NchantA
November 10th, 2000, 06:52
hello again owl and tsehp+ (and g-rom
)
ive RTFM on icedump, and have figured out the /tracex command, tsehp i have posted the routine above for reading, if u would like the target url, feel free to email me.
this is what i have tried:
use sice loader to load the normal.exe, after which the vbox screen pops up,
- set bpx on getprocaddress
I reasoned that since the .dll wouldnt be unpacked until after you press 'try', i would trace from there:
- set a /tracex imagebase imagebase+size
- a jmp eip
- f5, and dump file with peeditor(procdump seems to crash when dumping dll's attatched to active threads on my sytem
)
needless to say this didnt work...any idea why? im going to try and figure out how to call/use hydra soon ;P
NchantA
thanx all

ive RTFM on icedump, and have figured out the /tracex command, tsehp i have posted the routine above for reading, if u would like the target url, feel free to email me.
this is what i have tried:
use sice loader to load the normal.exe, after which the vbox screen pops up,
- set bpx on getprocaddress
I reasoned that since the .dll wouldnt be unpacked until after you press 'try', i would trace from there:
- set a /tracex imagebase imagebase+size
- a jmp eip
- f5, and dump file with peeditor(procdump seems to crash when dumping dll's attatched to active threads on my sytem

needless to say this didnt work...any idea why? im going to try and figure out how to call/use hydra soon ;P
NchantA
thanx all