Log in

View Full Version : New chameleon clock......


BlackB
March 18th, 2001, 05:50
Hi there reversers,

I downloaded the newest chameleon clock (17-03-2001), and i suspect that there are some changes in ASProtect protection.
I'm not really sure what the OEiP should be.....using tracex I come out on 4AEC30....but it's a call and it does not PUSH EBP; MOV EBP, ESP as every normal app starts. However, a little bit before that instruction there is a PUSH EBP, but it gets never executed.

RVA Start: BD144
Length: 688
IT RVA: 1130000
Length: 180

It's also little bit unclear where those "set memoryflags" call is made.....there are about thousands of calls

Btw, I spoke to risc lately, and he told he gave Alexey some anti-cracking advice and he told we had to "fear", heheheh. Just mentioning ;-)

btw, tutorial on Iris/Revirgin is finished. You can view it at http://blackb.tsx.org - Tutorials section - Iris
A copy of the essay will be available soon at +tsehp's site (I hope, heh)

greets

The Blackbird aka BlackB

risc
March 18th, 2001, 09:26
haha

i hate you so much right now (tm?)

'fairlight ate my hamster!'

MO`K
March 18th, 2001, 19:23
BlackB,

None of my home unix/netscape boxes are able to read your pages. Three different unices, two different netscape versions and a HotJava, all failed!

The main site comes up well, and so are the mini-index pages. I opened the tutorials pages, it went fine, but when i requested a tutorial, it 404ed me. I tried several times, different pages, no help.

I remember reading your pages on a win32 box at work, and it works, IMO there is some non-portable HTML/scripting in there, please try to fix it
(Hint:/blackb/c4n.css was not found on this server :-)

SpeKKeL
March 19th, 2001, 04:50
Hi blackb,

Well downloaded latest cham.clock 2.51.
I found 4aebfc as the entry point
and the beginning of the IAt at (4)bd140 till 4bd7ce

But when i tried to resolve the entry's, revirgin(1.01) keeps crashing on addresses like cc0343 etc, ???when i used the trace option.
Maybe i made some mistakes ????

Greetz SpeKKeL.

PK_BPX
March 19th, 2001, 06:42
Yes...Chameleon clock OEP is 4AEBFC..
but you can't dump it at oep ,you must dump at
offset 4927A4 ,because some flag may be set
in memory!

and i also crashing when using revirgin 1.01 trace option.
but i fixed some address by hand !