首页
社区
课程
招聘
[转帖]AMDUMPV62 - VERSION 1.2 (ActiveMark v6.2x), latest release
2007-10-31 23:14 3320

[转帖]AMDUMPV62 - VERSION 1.2 (ActiveMark v6.2x), latest release

2007-10-31 23:14
3320
From:ARTeam

by:condzero

info
----
1. Dump and fix ActiveMark v6.2x targets at 2nd layer EP
2. Search for (4) PEB DWORD address pointer references and
create necessary instructions at EP to update for current
execution of dumped file
3. Search for CPUID DWORD address pointer reference and
create necessary instructions at EP to update for current
execution on any machineid of dumped file
4. Better section alignment of dumped file
5. PUSH 2nd layer EP and RETN
6. Append overlay data to end of dumped file
7. Search for and patch VM DWORD address pointer reference
8. Provide the foundation for inline patching dumped file

Please read the readme.txt and document for more information.

Note: This is a dumping tool, not an unpacker or DRM removal tool.
If you have d/l'ed a previous version of this tool, you are
advised to get the latest v1.2 which includes all of the above
modifications.

Source code included.

Get it on the [ARTEAM] RCE related tools page.

cheers!

[培训]二进制漏洞攻防(第3期);满10人开班;模糊测试与工具使用二次开发;网络协议漏洞挖掘;Linux内核漏洞挖掘与利用;AOSP漏洞挖掘与利用;代码审计。

收藏
点赞1
打赏
分享
最新回复 (3)
雪    币: 85452
活跃值: (198780)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
linhanshi 2007-10-31 23:20
2
0
http://arteam.accessroot.com/releases/file_info/download1.php?file=AMDUMPV62_by_condzero.rar
雪    币: 85452
活跃值: (198780)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
linhanshi 2007-10-31 23:53
3
0
Here it:
上传的附件:
雪    币: 417
活跃值: (475)
能力值: ( LV9,RANK:1250 )
在线值:
发帖
回帖
粉丝
cyto 31 2007-11-1 07:15
4
0
很强大.
很和谐.
游客
登录 | 注册 方可回帖
返回