
Old 05-04-2004, 16:55
bedrock's Avatar
bedrock bedrock is offline
Friend
 
Join Date: May 2002
Posts: 96
Rept. Given: 8
Rept. Rcvd 5 Times in 2 Posts
Thanks Given: 21
Thanks Rcvd at 2 Times in 2 Posts
bedrock Reputation: 5
@Crk,

I downloaded AsprDbgr_build_106, but i dont know how to make a good dump of it... It asks loads of questions about dips, i have been reading about ASPR and dips, but i dont know what i need to do with these dips. Which ever point i dump, and after fixing import it always crashes with a delphi 216 runtim error?

more reading is needed...

--
bedrock
Reply With Quote
  #5  
Old 05-04-2004, 19:10
neogen
 
Posts: n/a
Quote:
Originally Posted by SvensK
Hmm, NOD32 displays a virus warning when trying to access that cracked .exe by TSRh. Did anyone else run into this problem?
Yeah i have here also a warning. This should be a virus, some others have the same problem... Kill it.

We should do it on our own

Cheers, neogen

Last edited by neogen; 05-04-2004 at 19:15.
Reply With Quote
  #6  
Old 05-04-2004, 19:15
IWarez IWarez is offline
Friend
 
Join Date: Jul 2003
Posts: 41
Rept. Given: 7
Rept. Rcvd 6 Times in 2 Posts
Thanks Given: 1
Thanks Rcvd at 0 Times in 0 Posts
IWarez Reputation: 7
Neh, it's not a virus. It's a custom crypting thingie and after that asprotect. As far as I can see it's a false warning.
Reply With Quote
  #7  
Old 05-04-2004, 22:01
SvensK
 
Posts: n/a
@neogen: Maybe we should share some notes on our progress.

I have found stolen and OEP to be the following:
0049899C > $ 55 PUSH EBP
0049899D . 8BEC MOV EBP,ESP
0049899F . 83EC 10 SUB ESP,10
004989A2 . B8 94834900 MOV EAX,G6FTPSer.00498394

And I found that what's causing the most trouble is the Call EAX @ 0040400E.
I get very different results when debugging my dumped exe and the original one.

Edit: My dumped .exe keeps jumping at all the JNB's where it shouldn't.


Regards
SvensK

Last edited by SvensK; 05-04-2004 at 22:03.
Reply With Quote
  #8  
Old 05-04-2004, 22:47
bedrock's Avatar
bedrock bedrock is offline
Friend
 
Join Date: May 2002
Posts: 96
Rept. Given: 8
Rept. Rcvd 5 Times in 2 Posts
Thanks Given: 21
Thanks Rcvd at 2 Times in 2 Posts
bedrock Reputation: 5
Hi SvensK,

After reading lots of posts about aspr and Labba's tute, i was still getting nowhere with this target (i'm still not sure i am very far ) But then i found R@diers tute #6 - Manual unpacking ASProtect 1.23 RC4 - 1.3.08.24 and this has helped, at least now i was able to find stolen bytes, i have the same values as you, but i put oep @ 49899B and there was a nop left before the calls.

0049899B > $ 55 PUSH EBP
0049899C . 8BEC MOV EBP,ESP
0049899E . 83EC 10 SUB ESP,10
004989A1 . B8 94834900 MOV EAX,dumped_.00498394
004989A6 . 90 NOP

But target still fails to run with generating Delphi 216 runtime errors, i traced in olly to the call eax @ 40400E you mention and this execute's around in a loop and finally causes an access violation

--
bedrock
Reply With Quote
  #9  
Old 05-05-2004, 05:05
neogen
 
Posts: n/a
Quote:
Originally Posted by IWarez
Neh, it's not a virus. It's a custom crypting thingie and after that asprotect. As far as I can see it's a false warning.
StudPE says it is ASPACK 2.12... Can somebody confirm it?

My current state: I didn't have the time due to much other projects... I will try it next days on my own...

Cheers, neogen
Reply With Quote
  #10  
Old 05-05-2004, 21:24
Crk
 
Posts: n/a
OEP is: 0049899C -> 0009899C

the 0 you see before this location belongs to some Dword value .. don't touch it!

but stolen bytes you give might be confuse... i tried

558BEC83C4D8B894834900

my exe is not crashing but ends somewhere where the programs quit or is not reading some part necessary to load ...

of course there are some aspr. checks as i said before... if you don't fix them the program will crash .... tip: RaiseException API

make sure also at 0042B68C the call dword has that RVA (dword value [FC824900]) in your dumped exe or will never work or even load at all

the only solution will be to trace with original one and step into the calls until program reach the code to be full loaded... then to trace with dumped one to see differences.

Call EAX @ 0040400E .... and where exactly is calling this.. RVA ?

Last edited by Crk; 05-05-2004 at 21:41.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 06:21.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )