Jump to content
View in the app

A better way to browse. Learn more.

Tuts 4 You

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

EP not set

Featured Replies

Posted

hi,

a minor issue: when scylla is used to iat-fix a file, it will not set the OEP of the file to the value given in the "OEP:" textbox.

d. :)

i complained before and i got answer that it works if you dump file with scylla.. you can change oep with any pe tool manually sad.png .my guess is that you need to change the characteristics in sections before rebuilding but i have never tried it...

post #4 an on
/>http://forum.tuts4you.com/topic/27579-prove-other-import-tools-dont-work-correctly-with-win-7/

Edited by donny

I still think that OEP correction and iat rebuilding are two separate workflows. They don't fit together. A dump tool should fix the OEP! Probably people are used to imprec, but it is the wrong way. Why should it be required to enter an OEP to fix an IAT? It doesnt make sense.

  • Author

why would the dump tool fix it? as far as the pe header is concerned (both on disk and in memory) the EP is the EP of the stub, not the OEP.

The dump tool cant know the OEP. Thus, there are 3 basic steps to unpacking a packer: 1) dump 2) fix iat 3) fix OEP.

Traditionally 2) and 3) are done by the IAT fixing tool, saving people the time of adjusting the RP themselves; as usually the OEP was given to the IAT fixing tool anyways.

And even if iat address & size were entered manually, people are used to this behavior from ImpRec/chimprec/.... and i see nothing wrong with that. :)

maybe we can have an option for that?

But hey, thankfully it`s opensource, so people can enhance i themselves. :)

Thus, there are 3 basic steps to unpacking a packer: 1) dump 2) fix iat 3) fix OEP.

That is funny. I thought this are the steps:

1) use debugger, go to OEP

2) dump at OEP, your debugger must point to the OEP

3) fix iat, your debugger doesn't need to be at the OEP

But I will add an option to the options dialog thumbs.gif

Edited by Aguila

  • Author
cupidarrow.gif

so this was not a BUG it was a FEATURE! doh.gif great update BIG THX clap.gifclap2.gifclap.gif

Create an account or sign in to comment

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.