07.02.2015 Views

The Art of Reversing by Ap0x - Tutoriali.org

The Art of Reversing by Ap0x - Tutoriali.org

The Art of Reversing by Ap0x - Tutoriali.org

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

pomocu klika na Save Tree dugme. Kada snimimo ovaj fajl otvoricemo ga<br />

pomocu notepada i videcemo sledece:<br />

Target: decryptme1.tElock0.96.exe<br />

OEP: 00001000 IATRVA: 00002000 IATSize: 00000014<br />

FThunk: 00002000 NbFunc: 00000005<br />

0 00002000 0000 009E0000<br />

0 00002004 0000 009E001D<br />

0 00002008 0000 009E003A<br />

0 0000200C 0000 00850000<br />

0 00002010 0000 0085001D<br />

Sada cemo traceovati kroz nasu metu pomocu Ollyja. Interesuju nas svi<br />

CALLovi ka API funkcijama. Dakle uci cemo u sledeci CALL sa F7:<br />

00401028 . E8 23060000 CALL decryptm.00401650<br />

I nacicemo se ovde:<br />

00401650 $- FF25 10204000 JMP NEAR DWORD PTR DS:[402010] 3BC7<br />

XOR EDI,EDI<br />

CMP EAX,EDI<br />

<strong>The</strong> <strong>Art</strong> <strong>of</strong> <strong>Reversing</strong> <strong>by</strong> <strong>Ap0x</strong> Page 215 <strong>of</strong> 293

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!