07.02.2015 Views

The Art of Reversing by Ap0x - Tutoriali.org

The Art of Reversing by Ap0x - Tutoriali.org

The Art of Reversing by Ap0x - Tutoriali.org

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

00408F01 E8 2A3E3E3E CALL 3E7ECD30<br />

i pritisnucemo F9 da dodjemo do te adrese. Posto ovaj CALL izgleda<br />

zanimljivo pritisnucemo F7 da udjemo u njega i naci cemo se ovde:<br />

00408F1A FFB5 DE9D4000 PUSH DWORD PTR SS:[EBP+409DDE] ; kernel32.77E60000<br />

00408F20 FF95 849C4000 CALL DWORD PTR SS:[EBP+409C84]<br />

00408F26 40 INC EAX<br />

Sada cemo polako ici sa F8 sve dok ne dodjemo do adrese:<br />

00408F32 E8 0C000000 CALL demo_tEl.00408F43<br />

U ovaj CALL moramo uci sa F7 jer ako pokusamo da ga predjemo sa F8<br />

program ce se startovati i mi cemo izgubiti nas OEP. Prebacili smo se malo<br />

nize i sada se nalazimo ovde:<br />

00408F43 FFB5 DE9D4000 PUSH DWORD PTR SS:[EBP+409DDE] ; kernel32.77E60000<br />

00408F49 FF95 849C4000 CALL DWORD PTR SS:[EBP+409C84]<br />

00408F4F 40 INC EAX<br />

00408F50 48 DEC EAX<br />

Sa F8 cemo izvrsiti sve dok ne dodjemo do adrese:<br />

00408F63 E8 11000000 CALL demo_tEl.00408F79<br />

kada cemo pritisnuti F7 da udjemo u CALL, a onda cemo pritiskati F8 sve dok<br />

ne dodjemo do:<br />

00408FF9 0000 ADD BYTE PTR DS:[EAX],AL<br />

00408FFB 0000 ADD BYTE PTR DS:[EAX],AL<br />

00408FFD F3:AA REP STOS BYTE PTR ES:[EDI]<br />

00408FFF 66:AB STOS WORD PTR ES:[EDI]

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!