Which plugins do you guys use at IDA / Ollydbg to search a signature in the engine?
Thanks!
06/27/2016 22:30luki180pl#2
The standard search works good in ida
06/27/2016 22:52TheRealPower#3
also to find a pattern? and to know which pointers are variable and which are static? cuz i know where the function is i want
06/28/2016 06:59luki180pl#4
I'm not sure but if you put a "?" instead of a byte it would mean that this byte could have any value
06/28/2016 10:00TheRealPower#5
Ye, so all the bytes which are 00 in the engine or well in my partern can be writen as an ? i assume?
Like if i got \x66\x8B\xED\x83\x00\x00\x00\x3D
it is like xxxx???x
06/28/2016 11:26meak1#6
Quote:
Originally Posted by TheRealPower
Ye, so all the bytes which are 00 in the engine or well in my partern can be writen as an ? i assume?
Like if i got \x66\x8B\xED\x83\x00\x00\x00\x3D
it is like xxxx???x
a dword are 4 bytes
06/28/2016 12:13luki180pl#7
I would make you a screenshot but I don't have access to my computer. If your function starts with for example 55 87 14 25 69 74 and last 4 bytes are relative address then you would write 55 87 ? ? ? ? To find this. I hope it's understandable what I say xd
06/28/2016 13:48TheRealPower#8
Yea i understand, but my question actually was how do i know if '14' in your example is a relative address or not? throught IDA
06/28/2016 14:44meak1#9
mb bec there stand a adress Call ????????????????????????????? [0x24244242] ???
06/28/2016 15:44luki180pl#10
Almost every time an instruction use memory address it should be replaced with '?'