All Activity
- Past hour
-
omar jasim joined the community
-
xtanderMIT joined the community
- Today
-
duckjr joined the community
-
An open source tool for analyzing vmp
Sean Park - Lovejoy replied to fjqisba's topic in Programming and Coding
@jackyjask maybe, we do not need it any more. @fjqisba how does this IDA plugin help to analyze the vmprotect virtual machine? I do not know how to use this. I will be really appreciated if you could explain about it. Many thanks in advance. Regards. sean. -
TwoEG joined the community
-
Sean Park - Lovejoy started following How to format specific text to correctly displaying text?
-
mastiel joined the community
-
AhmedNasserHK joined the community
-
Sean Park - Lovejoy started following Nuitka 2.1.5 (Python 3.11) and [C++ & MASM Source] - MyAppSecured v1.00 Beta (exe protector)
-
An open source tool for analyzing vmp
jackyjask replied to fjqisba's topic in Programming and Coding
@fjqisba is GhidraVmp.dll obsoleted and now one has to use Revampire.dll instead? -
multext joined the community
-
everafter111 joined the community
-
Jaejeong Kim joined the community
-
How to format specific text to correctly displaying text?
adoxa replied to LCF-AT's topic in Programming and Coding
If you want to change "standard" (&<>) HTML entities it would be simplest to search and replace manually; not sure what the best approach would be if you want to convert unknown HTML to text. Dialog text uses & to underline the next character, so they should be replaced with && for a literal &. -
How to format specific text to correctly displaying text?
Teddy Rogers replied to LCF-AT's topic in Programming and Coding
I don't know where you are sourcing your text from, possibly you can check the BOM - if it exists. If the text is a reliable source you could try utilising the IsTextUnicode function... Ted. - Yesterday
-
How to format specific text to correctly displaying text?
LCF-AT posted a topic in Programming and Coding
Hi guys, so I got a little problem again with those UNICODE / SYMBOL chars in text / buffer I want to format to readable text and print that on a static control. So first I got some text issues showing me some strange symbol chars instead of text like this below... "Youâ€" is "You’ve" ...and I was then using the MultiByteToWideChar function with CodePage CP_UTF8 to change my ANSI text buffer to UNICODE. After that the text was displaying correctly using SetDlgItemTextW function. FIne so far I thought. Then I found another problem with a other symbol like this... Q&A is Q&A ...and I tried to use the same function as above but in this case I got this results back... Qamp;A !? My question now is...when I have any unknown text in buffer as ASCII / ANSI style then I want to format / convert this text buffer into 100 % readable / Symbol buffer I want to use with SetDlgItemTextW (Unicode) function to display the text 100 % correctly as original etc. What is the right method for this? greetz -
v4tb changed their profile photo
-
How to find the constant value when debugging an enigma protected application? no answer ???
-
create backup(from olly) functionality in x64dbg
Sean Park - Lovejoy replied to Priboi's topic in x64dbg
@Priboi Many thanks for the video presentation. Now I get it. Your plugin would be helpful. Regards. sean. -
I said program not plugin. Debugged program makes changes in code/data for example while unpacking and you are able to see where these changes are when using my plugin.
-
create backup(from olly) functionality in x64dbg
Sean Park - Lovejoy replied to Priboi's topic in x64dbg
@Priboi when does the code/data change by your plugin? I did not use the feature of the ollydbg, also I did not know it is. Now I check it out in ollydbg. It is a good feature. In ollydbg, If I create backup, then I change some codes. by using view backup, I can view the backed up data. after it, again If I click view actual data, I can view the current modified code/data. But with your plugin, what should I do to check what is the backed up code/data and what is the current modified or actual code/data? Many thanks in advance. Regards. sean. -
[C++ & MASM Source] - MyAppSecured v1.00 Beta (exe protector)
Priboi replied to TomaHawk's topic in Programming Resources
Can someone share MyAppSecured v1.00 Beta source? I dont have account here: https://forum.exetools.com/showthread.php?t=19316 EDIT: nevermind founded here:- 1 reply
-
- 1
-
You dont have to do changes on yourself its not the purpose of this plugin because you know what you have changed. The code/data should be changed by program itself.
-
+ password-protect-video.com
-
An open source tool for analyzing vmp
Sean Park - Lovejoy replied to fjqisba's topic in Programming and Coding
-
Well, the project is still a demo. I updated the plugin and provided a program for my own testing,you can try that. https://github.com/fjqisba/VmpHelper/releases
-
An open source tool for analyzing vmp
Sean Park - Lovejoy replied to fjqisba's topic in Programming and Coding
I virtualized below part and tested it. 004010C2 6A 01 push 01 004010C4 53 push ebx 004010C5 FF15 1C614000 call dword ptr [0040611C] → USER32.dll!EndDialog 004010CB EB 09 jmp 004010D6 ↓ It is cahnged to thses codes. 00A810C2 | E9 27BA1800 | JMP win32gui.vmp.C0CAEE | 00A810C7 <win32gui | 57 | PUSH EDI | edi:EntryPoint 00A810C8 | C3 | RET | 00A810C9 <win32gui | 56 | PUSH ESI | esi:EntryPoint 00A810CA | C3 | RET | 00A810CB <win32gui | EB 09 | JMP win32gui.vmp.A810D6 | And I used your plugin by clicking the menu "VMP -> Show Graph" at the address of 00A810C2. then It hung. the IDA version is 8.3.23.0608.. Regards. sean. -
For current plugin, it seems too early to analyze vmp oep, because vmp does a lot of operations at the beginning. Maybe you should try writing a small function, use vmp encryption, and then use plugin to analyze the begin of vmp function.
-
An open source tool for analyzing vmp
Sean Park - Lovejoy replied to fjqisba's topic in Programming and Coding
Win32GUI.vmp.zip Regards. sean. -
An open source tool for analyzing vmp
jackyjask replied to fjqisba's topic in Programming and Coding
What are the preconditions to start de-virting 3.5.0 x86? I'm hitting only this: sample https://workupload.com/file/bDGty7XBnfW sometimes it is crashing, eg: BTW, what IDA versions do you support? -
Well, this is because it has not been fully developed yet. you can try sending samples to me so I can fix it.
- Last week
-
Sean Park - Lovejoy started following Nuitka 2.1.5 (Python 3.11)
-
An open source tool for analyzing vmp
Sean Park - Lovejoy replied to fjqisba's topic in Programming and Coding
An error!!! And for another example. Why does it just show one graph and no branches? but your github page shows like this. Regards. sean. -
nvd284 started following X0rby
-
View File Nuitka 2.1.5 (Python 3.11) Hi Nuitka compiled python 3.11 file Correct password doesn't important Just patching Thanks Submitter Sh4DoVV Submitted 04/18/2024 Category CrackMe
-
create backup(from olly) functionality in x64dbg
Sean Park - Lovejoy replied to Priboi's topic in x64dbg
Where can I see the differences when choosing "Compare Snapshot"? I clicked the menu of "Make Snapshot" before changing anything. Then as @Priboi said, started an application. after it, I changed some bytes. then clicked the "Compare Snapshot" menu. however I cannot notice anything to show the differences in the disassembly pane of the x64dbg. Thanks. Regards. sean. -
most possible using SetWindowDisplayAffinity API - more github.com/akinbicer/screen-capture-protector
-
Hi, everybody! I am developing an ida plugin which can be used to analyze vmp3.5 x86. If you are interested in vmp, Then you can view the source code of the project to learn it. Suggestions and PRs are welcome. https://github.com/fjqisba/VmpHelper
-