首页
社区
课程
招聘
[下载]Stud_PE v 2.4.0.1
发表于: 2008-4-4 23:05 4228

[下载]Stud_PE v 2.4.0.1

2008-4-4 23:05
4228
v 2.4.0.1 [2 apr 2008]
-fixed a bug with imported functions name lenght;
-added external signature verifier; writed a note about signatures;
-fixed RVA2RAW for UPACK which has EP inside PE HEADER; now imports are shown fine;
-added basic disassembler from hexeditor right click menu;
-fixed showing which export is in fact a forwarder to other dll; like HeapAlloc in kernel.dll;
-added process memory dumper/viewer; right click on the process you want to inspect; you can
use dissasambler (from right click menu inside the hexeditor) to see how the code looks at
  certain VA; the difference from other (dumpers LordPE, ProcDump, PETools) is that it can dump/view
  code blocks protected with PAGE_GUARD or NOACCESS flags.

Note about external signatures
------------------------------
-we have 2 kind of signatures :
        1. relative to entry point (ep_only=true); a number of bytes searched only at a location;
        2. absolute (ep_only=false); a number of bytes searched in entire file;
-relative signature can start with an offset (negative or positive) specified by
(offset=x , x can be ie. 5 or -7 relative to entry point); in addition the relative
signature can start with a number of unknown bytes (?? ?? ?? 3E 45 etc), in this case,
the starting number of those bytes will be considered as an positif offset; but remember,
this is only for (ep_only=true);

Signature rules:-sections with different names; section is ie:"[Name of the Packer v1.0]"
                 -sections with different signatures; for not wasting time;
                 -signature bytes must be hex represended (0-9,A-F);
                 -each signature lenght must be a multiple of 2;
                 -you can use as separator an empty space between each byte (2 hex char)
                  for good understanding (like: "signature = 00 A2 3F" , the same as
                  "signature = 00A23F";
                 -you can use wildcards as "??" if the byte can be everething inside a signature;
                 -only relative signatures (ep_only=true) can start with "??";

-when you fix external signatures file, you must fix first!!, section names (otherwise will
have checking mistakes for next verifications!!),then signature correctitude,then overlaping
signatures; you will have on clipboard the section's name or signature when an error is
found; just paste it to search box in notepad; if you have multiple sections with the same
name and different signatures, just rename it like mepacker_s1, mepacker_s2 etc.;
-avoid adding large signature; it will be a time killer; be smart!
-add signature at the end of the file (EOF) then see if your file is detected, for avoiding
signatures overlaping;
-the signatures verification is done only for those signatures starting at entry point! for
different offsets ( ie signatures starting with "?? ?? A2" etc. or offset=x) the code it
becomes to complicate, so it is easy to add those signatures at the EOF and see if it works;
-what is overlapping: look next 2 signatures "EB 02 ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? F6" and
"EB 02 ?? ?? EB 02"; it covers the same range of bytes; the short one is covered by longest;
in this case you may escape a packer because of this, depending of which is searched first;
it's recommended to put the longest first;

[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课

上传的附件:
收藏
免费 0
支持
分享
最新回复 (2)
雪    币: 209
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
2
我就不信没人汉化。。继续等。。
2008-4-4 23:20
0
雪    币: 200
活跃值: (11)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
3
2 in one
Stud PE v 2.4.0.1 + PE Detective V.1.2.1.1
PASS:http://reversengineering.wordpress.com
hxxp://rapidshare.com/files/104873813/2_IN_ONE.rar
2008-4-5 03:37
0
游客
登录 | 注册 方可回帖
返回
//