Log in

View Full Version : Anti-Unpacker Tricks


Plazmic
December 21st, 2010, 02:50
Hello everyone,

I've been lurking for a few days now on the webz searching for knowlege on packing/ unpacking information. It seems like a lot of the information I was recieving was dead posts/404/filenot found...ect. Instead of Asking "please unpack this file for me", you know the general please do all the work for me kind of thing. I decided to instead share with the group a site I stumbled upon. Hopefully its not a repost and if it is I apologize.
This site has a lot of good information on anti-unpacker trick and I figured anyone who took the time to learn the anti tricks it would help in understanding packing.

Thanks Plaz

http://pferrie.tripod.com/

Dont forget to check the stuff at the bottom of the page.

Indy
December 22nd, 2010, 18:00
http://pferrie2.tripod.com/papers/unpackers37.pdf ("http://pferrie2.tripod.com/papers/unpackers37.pdf")
Quote:
3. MULTI-TASKING


This mechanism has been described by me in 2009, in the manual located on virustech.

There was also a feature of the manual describes the Iret/Retf instructions in between the ring switch. The processor allows you to load a zero selector in the segment registers without generating a #GP. When switching between the ring reset the RPL field in the segment registers when they contain zero selector.

2377
2378