首页
社区
课程
招聘
[ZT]Oepfind 1.0 + src by Human 更新1.56
发表于: 2006-1-6 20:59 5058

[ZT]Oepfind 1.0 + src by Human 更新1.56

2006-1-6 20:59
5058
测试!

我对src感兴趣,测试可检测!

附件:oepfind.rar


[课程]Android-CTF解题方法汇总!

收藏
免费 1
支持
分享
最新回复 (20)
雪    币: 200
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
2
我感谢一下,收藏看看
2006-1-6 22:15
0
雪    币: 603
活跃值: (617)
能力值: ( LV12,RANK:660 )
在线值:
发帖
回帖
粉丝
3
支持,不过那个OEP按钮有点让人困惑...
2006-1-6 22:50
0
雪    币: 2223
活跃值: (866)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
4
点打开文件后就报错了……
怎么处理
2006-1-7 01:12
0
雪    币: 223
活跃值: (101)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
5
好多OPE啊:
2006-1-7 17:43
0
雪    币: 671
活跃值: (723)
能力值: ( LV9,RANK:1060 )
在线值:
发帖
回帖
粉丝
6
Let me try.
2006-1-7 18:29
0
雪    币: 93908
活跃值: (200199)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
7
oepfind v1.1 by Human/MiNT and deroko/ARTeam

附件:derokohuman.zip
2006-1-8 11:24
0
雪    币: 93908
活跃值: (200199)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
8
2006-1-8 11:25
0
雪    币: 2223
活跃值: (866)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
9
Good……!
2006-1-8 18:17
0
雪    币: 207
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
10
小声的问句 这是做啥的
2006-1-8 20:44
0
雪    币: 10500
活跃值: (2159)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
11
什么东西下来看看  找OEP?
2006-1-9 04:23
0
雪    币: 392
活跃值: (909)
能力值: ( LV9,RANK:690 )
在线值:
发帖
回帖
粉丝
12
好像就是Olly的代码区块内存访问断点,很容易anti的样子。。
2006-1-9 17:39
0
雪    币: 450
活跃值: (552)
能力值: ( LV9,RANK:690 )
在线值:
发帖
回帖
粉丝
13

during shittest christmas of my life, 2 weeks without net, 2 car fixes,i was so bored so i decided to code my own oepfinder. first was deroko [ARTEAM], but his version is big like hell and hard to understand.
what the differences?

-deroko src is in tasm
-well i used masm(but i also prefer tasm, but its dying )

-deroko patches EP
-i create process already as debugged no need for suspending etc

-deroko oepfinded stops after messagebox with oep
-mine stops on exitprocess so we can find oep inside asprotect that has unpacking code inside code section that is later overwritten with unpacked code

-deroko is using small debuger part that gives instruction length and sets int 3(CC)
-i dont use it just set guard page on first section

worked with most of single process protectors,packers
sdprotector and others detect that they are debugged

oep find 1.1
improved oep now asks is this oep if yes it will dettach from debuging,so last show when we press yes is our oep so write it down or!
use detach, i was bores with restoring stolen bytes by EBFE
so when you press detach and right oep is and choose yes, we will patch oep to EBFE so its in infinite loop, and you can attach with olly press F9 to run and F12 t break at our inf jump, now last step press ok on oep finder messagebox and i will restore stolen bytes, move cursor in olly and we are happy
enjoy!
Human

v1.2 support for parsing name with commandline

v1.3
removed 2 edit's where showed section and size
now listbox defaults to 1st section but you can choose other and then press oep or dettach. next move improve engine

附件:oepfindv13.rar 附件:oepfindv13.rar
2006-1-9 22:04
0
雪    币: 93908
活跃值: (200199)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
14
你辛苦!

明年winndy有意来帮忙吗/?
2006-1-9 22:33
0
雪    币: 450
活跃值: (552)
能力值: ( LV9,RANK:690 )
在线值:
发帖
回帖
粉丝
15
最初由 linhanshi 发布
你辛苦!

明年winndy有意来帮忙吗/?


呵呵,谢谢linhanshi大哥.
这可是累活啊,真诚道一声:你辛苦了!
我明年学习很忙,还要搞paper,学unpack,要进实验室,
不知有没有时间关注各大论坛最新动态。

要是有时间,很乐意为大家效劳!
2006-1-9 22:45
0
雪    币: 93908
活跃值: (200199)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
16
THANKS!
2006-1-10 01:56
0
雪    币: 450
活跃值: (552)
能力值: ( LV9,RANK:690 )
在线值:
发帖
回帖
粉丝
17

v1.31
added to listbox display of sections characteristics Read Write Execute

1.32 patch for kernel32.TerminateProcess so acprotect cant kill us, same is with yodas protector, but that one after detecting that parent process PID isnt explorer.exe PID kills us and itself. it will not kill us now but itself only, have to add more fixes. we patch kernel32 on dll_load_event due on createprocess only exe and ntdll.dll are loaded rest is later. stay tuned for more updates


附件:oepfindv132.rar 附件:oepfindv132.rar
2006-1-12 10:20
0
雪    币: 450
活跃值: (552)
能力值: ( LV9,RANK:690 )
在线值:
发帖
回帖
粉丝
18

v1.4
used length disasm engine from deroko to get instruction size. added int 3 patching for more accurate results. on my targets it now works on correct oep. if you find any file it doesnt work, send it to me. doesnt work on yodas protector due it checks if parentpid is pid of explorer.exe, i did a patch but then it doesnt want to work with acprotect, have to find a solution for both, and as we know life later for all of them. now probably next move is execryptor support
2006-1-14 09:10
0
雪    币: 93908
活跃值: (200199)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
19
最初由 winndy 发布


附件:oepfindv14.rar
2006-1-14 09:20
0
雪    币: 93908
活跃值: (200199)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
20
1.56
counting of axx violation exceptions added.
上传的附件:
2006-7-9 08:02
0
雪    币: 200
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
21
Thanks.!!
2006-7-14 00:55
0
游客
登录 | 注册 方可回帖
返回
//