Posted: Wed Jun 21, 2006 2:55 pm Post subject: haggar's ASProtect 1.23RC4 tutorial
hi ppl
i have reversed all the stuff in that tutorial haggar's ASProtect 1.23RC4 tutorial (http://www.reversing.be/article.php?story=20050329165716822). I have unpacked the proggy and understand all the stuph
i have an another question. it is about IAT rebuilding.
after unpacking i open ImpREC and select our proggy under olly
1. i write the OEP and Click IAT AutoSearch -> it gives a messagebox and says RVA:11000 and size:5000 . i change these sections after messagebox
2. then i click Get Imports.
3. i click Show Invalid
4. there are a lot stuph highlighted on the window. i RiGHT-Click and select one on the Haggars PLUGINS for imprec TO TRACE!!
5. this takes a lot time (a few minutes)
6. it finishes (in log part it says there are a lot failed things ???)
7. then i clicked on Fix Dump and it successfully rebuilds
BUT i couldnt open the unpacked and rebuilded Proggy
did i do smth wrong ??
where is the problem
thanks for your help
NOTE: i have searched your forum but really i couldnt find the exact answer
NOTE2: i use the same proggy same version (it is still downloadable)
and it gives the error; you know, a messagebox appers and it says this program confront with a SERIOUS problem SEND an error report or Dont Sent
this kinda message?
Posted: Wed Jun 21, 2006 9:06 pm Post subject: of course?
Quote:
before step 7 of course i delete all thunks
Well that may be the root of the problem, imo its inadvisable to delete all those marked as invalid unless you are resonably confident they (at least some of them) are not redirected function calls. Use tutorials as a guide only and don't just accept/assume everything in them as correct.
@bengunn:
Do you mean that shouldnt i delete those thunks? then what must i do?? Just Cut them or do nothing???
@Knight:
Dude i write in my first post, it is the same protection same file
However, lets say a diffrent proggy but same protection, logic is same, i find the OEP and stolen bytes but ınfortunately i cant rebuild the import??
Posted: Thu Jun 22, 2006 2:13 pm Post subject: invalid
Quote:
@bengunn:
Do you mean that shouldnt i delete those thunks? then what must i do?? Just Cut them or do nothing???
Actually the imprec plugin ASProtect 1.23 rc4 works perfectly on the target, I hadn't noticed you used 5000 for iat size, that is the reason for so many unresolved (invalid) 000008D8 is the correct size, you should not have any unresolved api's after using the plugin with this rva and size.
iat rva: 00011000
iat size : 000008D8
btw i 've overcome the problem before writing the stolen bytes on 00 bytes on Olly, i analyze the code. but i musn't. So first i write the stolen bytes on Olly, then analyze the code and rebuild the iat and it is ok!!
@bengunn:
hey dude as u said, i should take the IAT size: 000008D8 are you sure ??
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You can attach files in this forum You can download files in this forum