Jump to content
Tuts 4 You

[unpackme] Larp V2.0 Ultra


lena151

Recommended Posts

Good work, q ;) You need writing an *internal* tut on this lol. If that's OK with Lena ;) She's already planning an update lol..

Link to comment
Share on other sites

Damn, I was beat to it. I guess there is 3 ways to go about doing this, I have tried them all. First, the obvious way is just straight up load under a debugger, which is possible, although I did have a problem with one anti debug where I would get caught sometimes and not others, even when using a script to bypass already found anti. Second way is to just attach and hope you can find the code that looks like the lower half the the oep (lame), plus I dont think most people know how to attach with its setup. The third way is more of what quosego used I guess. There is no crc check in the code, which is weird, I thought earlier versions had it, anyway with no crc you can write an inline patch up, then EBFE when you want to stop. Since your just going to run it real quick, you can half-azz the patch, bad habit, but whatever. Another enjoyable reverse. :thumbsup:

Edited by What
Link to comment
Share on other sites

Impressive stuff mate, nice work :thumbsup:
Skillful & with a great sense of humor - lethal combination! :ph34r:
Good work, q ;) You need writing an *internal* tut on this lol. If that's OK with Lena ;) She's already planning an update lol..

Thnx all, Just the result of a lot of free time and wanting to be the first.. :cool:

Doubt if I could have waited much longer..

Will make something internal if it's allowed.. Including my scripts and api modder program..

quosego

Link to comment
Share on other sites

lena do you start the app on pc with 256 mb or 128 mb ram for testing

or start the app in 2 process and the second is crashing , on sp2

but the protection is good

Link to comment
Share on other sites

ahmadmansoor
My variant unpacked & script fix import redirect

hehe what this Pavka?? :happy: .....what the purpose from script if u can't pass the debugger detected :blink: ....

r u sure it is usefull :dry: ......How we know if it work ...without testing it (pls just don't say test it :whistling: )

Link to comment
Share on other sites

My variant unpacked & script fix import redirect

hehe what this Pavka?? :happy: .....what the purpose from script if u can't pass the debugger detected :blink: ....

r u sure it is usefull :dry: ......How we know if it work ...without testing it (pls just don't say test it :whistling: )

You can test so:

Make dump programs and make dump region of memory

push XXXXXXXX <---- dump region

ret

Load in Olly Dump & Load dump region and start a script :)

Link to comment
Share on other sites

ahmadmansoor
Load dump in Olly , end load dumped memory :)

Script static, only edit a mask under the region of memory!

I will give a try. after I back to my house ...because here i can't ..... but If i have any inquiry can i post it ..if this not bother u :confused:

Many Thanks for u :flowers:

Link to comment
Share on other sites

O plaudite, o plaudite, gloria victis?

Vae victis!!! Felix qui potuit rerum cognoscere causas. De facto errare humanum est et beati pauperes spiritu. Contraria contraiis curantur. O acta est fabula. Aaaaah! Para bellum si vis pacem! Aaaaaah! Morituri te salutant ... ita est! Victurus te saluto, lena151 te saluto, ... ita est!

Ave atque vale.

lena151.

  • Like 1
Link to comment
Share on other sites

Aio, quantitas magna frumentorum est. :lol:

O tempora! Ipso facto, ira furor brevis est ... veritas odium parit. Audaces fortuna juvat. Non omnia possumus omnes ... o fortunates nimium, sua si bona norint reverseras! O mores! Ita est ... ita diis placuit.

Aaaah! O mores! Ira furor brevis est. Ita est ... ita diis placuit.

Aaaaah! Alea jacta est! Quod erat demonstrandum.

Ave atque vale.

lena151.

Link to comment
Share on other sites

Aaaah! .......

Aaaaah! .........

lena151

Is it s.e.x.y conversation ? :blink: :biggrin:

( sorry ... was just a joke ! )

Edited by SUB Z3R0
Link to comment
Share on other sites

Sorry guys ... some good family news made that I couldn't resist a small joke ;)

I hope I didn't insult anybody.

lena151.

Link to comment
Share on other sites

Damn I am dumb, the only thing that was keeping my anti debug script from working everytime was, a normal GetTickCount with a sleep in between (if you do not know what I mean by normal, compared to other, you obviously didnt get very far). Difference needs to be 1A or something like that. Now to find one more anti debug, which is the catching of the debugger when I dont use hide toolz to hide the debugger, I figured there was no need before, but might as well.

Edited by What
Link to comment
Share on other sites

  • 2 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...