Log in

View Full Version : armadillo "magic jump"


hwti
November 6th, 2003, 20:46
Is there any tutorial newer than Ricardo Narvaja 's one ?

I had no problem for the dump, but in the second part, I can't find the "magic jump"
I found the function which should contain it (the code is a bit different than the tutorial), but the function is different inside, I tried every jump in the function, and I don't find any which works

JMI
November 6th, 2003, 21:45
This just illustrates the problem with trying to follow a tut "exactly." You have to realize that the protection makers read them also and try to make changes in their code to avoid what is shown in the tut. You have to use your brain to find out where to go next.

Regards.

Ricardo Narvaja
November 7th, 2003, 05:03
if you can more examples in all the tutes of armadillos has differents cases of magic jumps.

65-66-67-68-69-70-71-72-74-77-78-79-80-81-82-83-84-86-88-150

are all tuts on armadillo in differents versions and types and any has different magic jumps, if you put a BP in the line the program write the bad values to the iat and RUN TRACE till stop again in the same line, look in the run trace window, and the magic jump are there in the run trace list, trying a little you find a magic jump easily.

Ricardo


Quote:
[Originally Posted by JMI]This just illustrates the problem with trying to follow a tut "exactly." You have to realize that the protection makers read them also and try to make changes in their code to avoid what is shown in the tut. You have to use your brain to find out where to go next.

Regards.

Ricardo Narvaja
November 7th, 2003, 05:07
Ths page of crackslatinos when you find the tuts is

hxxp://www.crackslatinos.hispadominio.net/

and in my FTP are the programs to practice

Ricardo


Quote:
[Originally Posted by Ricardo Narvaja]if you can more examples in all the tutes of armadillos has differents cases of magic jumps.

65-66-67-68-69-70-71-72-74-77-78-79-80-81-82-83-84-86-88-150

are all tuts on armadillo in differents versions and types and any has different magic jumps, if you put a BP in the line the program write the bad values to the iat and RUN TRACE till stop again in the same line, look in the run trace window, and the magic jump are there in the run trace list, trying a little you find a magic jump easily.

Ricardo

hobferret
November 7th, 2003, 16:22
Quote:
[Originally Posted by Ricardo Narvaja]Ths page of crackslatinos when ypu find the tuts is

hxxp://www.crackslatinos.hispadominio.net/

and in my FTP are the programs to practice

Ricardo


Ricardo

I have just been looking at your site - on the home page you say; this is the english version - "Now I have also learned that today I am not so bad a cracker as before, hehe." + "I hope to be able to continue with this teaching what I go on learning in this world of cracking, making good friends......"

Well [B]amigo mio [B] you have so far done extremly well and passed much knowledge onto us all - thank you.

/hobferret

Ricardo Narvaja
November 7th, 2003, 16:37
thanks, is the true.

Ricardo

Quote:
[Originally Posted by hobferret]Ricardo

I have just been looking at your site - on the home page you say; this is the english version - "Now I have also learned that today I am not so bad a cracker as before, hehe." + "I hope to be able to continue with this teaching what I go on learning in this world of cracking, making good friends......"

Well [B]amigo mio [B] you have so far done extremly well and passed much knowledge onto us all - thank you.

/hobferret