FrankRizzo
April 17th, 2012, 21:15
I see lots of discussions here about attacking the protection through it's lsapi*.dll, but what if your target doesn't HAVE one?
I have a target that I'm tinkering with that doesn't. Searched the installation, and loaded it in IDA with "Break on DLL load" enabled, and watched the libs it loaded.
Has anyone seen this?
Any hints?
I have a target that I'm tinkering with that doesn't. Searched the installation, and loaded it in IDA with "Break on DLL load" enabled, and watched the libs it loaded.
Has anyone seen this?
Any hints?