hipu
June 24th, 2004, 18:16
hey everyone, just wanted to thank this wondefull forum for all his excellent info. i couldnt done it without you... i was messing with the magic jump for days untill i simply did a small search in the forums, and found the great post from SysCall (http://www.woodmann.net/forum/showthread.php?t=5891) which identifies the magic jump signature, which allowed me to easily trace it and patch quickly. tnx again 
magic jump signature as taken from syscall :

magic jump signature as taken from syscall :
Quote:
cmp dword ss:[ebp-xxxx],0 jnz yyy ; must be nopped MOVZX EAX, WORD PTR SS:[EBP-zzzz] TEST EAX, EAX |