Exetools  

Go Back   Exetools > General > General Discussion

Notices

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #7  
Old 08-09-2005, 22:58
TQN TQN is offline
VIP
 
Join Date: Apr 2003
Location: Vietnam
Posts: 358
Rept. Given: 143
Rept. Rcvd 24 Times in 13 Posts
Thanks Given: 196
Thanks Rcvd at 168 Times in 51 Posts
TQN Reputation: 24
My way with Delphi app:
- Load app with DeDe, export to the .map file to get the VCL event handler addresses.
- Load app in IDA, apply my Delphi Signature and b32vcl.sig.
- Load the exported map above with LoadMap plugin.
- Debug with IDA.
If you wish to debug with OllyDbg, use Mapgen great plugin for IDA of Servil (good job, Servil !) to export the IDA database to .map2 file, and load the .map2 file into OllyDbg with the modify MapConv plugin of Servil.
Sometime, Dede will not be able to decompile the unpacked Delphi app. So you should use "Dump Active Process" function of Dede, or use PE Explorer to decompile the unpacked app, and get the VCL event handle addresses.
As I known, the lastest version of Dede is v3.50.04 build 1635. You can download it from WASM.RU
Regards,
TQN

Last edited by TQN; 08-09-2005 at 23:00.
Reply With Quote
 


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Best Delphi reverse enginerering tool? jonwil General Discussion 11 03-14-2025 01:06


All times are GMT +8. The time now is 01:42.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )