<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/css" href="http://www.woodmann.com/collaborative/tools/skins/common/feed.css?97"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title>Collaborative RCE Tool Library - Dump Fixers</title>
		<link>http://www.woodmann.com/collaborative/tools/index.php/Special:FeedListing/Dump_Fixers/feed?feed_type=rss</link>
		<description>Update Notification Feed for Category: Dump Fixers</description>
		<language>en</language>
		<generator>MediaWiki 1.11.2 via dELTA feed generator</generator>
		<lastBuildDate>Fri, 03 Sep 2010 10:32:58 GMT</lastBuildDate>
		<item>
			<title>Tool Updated: LordPE</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/LordPE</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Dump_Fixers&quot;&gt;Dump Fixers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Import_Editors&quot;&gt;Import Editors&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Memory_Dumpers&quot;&gt;Memory Dumpers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:PE_Executable_Editors&quot;&gt;PE Executable Editors&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Process_Dumpers&quot;&gt;Process Dumpers&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;1.41 (Deluxe b)&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;September 30, 2009&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;LordPE is a tool e.g. for system programmers which is able to edit/view many parts of PE (Portable Executable) files, dump them from memory, optimize them, validate, analyze, edit,...&lt;br /&gt;&lt;br /&gt;Main features:&lt;br /&gt;&lt;br /&gt;    * Task viewer/dumper&lt;br /&gt;    * Huge PE editor (with big ImportTable viewer, ...)&lt;br /&gt;    * Break'n'Enter (break at the EntryPoint of dll or exe files)&lt;br /&gt;    * PE Rebuilder&lt;br /&gt;&lt;br /&gt;News:&lt;br /&gt;&lt;br /&gt;    * The first GUI PE editor in the world supporting the new PE32+ (64bit) format ?! (only editing support - no rebuilding, dumping, comparing etc.)&lt;br /&gt;    * New plugin interface added! You can develop LordPE Dump Engines (LDE) now.&lt;br /&gt;      Look at \Docs\LDE.tXt for more information.&lt;br /&gt;    * Added LDE: IntelliDump which can dump .NET CLR processes&lt;br /&gt;    * Added structure lister for SectionHeaderTable, PE headers and DataDirectories (the &amp;quot;L&amp;quot; buttons)&lt;br /&gt;    * Added hex edit buttons (the &amp;quot;H&amp;quot; buttons) in the DataDirectoryTable viewer&lt;br /&gt;    * Added PE.OptionalHeader.Magic and PE.OptionalHeader.NumberOfRvaAndSizes to the PE editor&lt;br /&gt;    * TLSTable DataDirectory is now editable&lt;br /&gt;    * Possibility to increment/decrement the number of DataDirectories added&lt;br /&gt;    * Etc etc etc...&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Tue, 29 Jun 2010 01:09:27 GMT</pubDate>								</item>
		<item>
			<title>Tool Updated: CHimpREC</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/CHimpREC</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Dump_Fixers&quot;&gt;Dump Fixers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:IAT_Restore_Tools&quot;&gt;IAT Restore Tools&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Import_Editors&quot;&gt;Import Editors&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Process_Dumpers&quot;&gt;Process Dumpers&lt;/a&gt;, &lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Unpacking_Tools&quot;&gt;Unpacking Tools&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;ReCon Edition&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;June 23rd, 2008&lt;/i&gt;
&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;CHimpREC: The Cheap Imports Reconstructor&lt;br /&gt;by TiGa of ARTeam&lt;br /&gt;IITAC (http://www.iitac.org)&lt;br /&gt;&lt;br /&gt;This is the 32/64-bit imports rebuilder that I introduced at ReCon 2008 in Montreal.&lt;br /&gt;Made for the best compatibility with WoW64 on x64-based Windows XP or Vista.&lt;br /&gt;&lt;br /&gt;This is the same version that was used at the conference.&lt;br /&gt;The first official release will come soon.&lt;br /&gt;&lt;br /&gt;+Features&lt;br /&gt;The first universal 64-bit imports rebuilder&lt;br /&gt;32-bit version included&lt;br /&gt;Interface similar to ImpREC&lt;br /&gt;Integrated 32/64-bit process dumper&lt;br /&gt;IAT AutoSearch from ImageBase or OEP&lt;br /&gt;Unshuffle thunks function&lt;br /&gt;Manual imports editor&lt;br /&gt;&lt;br /&gt;-Limitations&lt;br /&gt;No plugin support yet&lt;br /&gt;No AutoTrace feature&lt;br /&gt;No disassembler&lt;br /&gt;&lt;br /&gt;The Visual Studio 2005 SP1 redistributable package might be necessary too:&lt;br /&gt;x86:&lt;br /&gt;http://www.microsoft.com/downloads/details.aspx?familyid=200b2fd9-ae1a-4a14-984d-389c36f85647&amp;amp;displaylang=en&lt;br /&gt;x64:&lt;br /&gt;http://www.microsoft.com/downloads/details.aspx?familyid=EB4EBE2D-33C0-4A47-9DD4-B9A6D7BD44DA&amp;amp;displaylang=en&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Tue, 24 Jun 2008 18:00:02 GMT</pubDate>								</item>
		<item>
			<title>Tool Added: IDCDumpFix</title>
			<link>http://www.woodmann.com/collaborative/tools/index.php/IDCDumpFix</link>
			<description>&lt;P&gt;&lt;B&gt;Listed in categories:&lt;/B&gt;&amp;nbsp;&lt;I&gt;&lt;a href=&quot;http://www.woodmann.com/collaborative/tools/index.php/Category:Dump_Fixers&quot;&gt;Dump Fixers&lt;/a&gt;&lt;/I&gt;&lt;/P&gt;&lt;p&gt;&lt;b&gt;Most recent version:&lt;/b&gt;&lt;br /&gt;

&lt;/p&gt;&lt;p&gt;&lt;b&gt;Most recent release date:&lt;/b&gt;&lt;br /&gt;

&lt;/p&gt;&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br /&gt;
&lt;i&gt;Aids in quick RE of packed applications (including unclean dumps after OEP), where imports may have been destroyed etc.&lt;br /&gt;&lt;br /&gt;What you do is execute the malware, dump the running image with i.e. LordPE, attach to the image with OllyDbg and have Olly search for all intermodular calls. Then you copy the table of intermodular calls into IDCDumpfix and have it produce an IDC file which you can apply to the dumped image disassembly. Many addresses and functions will then be identified in the disassembly.&lt;/i&gt;
&lt;/p&gt;</description>
			<pubDate>Sat, 20 Oct 2007 16:32:47 GMT</pubDate>								</item>
	</channel>
</rss>