steve10120 Posted February 12, 2010 Posted February 12, 2010 Just experimenting.As the title suggests, successfully dump and rebuild the file.Difficulty: ?packed.rar
steve10120 Posted February 12, 2010 Author Posted February 12, 2010 Thanks. And,Difficulty: ?Only experimenting like I said, just wondering whether its worth totally re-basing the image if relocs are present.
Teddy Rogers Posted February 13, 2010 Posted February 13, 2010 The [unpackme] tag has been added to your topic title. Please remember to follow and adhere to the topic title format - thankyou! [This is an automated reply]
LCF-AT Posted February 13, 2010 Posted February 13, 2010 Difficulty: ? <-- No not really.So you know I can just give you my opinion.-no IAT redirection-no AntiDump / dump protection feature-no manipulation detection / CRC / PEYou should also insert more [self] and debug checks.So keep going maybe you next one will be harder.greetz
NullPointerException Posted February 13, 2010 Posted February 13, 2010 also you should pack bigger file if you are developing your own protector so we can fully test it. As for protection you should do what lcf said, plus: 1) try to hide the jmp to oep 2) add some primitive obfuscation (by using jumps) 3) dont make the code too linear: use calls inside calls to hide what your packer does. It's stupid but effective regarding antidebugs try to develop your own way to detect debuggers: altough they are more or less all known, try to make some little tricks (plugin detection, hook of patches made by plugins detection etc) last week i found a paper from blackhat explaining malware protection but i cant find it anymore. was nice for some inspiration
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now