Jump to content
Tuts 4 You

Scylla IAT AutoSearch


Extreme Coders

Recommended Posts

Extreme Coders
Posted (edited)

The other day I was testing an Asprotect 1.2 target.


 


Imprec 1.7e IAT Autosearch function successfully locates the IAT. ( Size  0x55C )


However Scylla v0.9.6b Autosearch fails.  (Size : Garbage value )


 


See the image for comparsion.


 


post-79240-0-37832800-1397196570_thumb.j  


Imprec


 


 


post-79240-0-85935600-1397196578_thumb.j


Scylla


Edited by Extreme Coders
Posted

hm I dont know. Can you give me the target?


 


The only explaination I have is that distorm fails to resolve the call dword ptr instructions. Is it somehow obfuscated?


Extreme Coders
Posted (edited)

@Aguila Sent you the target. The target is the protector binary itself.


I do not see any obfuscation in it.


It can be easily dumped and rebuilded in Imprec 1.7e. Although you have to trace (Level 1 -> disasm )  some calls.


Edited by Extreme Coders
Posted (edited)

Don't rely on autosearch. ALWAYS check the IAT manualy. Then you will not have any errors. These tools can put wrong start/end. The tools are ok but might have some problems sometimes.

:)

Edited by GIV
Extreme Coders
Posted (edited)

Thanks :)


Anyways the target is quite old, so bug fixing is not a priority.


Edited by Extreme Coders

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...