|
|
|
|||
|
General Subjects
|
| Anything GameHacking related, not multiplayer, that doesn't go in the other subforums below. |
|
||||||
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
(#2 (permalink))
|
|
Crew
![]() Posts: 170
Join Date: Sep 2006
Last Online: Today 04:49 AM Reputation:
![]() User is Offline
|
re: -
06-29-2009, 07:20 AM
Show's how to bypass one trick implemented by many packers.
Basically, find the 'pushad', usually one of, if not the first instructions. Step over. Hardware breakpoint dump value in esp. In other words, when 'popad' is executed break. Typically thereis either a jmp to OEP is push/ret to OEP after the popad. Once at OEP, dump file and fix imports with ImpRec. How the ESP trick actually works - KOrUPt Of course, themida may not use this method in which case my advice would be useless. But a cool trick nonetheless to know! Regarding specific themida help, not sure... maybe BiW Reversing - The challenge is yours can help. |
|
(#3 (permalink))
|
|
Posting Well
![]() Posts: 25
Join Date: Jan 2009
Last Online: 07-21-2009 10:21 PM Reputation:
![]() User is Offline
|
06-29-2009, 10:47 AM
Show's how to bypass one trick implemented by many packers.
Basically, find the 'pushad', usually one of, if not the first instructions. Step over. Hardware breakpoint dump value in esp. In other words, when 'popad' is executed break. Typically thereis either a jmp to OEP is push/ret to OEP after the popad. Once at OEP, dump file and fix imports with ImpRec. How the ESP trick actually works - KOrUPt Of course, themida may not use this method in which case my advice would be useless. But a cool trick nonetheless to know! Regarding specific themida help, not sure... maybe BiW Reversing - The challenge is yours can help. |
|
(#6 (permalink))
|
|
n00bie
|
06-30-2009, 03:45 AM
Unpacking as in cracking. try out ARTEAM REDIRECT. It has everything you need in the forums.
|
|
(#7 (permalink))
|
|
Posting Well
![]() Posts: 25
Join Date: Jan 2009
Last Online: 07-21-2009 10:21 PM Reputation:
![]() User is Offline
|
06-30-2009, 12:30 PM
Unpacking as in cracking. try out ARTEAM REDIRECT. It has everything you need in the forums.
|
|
(#8 (permalink))
|
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|
|
| New To Site? | Need Help? |