PDA

View Full Version : Unpacking project


ReVeR
07-26-2004, 01:13 PM
Hello.
i got a crackme that is packed and i wann unpack it...i don't wanna use any other tools available for it, but wann do it manualy to see how it is done...
any links will be greatly appriciated.
thx in advace

Eggi
07-26-2004, 01:35 PM
what do you mean with "tools". do you also mean without a debugger?

ReVeR
07-26-2004, 02:47 PM
no i meant without progrs that autometicaly unpack my program.

Eggi
07-26-2004, 03:01 PM
hxxp://www.reteam.org/

There is a tutorial about unpacking asprotect without tools.

JMI
07-26-2004, 04:51 PM
Enter "manual unpacking" (without the quotes) in the SEARCH button at the top of these Forums and in your favorite search engine and you will find enough information to last a long time.

Regards,

ZaiRoN
07-26-2004, 05:01 PM
Hi ReVeR,
feel free to attach your crackme here. Maybe others would like to play with it.

Zai

SvensK
07-27-2004, 06:00 AM
@Zai: Indeed

ReVeR
07-27-2004, 08:31 PM
ok here is the crack me, it takes 2 minutes to crack it (literally) once u unpacketed it...
so i don't think it is gonna be fun
but here it is anyways:

ZaiRoN
07-28-2004, 05:38 PM
Hi ReVeR.
>i don't wanna use any other tools available for it, but wann do it manualy to see how it is done...
I think we can divide the project into some little tasks, i.e. how to find the Original Entry Point, how to create a new IAT and so on. Did you think about something in particular?

ZaiRoN

ReVeR
07-28-2004, 05:41 PM
no, nothing in particular, i jsut wanted to learn how to unpack manualy...
i still gotta read some stuff on how to do it,

Ricardo Narvaja
07-28-2004, 06:45 PM
I made 4 parts of a tut of Manual unpack without Import Reconstructor, i use a script for make a list of the apis used and a little inject for use GetProcAddress and charge the values in the IAT, is a little hard for newbies but is very useful, is in spanish.

Download of my FTP quickly i'm unemployed now and in a little time i have no more internet connection.

http://www.ricnar456.dyndns.org/

or

http://www.ricnar456.dyndns.org/

user:crackslatinos
pass:fiaca22

folder:NUEVO CURSO-TEORIAS

253-IMPORT TABLES A MANO (parte 1).rar
254-IMPORT TABLES A MANO (parte 2).rar
255-IMPORT TABLES A MANO (parte 3).rar
256-IMPORT TABLES A MANO (parte 4).rar

Download quickly the day 20/8/2004 the ftp will be closed .

Ricardo Narvaja

dELTA
07-29-2004, 08:07 AM
Ricardo, I'm very sorry to hear that about your job.

Do you know if you will you distribute your tutorials somewhere else?

JMI
07-29-2004, 10:48 AM
Most of Ricardso's tuts are already preserved on the exetools FTP and have been there for some time and I downloaded a copy on my HD as well. I'll make sure I have them all from the cracklatinos site and be glad to help Ricardo if he has any problem restoring them when he gets back on his feet and back on the net again.

Currently that archive contains numbers 1-170, and 203-208, and 213 (English translation of the vbox tut).

Again Ricardo, best of luck to you and your family.

Regards,

Ricardo Narvaja
07-29-2004, 01:05 PM
Well i was working in the same place for 23 years, will be difficult for me but i try.

Thanks

Ricardo Narvaja

Ricardo Narvaja
07-29-2004, 01:10 PM
Well in the crakslatinos page

http://crackslatinos.hispadominio.net/

and in the ftp of exetools and the crackslatinos mail list continue your work, and i expect return when i found a job.

Ricardo Narvaja

dELTA
07-29-2004, 03:08 PM
Ok, I wish you the best of luck then, and expect to see you back soon!

JMI
07-29-2004, 07:28 PM
OK. I've now completed my personal archive of the NUEVO CURSO-TEORIAS folder and I'll upload the additional files to exetools shortly.

Ricardo you might want to make a small edit to the files titles.

Both

IMPORT TABLES A MANO (parte 3).rar
IMPORT TABLES A MANO (parte 4).rar

are labled as 256 and there is no 255.

Again thanks for all your great efforts and we hope to can get back to work and back to cracking very soon.

Regards,

Ricardo Narvaja
07-29-2004, 07:38 PM
Thanks the archive is renamed

255-IMPORT TABLES A MANO (parte 3).rar

256-IMPORT TABLES A MANO (parte 4).rar

Thanks

Ricardo Narvaja

JMI
07-29-2004, 07:44 PM


Regards,

klier
07-30-2004, 08:40 AM
>>it takes 2 minutes to crack it (literally) once u unpacketed it...
...and a few minutes more to let it count below -1
(solution at crackmes.de crashes below -1 on my XP SP1)
Regards,

ReVeR
07-30-2004, 01:01 PM
it is extremly easy, it took me 2 minutes literally to crack it after i unpacked it, but the problem was i want to redone it with manual unpalcing....reading ur tuts now ppl , thx

klier
07-30-2004, 01:15 PM
manual unpacking this target takes only 2 minutes too.
read "Manually UnPacking of Yoda's Crypter v1.1" from CoDe_InSiDe and "Manual unpacking y0da's Crypter v1.2" from hacnho.
Regards,

ReVeR
08-10-2004, 02:36 PM
hey, can u give me direct lines cuz i have no idea qwhere to look for them.....
sry

klier
08-10-2004, 05:06 PM
This lines may contain spelling faultz
htpp://www.hvanoline.net/furom/showtipic_27123.html
http://home.tiscali.be/detten/tits.htm
Ragards,

ReVeR
08-11-2004, 10:46 AM
ahem...i am sory but i can';t decipher those links....
i got for the first one wiht the errors corrected:
http://www.hudaonline.net/forum/showtopic_27123.html
doesn't work.
i got the second link working and there is 1 tut from the ones that u mentioned...
can u please look at the first link?
and i will try to get my spelling error free.

klier
08-11-2004, 01:09 PM
>>i got for the first one wiht the errors corrected:
>>http://www.hudaonline.net/forum/showtopic_27123.html
apparently not
bored now ,search yourself,you have all the keywords!
Regards,

ReVeR
08-11-2004, 01:55 PM
crap, i meant that i got the second one...i didn;t get the first one....
and what is this, decryption contest?
i mean there are alot of web sites that are close in spelling of ur given one.....
i got all teh keywords, but if u try to look through all the sites that can be made from ur link,.....gonna take shit load of time....

dELTA
08-11-2004, 06:02 PM
Google is your friend.

http://www.hvaonline.net/forum/index.php?showtopic=27123