首页
社区
课程
招聘
[转帖]Import Reconstructor 1.7c - Fixed by Newbie_Cracker
2010-8-2 21:32 4671

[转帖]Import Reconstructor 1.7c - Fixed by Newbie_Cracker

2010-8-2 21:32
4671
From:EXETOOLS

Hi buddies.

As you know ImpRec always has had problem to fix imports of dumped DLLs because of rebasing. It reads ImageBase from memory, but uses ImageBase of dll from header to calculates RVA of JMP/CALL API.
To fix that manually, you had to change ImageBase of dump to its value of mapped dll, and then fix imports by ImpRec.

By this fix, you don't need above procedure anymore. I patched ImpRec to overwrite ImageBase of dump with its new value.

There are some screenshots in attachment for comparison of v1.7c orginal and patched version.

Have fun.

[培训]《安卓高级研修班(网课)》月薪三万计划,掌握调试、分析还原ollvm、vmp的方法,定制art虚拟机自动化脱壳的方法

上传的附件:
收藏
点赞1
打赏
分享
最新回复 (2)
雪    币: 85328
活跃值: (198625)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
linhanshi 2010-9-15 01:03
2
0
ImpRec 1.7d

Hello to all.

I know it's an old topic, but I fixed some bugs in last fixed version.

[QUOTE]- Fixed bug introduced in 1.7b which destroys IAT Autosearch feature in some packed targets, like eXpressor 1.8 (Newbie_Cracker).
- Fixed crash introduced in 1.7b when DLL's PE header has "NO Access" flag (Newbie_Cracker).


Here is a sample to test the IATAutosearch failure in version 1.7b & 1.7c which has not beed exist in older versions.

Use this OEP = 739D to find imports.[/QUOTE]
上传的附件:
雪    币: 85328
活跃值: (198625)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
linhanshi 2010-10-1 06:54
3
0
ImpRec 1.7e

Another bug fix:

- Fixed a bug which avoids ImpREC to fix JMP DWORD [...] if it is located at the end of code section (Newbie_Cracker)
( Thanks to Nexus6 for report the bug and provide samples)


It's something like this:

.00429428: FF25D0E5A200                 jmp         memset ;msvcrt.dll
.0042942E: FF25D4E5A200                 jmp         memcpy ;msvcrt.dll
.00429434: FF2518E44200                 jmp         d,[0042E418]
end of code section regarding to PE header
 0002943A: 0000                         add         [eax],al
 0002943C: 0000                         add         [eax],al
 0002943E: 0000                         add         [eax],al
 00029440: 0000                         add         [eax],al
 00029442: 0000                         add         [eax],al
 00029444: 0000                         add         [eax],al
 00029446: 0000                         add         [eax],al
 00029448: 0000                         add         [eax],al


ImpREC 1.7e.rar

Программное обеспечение выпуска и Windows Crack Обучение
Нам-Dabei Guanyin Бодхисаттва Нам без митабха
上传的附件:
游客
登录 | 注册 方可回帖
返回