From Collaborative RCE Tool Library

Jump to: navigation, search

Relocation Tools


Tool name: PE1
Rating: 0.0 (0 votes)
Author: VLaaD                        
Website: N/A
Current version: 1.0
Last updated: Who knows
Direct D/L link: Locally archived copy
License type: Freeware for free people
Description: Little GUI tool useful for:

- Image rebase (if relocs are present, for now :)
- Recalc checksum
- Realign sections
- Strip section names
- Checksum fixing
- Excessive image directory cutoff (aggressive)

This one is my personal tool, so if something crashes, I have debugger (and you don't :)

P.S. This little thing is packed by RLPack by ap0x ("štitimo domaće, koristimo DOMAĆE exe-packere :)")
Pozdrav za vrlo talentovanu mladu ekipu koja je već do sada iza sebe ostavila dosta lepih stvari :)
Also listed in: (Not listed in any other category)
More details: Click here for more details, screenshots, related URLs & comments for this tool! (or to update its entry)



Tool name: PE32 Relocate
Rating: 0.0 (0 votes)
Author: ap0x                        
Website: http://ap0x.jezgra.net/patchers.html
Current version: 0.1
Last updated:
Direct D/L link: Locally archived copy
License type: Free
Description: PE32.Relocate 0.1
--------------------
How to use:
reloc.exe -f<FILE> -b<IMAGEBASE>

<FILE> = Path to PE32 file to relocate
<IMAGEBASE> = New ImageBase for relocated file [hex]

Example:
reloc.exe -fCrackme.exe -b00410000
Also listed in: (Not listed in any other category)
More details: Click here for more details, screenshots, related URLs & comments for this tool! (or to update its entry)



Tool name: PPEE (puppy)
Rating: 0.0 (0 votes)
Author: Zaderostam                        
Website: https://www.mzrst.com/
Current version: 1.09
Last updated: October 10, 2017
Direct D/L link: https://www.mzrst.com/puppy/PPEE(puppy)%201.10.zip
License type: Free
Description: This is a professional PE file explorer that lets you dig into all data directories available in the PE/PE64 file and edit them.
Export, Import, Resource, Exception, Certificate(Relies on Windows API), Base Relocation, Debug, TLS, Load Config, Bound Import, IAT, Delay Import and CLR are supported.
Two companion plugins are also provided. FileInfo, to query the file in the well-known malware repositories and take one-click technical information about the file such as its size, entropy, attributes, hashes, version info and so on. YaraPlugin, to test Yara rules against opened file.

Puppy is robust against malformed and crafted PE files which makes it handy for reversers, malware researchers and those who want to inspect PE files in more details.

Puppy is free and tries to be small, fast, nimble and friendly as your puppy!

Features:

Both PE32 and PE64 support
Examine YARA rules against opened file
Virustotal and OPSWAT's Metadefender query report
Statically analyze windows native and .Net executables
Robust Parsing of exe, dll, sys, scr, drv, cpl, ocx and more
Edit almost every data structure
Easily dump sections, resources and .Net assembly directories
Entropy and MD5 calculation of the sections and resource items
View strings including URL, Registry, Suspicious, ... embedded in files
Detect common resource types
Extract artifacts remained in PE file
Anomaly detection
Right-click for Copy, Search in web, Whois and dump
Built in hex editor
Explorer context menu integration
Descriptive information for data members
Refresh, Save and Save as menu commands
Drag and drop support
List view columns can sort data in an appropriate way
Open file from command line
Checksum validation
Plugin enabled

Feel free to use it ;)
Also listed in: .NET Executable Editors, Dependency Analyzer Tools, Entropy Analyzers, Exe Analyzers, Executable CRC Calculators, Executable File Editors & Patchers, Export Editors, Hex Editors, Import Editors, Malware Analysis Tools, PE Executable Editors, String Finders
More details: Click here for more details, screenshots, related URLs & comments for this tool! (or to update its entry)



Tool name: ReloX
Rating: 0.0 (0 votes)
Author: MackT/uCF2000                        
Website: n/a
Current version: 1.0
Last updated: August 23, 2009
Direct D/L link: Locally archived copy
License type: free
Description: The only relocation tool worth its bytes. Perfect for that 'final step' in unpacking those pesky dynamic link libraries.


{ from included readme.txt }

ReloX v1.0 * by MackT/uCF2000 in 2003

Disclaimer:
-----------
This program may crash, or in a worse case it may even reboot your computer, so please use it with caution. (Do not run it 3 hours into an unsaved coding session for example)

I am *NOT* responsible for any damage caused by the use of it.


Purpose:
--------
ReloX is a Win32 relocations rebuilder. It will create a .reloc section from different
based images.


What does it need?
------------------
- At least 2 different based images of a module. The more you have images, the more
your relocations will be reliable.


How does it work?
-----------------
1) - Select the first based image with the "..." button on the "Original" line.

The imagebase will be put automatically. If it is not right, modify it.

2) - Select the second based image with the "..." button on the "Compare to" line.

The imagebase will be put automatically. If it is not right, modify it.

3) - Click on "Select Sections" to select all sections which contain code for
comparison (default is all).

4) - Click on "Compare" to start comparison between the modules.

The result will be in the list control.

5) - If you have other based images, redo the same thing from 2) for all of them

6) - Click on "Fix PE Module" to select a pe file and fix with the new ".reloc" section.

(no backup needed just like ImpREC(tm))


Limitations
-----------
- It will only support 32 bits relocations of type (3).
(IMAGE_REL_BASED_HIGHLOW : The fixup applies the delta to the 32-bit field at Offset)


Thanks to
---------
Muffin and Snacker for testing.


Greetings to
------------
Michelle Branch, Jackie Chan and Jet Li.
Also listed in: (Not listed in any other category)
More details: Click here for more details, screenshots, related URLs & comments for this tool! (or to update its entry)



Tool name: RelocEditor
Rating: 0.0 (0 votes)
Author: Bitfry & Jupiter                        
Website: N/A
Current version: 1.0
Last updated:
Direct D/L link: Locally archived copy
License type: Free/Public Domain
Description: RelocEditor allows you to directly edit the Relocation table inside of the PE file and individual relocations. You can change the VA of individual relocations, edit or delete the whole table, individual blocks, etc.
Also listed in: (Not listed in any other category)
More details: Click here for more details, screenshots, related URLs & comments for this tool! (or to update its entry)


RSS feed Feed containing all updates and additions for this category.

RSS feed Feed containing all updates and additions for this category, including sub-categories.





Views
Category Navigation Tree
   Needs New Category  (3)