question about exe.

12/13/2013 15:25 franken6tain#1
hey guyz, i have a question about raising action limit. i looked over the tuts in here, but my exe differs so i wana ask how to find which codes i have to change, im kinda new to ollydb and im still learning how to use it. any help is apreciated :)
12/14/2013 00:03 Godricc#2
I don't know much about asm, but I know its already been done and the completed files are here on the forums already.
12/14/2013 07:01 .Genome.#3
Quote:
Originally Posted by Godricc View Post
I don't know much about asm, but I know its already been done and the completed files are here on the forums already.
But just taking it is kinda leeching. I think it's cool that he wants to do something for himself. Sadly I can't say what to look for either though.
12/14/2013 11:18 Godricc#4
Well, don't forget it's not entirely leeching. It was a release. Open for anyone to use.
12/14/2013 16:02 HellSpider#5
You can search for specific instructions with Ctrl+F. Usually it's better to search for a certain hex pattern using Ctrl+B.
12/15/2013 08:04 franken6tain#6
well hell im using your bmr exe, but searching the offsets used in the tut released didnt go well, so ill try this but i think i already did it that way :) thanks for help ill see what i can do :)
12/15/2013 17:16 HellSpider#7
Quote:
Originally Posted by franken6tain View Post
well hell im using your bmr exe, but searching the offsets used in the tut released didnt go well, so ill try this but i think i already did it that way :) thanks for help ill see what i can do :)
Yeah, the addresses are different in that exe. To use the pattern search, you must remember that you should not create patterns that have any relative instructions (calls and long jumps). Ex:

PUSH 0x1234 -> 68 34 12 00 00
CALL ADDR -> E8 + 4 bytes defining the address
ADD ESP,0x4 -> 83 C4 04

In this case the call should be skipped and the pattern will look like this:

68 34 12 00 00 E8 ?? ?? ?? ?? 83 C4 04

So you should replace all things that can vary with wildcard characters (??).
12/16/2013 16:22 franken6tain#8
thanks to hellspider and conquer93 ofc for helping with the exes :)
12/16/2013 16:57 conquer93#9
the exes i sended you did they work ?:)