Sturm
September 6th, 2004, 10:41
ASProtect 1.23 RC4 - 1.3.08.24 -> Alexey Solodovnikov is the version
i've used the search engine many times to find info on different things here (thus why this is one of my first posts), however there is a small problem i can't overcome with this program and it happened to me before on another program...and im wondering if someone could help me...
Following Labba and R@ider's tut, i get lost after doing the trace eip<900000 ( or the other technique used by R@ider )
in both their examples, they endup on a JMP that goes right back into the asprotection code...mine however ends up on a RET that doesn't go back to the protection code (which seems to be in the 00C000 range) but instead goes on to what seems to be the normal program code (in the 400000 range).
it might be the OEP but i doubt it'd be that easy..
has anyone encountered a similar problem...? if so..how did you bypass it?
my main interest is to learn how to unpack aspr correctly and not really unpack this specific target. however its really annoying me that i can't even find the OEP :|
tks
i've used the search engine many times to find info on different things here (thus why this is one of my first posts), however there is a small problem i can't overcome with this program and it happened to me before on another program...and im wondering if someone could help me...
Following Labba and R@ider's tut, i get lost after doing the trace eip<900000 ( or the other technique used by R@ider )
in both their examples, they endup on a JMP that goes right back into the asprotection code...mine however ends up on a RET that doesn't go back to the protection code (which seems to be in the 00C000 range) but instead goes on to what seems to be the normal program code (in the 400000 range).
it might be the OEP but i doubt it'd be that easy..
has anyone encountered a similar problem...? if so..how did you bypass it?
my main interest is to learn how to unpack aspr correctly and not really unpack this specific target. however its really annoying me that i can't even find the OEP :|
tks